Incident Manager Action Framework for Automated Security Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current incident management systems in enterprise networks face delays and inefficiencies in responding to data security incidents, particularly due to manual task creation and execution by Incident Response Team members, which can lead to increased costs and damage from self-replicating threats like malware, and do not scale with the growing number of subnetworks and devices.

Innovation Solution

A client/server-based action response framework within an Incident Manager application that automatically tracks and stores incident data, defines action conditions, and sends messages to devices for automated incident responses, using action scripts to execute actions on both message-enabled and non-message-enabled devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual task creation and execution by Incident Response Team members is used, then incident tracking capability is provided, but response delay increases and efficiency decreases

Engineering Contradiction:
Improveincident tracking capabilityVSAvoidresponse delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures action conditions and associated responses in advance. When an incident matches a predefined condition, the corresponding action is automatically executed without waiting for manual intervention. This preliminary setup of response protocols eliminates the time lag between incident detection and response execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The incident management system automatically executes responses without requiring Incident Response Team members to manually create and carry out tasks. The system self-services by autonomously matching incidents to predefined conditions and executing appropriate actions, thereby eliminating manual labor while maintaining reliable incident tracking.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual task creation and execution is used, then incident response capability is provided, but error rate increases due to manual operations

Engineering Contradiction:
Improveincident response capabilityVSAvoiderror rate
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system replaces manual mechanical operations with automated computer-based execution. Instead of Incident Response Team members manually creating and executing tasks, the system automatically matches incidents to predefined conditions and executes corresponding actions through software, eliminating human errors associated with manual operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs incident response execution autonomously without human intervention. By self-service automation, the system eliminates the possibility of manual errors in task creation and execution while maintaining the essential incident response capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If current incident management systems are used, then basic incident tracking is provided, but scalability is limited when the number of subnetworks and devices increases

Engineering Contradiction:
Improveincident tracking functionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system employs universal action conditions and standardized response protocols that can be applied across any number of subnetworks and devices. This multi-functional framework allows the same incident matching and execution mechanism to scale from small to large enterprise networks without requiring fundamental system changes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments incident management into independent, modular components: incident detection, condition matching, and action execution. This segmentation allows each component to operate independently and scale individually, enabling the system to handle increasing numbers of subnetworks and devices while maintaining efficient incident tracking.

Inventive Principle:
Principle #1Segmentation

4Productivity

If automated action execution is implemented, then response speed and efficiency are improved, but system complexity increases

Engineering Contradiction:
Improveresponse efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system pre-configures all action conditions and associated responses in advance, creating a library of predefined rules. This preliminary setup consolidates complexity into a one-time configuration phase, while the automated execution phase operates with simple matching logic, thereby improving response efficiency without requiring complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12542790B2Action response framework for data security incidents
Publication Date: 2026.02.03 WORKDAY INC
  • US12542790B2 patent drawing
  • US12542790B2 patent drawing
  • US12542790B2 patent drawing

AI summary

An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and/or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.