Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

64 results about "Incident response" patented technology

An incident response team or emergency response team (ERT) is a group of people who prepare for and respond to any emergency incident, such as a natural disaster or an interruption of business operations. Incident response teams are common in public service organizations as well as in organizations. This team is generally composed of specific members designated before an incident occurs, although under certain circumstances the team may be an ad hoc group of willing volunteers.

Predictive incident management device and system using cross-sensor temporal patterns and scalable rule processors

A predictive incident management system, consisting of: a sensor input module configured to receive heterogeneous telemetry data streams from mechanical, thermal, electrical and cyber sources; a temporal correlation control unit operationally coupled to the sensor input module, wherein the temporal correlation control unit is configured to normalize received data into a uniform time series envelope that includes identifiers, microsecond-precision timestamps, metric names, values, and context markers, and is further configured to compute sliding window-cross-sensor correlation matrices, event motifs, and lead-lag dependencies across multiple time granularities; a scalable rule processor that is communicatively linked to the control unit for temporal correlation, wherein the rule engine includes an in-memory runtime environment for processing complex events and a domain-specific declarative language, and is configured to apply rules that reference primitive sensor metrics, derived correlation features, and motive-based early warning vectors to classify, escalate, or resolve predicted incidents; A historical repository that is communicatively connected to both the temporal correlation control unit and the rule engine. The repository is configured to store tagged event histories, correlation motif dictionaries, rule versions, and rule origin metadata to ensure the verifiability and explainability of predictions; and An incident response interface is operationally connected to the rule engine. The incident response interface is configured to trigger automated workflows, including the generation of tickets for IT service management, chat ops notifications, the execution of orchestration playbooks, and direct machine control via industrial protocols. the system is configured to perform predictive analyses based on temporal correlations between sensors and to execute context-aware, rule-based incident management in real time.
Owner:GUTTIKONDA BHANU SEKHAR KRISHNA +4

Context repository management

Embodiments manage context repositories in computing environments to enhance automated security analysis. Embodiments obtain context records containing supplemental information associated with security events and integrates them into prompts for large language models (LLMs) to generate severity scores for event classification. Embodiments apply criteria to invalidate outdated or unreliable context records based on age, source reliability, and usage frequency, then modifies prompts and repositories accordingly. Enhanced prompts incorporate context record summaries and entity relationship mappings to improve subsequent event analysis. Embodiments dynamically evaluates context records through quality filters, consolidates duplicates, and maintains audit trails with provenance tracking. User interfaces are dynamically transformed based on telemetry metrics and user feedback to optimize analyst workflows. Embodiments enable organizations to maintain curated, high-quality context repositories that continuously improve AI-assisted security analysis while reducing false positives and enhancing incident response effectiveness.
Owner:DROPZONE AI INC

Real-Time Anomaly Prediction Using Extrapolated Telemetry Data

Systems and methods are disclosed for real-time anomaly prediction using near real-time data. The invention addresses delays in telemetry data collection from infrastructure components, by collecting metrics and logging this data in real-time. Extracted logged data undergoes initial analysis to identify patterns and anomalies, followed by cleaning to remove noise and errors. Feature engineering enhances the data, creating or modifying features to improve machine learning model performance. The system calculates weighted means of previous data values and computes first and second-order differences to capture immediate changes and trends. These calculations adjust the extrapolated value to accurately reflect current conditions. The adjusted data is integrated into the dataset and validated. The validated data trains and tests a machine learning model, which is then finalized and deployed for real-time anomaly detection. This system ensures accurate and timely anomaly prediction, enabling automated incident response to maintain the reliability and performance of infrastructure components.
Owner:BANK OF AMERICA CORP

Chaotic annealing ant colony-based adversarial blocking timeliness emergency material transportation toughness intelligent decision-making method

