Security Appliance Knowledge Graph for Proactive Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malicious activity in computing environments are reactive, identifying threats only after an attack has occurred, lacking the ability to predict potential attacks beforehand.

Innovation Solution

A security appliance monitors communication between user computers and destination computers, extracts selective information, associates it with security entity attributes, and generates a knowledge graph to detect potential threats by analyzing patterns and anomalies indicative of malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional malware scanning with signature matching is used, then detection accuracy for known threats is improved, but the ability to detect novel or dormant threats is worsened

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by monitoring and analyzing communication patterns before malicious activity is activated. It builds knowledge graphs of normal behavior patterns in advance, enabling detection of anomalies when threats become active, thus detecting threats before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transitions from traditional single-dimension signature matching to multi-dimensional analysis by creating knowledge graphs that incorporate temporal patterns, communication metadata, entity relationships, and behavioral contexts. This dimensional expansion enables detection of threats that lack known signatures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive monitoring of all communication is performed, then detection coverage is improved, but system complexity and processing overhead are worsened

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only relevant selective information from communication streams, such as metadata, entity identifiers, and pattern-relevant features, while discarding unnecessary data. This extraction approach maintains comprehensive monitoring coverage while reducing processing complexity and resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The knowledge graph structure serves multiple functions simultaneously: it stores entity relationships, captures temporal patterns, enables anomaly detection, and provides context for investigation. This multi-functionality reduces the need for separate systems for each detection task, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Use of energy by moving object

If reactive detection methods are used, then resource consumption is reduced, but the ability to prevent attacks is worsened

Engineering Contradiction:
Improveresource consumptionVSAvoidattack prevention capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system performs preliminary monitoring and pattern learning during normal operations without requiring intensive processing only when threats are detected. By continuously building knowledge graphs in the background and using lightweight anomaly detection algorithms, it maintains attack prevention capability while keeping resource consumption manageable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10218717B1System and method for detecting a malicious activity in a computing environment
Publication Date: 2019.02.26 ARISTA NETWORKS INC
  • US10218717B1 patent drawing
  • US10218717B1 patent drawing
  • US10218717B1 patent drawing

AI summary

System and method for detecting a likely threat from a malicious attack is disclosed. Communication between a user computer and a destination computer is monitored by a security appliance. Selective information from the communication is extracted. Selective information is associated to one or more attributes of a security entity. A knowledge graph is generated for a plurality of security entities based on the associated selective information.