IP Library Granted Patent US 12,407,718
Granted Patent B2
US 12,407,718 · App. 18/359,389 · Granted Sep 2, 2025

Incremental causal graph learning for attack forensics in computer systems

Inventors: Zhengzhang Chen (Princeton Junction, NJ); Haifeng Chen (West Windsor, NJ); Dongjie Wang (Orlando, FL)
Assignee: NEC Corporation
H04L63/145H04L41/0631H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,718
App. No.
18/359,389
Granted
Sep 2, 2025
Kind
B2
Abstract

A computer-implemented method for identifying attack origins is provided. The method includes detecting a trigger point from entity metrics data and key performance indicator (KPI) data, generating a learned causal graph by fusing a state-invariant causal graph with a state-dependent causal graph, backtracking from an attack detection point, via an incident backtrack and system recovery component, by using the learned causal graph to identify an attack origin when an intrusion or attack occurs, and displaying data relating to the attack origin on a visualization display for user analysis.

Claims (34)

1. A computer-implemented method for identifying attack origins, the method comprising:

detecting a trigger point from entity metrics data and key performance indicator (KPI) data;

generating a learned causal graph by fusing a state-invariant causal graph with a state-dependent causal graph;

backtracking from an attack detection point, via an incident backtrack and system recovery component, by using the learned causal graph to identify an attack origin in response to an intrusion or an attack occurring; and

displaying data relating to the attack origin on a visualization display for user analysis.

2. The computer-implemented method of claim 1 , wherein the trigger point detection involves constructing an initial system state space by using a time-lagged trajectory matrix.

3. The computer-implemented method of claim 2 , wherein the time-lagged trajectory matrix leverages non-linear kernel-based matrix decomposition to learn a robust subspace.

4. The computer-implemented method of claim 1 , wherein a disentangle graph learning-based incremental causal discovery framework is employed to generate the learned causal graph.

5. The computer-implemented method of claim 1 , wherein a prediction layer is used to predict future time-series data on the learned causal graph.

6. The computer-implemented method of claim 1 , wherein the learned causal graph is incrementally updated.

7. The computer-implemented method of claim 1 , wherein a state-invariant decoder is employed to learn invariant causal relations across two system states and wherein a state-dependent decoder is employed to learn new causal relations introduced by a new batch data.

8. A computer program product for identifying attack origins, the computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to perform a method comprising:

detecting a trigger point from entity metrics data and key performance indicator (KPI) data;

generating a learned causal graph by fusing a state-invariant causal graph with a state-dependent causal graph;

backtracking from an attack detection point, via an incident backtrack and system recovery component, by using the learned causal graph to identify an attack origin in response to an intrusion or an attack occurring; and

displaying data relating to the attack origin on a visualization display for user analysis.

9. The computer program product of claim 8 , wherein the trigger point detection involves constructing an initial system state space by using a time-lagged trajectory matrix.

10. The computer program product of claim 9 , wherein the time-lagged trajectory matrix leverages non-linear kernel-based matrix decomposition to learn a robust subspace.

11. The computer program product of claim 8 , wherein a disentangle graph learning-based incremental causal discovery framework is employed to generate the learned causal graph.

12. The computer program product of claim 8 , wherein a prediction layer is used to predict future time-series data on the learned causal graph.

13. The computer program product of claim 8 , wherein the learned causal graph is incrementally updated.

14. The computer program product of claim 8 , wherein a state-invariant decoder is employed to learn invariant causal relations across two system states and wherein a state-dependent decoder is employed to learn new causal relations introduced by a new batch data.

15. A computer processing system for identifying attack origins, comprising:

a memory device for storing program code; and

a processor device, operatively coupled to the memory device, for running the program code to:

detect a trigger point from entity metrics data and key performance indicator (KPI) data;

generate a learned causal graph by fusing a state-invariant causal graph with a state-dependent causal graph;

backtrack from an attack detection point, via an incident backtrack and system recovery component, by using the learned causal graph to identify an attack origin in response to an intrusion or an attack occurring; and

display data relating to the attack origin on a visualization display for user analysis.

16. The computer processing system of claim 15 , wherein the trigger point detection involves constructing an initial system state space by using a time-lagged trajectory matrix.

