Security Incident Prioritization via Local and Cloud Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security information and event management systems face challenges in efficiently prioritizing and analyzing security incidents at scale, as they cannot automatically identify urgency and often rely on costly, scalable cloud-based analysis for all incidents, leading to resource inefficiencies and suboptimal responses.

Innovation Solution

A method that selectively prioritizes security incidents for local and remote analysis based on local and remote contextual factors, using source weights, magnitude scores, and threat intelligence data to determine the need for cloud-based cognitive analytics, thereby optimizing resource usage and focusing advanced analysis on high-impact incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based analysis is used for all security incidents, then analysis comprehensiveness is improved, but resource efficiency and cost effectiveness deteriorate

Engineering Contradiction:
Improveanalysis comprehensivenessVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by implementing a two-tiered analysis system where different analysis methods are applied to different incidents based on their characteristics. High-priority incidents with multiple affected assets or severe impact scores receive comprehensive cloud-based cognitive analytics, while lower-priority incidents are handled by local rule-based analysis. This ensures that cloud resources are concentrated on incidents where they provide the most value, improving both analysis comprehensiveness for critical incidents and resource efficiency overall.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If cloud-based cognitive analytics are applied to all incidents, then detection accuracy is improved, but processing speed and response time deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the analysis process into two distinct phases: an initial local rule-based filtering stage that quickly processes all incidents to identify high-priority candidates, followed by a secondary cloud-based cognitive analytics stage that applies advanced detection only to those segmented high-priority incidents. This segmentation maintains high detection accuracy for critical incidents while preserving overall processing speed by avoiding the application of computationally intensive cloud analytics to every incident.

Inventive Principle:
Principle #1Segmentation

3Reliability

If advanced analysis resources are allocated to all incidents equally, then analysis thoroughness is improved, but resource utilization efficiency deteriorates

Engineering Contradiction:
Improveanalysis thoroughnessVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a dynamic resource allocation system that adjusts the level of analysis thoroughness based on incident priority. The system calculates priority scores based on multiple factors including the number of affected assets, asset criticality, and potential impact severity. High-priority incidents dynamically receive comprehensive cloud-based cognitive analytics with thorough analysis, while lower-priority incidents receive streamlined local analysis. This dynamic approach ensures optimal resource utilization efficiency while maintaining analysis thoroughness where it matters most.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11050773B2Selecting security incidents for advanced automatic analysis
Publication Date: 2021.06.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11050773B2 patent drawing
  • US11050773B2 patent drawing
  • US11050773B2 patent drawing

AI summary

Prioritizing security incidents for analysis is provided. A set of security information and event management data corresponding to each of a set of security incidents is retrieved. A source weight of a security incident and a magnitude of the security incident are used to determine a priority of the security incident within the set of security incidents. A local analysis of the security incident is performed based on the retrieved set of security information and event management data corresponding to the security incident and the determined priority of the security incident.