Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

47 results about "Incident response" patented technology

An incident response team or emergency response team (ERT) is a group of people who prepare for and respond to any emergency incident, such as a natural disaster or an interruption of business operations. Incident response teams are common in public service organizations as well as in organizations. This team is generally composed of specific members designated before an incident occurs, although under certain circumstances the team may be an ad hoc group of willing volunteers.

Real-Time Anomaly Prediction Using Extrapolated Telemetry Data

Systems and methods are disclosed for real-time anomaly prediction using near real-time data. The invention addresses delays in telemetry data collection from infrastructure components, by collecting metrics and logging this data in real-time. Extracted logged data undergoes initial analysis to identify patterns and anomalies, followed by cleaning to remove noise and errors. Feature engineering enhances the data, creating or modifying features to improve machine learning model performance. The system calculates weighted means of previous data values and computes first and second-order differences to capture immediate changes and trends. These calculations adjust the extrapolated value to accurately reflect current conditions. The adjusted data is integrated into the dataset and validated. The validated data trains and tests a machine learning model, which is then finalized and deployed for real-time anomaly detection. This system ensures accurate and timely anomaly prediction, enabling automated incident response to maintain the reliability and performance of infrastructure components.
Owner:BANK OF AMERICA CORP

Database system incident evaluation, classification, and resolution system

A computing services environment may include a database system, a vector store, a generative language model interface, and / or an incident response system. The database system may be configured to detect a database system incident affecting database system availability or performance and to generate a database incident report characterizing the database system incident. The generative language model interface may be configured to determine a textual description of the database system incident and identify one or more records of the plurality of records by completing an incident evaluation prompt via a generative language model. An incident response engine may be configured to determine an instruction to resolve the database incident based on the textual description and the one or more records, wherein the database system is configured to execute the instruction to update one or more configuration parameters.
Owner:SALESFORCE INC

Map-based emergency call management and dispatch

An emergency response system provides a map-based interface for a telecommunicator to view information about an incident and coordinate a response to the incident. The emergency response system gathers supplemental data regarding locations and other information that may be relevant in assisting with the incident. The interface may automatically select relevant supplemental information based on the incident and provide this incident-specific information for display on the interface. The user may then select a response on the interface such as a unit to dispatch that the system automatically implements, providing unified information and control for incidents, supplemental information, and incident response.
Owner:RAPIDDEPLOY INC

Response vehicle systems and methods

An incident response system can one or more processing circuits. The one or more processing circuits can acquire data from a communication device, receive an indication that a response vehicle is set to leave or has left a location proximate to an incident, and transmit a message to a server including the indication that the response vehicle is set to leave or has left the location proximate to the incident.
Owner:OSHKOSH CORPORATION

A Rapid Response Method and System for Traffic Incidents Based on Multi-Source Data Fusion

This application provides a method and system for rapid response to traffic incidents based on multi-source data fusion, relating to the field of traffic incident response technology. The method includes: extracting traffic feature vectors from multi-source traffic data for multi-source fusion calculation; determining whether abnormal traffic incidents exist in the fused situational data; when abnormal traffic incidents exist, determining the type and locating the information; generating an initial response plan based on the determined type and location information; pushing the initial response plan to the handling department's terminal and receiving execution status information from the handling department; recording the timestamps and operation logs of the entire process, and evaluating the effectiveness of this response process. This application addresses the technical problem of lacking multi-source traffic data fusion analysis in existing technologies, enabling rapid response to traffic incidents based on multi-source traffic data fusion, and achieving the technical effect of improving the accuracy of traffic incident identification.
Owner:INTELLIGENT INTER CONNECTION TECH CO LTD

