Automated Security Event Alerting and Escalation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information technology support organizations face challenges in efficiently managing and responding to security events on networked systems, such as virus and worm outbreaks, which can lead to downtime and increased burden on IT personnel.

Innovation Solution

A method and system that utilizes a trouble ticket alerting system and intrusion detection system to automatically create and escalate alerts for security events, notifying relevant personnel and potentially disconnecting affected systems from the network when necessary, to ensure timely action and minimize downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring and response to security events is used, then IT personnel can handle security concerns, but response time increases and downtime occurs

Engineering Contradiction:
Improvesecurity event response reliabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically detecting security events through intrusion detection systems, creating trouble tickets, and escalating alerts before human intervention is needed. This automated preliminary response eliminates the delay between event occurrence and initial response, directly reducing the loss of time while maintaining reliable security monitoring.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If IT personnel handle both non-security issues and security concerns, then all issues can be addressed, but the burden on IT personnel increases and response efficiency decreases

Engineering Contradiction:
ImproveIT personnel workload managementVSAvoidsecurity event response efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements self-service by automatically detecting security events, creating trouble tickets, assigning them to appropriate personnel, and escalating when necessary. This automates the security monitoring function that would otherwise require IT personnel attention, reducing their burden while improving security response efficiency through continuous automated surveillance.

Inventive Principle:
Principle #25Self-service

3Loss of time

If automated alerting and escalation system is implemented, then security events are detected and responded to promptly, but system complexity increases

Engineering Contradiction:
Improvesecurity event detection timeVSAvoidalerting system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system merges multiple functions into a unified automated alerting platform that combines intrusion detection, trouble ticket creation, escalation logic, and notification systems. By integrating these previously separate functions into one cohesive system, the complexity is managed centrally rather than distributed across multiple manual processes, making the automated response achievable without proportionally increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7551073B2Method, system and program product for alerting an information technology support organization of a security event
Publication Date: 2009.06.23 KYNDRYL INC
  • US7551073B2 patent drawing
  • US7551073B2 patent drawing
  • US7551073B2 patent drawing

AI summary

A method, system and program product for alerting an information technology support organization of a security event is provided. The method includes storing in a trouble ticket alerting system trouble tickets corresponding to security events logged for a system. Further, the method includes analyzing, at a pre-determined time interval, recently logged security events among the security events logged, the recently logged security events being logged within the pre-determined time interval, comparing a recent security event of the recently logged security events to each of the trouble tickets, automatically creating a new trouble ticket when no match is found to an existing trouble ticket and if the recent security event matches an existing trouble ticket, escalating the existing trouble ticket, such that an information technology support organization is alerted of the recent security event so that appropriate action can be taken to alleviate the recent security event.