Incident Management System for Cybersecurity Detection and Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in timely and effective response to security incidents due to overwhelming alerts, shortage of skilled personnel, and lack of organized incident response methodologies, leading to prolonged recovery times and operational, legal, and regulatory consequences.

Innovation Solution

The development of an incident management and response system (IMRS) that utilizes enterprise service bus integration, workflow automation, digital cybertagging, ontology-based context models, human-computer collaborative learning, and machine learning to rapidly detect and respond to cybersecurity incidents, providing real-time situational awareness and adaptive incident response plans.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If basic security monitoring and malware detection are implemented, then security event detection capability is improved, but alert volume increases overwhelming the system and response effectiveness deteriorates

Engineering Contradiction:
Improvesecurity event detection capabilityVSAvoidresponse effectiveness
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts and separates true security incidents from false positive alerts by implementing a prioritization framework that identifies and focuses only on high-risk events. This filters out the overwhelming majority of low-risk alerts, allowing security personnel to concentrate on actual threats rather than being distracted by noise from basic monitoring tools.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary prioritization layer between detection and response actions. This intermediary framework assesses risk levels, contextualizes alerts, and determines response priorities, serving as a mediator that transforms raw alert volume into manageable, prioritized incident queues that improve response effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If more security personnel are hired to handle increasing alerts, then incident response capability is improved, but operational costs increase

Engineering Contradiction:
Improveincident response capabilityVSAvoidoperational costs
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent implements automated self-service capabilities through machine learning models that automatically prioritize incidents, assess risk levels, and guide response actions. This automation reduces the manual labor required from security personnel, allowing the same team size to handle increased alert volumes without proportionally increasing operational costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of incident prioritization from manual assessment to automated risk scoring. By transforming subjective human judgment into objective, algorithm-driven prioritization, the system increases response capability without requiring additional personnel, thereby avoiding increased operational costs.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If comprehensive security monitoring is deployed across all systems, then security coverage is improved, but system complexity and false positives increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive security monitoring into prioritized tiers based on risk assessment. Instead of treating all monitored systems equally, the framework divides them into high-priority and low-priority segments, allowing comprehensive coverage while managing complexity through structured categorization and focused attention on critical segments.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If manual incident response methodologies are used, then response flexibility is improved, but response time increases

Engineering Contradiction:
Improveresponse flexibilityVSAvoidresponse time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-assessing incident priorities, pre-categorizing threats, and pre-planning response strategies based on risk levels. This preliminary processing occurs automatically before human responders engage, reducing the time required for manual assessment while preserving flexibility in executing predetermined response playbooks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11012466B2Computerized system and method for providing cybersecurity detection and response functionality
Publication Date: 2021.05.18 ECS FEDERAL LLC
  • US11012466B2 patent drawing
  • US11012466B2 patent drawing
  • US11012466B2 patent drawing

AI summary

Disclosed are systems and methods for improving interactions with and between computers in a search system supported by or configured with search servers, applications or platforms. The systems interact to identify and retrieve data across platforms, which data can be used to improve the quality of results data used in processing interactions between or among processors in such systems. The disclosed systems and methods provide an incident management and response software (IMRS) system that accelerates security incident detection and response. The IMRS provides an adaptive, event-driven workflow automation platform that can be customized to suit a large range of infrastructure environments and asset classes. The IMRS encompasses the management, automation and orchestration technologies applied in the detection and remediation of a computer network security incident (e.g., malware, advanced persistent threat, insider crime, denial of service attack, and the like).