Incident Triage Scoring Engine for Cloud Security Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional cybersecurity systems struggle to adapt to dynamic cloud environments and virtualized IT infrastructures, requiring significant manual efforts for security configuration updates and threat response, which can lead to delayed threat detection and increased resource usage.
Innovation Solution
A method that processes data to identify common paths among groups of actions for remediation, determines a core path based on frequent actions, and provides this path to an automated incident investigation engine for swift and efficient computer security threat response, utilizing machine learning for continuous improvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional manual security configuration approaches are used, then security controls can be implemented, but significant manual work is required to identify impacted assets and modify configurations when physical attributes change
Solution Approach 1:
The system automatically identifies impacted assets and modifies security control configurations when physical attributes change, eliminating the need for manual intervention. The automated incident investigation engine performs self-service by detecting changes in virtual machine attributes and autonomously updating security policies, thereby resolving the technical contradiction between ease of operation and time loss.
Solution Approach 2:
The patent replaces manual mechanical operations with automated computational processes. Instead of manually identifying impacted assets and modifying configurations, the system uses an automated engine that processes attribute changes and updates security controls programmatically, substituting human labor with machine-based automation to reduce both manual work effort and time consumption.
2Adaptability or versatility
If traditional cybersecurity systems are used in virtualized environments, then security controls can be maintained, but the systems cannot adapt well to dynamic cloud environments and virtualized IT infrastructures
Solution Approach 1:
The system transitions from static security configurations to dynamic adaptive security controls. The automated incident investigation engine continuously monitors virtual machine attributes and automatically adjusts security policies in response to environmental changes, enabling the security system to adapt dynamically to cloud environments while maintaining reliability through automated consistency enforcement.
Solution Approach 2:
The system implements feedback mechanisms where the automated incident investigation engine continuously monitors attribute changes and uses this information to automatically update security control configurations. This closed-loop feedback ensures that security controls remain effective and adapted to the current virtualized environment state, resolving the contradiction between adaptability and reliability.
3Productivity
If manual security configuration updates are performed, then security policies can be maintained, but delayed threat detection and increased resource usage occur
Solution Approach 1:
The system performs preliminary actions by pre-configuring automated response rules and security policies that are triggered automatically upon detecting specific attribute changes. This preliminary setup eliminates the need for delayed manual intervention, enabling immediate threat detection and response while optimizing resource usage through automated efficient processing rather than prolonged manual analysis.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for incident response are disclosed. In one aspect, a system includes a cognitive engine that is configured to receive data identifying actions performed in response to a computer security threat. Based on the data identifying the actions performed in response to the computer security threat, the system generates one or more workflows and a particular workflow that are associated with the computer security threat and that each identify one or more actions to remediate the computer security threat. The system also includes a scoring system and event triage engine that is configured to analyze the actions of the one or more workflows and of the particular workflow, and based on analyzing the actions of the one or more workflows and of the particular workflow, select a primary workflow as a workflow to respond to the computer security threat. The system also includes an automated incident investigation engine that is configured to receive an alert that identifies the computer security threat, and process the computer security threat according to the primary workflow that is associated with the computer security threat and that identifies one or more actions to remediate the computer security threat.