Security event response system and method based on intelligent analysis

The invention discloses a security event response system and method based on intelligent analysis, and relates to the technical field of network security, an asset business load integrated digital model is constructed, a cross-domain attack surface is identified based on cross-environment asset interaction data in the integrated digital model, and basic data support for subsequent simulation and reasoning is formed; based on the obtained asset, business and cross-domain attack surface data, an attack framework and a dynamic attacker portrait are fused to construct a causal knowledge graph, the causal relationship of unknown attacks is complemented through transfer learning and an unsupervised algorithm, and the causal knowledge graph is updated according to the dynamic change of the environment; according to the method, the conversion of the security event from passive tracing to active prediction is realized, high-risk threats are identified in advance through cross-domain attack path simulation and risk quantification, and the defense initiative is improved.
Owner:中交京津冀投资发展有限公司 +1

Connecting natural and security language in the embedding space for better threat hunting and incident response

Methods and apparatuses for improving the speed, quality, and relevance of automated responses provided by a question answering system for security data are described. The question answering system may generate and utilize a large language model that is trained to combine the language of security data, such as the language found in security logs and alerts, with natural language text. Given an input prompt (or a search query) from an end user of the question answering system, the question answering system may identify relevant content from the security data and display a response based on the relevant content. The question answering system may allow the end user of the question answering system to query security logs using natural language text without requiring the end user to provide a structured query and without requiring the security data be parsed and ingested into a database system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network security event response techniques using artificial intelligence

Systems and methods for providing cyber-security event responses are presented. The method includes providing the received event input into a large language model (LLM); mapping the received event input into a scene of a plurality of scenes based on an output of the LLM, each scene comprising a plurality of sub-scenes; receiving a user input through a user interface, the user interface configured to present a graphical representation of a set of sub-scenes of the plurality of sub-scenes; selecting a sub-scene based on the received event input; generating a query based on the received event input and a selection of a sub-scene of the plurality of sub-scenes; executing the query on a secure database, the secure database comprising a representation of the computing environment; and initiating a mitigation action based on a result of the executed query.
Owner:WIZ INC

Containers-Based Forensics for Persistent and Stateless Containers

Comprehensive systems and methods for conducting digital forensics and incident response in containerized computing environments. The system converts stateless containers into persistent containers to prevent automatic termination during forensic investigations. It quarantines the containers using virtual switches and firewalls, captures detailed forensic data including snapshots of all filesystem layers, kernel syscalls, and process data, and mirrors network traffic for secure analysis. The system retrieves logs and artifacts from current and previous nodes, correlates and compares this data using machine learning algorithms, and securely duplicates all artifacts to immutable storage. Automated orchestration ensures consistent execution of forensic processes, and the system reverts containers to their original stateless state post-investigation. A detailed audit log and secure archival of all forensic data are maintained for future reference or legal compliance. The invention addresses the unique challenges of securing and analyzing data in dynamic, distributed containerized environments.
Owner:BANK OF AMERICA CORP

Methods for non-invasive API discovery, monitoring and exploitation detection in third-party processes

System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.
Owner:WALLARM INC

Hardware-Anchored DAO Governance Engine with Quantum-Resistant Attestation

PendingUS20260205302A1BiotechnologyByzantine fault tolerance
Every major DAO governance failure traces to a common root cause: governance logic, voting, and treasury access reside in software that adversaries can reach. The disclosed invention provides a hardware-anchored DAO governance architecture defeating five adversary classes. A supply-chain attestation layer verifies firmware integrity against a public transparency log at node initialization. A Silicon Root-of-Trust Anchor Layer binds governance to processor-embedded cryptographic keys. A Heterogeneous TEE Orchestration Layer enforces Byzantine fault-tolerant canonical quorum through threshold BLS signatures across independent hardware architecture families. An Atomic Governance Transition Engine executes indivisible state changes: record incorporation, key destruction, counter advancement, and IOMMU treasury isolation. A Quantum-Resistant Governance Key Lifecycle Engine performs CRYSTALS-Kyber (ML-KEM, FIPS 203) key rotation with cryptographic agility. A Cross-Chain Governance Attestation Bridge publishes TEE-signed proofs to multiple blockchains. A Deterministic Governance Replay Engine reconstructs governance decisions in isolated sandboxes. An Automated Governance Incident Response Engine and Governance Regulator Verification Network provide hardware-enforced, independently auditable compliance enforcement.
Owner:BICKERSTAFF III GEORGE WILLIAM

