Automated Security Event Alerting and Escalation System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information technology support organizations face challenges in efficiently managing and responding to security events on networked systems, such as virus and worm outbreaks, which can lead to downtime and increased burden on IT personnel.
Innovation Solution
A method and system that utilizes a trouble ticket alerting system and intrusion detection system to automatically create and escalate alerts for security events, notifying relevant personnel and potentially disconnecting affected systems from the network when necessary, to ensure timely action and minimize downtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual monitoring and response to security events is used, then IT personnel can handle security concerns, but response time increases and downtime occurs
Solution Approach 1:
The system performs preliminary actions by automatically detecting security events through intrusion detection systems, creating trouble tickets, and escalating alerts before human intervention is needed. This automated preliminary response eliminates the delay between event occurrence and initial response, directly reducing the loss of time while maintaining reliable security monitoring.
2Ease of operation
If IT personnel handle both non-security issues and security concerns, then all issues can be addressed, but the burden on IT personnel increases and response efficiency decreases
Solution Approach 1:
The system implements self-service by automatically detecting security events, creating trouble tickets, assigning them to appropriate personnel, and escalating when necessary. This automates the security monitoring function that would otherwise require IT personnel attention, reducing their burden while improving security response efficiency through continuous automated surveillance.
3Loss of time
If automated alerting and escalation system is implemented, then security events are detected and responded to promptly, but system complexity increases
Solution Approach 1:
The system merges multiple functions into a unified automated alerting platform that combines intrusion detection, trouble ticket creation, escalation logic, and notification systems. By integrating these previously separate functions into one cohesive system, the complexity is managed centrally rather than distributed across multiple manual processes, making the automated response achievable without proportionally increasing overall system complexity.
Data Source
AI summary
A method, system and program product for alerting an information technology support organization of a security event is provided. The method includes storing in a trouble ticket alerting system trouble tickets corresponding to security events logged for a system. Further, the method includes analyzing, at a pre-determined time interval, recently logged security events among the security events logged, the recently logged security events being logged within the pre-determined time interval, comparing a recent security event of the recently logged security events to each of the trouble tickets, automatically creating a new trouble ticket when no match is found to an existing trouble ticket and if the recent security event matches an existing trouble ticket, escalating the existing trouble ticket, such that an information technology support organization is alerted of the recent security event so that appropriate action can be taken to alleviate the recent security event.


