Entity-Based Incident Timelines for Cloud Security Investigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The sheer scale and complexity of cloud infrastructure log data make it difficult for security teams to extract actionable insights in real time, leading to slow response times and increased risk of misinterpretation or oversight in cybersecurity incidents.

Innovation Solution

A system that generates entity-specific timelines by querying actions of relevant entities in a cloud computing environment, including entity resolution, dynamic query generation, and interactive visualization to support rapid incident investigation and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional security incident response systems provide raw or semi-structured data, then data completeness is maintained, but investigator efficiency and response time deteriorate due to manual connection requirements

Engineering Contradiction:
Improveinvestigator efficiencyVSAvoiddata processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an automated incident response system that acts as an intermediary between raw security data and investigators. This system automatically connects disparate events, generates structured incident reports, and presents synthesized findings, thereby maintaining data completeness while eliminating manual connection work and improving investigator efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by automatically analyzing security data, connecting disparate events, and generating structured incident reports before investigators receive the data. This preliminary processing reduces the complexity investigators would otherwise face while maintaining complete data integrity.

Inventive Principle:
Principle #10Preliminary action

2Speed

If manual connection of disparate events is required, then data accuracy is maintained through human judgment, but response time deteriorates due to manual interpretation processes

Engineering Contradiction:
Improveresponse timeVSAvoidoperational simplicity
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The system performs self-service by automatically connecting disparate events, interpreting security data, and generating incident reports without requiring manual human judgment for each connection. This automation dramatically reduces response time while maintaining operational simplicity through standardized processing algorithms.

Inventive Principle:
Principle #25Self-service

3Reliability

If vast volumes of logs and telemetry data are collected, then detection capability is improved, but information extraction difficulty increases due to data scale and complexity

Engineering Contradiction:
Improvedetection capabilityVSAvoidactionable insights extraction
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies extraction by automatically identifying and extracting actionable insights from vast volumes of logs and telemetry data. The system filters out noise, connects relevant events, and presents only the critical information needed for incident response, thereby maintaining detection capability while dramatically reducing the difficulty of extracting actionable insights.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12563089B1Techniques for cybersecurity incident investigation utilizing timeline generation based on entity queries
Publication Date: 2026.02.24 WIZ INC
  • US12563089B1 patent drawing
  • US12563089B1 patent drawing
  • US12563089B1 patent drawing

AI summary

A system and method for entity-based timeline generation in cybersecurity investigation and remediation of detected issues thereof is presented. The method includes: receiving an incident record, wherein the incident record is generated based on a cybersecurity incident in a cloud computing environment; extracting a plurality of entities from the incident record, each entity deployed in at least the cloud computing environment; generating an entity-specific query for each of the plurality of entities extracted from the incident record; generating a timeline data structure based on at least a result of executing an entity-specific query, wherein the timeline data structure includes a user interface configured to receive a user input; and initiating a remediation action in the cloud computing environment, the remediation action selected from the user interface.