Incident response system and incident response method

An incident response system and an incident response method [that] are able to generate and configure a processing workflow that includes a combination of external systems and individual processing components depending on the type of risk in order to respond to individual incidents. The incident response system, which responds to the individual incidents, includes a playbook DB, a playbook selection section, a workflow generation section, and a workflow engine section. The playbook DB stores processing workflows which are response flows for incidents of risks, as playbooks for individual types of risks. The playbook selection section acquires incident information regarding an incident that has occurred or appears to occur, and extracts a corresponding one of the playbooks that is appropriate for the incident from the playbooks created for the individual types of risks. The workflow generation section generates the processing workflows appropriate for the individual incidents incident.
Owner:HITACHI LTD

Action response framework for data security incidents

An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and / or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.
Owner:WORKDAY INC

Incident response notification system

PendingUS20260255142A1EngineeringService usage
An incident response notification system may be provided by receiving, at a central service from a wireless communication device associated with a sensor deployed in an environment with a plurality of sensors, a status report; verifying, by the central service, a location of the sensor in the environment; updating, by the central service, a map of the environment with the status report; processing, by the central service, pending status reports, including the status report, to identify an incident flow; generating, by the central service, a reaction plan based on the map and the incident flow; and outputting, via the central service, the reaction plan.
Owner:SUBRAHMANYAM PILAKA VENKATA

Property security event processing method, system and electronic device

PendingCN122551527AThe InternetSpatial database
This application relates to the technical fields of property management and the Internet of Things, and discloses a method, system, and electronic device for handling property security incidents. The method includes: acquiring property security incident information, wherein the incident information includes the incident type and a spatially unique identifier for the alarm device; querying a spatial database based on the spatial unique identifier to determine the spatial information of the space where the alarm device is located; determining the risk level by performing a risk assessment using a preset event spatial risk matrix based on the incident type and spatial information; triggering a corresponding tiered response plan according to the risk level; and handling the property security incident based on the tiered response plan. This method can improve the accuracy of property security incident response.
Owner:CHENGDU XUMI YUNTU ARCHITECTURAL DESIGN CO LTD

Smart Incident Response

PendingUS20260127515A1InstrumentsMedicineBus
An event management bus is configured to ingest events from a plurality of monitoring tools at a defined acceptance rate. Events received in excess of the acceptance rate are rejected, and a rejection notification is transmitted. For an ingested event, an incident is triggered. A machine-learning model, selected based on a determined incident type, initiates a process to identify a resolution for the incident. An action determined as a result of the process is executed by an action execution tool. Feedback data indicating the effectiveness of the executed action in resolving the incident is received. The machine-learning model is then retrained using the feedback data.
Owner:PAGERDUTY INC

Attack source identification system and method based on open source network real-time monitoring

The invention aims to provide an attack source identification system and method based on open source network real-time monitoring. The system comprises a data acquisition module, a data standardization module, an information addition module, a clustering module and an attack association analysis module. The data acquisition module is used for acquiring IOC data from multiple ways; the data standardization module is used for performing standardization formatting processing on the IOC data; the information adding module is used for adding context information based on the standardized IOC data; the clustering module is used for performing clustering analysis on the IOC data; and the attack association analysis module counts the clustering result and the APT organization association degree and outputs an association result. According to the method, the scattered IOC and the specific APT organization can be associated and attributed, the attack link of the IOC can be possibly output, and deep and actionable context intelligence is provided for threat hunting and event response.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT GUANGXI BRANCH

Laboratory digital safety workspace management method, system and equipment based on trusted computing and medium

