IP Library Granted Patent US 12,675,488
Granted Patent B2
US 12,675,488 · App. 17/459,661 · Granted Jul 7, 2026

Cygraph graph data ingest and enrichment pipeline

Inventors: Stephen F. Purdy (Springfield, VA); Steven E. Noel (Woodbridge, VA); Edward A. Overly (Oak Hill, VA); Annie T. O'Rourke (Red Bank, NJ)
Assignee: The MITRE Corporation
G06F16/24568G06F11/328G06F16/24534G06F16/258G06F16/9024H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,675,488
App. No.
17/459,661
Filed
Aug 27, 2021
Granted
Jul 7, 2026
Kind
B2
Art Unit
2163
USPC
707/769
Abstract

Methods and systems are described for assessing a computer network using a graph model. In some instances, the methods comprise: receiving data from at least one data stream of a plurality of data streams, wherein the plurality of data streams comprise computer network data provided by one or more data brokers, and wherein the data received from different data streams of the plurality comprise different data formats; converting the data received from the at least one data stream to a common data format comprising a node or an edge; updating a graph model comprising a plurality of nodes and edges stored within a graph database according to the node or edge of the converted data; and providing a user of the computer network with a visualization of a status of the computer network.

Claims (65)

1 . A method for assessing a computer network using a graph model comprising:

receiving data from a plurality of data streams, wherein each of the plurality of data streams is received from an associated data broker and comprises computer network data from a plurality of network sensors, and wherein the data received from different data streams of the plurality of data streams comprise different data formats;

converting, using a first conversion module corresponding to a first data format of the different data formats and configured to receive a first data stream of the plurality of data streams, data from the first data stream to a first converted dataset comprising a graph database format of a graph database comprising a first node or a first edge, wherein the data from the first data stream comprises data of the first format received from an associated first plurality of network sensors;

converting, using a second conversion module corresponding to a second data format of the different data formats and configured to receive a second data stream of the plurality of data streams, data from the second data stream to a second converted data set comprising the graph database format of the graph database comprising a second node or a second edge, wherein the data from the second data stream comprises data of the second format received from an associated second plurality of network sensors;

updating a graph model comprising a plurality of nodes and edges stored within the graph database according to at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset, wherein the graph model is updated based on predefined levels of priority associated with a type or a property of the converted data, and wherein the predefined levels of priority govern whether the converted data modifies an existing node or edge of the graph model;

generating an interactive user interface comprising a user-modifiable visualization of the graph model;

receiving a user input via the interactive user interface, wherein the user input comprises a clustering instruction for managing complexity of the visualization of the graph model, the clustering instruction associated with at least one node property; and

managing complexity of the visualization of the graph model based on the clustering instruction by:

identifying a plurality of nodes associated with the at least one node property, and

displaying the plurality of nodes associated with the at least one node property as a single displayed node and displaying a plurality of non-clustered nodes in association with the single displayed node such that relationships between the non-clustered nodes and the plurality of nodes associated with the at least one node property are preserved.

2 . The method of claim 1 , wherein the data received from the plurality of data streams is received on an intermittent basis.

3 . The method of claim 1 , wherein the data received from the plurality of data streams comprises data indicating a present state of the computer network.

4 . The method of claim 1 , wherein the plurality of data streams comprise a network infrastructure data stream, a network information flow data stream, a network vulnerability scan data stream, a network intrusion detection alert data stream, a network mission dependencies data stream, an arbitrary data stream, or any combination thereof.

5 . The method of claim 1 , wherein converting the received data to the graph database format is performed independently of existing graph models stored within the graph database.

6 . The method of claim 1 , wherein a node comprises information about a network device, a network computer, a network machine, a network cyberspace asset, a network domain, a network rule, a network mission objective, a network mission asset, a network mission task, a network alert, a network vulnerability state, a network vulnerability score, a cyberattack classification, an organization, a user, a geographical area, or any combination thereof.

7 . The method of claim 1 , wherein the graph database format for at least one of the first node and the second node comprises a unique identifier (UID), a category description, a display name description, one or more key-value property fields, and an aggregation field.

8 . The method of claim 7 , wherein the aggregation field comprises instructions for modifying the one or more key-value property fields of a corresponding node within the graph model when at least one of the first node and the second node is integrated with the graph model.

9 . The method of claim 1 , wherein an edge comprises information about a relationship between a starting node and a destination node.

