Incident Triage Scoring Engine for Cloud Security Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity systems struggle to adapt to dynamic cloud environments and virtualized IT infrastructures, requiring significant manual efforts for security configuration updates and threat response, which can lead to delayed threat detection and increased resource usage.

Innovation Solution

A method that processes data to identify common paths among groups of actions for remediation, determines a core path based on frequent actions, and provides this path to an automated incident investigation engine for swift and efficient computer security threat response, utilizing machine learning for continuous improvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional manual security configuration approaches are used, then security controls can be implemented, but significant manual work is required to identify impacted assets and modify configurations when physical attributes change

Engineering Contradiction:
ImproveManual configuration workVSAvoidTime to identify impacted assets and modify configurations
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system automatically identifies impacted assets and modifies security control configurations when physical attributes change, eliminating the need for manual intervention. The automated incident investigation engine performs self-service by detecting changes in virtual machine attributes and autonomously updating security policies, thereby resolving the technical contradiction between ease of operation and time loss.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical operations with automated computational processes. Instead of manually identifying impacted assets and modifying configurations, the system uses an automated engine that processes attribute changes and updates security controls programmatically, substituting human labor with machine-based automation to reduce both manual work effort and time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If traditional cybersecurity systems are used in virtualized environments, then security controls can be maintained, but the systems cannot adapt well to dynamic cloud environments and virtualized IT infrastructures

Engineering Contradiction:
ImproveAdaptability to dynamic cloud environmentsVSAvoidSecurity control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system transitions from static security configurations to dynamic adaptive security controls. The automated incident investigation engine continuously monitors virtual machine attributes and automatically adjusts security policies in response to environmental changes, enabling the security system to adapt dynamically to cloud environments while maintaining reliability through automated consistency enforcement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the automated incident investigation engine continuously monitors attribute changes and uses this information to automatically update security control configurations. This closed-loop feedback ensures that security controls remain effective and adapted to the current virtualized environment state, resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #23Feedback

3Productivity

If manual security configuration updates are performed, then security policies can be maintained, but delayed threat detection and increased resource usage occur

Engineering Contradiction:
ImproveThreat detection speedVSAvoidComputing resources consumed
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system performs preliminary actions by pre-configuring automated response rules and security policies that are triggered automatically upon detecting specific attribute changes. This preliminary setup eliminates the need for delayed manual intervention, enabling immediate threat detection and response while optimizing resource usage through automated efficient processing rather than prolonged manual analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3319004B1Incident triage scoring engine
Publication Date: 2021.03.10 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP3319004B1 patent drawingFigure 1
  • EP3319004B1 patent drawingFigure 2
  • EP3319004B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for incident response are disclosed. In one aspect, a system includes a cognitive engine that is configured to receive data identifying actions performed in response to a computer security threat. Based on the data identifying the actions performed in response to the computer security threat, the system generates one or more workflows and a particular workflow that are associated with the computer security threat and that each identify one or more actions to remediate the computer security threat. The system also includes a scoring system and event triage engine that is configured to analyze the actions of the one or more workflows and of the particular workflow, and based on analyzing the actions of the one or more workflows and of the particular workflow, select a primary workflow as a workflow to respond to the computer security threat. The system also includes an automated incident investigation engine that is configured to receive an alert that identifies the computer security threat, and process the computer security threat according to the primary workflow that is associated with the computer security threat and that identifies one or more actions to remediate the computer security threat.