The invention discloses a laboratory digital safety workspace management method, system and device based on trusted computing and a medium, and belongs to the technical field of laboratory information safety management, and the method comprises the steps: measuring a starting chain through trusted hardware, uploading a measurement value after verification, completing multi-factor authentication and encryption channel establishment, and carrying out strategy conformity check; creating a resource isolated working space, loading a security policy in real time, and monitoring user behaviors and peripheral access; carrying out enhanced authentication and encryption verification transmission; and generating a tamper-proof chained auditing log, and automatically starting hierarchical response and joint treatment based on the log and a monitoring result to form a traceable responsibility judgment link. According to the invention, the operation environment of the terminal system is ensured to be credible based on the trusted computing root, multi-task isolation and data leakage prevention are realized by adopting a containerized digital workspace, authority control is implemented through an identity and task adaptive security policy, and the security event response capability and operation traceability are improved by means of real-time monitoring and auditing a log library.
Owner:YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD +1

Incident response support method and incident response support system

An incident response support system searches for the past case information based on a symptom and system information of the target system as an input of a natural language using a language model for generating an output in response to the input, and acquire the past case in which the symptom and the system information are coincident or similar. Then, the incident response support system groups the past case by the separation action included in the acquired past case using the language model, and outputs the grouped past case together with the separation action.
Owner:HITACHI LTD

Method of generating a trigger initiating an emergency incident response workflow

A computer-implemented method of generating a trigger initiating an emergency incident response workflow and a device implementing the method is disclosed. Emergency notification data associated with at least one emergency notification reporting a first incident is received. Based on the emergency notification data, a first sensor data originating from one or more sensors is retrieved, the first sensor data associated with a time and location of the first incident. At least one alarm-escalating trigger is generated. The alarm escalating trigger comprises an alarm-escalating condition and a first-type emergency incident response workflow, the alarm-escalating condition being based on at least a portion of the first sensor data. The alarm-escalating trigger, when implemented by an implementing device, triggers the first-type emergency incident response workflow in response to receiving a second sensor data originating from one or more implementing sensors, the second sensor data meeting the alarm-escalating condition.
Owner:MOTOROLA SOLUTIONS INC

Automated engagement of technical incident response teams using artificial intelligence

Methods and apparatuses for automated engagement of technical incident response teams using artificial intelligence include a server that receives an incident response request including unstructured computer text comprising a description of an active technical incident and a requested incident response team. The server converts the unstructured computer text into a first vector and compares the first vector to historical vectors generated from incident descriptions contained in historical incident tickets, each historical incident ticket having an assigned incident response team. The server generates a similarity score for each historical incident ticket based upon the comparison between the corresponding historical vector and the first vector and identifies proposed incident response teams using the assigned teams from the historical incident tickets that have a similarity score above a threshold. The server connects to computing devices of team members on the proposed teams to establish a communication channel for the active technical incident.
Owner:FMR CORP

Network security event response device

PendingCN121876286Aachieve regulatory effectsmooth meshingStands/trestlesAlarmsControl engineeringSlide plate
The invention relates to the technical field of network security, and discloses a network security event response device, which comprises a response device body, the response device body comprises an adjusting seat, the bottom of the inner wall of the adjusting seat is fixedly connected with a servo motor, the output end of the servo motor is fixedly connected with an adjusting screw rod, and the adjusting screw rod is fixedly connected with the adjusting seat. And the bottom of the surface of the adjusting screw rod is in threaded connection with an adjusting screw sleeve. According to the network security event response device, an adjusting screw rod is driven to rotate through a servo motor, an adjusting screw sleeve is moved through rotation of the adjusting screw rod, a side block is driven to move through movement of the adjusting screw sleeve, a sliding plate is driven to move through movement of the side block, an adjusting column is moved through movement of the sliding plate, and an alarm can be moved through movement of the adjusting column; the adjusting effect can be achieved, and the problems that due to limitation of the height and angle of an existing response device, response is not timely enough, and the safety performance of the response device is greatly reduced are solved.
Owner:SHANGHAI BOJUN ELECTRONIC TECHNOLOGY CO LTD