10 . The method of claim 1 , wherein the graph database format for an edge comprises a unique identifier (UID), a category description, a display name description, a starting node UID, a destination node UID, one or more key-value property fields, and an aggregation field.

11 . The method of claim 1 , wherein updating the graph model comprises adding at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset.

12 . The method of claim 1 , wherein updating the graph model comprises deleting a node or edge of the plurality of nodes and edges stored within the graph model that corresponds to at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset.

13 . The method of claim 1 , wherein updating the graph model comprises modifying a property associated with a node or edge of the plurality of nodes and edges stored within the graph model according to that of at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset.

14 . The method of claim 1 , wherein the graph model is updated based on a precedence table, wherein the precedence table defines levels of priority associated with a type or a property of the first converted dataset and the second converted dataset.

15 . The method of claim 1 , wherein updating the graph model comprises:

comparing a node type of the first node to a node type of a corresponding node in the graph model;

determining a relative importance between the node type of the first node and the node type of the corresponding node; and

modifying the corresponding node based on the relative importance of the node type first node and the node type of the corresponding node.

16 . The method of claim 1 , wherein the clustering instruction comprises a selection of the least one node property and identifying the plurality of nodes associated with the at least one node property comprises identifying a plurality of nodes comprising the at least one node property selected by the user.

17 . A computing system for assessing a computer network using a graph database, comprising:

one or more data input devices configured to receive data from a plurality of data streams;

one or more processors;

memory; and

one or more programs stored in the memory that, when executed by the one or more processors, cause the one or more processors to perform a method comprising:

receiving the data from the plurality of data streams, wherein each of the plurality of data streams is received from an associated data broker and comprises computer network data from a plurality of network sensors, and wherein the data received from different data streams of the plurality of data streams comprise a plurality of different data formats;

converting, using a first conversion module corresponding to a first data format of the different data formats and configured to receive a first data stream of the plurality of data streams, data from the first data stream to a first converted dataset comprising a graph database format comprising a first node or a first edge, wherein the data from the first data stream comprises data of the first format received from an associated first plurality of network sensors;

converting, using a second conversion module corresponding to a second data format of the different data formats and configured to receive a second data stream of the plurality of data streams, data from the second data stream to a second converted dataset comprising the graph database format comprising a second node or a second edge, wherein the data from the second data stream comprises data of the second format received from an associated second plurality of network sensors;

updating a graph model comprising a plurality of nodes and edges stored within the graph database according to at least one of the first node, the second node, the first edge, and second edge of the first converted dataset and the second converted dataset, wherein the graph model is updated based on predefined levels of priority associated with a type or a property of the converted data, and wherein the predefined levels of priority govern whether the converted data modifies an existing node or edge of the graph model;

generating an interactive user interface comprising a user-modifiable visualization of the graph model;

receiving a user input via the interactive user interface, wherein the user input comprises a clustering instruction for managing complexity of the visualization of the graph model, the clustering instruction associated with at least one node property; and

managing complexity of the visualization of the graph model based on the clustering instruction by:

identifying a plurality of nodes associated with the at least one node property, and

displaying the plurality of nodes associated with the at least one node property as a single displayed node and displaying a plurality of non-clustered nodes in association with the single displayed node such that relationships between the non-clustered nodes and the plurality of nodes associated with the at least one node property are preserved.

18 . The computing system of claim 17 , wherein the data received from the plurality of data streams is received on an intermittent basis.

19 . The computing system of claim 17 , wherein the data received from the plurality of data streams comprises data indicating a present state of the computer network.

20 . The computing system of claim 17 , wherein the plurality of data streams comprise a network infrastructure data stream, a network information flow data stream, a network vulnerability scan data stream, a network intrusion detection alert data stream, a network mission dependencies data stream, an arbitrary data stream, or any combination thereof.

21 . The computing system of claim 20 , wherein converting the received data to the graph database format is performed independently of existing graph models stored within the graph database.

22 . The computing system of claim 17 , wherein the a node comprises information about a network device, a network computer, a network machine, a network cyberspace asset, a network domain, a network rule, a network mission objective, a network mission asset, a network mission task, a network alert, a network vulnerability state, a network vulnerability score, a cyberattack classification, an organization, a user, a geographical area, or any combination thereof.

23 . The computer system of claim 17 , wherein an edge comprises information about a relationship between a starting node and a destination node.

