Predicted Resolution Time Allocation for IT Incident Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of IT environments with multiple computing components and limited administrative resources makes it cumbersome to manage and respond to security incidents efficiently, such as viruses, malware, and hardware failures, leading to prolonged resolution times.
Innovation Solution
An incident management system that identifies incidents, accesses incident response information for multiple analysts, determines predicted resolution times based on their past performance, and selects the most suitable analyst to respond to the incident, optimizing response times by considering availability, expertise, and queue lengths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If more computing components are added to the IT environment, then the system capability and service coverage are improved, but the number of security threats and incidents increases
Solution Approach 1:
The patent introduces an automated incident response system that acts as an intermediary between security threats and administrative personnel. This system includes components for automated incident detection, analysis, classification, and response coordination, serving as a mediator that handles the increasing security threats generated by expanded IT environments without requiring proportional increases in human administrative resources
2Productivity
If more administrative personnel are added, then the incident response capacity is improved, but the coordination complexity and costs increase
Solution Approach 1:
The patent implements a self-service automated incident response system that independently performs incident detection, analysis, classification, and response execution. The system automatically manages its own workflow, tracks incident status, and coordinates responses without requiring human intervention for routine tasks, thereby increasing response capacity while eliminating coordination complexity associated with multiple administrative personnel
Solution Approach 2:
The patent replaces the mechanical system of human administrative personnel coordination with an automated computational system. The automated incident response system uses algorithms, machine learning models, and automated workflows to perform tasks previously requiring human analysts, thereby increasing response capacity while eliminating the coordination overhead inherent in managing multiple human administrators
3Ease of operation
If manual incident management is used, then flexibility in handling incidents is maintained, but response times are prolonged
Solution Approach 1:
The patent implements preliminary action by pre-configuring response playbooks, classification rules, and automated workflows before incidents occur. The system pre-processes incident data, automatically classifies incidents into categories, and prepares predetermined response actions, enabling rapid response execution when incidents occur without sacrificing the flexibility to handle diverse incident types
Solution Approach 2:
The patent ensures continuity of useful action by implementing an automated incident response system that operates continuously without interruption. The system maintains constant monitoring, immediate incident detection, and uninterrupted response execution, eliminating the delays inherent in manual incident management while maintaining flexibility through configurable response workflows that can adapt to different incident scenarios
Data Source
AI summary
Described herein are systems, methods, and software to enhance the management of responses to incidents. In one example, a method of improving responses to incidents in an information technology environment includes identifying an incident associated with a component of the information technology environment. The method further provides determining a predicted resolution time for the incident by each analyst of the plurality of analysts based on the incident response information and selecting an analyst to resolve the incident based on the predicted resolution times.


