Cybersecurity Playbook Generation via Feature Space Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity incident response systems, such as the IncMan platform, face challenges in providing tailored responses to incidents due to limitations in playbook selection and customization, particularly in handling complex features and metrics, and require manual user effort to aggregate similar incidents, which is time-consuming and knowledge-intensive.

Innovation Solution

The system employs a custom machine learning approach that re-engineers feature computation to handle complex features, implements a parent matching algorithm, and updates feature weights based on user feedback, enabling automated playbook generation and parent recommendation, thereby improving the efficiency and accuracy of incident response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual user effort is used to aggregate similar incidents, then incident aggregation can be performed, but it is time-consuming and knowledge-intensive

Engineering Contradiction:
Improveautomated incident aggregationVSAvoidtime for manual aggregation
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical aggregation processes with an automated machine learning system that computes feature-based similarities between incidents. The system automatically identifies and groups similar incidents using computational algorithms, eliminating the need for manual user effort and significantly reducing the time required for incident aggregation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables incidents to be automatically aggregated through self-service mechanisms where the machine learning model autonomously processes incident data, computes similarities based on featured fields, and performs grouping without requiring user intervention. This self-organizing capability allows the system to continuously improve its aggregation accuracy over time.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If pre-constructed playbooks are selected based only on incident type, then playbook selection is simplified, but other incident fields are not taken into account reducing customization accuracy

Engineering Contradiction:
Improveplaybook selection processVSAvoidplaybook matching accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent transforms the playbook selection process by changing the parameters used for matching from simple incident type classification to a multi-dimensional feature-based approach. The system computes similarities across multiple incident fields (parameters) and uses these computed similarities to select and customize playbooks, thereby improving matching accuracy while maintaining ease of operation through automated processing.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system dynamically adjusts playbook selection and customization based on real-time computation of incident similarities. Rather than using static type-based matching, the system dynamically evaluates multiple incident fields and adapts playbook recommendations based on the computed similarity scores, enabling both ease of operation and high precision simultaneously.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If custom machine learning system generates tailored playbooks using multiple incident fields, then playbook customization accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveplaybook customization accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex machine learning system into distinct functional modules: feature extraction modules that process individual incident fields, similarity computation modules that calculate distances between incidents, and playbook generation modules that create customized responses. This segmentation manages system complexity by organizing functions into independent, manageable components while maintaining high customization accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs universal machine learning algorithms and data structures that can handle multiple incident fields and various similarity metrics through a unified framework. This multi-functional approach allows the system to process different types of incident data using the same core methodology, reducing overall system complexity while achieving high customization accuracy across diverse scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If feature weights are updated based on user feedback, then system adaptability is improved, but additional processing steps are required

Engineering Contradiction:
Improvesystem adaptability to user preferencesVSAvoidfeedback processing mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where user interactions with generated playbooks are captured and used to update feature weights in the machine learning model. This feedback loop allows the system to learn from user preferences and continuously improve its incident similarity computations and playbook generation, enhancing adaptability while managing complexity through automated feedback processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11695798B2Cybersecurity incident response and security operation system employing playbook generation and parent matching through custom machine learning
Publication Date: 2023.07.04 SUMO LOGIC INC
  • US11695798B2 patent drawing
  • US11695798B2 patent drawing
  • US11695798B2 patent drawing

AI summary

A cybersecurity incident is registered at a security incident response platform. At a playbook generation system, details are received of the cybersecurity incident from the security incident response platform. At least some of the details correspond to a set of features of the cybersecurity incident. A set or subset of nearest neighbors of the cybersecurity incident is localized in a feature space. The nearest neighbors of the cybersecurity incident are other cybersecurity incidents having a distance from the cybersecurity incident within the feature space that is defined by differences in features of the nearest neighbors with respect to the set of features of the cybersecurity incident. A playbook is created for responding to the cybersecurity incident having prescriptive procedures based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents. The differences in features of the nearest neighbors with respect to the set of features of the cybersecurity incident are calculated, for at least one feature, using a present-or-equal metric, and for at least one other feature, using a symmetric difference metric. The playbook generation system is also a parent recommendation system, which identifies a parent for the cybersecurity incident, based on distances of the nearest neighbors of the cybersecurity incident in the feature space. The parent recommendation system adjusts, based on the recommended parent or the parent other than the recommended parent being selected, weights of features upon which distances in the feature space are based.