The invention discloses a chaos annealing ant colony-based adversarial blocking timeliness emergency material transportation toughness intelligent decision-making method, and relates to the technical field of intelligent emergency scheduling and optimization. The method comprises the steps of 1, extracting scene data and converting the scene data into model parameters; step 2, constructing a mathematical model for survivability optimization; 3, initializing algorithm parameters and generating an initial path; 4, dynamically adjusting the temperature and the pheromone volatilization rate; 5, generating an adversarial blocking perception path and implementing detour repair; 6, updating pheromone distribution based on an annealing criterion; and step 7, locking the critical path and outputting an optimal transportation scheme. According to the method, timely delivery of materials can be guaranteed in a complex road network blocking and emergency demand scene, the timeliness and toughness of an emergency transportation system are improved through a chaos annealing mechanism and an adversarial blocking simulation technology, the method can be widely applied to the fields of natural disaster rescue, public health event response and the like, and a scientific basis is provided for emergency decision making.
Owner:BEIHANG UNIV

Database system incident evaluation, classification, and resolution system

A computing services environment may include a database system, a vector store, a generative language model interface, and / or an incident response system. The database system may be configured to detect a database system incident affecting database system availability or performance and to generate a database incident report characterizing the database system incident. The generative language model interface may be configured to determine a textual description of the database system incident and identify one or more records of the plurality of records by completing an incident evaluation prompt via a generative language model. An incident response engine may be configured to determine an instruction to resolve the database incident based on the textual description and the one or more records, wherein the database system is configured to execute the instruction to update one or more configuration parameters.
Owner:SALESFORCE INC

Virtual DCS Security Operator for Incident Detection and Response

A method for security incident detection in a cloud-native distributed control system (DCS) in industrial process automation includes monitoring information technology, IT-related data and operation technology, OT-related data at a production process and at a containerized DCS associated with the production process. The method further comprises joint analysing of first data indicative of first monitoring data from the monitoring of the IT-related data and of second data indicative of second monitoring data from the monitoring of the OT-related data. The method further comprises, based on the joint analysing, detecting a security incident under consideration of predetermined security incident detection rules: The method further comprises, based on a result of the detecting, responding on a detected security incident for handling of the detected security incident under consideration of predetermined security incident response rules.
Owner:ABB (SCHWEIZ) AG

Systems and methods for AI-based real-time incident response intelligence

An emergency response data system (ERDS) provides AI-based real-time intelligence during a response to an incident. The system includes a monitoring module configured to receive and process incident metadata from an emergency system, such as a Computer-Aided Dispatch (CAD) system, wherein the incident metadata includes location, type of emergency, units dispatched, and comments. An analysis module analyzes the incident metadata and identifies changes in incident circumstances, including comparing current comments with historical comments corresponding to the location. A data retrieval module accesses and retrieves public record information corresponding to the location, including property data, tax records, real estate records, historical records, and permits. An insight generation module generates real-time insights and updates regarding the incident, including reclassifying the type of emergency based on the analyzed metadata and retrieved public records. An alert module transmits the real-time insights to emergency personnel, including field responders and Emergency Communication Centers (ECC).
Owner:RAPIDSOS

Map-based emergency call management and dispatch

An emergency response system provides a map-based interface for a telecommunicator to view information about an incident and coordinate a response to the incident. The emergency response system gathers supplemental data regarding locations and other information that may be relevant in assisting with the incident. The interface may automatically select relevant supplemental information based on the incident and provide this incident-specific information for display on the interface. The user may then select a response on the interface such as a unit to dispatch that the system automatically implements, providing unified information and control for incidents, supplemental information, and incident response.
Owner:RAPIDDEPLOY INC

Response vehicle systems and methods

An incident response system can one or more processing circuits. The one or more processing circuits can acquire data from a communication device, receive an indication that a response vehicle is set to leave or has left a location proximate to an incident, and transmit a message to a server including the indication that the response vehicle is set to leave or has left the location proximate to the incident.
Owner:OSHKOSH CORPORATION

A Rapid Response Method and System for Traffic Incidents Based on Multi-Source Data Fusion

