Cybersecurity Incident Response Utility Estimation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Forensic investigations of cybersecurity incidents are time-consuming and challenging due to the vast volume of innocuous occurrences, making it difficult to distinguish security problems from non-threatening events, which can lead to unchecked risks if the system remains functional or disruptive if quarantined prematurely.
Innovation Solution
A method and system that estimate the utility of investigating security events based on objective and subjective indicators, selecting key events for prioritization, and guiding investigators to focus on those likely to provide clues to the root cause and scope of the incident, using reputation, frequency, adjacency, and investigator interest data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If forensic investigators manually examine all security events to ensure thorough investigation, then investigation completeness is improved, but investigation time and resource consumption increase significantly
Solution Approach 1:
The patent introduces an automated utility estimation system that acts as an intermediary between raw security events and investigator attention. This system calculates utility scores based on multiple indicators (reputation, frequency, adjacency, investigator interest) and presents prioritized event lists, thereby mediating the information overload problem and enabling investigators to focus on high-value events without manual examination of all events
Solution Approach 2:
The patent replaces the manual mechanical process of examining all security events with an automated computational system that estimates utility scores and ranks events. This substitution uses algorithms to process reputation data, frequency data, adjacency data, and investigator interest data, transforming the manual sorting and prioritization task into an automated information processing system
2Productivity
If the system remains fully functional during security investigations, then system availability is improved, but security risks remain unchecked
Solution Approach 1:
The patent implements preliminary action by estimating the utility of investigating each security event before full investigation begins. By calculating utility scores based on reputation, frequency, adjacency, and investigator interest indicators in advance, the system identifies high-priority events that require immediate attention, enabling proactive security response while maintaining system operation for lower-priority events
3Productivity
If investigators focus on high-priority events only, then investigation efficiency is improved, but risk of missing critical low-priority events increases
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting the priority classification of security events based on multiple changing parameters including reputation data, frequency data, adjacency data, and investigator interest data. The utility estimation system continuously evaluates these parameters and updates event priorities, allowing the system to adapt to changing threat landscapes and investigator needs while maintaining comprehensive coverage
Data Source
Figure 1~2
Figure 3
AI summary
A cybersecurity engine can guide a forensic investigation of a security incident by estimating the utility of investigating events associated with the security incident, selecting a subset of such events based on the estimated utilities, and presenting data associated with the selected events to the investigator. A method for guiding a response to a security incident may include estimating, for each of a plurality of security events associated with the security incident, a utility of investigating the security event. The method may further include selecting a subset of the security events based, at least in part, on the estimated utilities of investigating the security events. The method may further include guiding the response to the security incident by presenting, to a user, data corresponding to the selected security events.