24 . The computer system of claim 17 , wherein updating the graph model comprises an action selected from the group consisting of adding at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset, deleting a node or edge of the plurality of nodes and edges stored within the graph model that corresponds to at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset, or modifying a property associated with a node or edge of the plurality of nodes and edges stored within the graph model according to that of at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset.

25 . The computing system of claim 17 , wherein the graph model comprises a plurality of layers, each layer associated with a type of computer-network information and comprising a subset of the plurality of nodes and edges in the graph model.

26 . The computing system of claim 25 , wherein the method further comprises sending an alert to the user of the computer network when the graph model has been updated.

27 . The computing system of claim 26 , wherein the method further comprises receiving a domain-specific data query from the user of the computer network.

28 . The computing system of claim 27 , wherein the method further comprises converting the received domain-specific data query to a graph database native query that, when executed upon the graph database, returns matching subgraphs from the plurality of layers of the graph model.

29 . The computing system of claim 28 , wherein the method further comprises providing the user of the computer network with a visualization of the returned matching subgraphs from across the layers of the graph model.

30 . The computing system of claim 17 , wherein the method further comprises allowing the user of the computer network to select a graph dataset from a plurality of graph datasets associated with the graph database.

31 . A non-transitory computer readable storage medium having stored thereon a set of instructions for assessing a computer network using a graph database that, when executed by a computing system, cause the computing system to:

receive data from a plurality of data streams, wherein each of the plurality of data streams received from an associated data broker by and comprises computer network data from a plurality of network sensors, and wherein the data received from different data streams of the plurality of data streams comprise a plurality of different data formats;

convert, using a first conversion module corresponding to a first data format of the different data formats and configured to receive a first data stream of the plurality of data stream, data from the first data stream to a first converted dataset comprising a graph database format comprising a first node or a first edge, wherein the data from the first data stream comprises data of the first format received from an associated first plurality of network sensors;

convert, using a second conversion module corresponding to a second data format of the different data formats and configured to receive a second data stream of the plurality of data streams, data from the second data stream to a second converted dataset comprising the graph database format comprising a second node or a second edge, wherein the data from the second data stream comprises data of the second format received from an associated second plurality of network sensors;

update a graph model comprising a plurality of nodes and edges stored within the graph database according to at least one of the first node, the second node, the first edge, and the second edge of the first converted dataset and the second converted dataset, wherein the graph model is updated based on predefined levels of priority associated with a type or a property of the converted data, and wherein the predefined levels of priority govern whether the converted data modifies an existing node or edge of the graph model;

generate an interactive user interface comprising a user-modifiable visualization of the graph model;

receive a user input via the interactive user interface, wherein the user input comprises a clustering instruction for managing complexity of the visualization of the graph model, the clustering instruction associated with at least one node property; and

managing complexity of the visualization of the graph model based on the clustering instruction by:

identifying a plurality of nodes associated with the at least one node property, and