This application provides a method and system for rapid response to traffic incidents based on multi-source data fusion, relating to the field of traffic incident response technology. The method includes: extracting traffic feature vectors from multi-source traffic data for multi-source fusion calculation; determining whether abnormal traffic incidents exist in the fused situational data; when abnormal traffic incidents exist, determining the type and locating the information; generating an initial response plan based on the determined type and location information; pushing the initial response plan to the handling department's terminal and receiving execution status information from the handling department; recording the timestamps and operation logs of the entire process, and evaluating the effectiveness of this response process. This application addresses the technical problem of lacking multi-source traffic data fusion analysis in existing technologies, enabling rapid response to traffic incidents based on multi-source traffic data fusion, and achieving the technical effect of improving the accuracy of traffic incident identification.
Owner:INTELLIGENT INTER CONNECTION TECH CO LTD

Security event response system and method based on intelligent analysis

The invention discloses a security event response system and method based on intelligent analysis, and relates to the technical field of network security, an asset business load integrated digital model is constructed, a cross-domain attack surface is identified based on cross-environment asset interaction data in the integrated digital model, and basic data support for subsequent simulation and reasoning is formed; based on the obtained asset, business and cross-domain attack surface data, an attack framework and a dynamic attacker portrait are fused to construct a causal knowledge graph, the causal relationship of unknown attacks is complemented through transfer learning and an unsupervised algorithm, and the causal knowledge graph is updated according to the dynamic change of the environment; according to the method, the conversion of the security event from passive tracing to active prediction is realized, high-risk threats are identified in advance through cross-domain attack path simulation and risk quantification, and the defense initiative is improved.
Owner:中交京津冀投资发展有限公司 +1

Connecting natural and security language in the embedding space for better threat hunting and incident response

Methods and apparatuses for improving the speed, quality, and relevance of automated responses provided by a question answering system for security data are described. The question answering system may generate and utilize a large language model that is trained to combine the language of security data, such as the language found in security logs and alerts, with natural language text. Given an input prompt (or a search query) from an end user of the question answering system, the question answering system may identify relevant content from the security data and display a response based on the relevant content. The question answering system may allow the end user of the question answering system to query security logs using natural language text without requiring the end user to provide a structured query and without requiring the security data be parsed and ingested into a database system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network security event response techniques using artificial intelligence

Systems and methods for providing cyber-security event responses are presented. The method includes providing the received event input into a large language model (LLM); mapping the received event input into a scene of a plurality of scenes based on an output of the LLM, each scene comprising a plurality of sub-scenes; receiving a user input through a user interface, the user interface configured to present a graphical representation of a set of sub-scenes of the plurality of sub-scenes; selecting a sub-scene based on the received event input; generating a query based on the received event input and a selection of a sub-scene of the plurality of sub-scenes; executing the query on a secure database, the secure database comprising a representation of the computing environment; and initiating a mitigation action based on a result of the executed query.
Owner:WIZ INC

Containers-Based Forensics for Persistent and Stateless Containers

Comprehensive systems and methods for conducting digital forensics and incident response in containerized computing environments. The system converts stateless containers into persistent containers to prevent automatic termination during forensic investigations. It quarantines the containers using virtual switches and firewalls, captures detailed forensic data including snapshots of all filesystem layers, kernel syscalls, and process data, and mirrors network traffic for secure analysis. The system retrieves logs and artifacts from current and previous nodes, correlates and compares this data using machine learning algorithms, and securely duplicates all artifacts to immutable storage. Automated orchestration ensures consistent execution of forensic processes, and the system reverts containers to their original stateless state post-investigation. A detailed audit log and secure archival of all forensic data are maintained for future reference or legal compliance. The invention addresses the unique challenges of securing and analyzing data in dynamic, distributed containerized environments.
Owner:BANK OF AMERICA CORP

Methods for non-invasive API discovery, monitoring and exploitation detection in third-party processes

