Incident Manager Threat Intelligence Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current incident management systems are inadequate in tracking and responding to cyber threats, as they fail to provide comprehensive insights into suspicious activities and trends across data security incidents, relying solely on manual processes and limited threat intelligence sources.
Innovation Solution
The Incident Manager collaboration tool integrates with various threat intelligence sources to create incident objects and artifacts, correlating data from first and second-level TISs to identify malicious activities and potential trends, enabling automated responses and enhanced threat detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If current incident management systems are used to track data security incidents, then basic incident tracking is possible, but comprehensive insights into suspicious activities and trends cannot be obtained
Solution Approach 1:
The patent combines multiple threat intelligence sources (first-level TIS for known threats and second-level TIS for metadata and usage data) into a unified incident management system. This merging allows the system to correlate data from diverse sources to generate comprehensive insights about suspicious activities and trends, resolving the contradiction between information completeness and system complexity.
Solution Approach 2:
The incident management system is designed to perform multiple functions: tracking incidents, querying threat intelligence sources, correlating data from multiple TISs, identifying suspicious activities, and detecting trends. This multi-functionality enables comprehensive insights without requiring separate specialized systems, addressing the contradiction by consolidating capabilities within a single universal platform.
2Productivity
If manual processes are used for threat tracking, then system simplicity is maintained, but response speed and detection capability are insufficient
Solution Approach 1:
The system implements automated querying of threat intelligence sources and automatic correlation of data from multiple TISs. The incident management system performs these tasks autonomously without requiring manual intervention, thereby improving response speed and detection capability while reducing the operational burden on users.
Solution Approach 2:
The system automatically correlates data from threat intelligence sources and provides feedback about suspicious activities and trends to users. This automated feedback loop enables rapid detection and response to threats without manual analysis, resolving the contradiction between productivity and ease of operation by making the system work autonomously.
3Measurement precision
If limited threat intelligence sources are used, then system complexity is reduced, but threat detection accuracy is insufficient
Solution Approach 1:
The patent segments threat intelligence sources into two distinct levels: first-level TIS for known threats (providing baseline detection accuracy) and second-level TIS for metadata and usage data (providing contextual information for trend analysis). This segmentation allows the system to incorporate multiple data sources while maintaining manageable complexity through structured organization.
Solution Approach 2:
The system adds a new dimension to threat detection by incorporating second-level TIS that provide metadata and usage data beyond simple threat identification. This dimensional expansion enables the system to detect trends and suspicious activities that single-level systems cannot identify, improving detection accuracy while managing complexity through hierarchical organization of intelligence sources.
Data Source
AI summary
An incident response system and method for tracking data security incidents in enterprise networks is disclosed. An Incident Manager application (IM) stores incident objects and incident artifacts (IAs) created in response to the incidents, where the incident objects include the information for the incident and the IAs are associated with data resources (e.g. IP addresses and malware hashes) identified within the incident objects. In response to creation of the IAs, the IM issues queries against one or more external threat intelligence sources (TISs) to obtain information associated with the IAs and augments the IAs with the obtained information. In examples, the IM can identify known threats by comparing the contents of IAs against TIS(s) of known threats, and can identify potential trends by correlating the created incident objects and augmented IAs for an incident with incident objects and IAs stored for other incidents.


