Dynamic Processing Hierarchies for Cyber Incident Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated cyber incident management is infeasible due to the evolving nature of cyber incidents, which are designed to evade automatic detection, leading to a challenging and time-consuming process of updating and reviewing large quantities of data.

Innovation Solution

The implementation of dynamic processing hierarchies in cyber incident management systems, which allows for the transition between fully automated and partially manual processing tiers based on the characteristics of the cyber incident, enabling more agile and effective detection and resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated processing is used for all cyber incidents, then productivity is improved, but reliability deteriorates because cyber incidents are designed to evade automatic detection

Engineering Contradiction:
Improveincident processing speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically transitions between automated and manual processing modes based on incident characteristics. The cyber incident management system evaluates each incident and routes it to appropriate processing hierarchies, allowing the system to be agile and adapt to evolving incident types that may evade static automated detection rules.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple data structures with different processing hierarchies are maintained, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvehandling diverse incident typesVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments incident processing into multiple specialized data structures, each with its own processing hierarchy tailored to specific incident types. This allows each segment to be optimized for its particular function while the overall system manages complexity through modular organization of these segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides a universal framework that can handle diverse incident types through multiple processing hierarchies. The framework unifies the management of different data structures while allowing each to specialize in specific incident characteristics, achieving both versatility and manageable complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If playbooks are constantly updated to match evolving cyber incidents, then detection precision is improved, but loss of time increases due to the time-consuming update and review process

Engineering Contradiction:
Improveincident detection precisionVSAvoidplaybook update time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple processing hierarchies and data structures that can be rapidly activated based on incident characteristics. Rather than updating playbooks for each new incident type, the system has pre-prepared processing paths that can be selected and activated quickly, reducing the time loss associated with constant playbook updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12335316B2Methods and systems for processing cyber incidents in cyber incident management systems using dynamic processing hierarchies
Publication Date: 2025.06.17 CAPITAL ONE SERVICES LLC
  • US12335316B2 patent drawing
  • US12335316B2 patent drawing
  • US12335316B2 patent drawing

AI summary

Methods and systems are also described for an integrated cyber incident management system that may store native data corresponding to fields of cyber incident management system (or other non-integrated systems) and integration data (e.g., viewable through a user interface of the integrated cyber incident management system), which describes a relationship of the native data to the integrated cyber incident management system, at a structure node in the architecture of the integrated cyber incident management system. The structure node may correspond to the convergence of two structures in the architecture of the integrated cyber incident management system. Each structure may itself correspond to a native hierarchal relationship in a non-integrated cyber incident management system.