Automated Incident Response System for Cybersecurity Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity incident response systems often rely on external threat detection and response, which can be inefficient and may not effectively address ongoing threats.

Innovation Solution

The system implements an automated incident response method where incident detection signals are transmitted to an automated response system, allowing for real-time analysis of threat properties and determining appropriate responses based on threat severity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external threat detection systems are used to identify cybersecurity incidents, then threat detection capability is provided, but response efficiency is reduced due to reliance on external systems

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an automated response system as an intermediary between external threat detection systems and the computer system. This intermediary receives incident detection signals from external systems, analyzes them locally, and automatically executes responses without waiting for external system actions, thereby reducing response time while maintaining detection reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system pre-configures multiple predetermined responses to different types of cybersecurity incidents and stores them in a database. When an incident is detected, the system quickly matches the incident to a pre-prepared response rather than creating one from scratch, enabling rapid automated response while relying on external systems for initial threat detection

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive incident analysis is performed to determine appropriate responses, then response accuracy is improved, but processing time increases

Engineering Contradiction:
Improveresponse accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-analyzes and categorizes different types of cybersecurity incidents, storing predetermined responses with associated confidence levels in a database. This preliminary preparation allows the system to quickly match detected incidents to appropriate responses without performing comprehensive analysis from scratch, maintaining accuracy while reducing processing time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated response system performs self-analysis by evaluating incident detection signals against stored incident patterns and automatically selecting appropriate responses based on confidence levels. This self-service capability eliminates the need for lengthy manual or external system analysis, providing both accuracy and speed

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12294607B2Method and system for determining an automated incident response
Publication Date: 2025.05.06 GRP IB GLOBAL PTE LTD
  • US12294607B2 patent drawing
  • US12294607B2 patent drawing
  • US12294607B2 patent drawing

AI summary

A method and a system of responding to a cybersecurity incident are disclosed. The method comprises: receiving incident data of at least one incident from a given computer system; analyzing the incident data of the at least one incident, including determining whether the at least one incident has been prevented before; in response to determining that the at least one incident has not been prevented yet in the given computer system, determining, based on the incident data, a threat severity of the at least one incident; and in response to the threat severity of the at least one incident exceeding a predetermined threat severity threshold, determining, based on the incident data, one or more responses to the at least one incident for responding thereto in the given computer system.