Incident Manager Threat Intelligence Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current incident management systems are inadequate in tracking and responding to cyber threats, as they fail to provide comprehensive insights into suspicious activities and trends across data security incidents, relying solely on manual processes and limited threat intelligence sources.

Innovation Solution

The Incident Manager collaboration tool integrates with various threat intelligence sources to create incident objects and artifacts, correlating data from first and second-level TISs to identify malicious activities and potential trends, enabling automated responses and enhanced threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If current incident management systems are used to track data security incidents, then basic incident tracking is possible, but comprehensive insights into suspicious activities and trends cannot be obtained

Engineering Contradiction:
Improvecomprehensive insights into suspicious activities and trendsVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent combines multiple threat intelligence sources (first-level TIS for known threats and second-level TIS for metadata and usage data) into a unified incident management system. This merging allows the system to correlate data from diverse sources to generate comprehensive insights about suspicious activities and trends, resolving the contradiction between information completeness and system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The incident management system is designed to perform multiple functions: tracking incidents, querying threat intelligence sources, correlating data from multiple TISs, identifying suspicious activities, and detecting trends. This multi-functionality enables comprehensive insights without requiring separate specialized systems, addressing the contradiction by consolidating capabilities within a single universal platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If manual processes are used for threat tracking, then system simplicity is maintained, but response speed and detection capability are insufficient

Engineering Contradiction:
Improveresponse speed and detection capabilityVSAvoidmanual operation requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system implements automated querying of threat intelligence sources and automatic correlation of data from multiple TISs. The incident management system performs these tasks autonomously without requiring manual intervention, thereby improving response speed and detection capability while reducing the operational burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system automatically correlates data from threat intelligence sources and provides feedback about suspicious activities and trends to users. This automated feedback loop enables rapid detection and response to threats without manual analysis, resolving the contradiction between productivity and ease of operation by making the system work autonomously.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If limited threat intelligence sources are used, then system complexity is reduced, but threat detection accuracy is insufficient

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidnumber of threat intelligence sources
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments threat intelligence sources into two distinct levels: first-level TIS for known threats (providing baseline detection accuracy) and second-level TIS for metadata and usage data (providing contextual information for trend analysis). This segmentation allows the system to incorporate multiple data sources while maintaining manageable complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to threat detection by incorporating second-level TIS that provide metadata and usage data beyond simple threat identification. This dimensional expansion enables the system to detect trends and suspicious activities that single-level systems cannot identify, improving detection accuracy while managing complexity through hierarchical organization of intelligence sources.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10003610B2System for tracking data security threats and method for same
Publication Date: 2018.06.19 WORKDAY INC
  • US10003610B2 patent drawing
  • US10003610B2 patent drawing
  • US10003610B2 patent drawing

AI summary

An incident response system and method for tracking data security incidents in enterprise networks is disclosed. An Incident Manager application (IM) stores incident objects and incident artifacts (IAs) created in response to the incidents, where the incident objects include the information for the incident and the IAs are associated with data resources (e.g. IP addresses and malware hashes) identified within the incident objects. In response to creation of the IAs, the IM issues queries against one or more external threat intelligence sources (TISs) to obtain information associated with the IAs and augments the IAs with the obtained information. In examples, the IM can identify known threats by comparing the contents of IAs against TIS(s) of known threats, and can identify potential trends by correlating the created incident objects and augmented IAs for an incident with incident objects and IAs stored for other incidents.