17. The computer processing system of claim 16 , wherein the time-lagged trajectory matrix leverages non-linear kernel-based matrix decomposition to learn a robust subspace.

18. The computer processing system of claim 15 , wherein a disentangle graph learning-based incremental causal discovery framework is employed to generate the learned causal graph.

19. The computer processing system of claim 15 , wherein a prediction layer is used to predict future time-series data on the learned causal graph.

20. The computer processing system of claim 15 , wherein the learned causal graph is incrementally updated.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 071692/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2023
From: CHEN, ZHENGZHANG; CHEN, HAIFENG; WANG, DONGJIE
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 064390/0652 →
Continuity (4)
Provisional Application 63450989 · Mar 9, 2023
Provisional Application 63442155 · Jan 31, 2023
Provisional Application 63397955 · Aug 15, 2022
Related Publication 20240214414A1 · Jun 27, 2024
References Cited (22)
US 9736173B2 · Li et al. · 2017 [cited by applicant]
US 10289841B2 · Tang et al. · 2019 [cited by applicant]
US 10298607B2 · Tang et al. · 2019 [cited by applicant]
US 10379849B1 · Jasinski · 2019 [cited by examiner]
US 20100161307A1 · Bharadwaj · 2010 [cited by examiner]
US 20180336349A1 · Zhang · 2018 [cited by examiner]
US 20220070068A1 · Earhart · 2022 [cited by examiner]
US 20220382614A1 · Chen et al. · 2022 [cited by applicant]
US 20230069074A1 · Chen et al. · 2023 [cited by applicant]
US 20230080424A1 · Yu · 2023 [cited by examiner]
US 20230325269A1 · Gusat · 2023 [cited by examiner]
US 20240061740A1 · Chen · 2024 [cited by examiner]
Wang et al., Disentangled Causal Graph Learning for Online Unsupervised Root Cause Analysis, arXiv preprint arXiv:2305.10638, pp. 1-11 (May 2023) (Year: 2023). [cited by examiner]
Wang et al., Incremental causal graph learning for online root cause analysis, In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 2269-2278 (Aug. 2023) (Year: 2023). [cited by examiner]
Wang et al., Incremental Causal Graph Learning for Online Unsupervised Root Cause Analysis, arXiv preprint arXiv:2305.10638, pp. 1-10 (May 2023) (Year: 2023). [cited by examiner]
Dong, B., Chen, Z., Tang, L. A., Chen, H., Wang, H., Zhang, K., . . . & Li, Z. (Nov. 27, 2020). Anomalous event sequence detection. IEEE Intelligent Systems, 36(3), 5-13. [cited by applicant]
Lin, Y., Chen, Z., Cao, C., Tang, L. A., Zhang, K., Cheng, W., & Li, Z. (Oct. 17, 2018). Collaborative alert ranking for anomaly detection. In Proceedings of the 27th ACM International Conference on Information and Know… [cited by applicant]
Dong, B., Chen, Z., Wang, H., Tang, L. A., Zhang, K., Lin, Y., . . . & Chen, H. (Nov. 6, 2017). Efficient discovery of abnormal event sequences in enterprise security systems. In Proceedings of the 2017 ACM on Conferenc… [cited by applicant]
Wang, D., Chen, Z., Ni, J., Tong, L., Wang, Z., Fu, Y., & Chen, H. (Feb. 3, 2023). Hierarchical graph neural networks for causal discovery and root cause localization. arXiv preprint arXiv:2302.01987. [cited by applicant]
Cheng, W., Zhang, K., Chen, H., Jiang, G., Chen, Z., & Wang, W. (Aug. 13, 2016). Ranking causal anomalies via temporal and dynamical analysis on vanishing correlations. In Proceedings of the 22nd ACM SIGKDD Internationa… [cited by applicant]
Cai, L., Chen, Z., Luo, C., Gui, J., Ni, J., Li, D., & Chen, H. (Oct. 26, 2021). Structural temporal graph neural networks for anomaly detection in dynamic graphs. In Proceedings of the 30th ACM international conference… [cited by applicant]
Luo, C., Chen, Z., Tang, L. A., Shrivastava, A., Li, Z., Chen, H., & Ye, J. (Jul. 19, 2018). TINET: learning invariant networks via knowledge transfer. In Proceedings of the 24th ACM SIGKDD International Conference on K… [cited by applicant]