System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.
Owner:WALLARM INC

Document generation device, document generation method, and program

To improve efficiency of a reporting process in incident response and improve reporting accuracy.SOLUTION: Report destination determination means determines a report destination for an incident based on information related to the incident. First prompt acquisition means acquires a basic prompt corresponding to the determined report destination. Second prompt acquisition means acquires an optional prompt based on a condition including the report destination. Prompt generation means combines the basic prompt and the optional prompt to generate a combined prompt. Document generation means inputs the combined prompt into a language model to generate a report document regarding the incident.SELECTED DRAWING: Figure 2
Owner:NEC CORP

Hardware-Anchored DAO Governance Engine with Quantum-Resistant Attestation

PendingUS20260205302A1BiotechnologyByzantine fault tolerance
Every major DAO governance failure traces to a common root cause: governance logic, voting, and treasury access reside in software that adversaries can reach. The disclosed invention provides a hardware-anchored DAO governance architecture defeating five adversary classes. A supply-chain attestation layer verifies firmware integrity against a public transparency log at node initialization. A Silicon Root-of-Trust Anchor Layer binds governance to processor-embedded cryptographic keys. A Heterogeneous TEE Orchestration Layer enforces Byzantine fault-tolerant canonical quorum through threshold BLS signatures across independent hardware architecture families. An Atomic Governance Transition Engine executes indivisible state changes: record incorporation, key destruction, counter advancement, and IOMMU treasury isolation. A Quantum-Resistant Governance Key Lifecycle Engine performs CRYSTALS-Kyber (ML-KEM, FIPS 203) key rotation with cryptographic agility. A Cross-Chain Governance Attestation Bridge publishes TEE-signed proofs to multiple blockchains. A Deterministic Governance Replay Engine reconstructs governance decisions in isolated sandboxes. An Automated Governance Incident Response Engine and Governance Regulator Verification Network provide hardware-enforced, independently auditable compliance enforcement.
Owner:BICKERSTAFF III GEORGE WILLIAM

Incident response system and incident response method

An incident response system and an incident response method [that] are able to generate and configure a processing workflow that includes a combination of external systems and individual processing components depending on the type of risk in order to respond to individual incidents. The incident response system, which responds to the individual incidents, includes a playbook DB, a playbook selection section, a workflow generation section, and a workflow engine section. The playbook DB stores processing workflows which are response flows for incidents of risks, as playbooks for individual types of risks. The playbook selection section acquires incident information regarding an incident that has occurred or appears to occur, and extracts a corresponding one of the playbooks that is appropriate for the incident from the playbooks created for the individual types of risks. The workflow generation section generates the processing workflows appropriate for the individual incidents incident.
Owner:HITACHI LTD

Action response framework for data security incidents

An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and / or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.
Owner:WORKDAY INC

Incident response notification system

PendingUS20260255142A1EngineeringService usage
An incident response notification system may be provided by receiving, at a central service from a wireless communication device associated with a sensor deployed in an environment with a plurality of sensors, a status report; verifying, by the central service, a location of the sensor in the environment; updating, by the central service, a map of the environment with the status report; processing, by the central service, pending status reports, including the status report, to identify an incident flow; generating, by the central service, a reaction plan based on the map and the incident flow; and outputting, via the central service, the reaction plan.
Owner:SUBRAHMANYAM PILAKA VENKATA

Applying A Machine Learning Model To Generate A Ranked List Of Candidate Actions For Addressing An Incident

Techniques for providing candidate actions to a service agent based on a customer incident and associated attributes are disclosed. In one or more embodiments, a customer incident response system allows a customer support team to leverage a data ecosystem available to provide service agents with contextually relevant insights into a current data context that describes the customer incident. The system allows an administrator to configure connections to endpoints for external and / or third-party services, including artificial intelligence (AI), machine learning, static content, temporally based content, and rules-based content. Once configured, the system displays a series of insight cards near an incident workspace, where each insight card includes an action that the service agent may execute to attempt to resolve the customer incident. The system allows for external AI engines to generate insights and potential next actions to address the customer incident while enjoying a simplified setup.
Owner:ORACLE INT CORP

