Patent · US Active

Iterative constraint solving in abstract graph matching for cyber incident reasoning

US11941054B2 · kind B2 · utility

3Cited by
21References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 12, 2018
Grant dateMar 26, 2024
Priority date
Expiry dateNov 16, 2039

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06N20/00
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A technique for storage-efficient cyber incident reasoning by graph matching. The method begins with a graph pattern that comprises a set of elements with constraints and connections among them. A graph of constraint relations (GoC) in the graph pattern is derived. An activity graph representing activity data captured in association with a host machine is then obtained. In response to a query, one or more subgraphs of the activity graph that satisfy the graph pattern are then located and, in particular, by iteratively solving constraints in the graph pattern. In particular, a single element constraint is solved to generate a result, and that result is propagated to connected constraints in the graph of constraint relations. This process continues until all single element constraints have been evaluated, and all propagations have been performed. The subgraphs of the activity graph that result are then returned in response to a database query.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.