Automated Cybersecurity Alert Triage and Remediation Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity incident response processes are manual, slow, and prone to errors, as they lack automated tools for accurate and efficient alert triage, enrichment, and remediation, leading to inconsistent adherence to processes and inadequate documentation.

Innovation Solution

An automated cybersecurity alert triage ranking engine and expert assessment and remediation system that parses and ranks alerts, enriches them with contextual data, and performs dynamic re-ranking, using machine learning to automatically take remedial actions and inform users via email, with customizable algorithms and integrated expert systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual incident response processes are used, then human flexibility and intelligence can be applied, but the process becomes slow and error-prone

Engineering Contradiction:
Improveaccuracy of alert processingVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service through purpose-built tools that automatically parse, enrich, rank, and remediate security alerts without requiring manual human intervention for each alert, thereby improving both speed and accuracy simultaneously

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical processes of alert analysis and remediation are replaced with automated computational systems including machine learning models, expert systems, and scripted workflows that process alerts consistently and rapidly without human error

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual alert processing is performed, then human judgment can be applied, but consistency and documentation are inadequate

Engineering Contradiction:
Improveconsistency of process adherenceVSAvoidalert processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated system performs alert processing consistently according to predefined rules and machine learning models, eliminating variability in human judgment while maintaining documentation through automated logging and auditing capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where machine learning models are continuously trained on historical alert data and outcomes, improving consistency and accuracy over time while automated documentation tracks all processing decisions for auditing purposes

Inventive Principle:
Principle #23Feedback

3Productivity

If non-purpose built tools are used, then existing resources can be leveraged, but accuracy and speed are insufficient

Engineering Contradiction:
Improvealert processing speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent integrates multiple functions including alert parsing, enrichment, ranking, and remediation into a single purpose-built automated incident response platform, reducing the need for multiple separate tools while improving processing speed and accuracy

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges previously separate manual processes and tools into an integrated automated workflow where alert parsing, enrichment from multiple sources, machine learning-based ranking, and remediation actions are combined into a unified system that improves throughput without proportionally increasing complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10873596B1Cybersecurity alert, assessment, and remediation engine
Publication Date: 2020.12.22 SWIMLANE INC
  • US10873596B1 patent drawing
  • US10873596B1 patent drawing
  • US10873596B1 patent drawing

AI summary

The invention includes a computerized method for interfacing with a security hardware appliance for assessing potential remedial action in response to a potential information security threat by automatically ingesting and parsing incoming alerts from a security hardware appliance, automatically extracting relevant data elements from the alert, using the extracted information to supplement the alert by querying and retrieving from other systems, and automatically ranking the alerts in terms of importance using an engine that combines information, and issuing a command to take remedial, containment, or other programmed action on the alerts automatically.