Property security event processing method, system and electronic device

PendingCN122551527AThe InternetSpatial database
This application relates to the technical fields of property management and the Internet of Things, and discloses a method, system, and electronic device for handling property security incidents. The method includes: acquiring property security incident information, wherein the incident information includes the incident type and a spatially unique identifier for the alarm device; querying a spatial database based on the spatial unique identifier to determine the spatial information of the space where the alarm device is located; determining the risk level by performing a risk assessment using a preset event spatial risk matrix based on the incident type and spatial information; triggering a corresponding tiered response plan according to the risk level; and handling the property security incident based on the tiered response plan. This method can improve the accuracy of property security incident response.
Owner:CHENGDU XUMI YUNTU ARCHITECTURAL DESIGN CO LTD

Smart Incident Response

PendingUS20260127515A1InstrumentsMedicineBus
An event management bus is configured to ingest events from a plurality of monitoring tools at a defined acceptance rate. Events received in excess of the acceptance rate are rejected, and a rejection notification is transmitted. For an ingested event, an incident is triggered. A machine-learning model, selected based on a determined incident type, initiates a process to identify a resolution for the incident. An action determined as a result of the process is executed by an action execution tool. Feedback data indicating the effectiveness of the executed action in resolving the incident is received. The machine-learning model is then retrained using the feedback data.
Owner:PAGERDUTY INC

Attack source identification system and method based on open source network real-time monitoring

The invention aims to provide an attack source identification system and method based on open source network real-time monitoring. The system comprises a data acquisition module, a data standardization module, an information addition module, a clustering module and an attack association analysis module. The data acquisition module is used for acquiring IOC data from multiple ways; the data standardization module is used for performing standardization formatting processing on the IOC data; the information adding module is used for adding context information based on the standardized IOC data; the clustering module is used for performing clustering analysis on the IOC data; and the attack association analysis module counts the clustering result and the APT organization association degree and outputs an association result. According to the method, the scattered IOC and the specific APT organization can be associated and attributed, the attack link of the IOC can be possibly output, and deep and actionable context intelligence is provided for threat hunting and event response.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT GUANGXI BRANCH

Incident response simulation and learning system

A method of simulating an emergency response training scenario to users in different locations, including customizing a scenario, initiating a game state having a threat level and a time remaining, assigning a role to each of a plurality of users wherein each of the users uses a device, assigning digital assets within the scenario to each of the users, displaying an introduction sequence, initiating an incident and simultaneously notifying a first group of at least two users, logging and scoring a chosen response from the possible responses compared to a scoring system, updating the game state whereby the threat level is raised or lowered and the time remaining is increased or decreased, triggering another event to at least two of the plurality of users, and communicating a score calculated in the logging and scoring step to at least one user on one of the at least one client device.
Owner:CYBERCADE INC

Laboratory digital safety workspace management method, system and equipment based on trusted computing and medium

The invention discloses a laboratory digital safety workspace management method, system and device based on trusted computing and a medium, and belongs to the technical field of laboratory information safety management, and the method comprises the steps: measuring a starting chain through trusted hardware, uploading a measurement value after verification, completing multi-factor authentication and encryption channel establishment, and carrying out strategy conformity check; creating a resource isolated working space, loading a security policy in real time, and monitoring user behaviors and peripheral access; carrying out enhanced authentication and encryption verification transmission; and generating a tamper-proof chained auditing log, and automatically starting hierarchical response and joint treatment based on the log and a monitoring result to form a traceable responsibility judgment link. According to the invention, the operation environment of the terminal system is ensured to be credible based on the trusted computing root, multi-task isolation and data leakage prevention are realized by adopting a containerized digital workspace, authority control is implemented through an identity and task adaptive security policy, and the security event response capability and operation traceability are improved by means of real-time monitoring and auditing a log library.
Owner:YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD +1

Incident response support method and incident response support system

An incident response support system searches for the past case information based on a symptom and system information of the target system as an input of a natural language using a language model for generating an output in response to the input, and acquire the past case in which the symptom and the system information are coincident or similar. Then, the incident response support system groups the past case by the separation action included in the acquired past case using the language model, and outputs the grouped past case together with the separation action.
Owner:HITACHI LTD