How Graph Analysis Connects Suspicious Sessions
Detection that examines one record at a time can only see what that record contains. Building a graph of entities and the attributes they share makes coordination visible as structure, which is information no individual record holds.
Entities and attributes become nodes
The graph contains nodes for accounts, sessions and devices, and also nodes for the attribute values they share: an address, a payment instrument, a contact detail, a device characteristic.
Edges connect an entity to each attribute value it presented. Two accounts that used the same value are connected through that value's node rather than directly to each other.
This representation is deliberate, because it makes the degree of an attribute node visible. A value shared by thousands of accounts is obviously a poor basis for linkage.
Coordination shows up as density
Legitimate accounts connect sparsely. A person shares a household address with a few others and a device with fewer, producing small loosely connected regions.
Coordinated operations produce dense regions, because reusing infrastructure and details is cheaper than varying everything and the reuse creates many overlapping connections.
Density is measurable directly, and it is a property of the region rather than of any node in it, which is why examining accounts individually never reveals it.
High-degree nodes must be discounted
Common values connect enormous numbers of unrelated entities. A carrier address or a widely shared device configuration will link half a population if treated naively.
Weighting edges inversely to how common the attribute is prevents this, so rare shared values dominate the structure and common ones contribute almost nothing.
Without that weighting the graph collapses into one giant connected region, which is the most common failure when these systems are first built.
Propagation spreads evidence carefully
Once part of a region is known to be problematic, the confidence can be propagated along edges to reach entities that showed no individual signal.
Propagation must decay with distance and with edge weight, or a single confirmed case eventually implicates everything reachable from it, which on a connected graph is nearly everything.
Tuning the decay is what separates a system that finds the rest of an operation from one that produces sprawling false clusters.
Structure is evidence of connection, not of intent
A dense cluster demonstrates that entities are related. It does not demonstrate what the relationship is, and legitimate explanations exist for most structures a graph can produce.
Households, small businesses, shared workplaces and public terminals all generate genuine density. Treating structure as a verdict rather than as a reason to look more closely is where graph systems cause their worst errors, and the errors arrive in groups.