Automated Risk Scoring for Incident Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cybersecurity teams face challenges in effectively prioritizing and addressing incidents due to the high volume of alerts, often relying on expertise rather than data-driven approaches, which can lead to inefficiencies in resource allocation and threat mitigation.

Innovation Solution

A system and method for generating risk scores based on actual loss events, using a dataset that includes breach data and insurance data to determine attack tactic risk scores, incident risk scores, and asset risk scores, thereby providing a data-driven approach to prioritize incidents and allocate resources effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security operations analysts manually determine whether incidents are malicious, then expertise-based judgment can be applied, but the high quantity of incidents makes this approach inefficient and challenging

Engineering Contradiction:
Improveincident prioritization accuracyVSAvoidincident processing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual analyst judgment (mechanical human decision-making) with an automated risk scoring system that uses machine learning models and historical loss event data to objectively prioritize incidents. This substitution enables both high accuracy through sophisticated algorithms and high throughput through automation, resolving the contradiction between precision and productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary risk scoring system that processes incidents between detection and response phases. This intermediary layer automatically evaluates incidents using multiple data sources and algorithms, providing prioritized outputs that guide analyst attention without requiring manual evaluation of every incident, thus improving both accuracy and throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations focus on investigating all incidents thoroughly, then comprehensive security coverage is achieved, but resource allocation becomes inefficient due to the high volume of alerts

Engineering Contradiction:
Improvesecurity coverage completenessVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by providing different levels of analysis and attention to different incidents based on their risk scores. High-risk incidents receive comprehensive investigation resources, while low-risk incidents receive automated handling or minimal attention. This differentiated approach maintains overall security reliability while optimizing resource allocation and reducing time loss.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by focusing investigative resources on the most critical incidents rather than treating all incidents equally. The risk scoring system identifies a subset of high-priority incidents that warrant thorough investigation, allowing organizations to achieve sufficient security coverage without wasting resources on low-risk false positives, thus improving resource allocation efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If data-driven approaches are used to prioritize incidents, then resource allocation efficiency improves, but the complexity of processing and analyzing multiple data sources increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoiddata processing system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex data processing task into distinct modular components: data collection from multiple sources, data normalization and cleaning, feature extraction, risk scoring calculation, and incident prioritization output. Each module handles a specific aspect of the data flow, making the overall system more manageable and maintainable while achieving efficient resource allocation through automated analysis.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230316192A1Systems and methods for generating risk scores based on actual loss events
Publication Date: 2023.10.05 CISCO TECHNOLOGY INC
  • US20230316192A1 patent drawing
  • US20230316192A1 patent drawing
  • US20230316192A1 patent drawing

AI summary

In one embodiment, a method includes determining an attack tactic risk score for one or more attack tactics based on a dataset of actual loss events and determining an incident risk score for an incident based on the one or more attack tactic risk scores. The method also includes determining a priority value for an asset. The asset is associated with the incident. The method further includes generating an asset risk score for the asset based on the priority value of the asset and the incident risk score.