Cyber Threat Analysis Framework with Dynamic Incident Timeline

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber threat analysis frameworks face challenges in efficiently collecting and providing analysis and remediation action information to clients, which can lead to decreased efficiency in the remediation process and increased prevalence of cyber threats due to delays.

Innovation Solution

A computing platform generates an enhanced cyber threat analysis framework that collects cyber threat investigation information in real time through a threat framework interface and provides a client interface with a time-series graphical representation of actions taken, allowing clients to view the incident response lifecycle dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If analysts manually record analysis and remediation action information, then clients can access this information, but the efficiency of the cyber threat remediation process decreases due to delays

Engineering Contradiction:
Improveclient access to analysis informationVSAvoidremediation process efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system automatically captures and stores analysis and remediation action information in real-time as analysts perform their work, without requiring preliminary manual recording. The threat framework interface continuously collects data about actions taken, ensuring information is available to clients while not interrupting the remediation workflow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs automatic documentation of the remediation process without requiring analyst intervention. The threat framework interface self-records all analysis and remediation actions, eliminating the burden on analysts to manually document their work while ensuring complete information capture for client access.

Inventive Principle:
Principle #25Self-service

2Productivity

If analysts focus on immediate threat remediation without recording information, then remediation efficiency increases, but clients cannot access analysis information or provide feedback

Engineering Contradiction:
Improveremediation speedVSAvoidclient access to remediation information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system maintains continuous automatic recording of remediation actions throughout the entire incident response lifecycle. The threat framework interface operates continuously in the background, capturing all analyst actions and remediation steps without interruption, ensuring both rapid remediation execution and complete information availability to clients.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The threat framework interface acts as an intermediary between the analyst's remediation actions and client information access. It automatically captures actions performed by analysts and makes this information available to clients through the computing platform, eliminating the need for analysts to manually bridge this information gap.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a traditional manual information collection system is used, then clients can receive updates, but the complexity of the system increases and delays occur

Engineering Contradiction:
Improveclient information accessVSAvoidinformation collection system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system merges the information collection, storage, and dissemination functions into a single integrated threat framework interface. This unified system automatically captures remediation actions, stores them centrally, and provides real-time access to clients through the computing platform, eliminating the need for multiple separate manual processes and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The threat framework interface serves multiple functions simultaneously: it monitors threats, tracks analyst remediation actions, stores information, and provides real-time updates to clients. This multi-functional design consolidates what would otherwise require separate systems into one universal platform, reducing complexity while improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250106229A1Automated incident response tracking and enhanced framework for cyber threat analysis
Publication Date: 2025.03.27 TRUSTWAVE HOLDINGS INC
  • US20250106229A1 patent drawing
  • US20250106229A1 patent drawing
  • US20250106229A1 patent drawing

AI summary

Several features of cybersecurity frameworks are disclosed. In one example, a computing platform receives, from an enterprise user device, cyber threat investigation information indicating actions performed to address an identified threat for a client through an incident response lifecycle of the identified threat. This computing platform receives, from a client user device, a request for the cyber threat investigation information, and generates, using this cyber threat investigation information, a client interface, which includes a time-series graphical representation of the actions performed to address the identified threat and a play button, selection of which may cause automated progression through the time-series graphical representation within the client interface. This computing platform sends, to the client user device, the client interface and commands to display the client interface, which may cause the client user device to display the client interface.