Incident Response Platform Using Anonymized Action Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and coordinating incident response across multiple information technology environments with varying hardware and software configurations becomes cumbersome due to the increasing number of computing components and limited administrative resources, making it difficult to investigate and remediate potential security threats effectively.

Innovation Solution

An incident service system that operates across multiple IT environments, identifies incidents, anonymizes action implementation information, and provides action suggestions to analyst systems based on trends and successfulness ratings from other environments, facilitating coordinated response efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If more computing components are added to IT environments, then service capabilities and functionality are improved, but the number of security targets and management complexity increase

Engineering Contradiction:
Improveservice capabilitiesVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines incident response capabilities across multiple IT environments into a single centralized platform. Analysts can investigate and respond to security incidents affecting virtual machines, physical servers, cloud instances, and containers from one unified interface, merging previously分散 management functions into a consolidated system that reduces complexity while maintaining support for diverse computing components

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The incident response platform is designed to universally handle security incidents across heterogeneous IT environments including on-premises data centers, cloud platforms, and hybrid architectures. The system provides multi-functional capabilities to investigate, analyze, and respond to threats regardless of the underlying infrastructure type, enabling a single tool to manage diverse security targets

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If administrative personnel and resources are increased, then incident investigation and remediation capabilities are improved, but operational costs and resource requirements increase

Engineering Contradiction:
Improveincident response capabilityVSAvoidadministrative resources
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The platform incorporates automated incident response capabilities that perform investigations and remediation actions with minimal human intervention. Automated workflows can collect evidence, analyze threats, and execute response actions based on predefined playbooks, enabling the system to serve itself for routine incident handling tasks and reducing dependency on large teams of administrative personnel

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where incident response outcomes are captured and used to continuously improve automated workflows and threat detection algorithms. This learning capability allows the platform to become more efficient over time, extracting maximum productivity from existing administrative resources through data-driven improvements rather than requiring proportional increases in staff

Inventive Principle:
Principle #23Feedback

3Reliability

If coordination of incident response across multiple environments is improved, then security remediation effectiveness is enhanced, but system complexity and integration requirements increase

Engineering Contradiction:
Improvesecurity remediation effectivenessVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The incident response platform acts as an intermediary layer between security analysts and diverse IT environments. It provides standardized interfaces and protocols that translate between different environment-specific formats and a unified incident response model, mediating the coordination between various systems without requiring direct complex integrations between each environment and every response tool

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The platform segments incident response functionality into modular components that can be independently configured for different IT environments. Each environment type (virtual machines, cloud instances, containers) can be connected through separate, standardized integration points, allowing the system to manage complexity through modular architecture rather than requiring monolithic integration of all environments simultaneously

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11811587B1Generating incident response action flows using anonymized action implementation data
Publication Date: 2023.11.07 CISCO TECHNOLOGY INC
  • US11811587B1 patent drawing
  • US11811587B1 patent drawing
  • US11811587B1 patent drawing

AI summary

Described herein are systems, methods, and software to enhance the management of responses to incidents. In one example, a method of improving incident response comprises identifying an incident in an information technology (IT) environment associated with a first entity of a plurality of entities, and identifying action implementation information related to the incident. The method further anonymizes the action implementation information for the incident, and determines action suggestions based at least on the anonymized action implementation information.