Shape is SignalStructured Intelligence
Concept

Structural detection
for cybersecurity.

Structural detection for cybersecurity identifies attacks by measuring change in the relationships between machines, accounts and services, rather than by matching individual events against known attack patterns. The unit of analysis is not the event. It is what connects to what, and how that has moved.

It is a detection approach, not a product. This page defines it, distinguishes it from signature, behavioural and anomaly detection, and states where it does not help. Structured Intelligence implements it in SIET.

The observation it rests on

An attacker cannot achieve anything without interacting with something. To move laterally they must reach a machine they have not reached before. To collect data they must open something they do not usually open. To persist they must run something that was not running. To exfiltrate they must talk to somewhere new.

Every one of those actions changes the relationships in the environment. Not the content of a log line, not a payload, not a hash: the arrangement of which things are connected to which, and how much.

That change is observable without knowing anything about the attacker. You do not need their tooling, their infrastructure, their technique or their name. You need to know what the environment normally looks like, and to notice when it stops looking like that.

A workstation that has spoken to three machines for a year starts speaking to twelve. An account seen on one host appears on nine. A service that saw four requests a minute sees four hundred. A printer starts offering a file share.

None of those events is malicious on its face. Each is a departure from an established structure, and the departure is the signal.

Why it is not the same as anomaly detection

This is the most common misreading, and the distinction is worth being precise about.

Every detection method is, in some sense, a claim about what is abnormal. A rule that fires on a document spawning a shell is somebody’s claim about abnormality. The difference is not anomaly versus rule. It is static versus derived.

A rule library was written against a different environment at a point in time and then frozen. A statistical threshold was set by a person who had to guess. Both are constants applied to a system that does not hold still, which is why detection content decays: not because the technique changed, but because the environment did and the constant did not.

Structural detection derives what counts as normal from the recorded history of each part of the environment, and keeps deriving it. Nobody picks a number. A quiet domain controller and a busy one are judged on their own terms, without anyone configuring either.

The three kinds of departure

In practice, structure moves in three ways, and each maps to attack behaviour.

01

It grows

Something does far more than it has ever done. Load, credential brute forcing, flooding.

02

It spreads

Something reaches further than it has ever reached. Scanning, lateral movement, propagation.

03

It appears

Something happens that has never happened here at all. The strongest of the three, because it needs no threshold to decide.

How it compares

These approaches are not mutually exclusive, and most estates run several. The distinction is what each one needs in order to work.

ApproachThe question it asksWhat it requiresWhat it misses
Signature detectionDoes this event match something known to be bad?A description of the attack, written after somebody survived itAnything nobody has described yet
Behavioural detectionIs this entity behaving unusually for an entity of its kind?A model of normal, usually trained on labelled or peer dataActivity that looks ordinary in isolation but is not, in context
Anomaly detectionIs this value statistically unusual?A distribution, and a threshold somebody choseAttacks that stay inside normal ranges, while flagging benign outliers
Structural detectionHas the shape of the relationships in this environment changed?The environment’s own recorded history. Nothing elseActivity that changes no relationship at all

What follows from it

Four consequences fall out of the approach rather than being features added to it.

The domain boundaries stop applying

Detection is normally sold by telemetry type: network detection for the wire, endpoint detection for the host, identity detection for accounts, cloud detection for workloads. Each is a separate product because each was built to read one kind of data. A relationship between an account and a host is the same kind of object as one between two hosts, so the boundary that produced four products is not a property of the problem.

No detection content to maintain

There is no rule library, because nothing is described in advance. Nothing decays as the environment changes, because what counts as normal is recomputed from the environment itself.

Investigation comes free

Conventional detection strips context on the way in, so somebody has to reconstruct it afterwards. A structural finding already knows what connected to what, so the blast radius is not computed later, it is what was detected.

Novel attacks are not special

A technique nobody has published still has to change something to achieve anything. There is no separate capability for unknown attacks, because knowing the attack was never part of it.

Where it does not help

Structural detection sees change in relationships. Activity that changes no relationship is invisible to it: an implant that sits dormant and does nothing, a single connection carrying no repeated pattern, misuse that stays entirely within what an account normally does. It is also not a preventive control. It tells you the shape moved; it does not stop the traffic.

In practice

SIET is an implementation of this.

Structured Intelligence built SIET to apply structural detection to enterprise security telemetry. It was evaluated against CICIDS2017, a public intrusion benchmark, where it detected every attack in the dataset with no signatures and no prior knowledge of any of them, at a median time to detect under one minute and three cases on a benign control day.

Because the benchmark is public, the figures can be reproduced rather than taken on trust. UK patent pending, GB2619729.3.