Dynamic Processing Hierarchies for Cyber Incident Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated cyber incident management is infeasible due to the evolving nature of cyber incidents, which are designed to evade automatic detection, leading to a challenging and time-consuming process of updating and reviewing large quantities of data.
Innovation Solution
The implementation of dynamic processing hierarchies in cyber incident management systems, which allows for the transition between fully automated and partially manual processing tiers based on the characteristics of the cyber incident, enabling more agile and effective detection and resolution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated processing is used for all cyber incidents, then productivity is improved, but reliability deteriorates because cyber incidents are designed to evade automatic detection
Solution Approach 1:
The system dynamically transitions between automated and manual processing modes based on incident characteristics. The cyber incident management system evaluates each incident and routes it to appropriate processing hierarchies, allowing the system to be agile and adapt to evolving incident types that may evade static automated detection rules.
2Adaptability or versatility
If multiple data structures with different processing hierarchies are maintained, then adaptability is improved, but device complexity increases
Solution Approach 1:
The system segments incident processing into multiple specialized data structures, each with its own processing hierarchy tailored to specific incident types. This allows each segment to be optimized for its particular function while the overall system manages complexity through modular organization of these segments.
Solution Approach 2:
The system provides a universal framework that can handle diverse incident types through multiple processing hierarchies. The framework unifies the management of different data structures while allowing each to specialize in specific incident characteristics, achieving both versatility and manageable complexity.
3Measurement precision
If playbooks are constantly updated to match evolving cyber incidents, then detection precision is improved, but loss of time increases due to the time-consuming update and review process
Solution Approach 1:
The system performs preliminary actions by pre-configuring multiple processing hierarchies and data structures that can be rapidly activated based on incident characteristics. Rather than updating playbooks for each new incident type, the system has pre-prepared processing paths that can be selected and activated quickly, reducing the time loss associated with constant playbook updates.
Data Source
AI summary
Methods and systems are also described for an integrated cyber incident management system that may store native data corresponding to fields of cyber incident management system (or other non-integrated systems) and integration data (e.g., viewable through a user interface of the integrated cyber incident management system), which describes a relationship of the native data to the integrated cyber incident management system, at a structure node in the architecture of the integrated cyber incident management system. The structure node may correspond to the convergence of two structures in the architecture of the integrated cyber incident management system. Each structure may itself correspond to a native hierarchal relationship in a non-integrated cyber incident management system.


