ALink: Real-Time and Scalable Graph Architecture for Linking Alerts in Threat Detection

Kenneth Osborne, Ryan Foltz, Derek Lin · 2025

Enterprise security operations centers face an overwhelming volume of alerting events to investigate. Whether fact-based or anomaly-based, these alerts—generated by various security products and services—are challenging to process manually, especially when analyzed in isolation. Connecting the dots by pivoting between individual alerts during investigations is both time-consuming and labor-intensive. Security practitioners need a system that can intelligently group related alerts into cases, enabling better prioritization and automating the manual process of event correlation. This paper introduces a scalable architecture featuring a graph database-embedded pipeline designed to link streaming input alerts that meet linking criteria to real-time streaming output scored paths as cases to investigate.

Read the paper · More papers on PaperTik