Security Incident Disposition via Cognitive Knowledge Graph Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP reputation systems are centrally managed, leading to slow propagation of important IP reputation information, which can result in unnecessary exposure of client systems to rogue sources and increased vulnerability to advanced persistent threats due to the reliance on human intervention for analyzing potential security incidents.
Innovation Solution
A security incident disposition system that utilizes a cognitive evaluation of security knowledge graphs, processed by a trained machine learning model, to extract features and generate predictive dispositions for security incidents, providing automated recommendations for responsive actions such as blocking access or escalating notifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized IP reputation service is used to manage and distribute security information, then the system structure is simplified and centralized control is achieved, but the propagation speed of security information becomes slow and client systems remain exposed to threats during update delays
Solution Approach 1:
The patent segments the centralized IP reputation service into distributed peer-to-peer components. Each IDS system becomes an independent node that can discover and share security information directly with other nodes without relying on a central server, thereby maintaining simplified structure while enabling fast propagation through the distributed network.
Solution Approach 2:
The patent introduces a new dimension of information propagation by implementing both centralized and distributed pathways. Security information can flow through traditional centralized channels while simultaneously propagating through the distributed peer-to-peer network, creating multi-dimensional information distribution that resolves the speed contradiction.
2Extent of automation
If manual analysis by human analysts is used to evaluate security incidents, then the system requires less automation complexity, but the response time becomes slow and advanced persistent threats can exploit the analysis delay
Solution Approach 1:
The patent implements feedback mechanisms where IDS systems continuously monitor security incidents, automatically evaluate them using machine learning models, and feed results back into the distributed network. This creates a closed-loop system where analysis results rapidly propagate to other nodes, enabling fast response without manual intervention while maintaining system simplicity.
Solution Approach 2:
The patent enables IDS systems to perform self-service security analysis through automated machine learning evaluation of security incidents. Each system independently evaluates threats and generates disposition recommendations without requiring human analyst intervention, thereby reducing response time while minimizing automation complexity through use of pre-trained models.
3Reliability
If centralized IP reputation services are used, then vendor control over security information is maintained, but the system becomes vulnerable to single points of failure and propagation delays affect all clients simultaneously
Solution Approach 1:
The patent implements preliminary action by having IDS systems pre-cache security information and maintain local reputation databases. When security information needs to propagate, systems can immediately use their pre-stored data rather than waiting for centralized updates, thereby maintaining high reliability and reducing vulnerability to propagation delays while preserving vendor control through selective synchronization.
Data Source
AI summary
Mechanisms are provided to perform security incident disposition operations. A security incident is received that includes a security incident data structure comprising metadata describing properties of the security incident, and a corresponding security knowledge graph which includes nodes representing elements associated with the security incident and edges representing relationships between the nodes. The security incident data structure and security knowledge graph are processed to extract a set of security incident features corresponding to the security incident and input the extracted set of security incident features into a trained security incident machine learning model. The model generates a disposition classification output based on results of processing the extracted set of security incident features. The disposition classification output is output to the source of the security incident data structure.


