Incident Manager Action Framework for Automated Security Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current incident management systems in enterprise networks face delays and inefficiencies in responding to data security incidents, particularly due to manual task creation and execution by Incident Response Team members, which can lead to increased costs and damage from self-replicating threats like malware, and do not scale with the growing number of subnetworks and devices.
Innovation Solution
A client/server-based action response framework within an Incident Manager application that automatically tracks and stores incident data, defines action conditions, and sends messages to devices for automated incident responses, using action scripts to execute actions on both message-enabled and non-message-enabled devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual task creation and execution by Incident Response Team members is used, then incident tracking capability is provided, but response delay increases and efficiency decreases
Solution Approach 1:
The system pre-configures action conditions and associated responses in advance. When an incident matches a predefined condition, the corresponding action is automatically executed without waiting for manual intervention. This preliminary setup of response protocols eliminates the time lag between incident detection and response execution.
Solution Approach 2:
The incident management system automatically executes responses without requiring Incident Response Team members to manually create and carry out tasks. The system self-services by autonomously matching incidents to predefined conditions and executing appropriate actions, thereby eliminating manual labor while maintaining reliable incident tracking.
2Reliability
If manual task creation and execution is used, then incident response capability is provided, but error rate increases due to manual operations
Solution Approach 1:
The system replaces manual mechanical operations with automated computer-based execution. Instead of Incident Response Team members manually creating and executing tasks, the system automatically matches incidents to predefined conditions and executes corresponding actions through software, eliminating human errors associated with manual operations.
Solution Approach 2:
The system performs incident response execution autonomously without human intervention. By self-service automation, the system eliminates the possibility of manual errors in task creation and execution while maintaining the essential incident response capability.
3Reliability
If current incident management systems are used, then basic incident tracking is provided, but scalability is limited when the number of subnetworks and devices increases
Solution Approach 1:
The system employs universal action conditions and standardized response protocols that can be applied across any number of subnetworks and devices. This multi-functional framework allows the same incident matching and execution mechanism to scale from small to large enterprise networks without requiring fundamental system changes.
Solution Approach 2:
The system segments incident management into independent, modular components: incident detection, condition matching, and action execution. This segmentation allows each component to operate independently and scale individually, enabling the system to handle increasing numbers of subnetworks and devices while maintaining efficient incident tracking.
4Productivity
If automated action execution is implemented, then response speed and efficiency are improved, but system complexity increases
Solution Approach 1:
The system pre-configures all action conditions and associated responses in advance, creating a library of predefined rules. This preliminary setup consolidates complexity into a one-time configuration phase, while the automated execution phase operates with simple matching logic, thereby improving response efficiency without requiring complex real-time decision-making.
Data Source
AI summary
An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and/or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.


