Cybersecurity Incident Response Utility Estimation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Forensic investigations of cybersecurity incidents are time-consuming and challenging due to the vast volume of innocuous occurrences, making it difficult to distinguish security problems from non-threatening events, which can lead to unchecked risks if the system remains functional or disruptive if quarantined prematurely.

Innovation Solution

A method and system that estimate the utility of investigating security events based on objective and subjective indicators, selecting key events for prioritization, and guiding investigators to focus on those likely to provide clues to the root cause and scope of the incident, using reputation, frequency, adjacency, and investigator interest data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If forensic investigators manually examine all security events to ensure thorough investigation, then investigation completeness is improved, but investigation time and resource consumption increase significantly

Engineering Contradiction:
Improveinvestigation completenessVSAvoidinvestigation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an automated utility estimation system that acts as an intermediary between raw security events and investigator attention. This system calculates utility scores based on multiple indicators (reputation, frequency, adjacency, investigator interest) and presents prioritized event lists, thereby mediating the information overload problem and enabling investigators to focus on high-value events without manual examination of all events

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of examining all security events with an automated computational system that estimates utility scores and ranks events. This substitution uses algorithms to process reputation data, frequency data, adjacency data, and investigator interest data, transforming the manual sorting and prioritization task into an automated information processing system

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If the system remains fully functional during security investigations, then system availability is improved, but security risks remain unchecked

Engineering Contradiction:
Improvesystem availabilityVSAvoidsecurity risk mitigation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by estimating the utility of investigating each security event before full investigation begins. By calculating utility scores based on reputation, frequency, adjacency, and investigator interest indicators in advance, the system identifies high-priority events that require immediate attention, enabling proactive security response while maintaining system operation for lower-priority events

Inventive Principle:
Principle #10Preliminary action

3Productivity

If investigators focus on high-priority events only, then investigation efficiency is improved, but risk of missing critical low-priority events increases

Engineering Contradiction:
Improveinvestigation efficiencyVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting the priority classification of security events based on multiple changing parameters including reputation data, frequency data, adjacency data, and investigator interest data. The utility estimation system continuously evaluates these parameters and updates event priorities, allowing the system to adapt to changing threat landscapes and investigator needs while maintaining comprehensive coverage

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3433995B1Systems and techniques for guiding a response to a cybersecurity incident
Publication Date: 2023.12.13 CARBON BLACK
  • EP3433995B1 patent drawingFigure 1~2
  • EP3433995B1 patent drawingFigure 3

AI summary

A cybersecurity engine can guide a forensic investigation of a security incident by estimating the utility of investigating events associated with the security incident, selecting a subset of such events based on the estimated utilities, and presenting data associated with the selected events to the investigator. A method for guiding a response to a security incident may include estimating, for each of a plurality of security events associated with the security incident, a utility of investigating the security event. The method may further include selecting a subset of the security events based, at least in part, on the estimated utilities of investigating the security events. The method may further include guiding the response to the security incident by presenting, to a user, data corresponding to the selected security events.