Time-Varying Graph Network Data Analysis for Security Incident Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computer networks face difficulties in managing and analyzing security incidents due to their complexity, making it challenging to determine the origin, spread, and dynamics of attacks, as well as identifying compromised devices and security vulnerabilities.

Innovation Solution

The method involves processing network data to generate a time-varying graph data structure, which represents communications between computing devices over time, allowing for the analysis of network dynamics and security incidents by indexing data over multiple time periods and using metrics like graph clustering and belief propagation to identify anomalous behavior and track the spread of infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network analysis methods are used, then the system is simple to implement, but it cannot effectively analyze security incidents in complex modern networks

Engineering Contradiction:
Improvesecurity incident analysis capabilityVSAvoidnetwork structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex network into discrete graph elements (nodes representing devices, edges representing communications) organized by time periods. This segmentation allows the system to manage complexity by breaking down the network into analyzable units while maintaining the ability to analyze security incidents across the entire network structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a time dimension to the network analysis by organizing graph data into time-period-specific representations. This dimensional transformation enables the system to track how network communications and security incidents evolve over time, providing deeper analytical capability without being overwhelmed by the static complexity of the network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If detailed network communication data is collected, then analysis accuracy is improved, but data processing complexity and time increase

Engineering Contradiction:
Improvesecurity incident detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments network communication data into time-period-specific graph representations, processing data in manageable temporal chunks rather than attempting to analyze all data simultaneously. This segmentation maintains detection accuracy by preserving temporal patterns while reducing the computational burden of processing entire network datasets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary organization of network data into structured graph formats with defined nodes, edges, and time-period associations before conducting security incident analysis. This preliminary structuring enables faster query execution and more efficient analysis operations on already-organized data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10791131B2Processing network data using a graph data structure
Publication Date: 2020.09.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10791131B2 patent drawing
  • US10791131B2 patent drawing
  • US10791131B2 patent drawing

AI summary

Certain described examples are directed towards analyzing network data. The network data is processed to generate a graph data structure that has edges that are associated with communication times from the network data and nodes that are associated with computer devices. Representations of the graph data structure are generated over time. Given an indication of at least a computing device, for example as involved in anomalous activity or a security incident, the representations of the graph data structure may be used to determine further associated computer devices that are associated with the indicated device.