displaying the plurality of nodes associated with the at least one node property as a single displayed node and displaying a plurality of non-clustered nodes in association with the single displayed node such that relationships between the non-clustered nodes and the plurality of nodes associated with the at least one node property are preserved.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: PURDY, STEPHEN F.; NOEL, STEVEN E.; OVERLY, EDWARD A.; O'ROURKE, ANNIE T.
To: THE MITRE CORPORATION
Reel/Frame 058605/0348 →
Continuity (1)
Related Publication 20230065398A1 · Mar 2, 2023
References Cited (64)
US 7627900B1 · Noel et al. · 2009 [cited by applicant]
US 7904962B1 · Jajodia et al. · 2011 [cited by applicant]
US 8775476B2 · Henderson · 2014 [cited by applicant]
US 10216902B2 · Vesto et al. · 2019 [cited by applicant]
US 10410152B2 · Apshankar et al. · 2019 [cited by applicant]
US 10445322B1 · Kommera et al. · 2019 [cited by applicant]
US 10726070B2 · Sanchez et al. · 2020 [cited by applicant]
US 10860613B2 · Jacob et al. · 2020 [cited by applicant]
US 11070579B1 · Kiernan · 2021 [cited by examiner]
US 11256759B1 · Chen · 2022 [cited by examiner]
US 20170006135A1 · Siebel · 2017 [cited by examiner]
US 20170060972A1 · Mchugh et al. · 2017 [cited by applicant]
US 20170076092A1 · Kashyap · 2017 [cited by examiner]
US 20170109907A1 · Hamedani · 2017 [cited by examiner]
US 20170289187A1 · Noel · 2017 [cited by examiner]
US 20180075159A1 · Lin · 2018 [cited by examiner]
US 20180314921A1 · Mercep · 2018 [cited by examiner]
US 20190050445A1 · Griffith et al. · 2019 [cited by applicant]
US 20190095472A1 · Griffith · 2019 [cited by examiner]
US 20190190927A1 · Peng · 2019 [cited by examiner]
US 20190303383A1 · Thomas · 2019 [cited by applicant]
US 20200076834A1 · Ladnai · 2020 [cited by examiner]
US 20200257731A1 · Srinivas et al. · 2020 [cited by applicant]
US 20200358804A1 · Crabtree · 2020 [cited by examiner]
US 20200401908A1 · Ortega et al. · 2020 [cited by applicant]
US 20210248152A1 · Bastide · 2021 [cited by examiner]
US 20220394082A1 · Keren · 2022 [cited by examiner]
CN 111259205A · 2020 [cited by applicant]
WO WO2017039703A1 · 2017 [cited by examiner]
Bhatia et al. “Tools and Infrastructure for Supporting Enterprise Knowledge Graphs,” IBM Research: 1-6. [cited by applicant]
Conti et al. “Towards a Cyber Common Operating Picture,” 2013 5th International Conference on Cyber Conflict (CYCON 2013), Jun. 4-7, 2013, Tallinn, Estonia; 17 pages. [cited by applicant]
Defense Information Systems Agency (DISA). (May 22, 2017) “DISA's Big Data Platform and Analytics Capabilities,” located at http://www.disa.mil/newsandevents/2016/Big-Data-Platform, visited on May 22, 2017. (2 pages). [cited by applicant]
Defense Information Systems Agency. (May 23, 2017) “Assured Compliance Assessment Solution (ACAS),” located at http://www.disa.mil/cybersecurity/network-defense/acas, visited on May 23, 2017. (4 pages). [cited by applicant]
Eifrem. (Oct. 21, 2015) “Meet openCypher: The SQL for Graphs,” located at https://neo4j.com/blog/opencypher-sql-for-graphs, visited on Oct. 21, 2015. (6 pages). [cited by applicant]
Gormley, C. and Tong, Z. (2015). Elasticsearch: The Definitive Guide. M. Loukides and B. Anderson, O'Reilly Media, Inc., pp. 1-686. [cited by applicant]
Heinbockel et al. (2016). “Mission Dependency Modeling for Cyber Situational Awareness,” Nato IST-148 Symposium on Cyber Defence Situation Awareness: 14 pages. [cited by applicant]
Ingols et al. “Practical Attack Graph Generation for Network Defense,” 2006 22nd Computer Security Applications Conference, Dec. 11-15, 2006, Miami Beach, Florida; USA;10 pages. [cited by applicant]
Kordy et al. (Nov. 2014). “DAG-Based Attack and Defense Modeling: Don't Miss the Forest for the Attack Trees,” Computer Science Review 13-14:50 pages. [cited by applicant]
Lallie et al. (Nov. 9, 2017). “An Empirical Evaluation of the Effectiveness of Attack Graphs and Fault Trees in Cyber-Attack Perception,” IEEE Transactions on Information Forensics and Security 13(5): 1-13. [cited by applicant]
McGillicudy. (Apr. 3, 2017) “Flow Data is Top Source for Network Analysis,” located at https://www.kentik.com/flow-data-is-top-source-for-network-analysis, visited on Jan. 8, 2026. (7 pages). [cited by applicant]
