Incident Triage Engine Prioritizing Security Responses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security information and event management systems lack efficient incident triage and prioritization mechanisms, leading to inconsistent response processes and resource allocation challenges when dealing with multiple concurrent security incidents, which can result in suboptimal resolution times and performance metrics.

Innovation Solution

An incident triage engine that utilizes loss algorithms to prioritize responses based on the potential loss of assets, resources required, and time needed to respond, integrating with existing SIEM environments to automate the process and provide consistent metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual validation and registration of security events is performed by security analysts, then flexibility in handling diverse incident types is maintained, but response time and consistency deteriorate due to ad-hoc processing

Engineering Contradiction:
Improveflexibility in handling incident typesVSAvoidresponse time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining incident types, response procedures, and prioritization criteria before incidents occur. When an incident is detected, the engine automatically matches it to pre-defined templates and executes predetermined response actions, eliminating the need for ad-hoc manual processing while maintaining adaptability through configurable incident type definitions.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If multiple security incidents are handled concurrently with limited resources, then operational efficiency is improved, but prioritization accuracy deteriorates due to lack of systematic evaluation

Engineering Contradiction:
Improveoperational efficiencyVSAvoidprioritization accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system changes parameters by evaluating incidents based on multiple quantifiable factors including asset criticality, incident severity, time sensitivity, and resource requirements. The engine dynamically adjusts prioritization based on these parameter changes, enabling accurate prioritization while efficiently managing limited resources through automated multi-criteria evaluation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If standardized workflows are implemented to automate standard actions, then response consistency is improved, but adaptability to complex or unique incidents deteriorates

Engineering Contradiction:
Improveresponse consistencyVSAvoidadaptability to complex incidents
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies dynamics by making the automated response workflow adaptable rather than rigid. The incident response engine dynamically selects and executes appropriate responses based on incident characteristics, allowing standardized procedures for common incidents while automatically adapting to complex situations through flexible rule-based decision-making and manual intervention capabilities when needed.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If manual analysis of security events is performed by senior team members, then complex incident evaluation is possible, but scalability deteriorates due to dependency on individual expertise

Engineering Contradiction:
Improveincident evaluation qualityVSAvoidscalability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements self-service by enabling the incident response engine to autonomously perform incident evaluation, prioritization, and response execution without continuous manual intervention. The engine uses built-in algorithms and rules to independently handle incidents, scaling operations to match the volume of security events while maintaining evaluation quality through systematic automated analysis rather than manual expertise.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9369481B2Incident triage engine
Publication Date: 2016.06.14 ACCENTURE GLOBAL SERVICES LTD
  • US9369481B2 patent drawing
  • US9369481B2 patent drawing
  • US9369481B2 patent drawing

AI summary

An incident triage engine performs incident triage in a system by prioritizing responses to incidents within the system. One prioritization method may include receiving attributes of incidents and assets in the system, generating cumulative loss forecasts for the incidents, and prioritizing the responses to the incidents based on the cumulative loss forecasts for the incidents. Another prioritization method may include determining different arrangements of incidents within a response queue, calculating cumulative queue loss forecasts for the different arrangements of incidents within the response queue, and arranging the incidents in the response queue based on the arrangement of incidents that minimizes the total loss to the system over the resolution of all of the incidents present in the response queue.