Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Assignees

Noblis Inc

Member
Noblis
Noblis

Noblis is a nonprofit research and technical organization supporting federal missions in defense, health, environment, and security. Emphasizing applied sciences, engineering, digital transformation, artificial intelligence, cloud, and cybersecurity, Noblis provides objective solutions for government agencies confronting complex operational and scientific challenges.

Publication Number

US-11550788-B2

Patent

Publication Date

2023-01-10

Expiration Date


Abstract

Data investigations are performed by querying a plurality of data sources. A system receives an investigation input and queries a plurality of data sources in accordance with the received input. The system receives, in response to the querying, response data from the plurality of data sources, and generates and stores a data structure representing relationships between the first investigation input and the first response data. The data structure may be in the form of a knowledge graph. The system may generate and display a visualization of the data structure. The system may generate and store a record of investigation steps used to generate the data structure, such that the investigation steps may be applied in future instances, for example using different inputs, to generate new data structures.

Core Innovation

A data investigation system receives a first investigation input at a query controller and queries a plurality of data sources in accordance with the first investigation input. It receives first response data from the plurality of data sources and generates and stores a data structure representing relationships between the first investigation input and the first response data, where the data structure comprises a knowledge graph. The system also generates and stores a record of a first set of investigation steps used to generate the data structure.

In accordance with the stored record of the first set of investigation steps, the system applies the first set of investigation steps to a plurality of different entities to generate a plurality of respective data structures. The system trains a machine learning algorithm based on the plurality of respective data structures, where training includes training the machine learning algorithm to classify data structures generated using the first set of investigation steps and generated with respect to different respective entities into one or a set of predefined classifications.

The system displays a visual representation of the data structure comprising the knowledge graph. The system receives a second investigation input at the query controller by detecting selection of a node of the visual representation of the knowledge graph, displays an indication of a set of options for generating investigation inputs based on the selected node, and in response queries the plurality of data sources in accordance with the second investigation input comprising the indication of the node and the selection of the option.

The system receives second response data from the plurality of data sources and augments the data structure, such that the data structure represents relationships between the second investigation input and the second response data.

Claims Coverage

The document includes three independent claim sets: a method for performing a data investigation, a system for performing the same data investigation, and a non-transitory computer-readable storage medium storing instructions to perform the same data investigation. Each independent claim includes five inventive features.

Knowledge graph data structure from investigation input and response data

Generating and storing, based on the first response data, a data structure representing relationships between the first investigation input and the first response data, wherein the data structure comprises a knowledge graph.

Investigation steps record for re-application across entities

Generating and storing a record of a first set of investigation steps used to generate the data structure, and in accordance with the stored record, applying the first set of investigation steps to a plurality of different entities to generate a plurality of respective data structures.

Machine learning classification trained on entity-specific data structures

Training a machine learning algorithm based on the plurality of respective data structures to classify data structures generated using the first set of investigation steps and generated with respect to different respective entities into one or a set of predefined classifications.

Interactive node selection to generate second investigation input

Displaying a visual representation of the data structure comprising the knowledge graph, receiving a second investigation input by detecting selection of a node of the visual representation, and displaying an indication of a set of options for generating investigation inputs based on the selected node.

Re-querying based on node-selected option and augmenting the knowledge graph

In response to receiving the second investigation input, querying the plurality of data sources in accordance with the second investigation input comprising the indication of the node and the selection of the option, receiving second response data, and augmenting the data structure such that it represents relationships between the second investigation input and the second response data.

Across the independent claims, the invention is characterized by constructing and storing a knowledge graph data structure that represents relationships between investigation inputs and response data, recording investigation steps and re-applying them across different entities, training a machine learning algorithm to classify those data structures into one or a set of predefined classifications, and supporting interactive refinement by detecting selection of nodes in the knowledge-graph visualization to generate second investigation inputs that trigger additional querying and knowledge-graph augmentation.

Stated Advantages

Documented Applications

Cybersecurity investigation, including querying heterogeneous data sources such as WHOIS, DIG, and passive DNS (passive Domain Name System).

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.