Security Incident Disposition via Cognitive Knowledge Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IP reputation systems are centrally managed, leading to slow propagation of important IP reputation information, which can result in unnecessary exposure of client systems to rogue sources and increased vulnerability to advanced persistent threats due to the reliance on human intervention for analyzing potential security incidents.

Innovation Solution

A security incident disposition system that utilizes a cognitive evaluation of security knowledge graphs, processed by a trained machine learning model, to extract features and generate predictive dispositions for security incidents, providing automated recommendations for responsive actions such as blocking access or escalating notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized IP reputation service is used to manage and distribute security information, then the system structure is simplified and centralized control is achieved, but the propagation speed of security information becomes slow and client systems remain exposed to threats during update delays

Engineering Contradiction:
Improvesystem structureVSAvoidpropagation speed of security information
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent segments the centralized IP reputation service into distributed peer-to-peer components. Each IDS system becomes an independent node that can discover and share security information directly with other nodes without relying on a central server, thereby maintaining simplified structure while enabling fast propagation through the distributed network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of information propagation by implementing both centralized and distributed pathways. Security information can flow through traditional centralized channels while simultaneously propagating through the distributed peer-to-peer network, creating multi-dimensional information distribution that resolves the speed contradiction.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Extent of automation

If manual analysis by human analysts is used to evaluate security incidents, then the system requires less automation complexity, but the response time becomes slow and advanced persistent threats can exploit the analysis delay

Engineering Contradiction:
Improveautomation of security analysisVSAvoidresponse time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent implements feedback mechanisms where IDS systems continuously monitor security incidents, automatically evaluate them using machine learning models, and feed results back into the distributed network. This creates a closed-loop system where analysis results rapidly propagate to other nodes, enabling fast response without manual intervention while maintaining system simplicity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables IDS systems to perform self-service security analysis through automated machine learning evaluation of security incidents. Each system independently evaluates threats and generates disposition recommendations without requiring human analyst intervention, thereby reducing response time while minimizing automation complexity through use of pre-trained models.

Inventive Principle:
Principle #25Self-service

3Reliability

If centralized IP reputation services are used, then vendor control over security information is maintained, but the system becomes vulnerable to single points of failure and propagation delays affect all clients simultaneously

Engineering Contradiction:
Improvesystem availabilityVSAvoidvulnerability to propagation delays
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by having IDS systems pre-cache security information and maintain local reputation databases. When security information needs to propagate, systems can immediately use their pre-stored data rather than waiting for centralized updates, thereby maintaining high reliability and reducing vulnerability to propagation delays while preserving vendor control through selective synchronization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11308211B2Security incident disposition predictions based on cognitive evaluation of security knowledge graphs
Publication Date: 2022.04.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11308211B2 patent drawing
  • US11308211B2 patent drawing
  • US11308211B2 patent drawing

AI summary

Mechanisms are provided to perform security incident disposition operations. A security incident is received that includes a security incident data structure comprising metadata describing properties of the security incident, and a corresponding security knowledge graph which includes nodes representing elements associated with the security incident and edges representing relationships between the nodes. The security incident data structure and security knowledge graph are processed to extract a set of security incident features corresponding to the security incident and input the extracted set of security incident features into a trained security incident machine learning model. The model generates a disposition classification output based on results of processing the extracted set of security incident features. The disposition classification output is output to the source of the security incident data structure.