Adaptive security event response method and system based on AI agent

This application relates to an adaptive security incident response method and system based on an AI agent, belonging to the field of cybersecurity. It includes: in the incident perception phase, the AI ​​agent obtains a first incident to be evaluated based on real-time collected multi-source network security data; in the risk assessment phase, the AI ​​agent obtains an attack graph of the network, performs adaptive risk analysis on multiple paths of the first incident to be evaluated within the attack graph, and obtains a secure path for the first incident to be evaluated; in the intelligent decision-making phase, the AI ​​agent generates a response decision for the first incident to be evaluated based on the secure path; and in the response execution phase, the AI ​​agent executes corresponding security protection actions based on the response decision. This application can improve the response efficiency of cybersecurity, reduce reliance on and intervention by humans, promptly perceive security incidents, prevent the expansion of network asset losses, and is applicable to large-scale and diverse cybersecurity protection scenarios, thereby improving the protection capabilities against emerging threats.
Owner:BEIJING HUAQING XINAN TECH CO LTD

Early incident response support system and early incident response support method

To efficiently support examination of initial response to an incident.SOLUTION: The present application relates to an initial incident response support system for supporting an initial response to an incident detected in a plant facility. The initial incident response support system acquires incident information related to an incident, and creates initial incident information for examining an initial response based on the incident information. The initial incident information is output to at least one display terminal that can be referred to by a plurality of staff members in charge of initial response.SELECTED DRAWING: Figure 3
Owner:MITSUBISHI HEAVY IND LTD

Pattern analysis threat detection engine

ActiveUS12676868B2EngineeringData mining
A network system of pattern analysis includes a centralized AI-based pattern analysis engine and each computing device comprises a local AI-based pattern analysis engine. The pattern analysis engine(s) each analyze computing operations on a local machine basis or a on a network basis depending on where installed. The AI-based pattern analysis engines identify common activity patterns for each machine and exclude the common activity patterns from further analysis of the computing operations, leading to more efficient identification of activity patterns indicative of nefarious activity. Once detected, the AI-based pattern analysis engines trigger an incident response to counter the nefarious activities. The AI-based pattern analysis engines include AI models that are continually or periodically trained to update the baseline common activity patterns.
Owner:BANK OF AMERICA CORP

Smart urban management system

The present disclosure provides a system to manage and secure a facility comprising an interconnected network of sensors and IoT devices. The system comprises a backend server adapted to collect data from the network, the server comprising data processing modules including: a machine learning module configured to process collected data using AI algorithms to identify patterns, detect anomalies, and generate insights; an environmental learning module configured to analyze insights, monitor environmental factors, and develop adaptive strategies for sustainable resource utilization; a data governance module configured to classify and manage collected data according to predefined protocols, ensuring data integrity and compliance; and a communication module configured to monitor network traffic, isolate anomalies, and implement real-time event-action protocols for incident response. The system comprises a centralized management platform adapted to receive output from the processing modules and present real-time insights.
Owner:BJONTEGARD BERNT ERIK +1

Registry control for incident response

Systems and methods for management of registry data within a computing environment, for example using a dual cache mechanism. The method comprises use of a fast registry cache and a persistent registry cache to manage different aspects of the registry call information. The method further comprises integration of the registry call information with endpoint detection and response support.
Owner:ACRONIS INT

System and method for collaborative smart evidence gathering and investigation for incident response, attack surface management, and forensics in a computing environment

ActiveUS12566844B2Platform integrity maintainanceSimilarity analysisEngineering
A system and method for collaborative smart evidence gathering and investigation for incident response attack surface management and forensics in a computing environment is disclosed. The system obtains evidence data from multiple sources with various entry points, capturing contextual information. Further, the system processes the data using an artificial intelligence (AI) root cause analysis, graph augmented retrieval, semantic classifier, meaning extraction, and causal discovery model. Furthermore, the system performs similarity analysis to assess evidence quality, sufficiency, and completeness. Based on the evaluation, the system determines appropriate actions to be taken on the processed evidence data. Additionally, the system executes the actions to resolve the incidents effectively by using a smart expert system, a human agent participation, or an AI co-pilot, as a first-class investigator and collaborator in the process.
Owner:UNO AI INC