Security Incident Prioritization via Local and Cloud Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security information and event management systems face challenges in efficiently prioritizing and analyzing security incidents at scale, as they cannot automatically identify urgency and often rely on costly, scalable cloud-based analysis for all incidents, leading to resource inefficiencies and suboptimal responses.
Innovation Solution
A method that selectively prioritizes security incidents for local and remote analysis based on local and remote contextual factors, using source weights, magnitude scores, and threat intelligence data to determine the need for cloud-based cognitive analytics, thereby optimizing resource usage and focusing advanced analysis on high-impact incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based analysis is used for all security incidents, then analysis comprehensiveness is improved, but resource efficiency and cost effectiveness deteriorate
Solution Approach 1:
The patent applies local quality by implementing a two-tiered analysis system where different analysis methods are applied to different incidents based on their characteristics. High-priority incidents with multiple affected assets or severe impact scores receive comprehensive cloud-based cognitive analytics, while lower-priority incidents are handled by local rule-based analysis. This ensures that cloud resources are concentrated on incidents where they provide the most value, improving both analysis comprehensiveness for critical incidents and resource efficiency overall.
2Measurement precision
If cloud-based cognitive analytics are applied to all incidents, then detection accuracy is improved, but processing speed and response time deteriorate
Solution Approach 1:
The patent segments the analysis process into two distinct phases: an initial local rule-based filtering stage that quickly processes all incidents to identify high-priority candidates, followed by a secondary cloud-based cognitive analytics stage that applies advanced detection only to those segmented high-priority incidents. This segmentation maintains high detection accuracy for critical incidents while preserving overall processing speed by avoiding the application of computationally intensive cloud analytics to every incident.
3Reliability
If advanced analysis resources are allocated to all incidents equally, then analysis thoroughness is improved, but resource utilization efficiency deteriorates
Solution Approach 1:
The patent implements a dynamic resource allocation system that adjusts the level of analysis thoroughness based on incident priority. The system calculates priority scores based on multiple factors including the number of affected assets, asset criticality, and potential impact severity. High-priority incidents dynamically receive comprehensive cloud-based cognitive analytics with thorough analysis, while lower-priority incidents receive streamlined local analysis. This dynamic approach ensures optimal resource utilization efficiency while maintaining analysis thoroughness where it matters most.
Data Source
AI summary
Prioritizing security incidents for analysis is provided. A set of security information and event management data corresponding to each of a set of security incidents is retrieved. A source weight of a security incident and a magnitude of the security incident are used to determine a priority of the security incident within the set of security incidents. A local analysis of the security incident is performed based on the retrieved set of security information and event management data corresponding to the security incident and the determined priority of the security incident.


