Temporal Graph Event Detection for Cyberattack Campaign Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems struggle to identify and characterize complex cyberattack campaigns due to their sophistication and pervasive nature, often failing to uncover correlations within threat detection data and providing incomplete or imprecise breach characterizations.

Innovation Solution

The use of temporal graphs to represent cyberattack campaigns based on detection events, analyzing time-dependent relationships among network entities, and employing visualization tools to track and understand the evolution of these campaigns, enabling comprehensive incident response and data collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If commonplace automated cybersecurity products are used to detect cyberattack campaigns, then basic threat detection capability is provided, but the ability to identify complex and sophisticated cyberattack campaigns fails

Engineering Contradiction:
Improvecyberattack campaign identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cyberattack campaign detection process into multiple specialized modules: temporal graph construction module that creates time-evolving representations of network entities, correlation analysis module that identifies relationships between detection events, and campaign characterization module that synthesizes breach information. This segmentation allows each module to specialize in specific aspects of campaign detection, improving overall reliability without requiring a single monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces temporal graphs as an intermediary data structure that mediates between raw detection events and campaign identification. The temporal graph serves as a intermediary representation that captures time-dependent relationships among network entities, enabling the system to uncover subtle correlations that would be difficult to detect directly from raw security event data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If traditional detection methods are used, then simple threats may be detected, but correlations within threat detection data remain uncovered

Engineering Contradiction:
Improvecorrelation information recoveryVSAvoiddetection difficulty
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds the temporal dimension to traditional detection methods by constructing temporal graphs that evolve over time. This dimensional transformation allows the system to capture time-dependent relationships and correlations among detection events that single-point-in-time analysis would miss. The temporal aspect enables tracking of campaign evolution and identification of subtle patterns across multiple time points.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent creates a composite analytical approach that combines multiple detection event types, temporal relationships, and network entity interactions into a unified temporal graph representation. This composite structure integrates diverse data sources and relationship types, enabling the system to recover correlation information that would be lost when analyzing individual event types or time points separately.

Inventive Principle:
Principle #40Composite materials

3Measurement precision

If comprehensive data collection is performed to characterize breaches completely, then accurate campaign identification is achieved, but the volume of data to be processed becomes unmanageable

Engineering Contradiction:
Improvebreach characterization precisionVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant features from the vast volume of detection event data by constructing temporal graphs that focus on time-dependent relationships among network entities. Rather than processing all raw security event data, the system extracts key temporal patterns and entity interactions that are most indicative of cyberattack campaigns, significantly reducing the effective data volume while maintaining characterization precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by focusing analysis on specific temporal windows and localized network entity interactions rather than uniformly processing all data. The temporal graph structure allows the system to concentrate computational resources on locally relevant relationships and time periods, achieving precise breach characterization without the need to uniformly process the entire dataset at full detail.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12513161B2Systems and methods for event detection
Publication Date: 2025.12.30 COMCAST CABLE COMM LLC
  • US12513161B2 patent drawing
  • US12513161B2 patent drawing
  • US12513161B2 patent drawing

AI summary

Technologies are provided for identification of cyberattack campaigns. Cyberattack campaigns are represented by temporal graphs based on detection events representing suspicious activities in a computer network. Temporal relationships and property relationships among the detection events dictate the node and edge structure of a temporal graph representing a cyberattack campaign. By tracking how those relationships change over time, changes to the node and edge structure of the temporal graph can be determined. Those changes reveal the dynamics of the cyberattack campaign by identifying time-dependent changes in the connections across multiple network entities that are involved in the cyberattack campaign. Accordingly, the temporal graph may represent the entire evolution of a cyberattack campaign since its inception in a computer network.