National Vulnerability Database. (Jan. 8, 2026) “NVD - National Vulnerability Database,” located at https://nvd.nist. gov, visited on Jan. 8, 2026. (3 pages). [cited by applicant]
Noel et al. (Jan. 2016). “CyGraph: Graph-Based Analytics and Visualization for Cybersecurity,” Cognitive Computing: Theory and Applications, Handbook of Statistics: 1-51. [cited by applicant]
Noel et al. “An Overview of MITRE Cyber Situational Awareness Solutions,” NATO Cyber Defence Situational Awareness Solutions Conference, Aug. 2015, Bucharest, Romania; 1-17. [cited by applicant]
Noel et al. “Analyzing Mission Impacts of Cyber Actions (Amica),” Nato IST-128 Workshop on Cyber Attack Detection, Forensics and Attribution for Assessment of Mission Impact, Jun. 15-17, 2015 and Istanbul, Turkey; 16 pa… [cited by applicant]
Noel et al. “Big-Data Architecture for Cyber Attack Graphs,” IEEE Symposium on Technologies for Homeland Security (HST), Apr. 14-16, 2015, Boston, Massachusetts, USA;6 pages. [cited by applicant]
Noel et al. “Big-Data Graph Knowledge Bases for Cyber Resilience,” Nato IST-153/RWS-21 Workshop on Cyber Resilience, Oct. 23-25, 2017, Munich, Germany; 16 pages. [cited by applicant]
Noel et al. “Metrics Suite for Network Attack Graph Analytics,” 9th Annual Cyber and Information Security Research Conference (CISRC), Apr. 8-10, 2014, Oak Ridge, Tennessee, USA; 4 pages. [cited by applicant]
Noel et al. “Mission-Focused Cyber Situational Understanding via Graph Analytics,” 2018 10th International Conference on Cyber Conflict, May 29-Jun. 1, 2018, Tallinn, Estonia; 17 pages. [cited by applicant]
Noel. “Interactive Visualization and Text Mining for the CAPEC Cyber Attack Catalog,” ACM Interactive User Interfaces Workshop on Visual Text Analytics, Mar. 29 - Apr. 1, 2015, Atlanta, Georgia, USA; 8 pages. [cited by applicant]
O'Hare et al. “A Graph-Theoretic Visualization Approach to Network Risk Analysis,” IEEE Workshop on Visualization for Computer Security, Sep. 15, 2008, Cambridge, Massachusetts, USA; pp. 60-67. [cited by applicant]
Punnoose et al. “Rya: A Scalable RDF Triple Store for the Clouds,” 1st International Workshop on Cloud Intelligence, Aug. 31, 2012, Istanbul, Turkey; 8 pages. [cited by applicant]
RedSeal Networks. (May 21, 2018) “RedSeal. The foundation for digital resilience.” located at http://www. redsealnetworks.com, visited on Jan. 8, 2026. (5 pages). [cited by applicant]
Robinson, I., Webber, J. and Eifrem, E. (2015). Graph Databases. M. Beaugureau, O'Reilly Media, Inc., pp. 1-218. [cited by applicant]
Rodriguez et al. (Jan. 1, 2009). “Exposing Multi-Relational Networks to Single-Relational Network Analysis Algorithms,” Journal of Informetrics 4(1):27 pages. [cited by applicant]
Sandia National Laboratories. (Nov. 20, 2019) “Computer & Information Sciences (Labs Accomplishments May 2017),” located at http://www.sandia.gov/news/publications/lab_accomplishments/articles/2017, visited on Nov. 20, … [cited by applicant]
Skybox Security. (Feb. 24, 2018) “What Can Skybox Do for You?” located at http://www.skyboxsecurity.com, visited on Feb. 24, 2018. (5 pages). [cited by applicant]
Splunk. (May 31, 2017) “What Is Splunk?,” located at https://www.splunk.com, visited on [May 31, 2017]. (9 pages). [cited by applicant]
Sqrrl. (Feb. 1, 2018) “What is Sqrrl?” located at https://sqrrl.com, visited on Feb. 1, 2018. (2 pages). [cited by applicant]
The Apache Software Foundation. (Jun. 2, 2017) “Apache Storm,” located at http://storm.apache.org, visited on Jun. 2, 2017. (4 pages). [cited by applicant]
The Apache Software Foundation. (May 3, 2017) “Apache Accumulo,” located at https://accumulo.apache.org, visited on May 3, 2017. (3 pages). [cited by applicant]
The MITRE Corporation. (Jan. 8, 2026) “Cyber Command System (CyCS),” located at http://www.mitre.org/research/technology-transfer/technology-licensing/cyber-command-system-cycs, visited on Jan. 8, 2026. (3 pages). [cited by applicant]
W3C Recommendation. (Jan. 8, 2026) “SPARQL 1.1 Query Language,” located at https://www.w3.org/TR/ sparql11-query, visited on Jan. 8, 2026. (97 pages). [cited by applicant]
Wikipedia. (Jul. 19, 2011) “Host Based Security System,” located at https://en.wikipedia.org/wiki/Host_Based_Security_System, visited on Jul. 19, 2011. (5 pages). [cited by applicant]
Wireshark. (May 21, 2017) “About Wireshark,” located at https://www.wireshark.org, visited on May 21, 2017. (6 pages). [cited by applicant]