Automated Security Incident Ranking System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual cyber-security incident management is inefficient and prone to inaccurate prioritization due to the reliance on individual analysts, leading to potential data loss, revenue loss, and increased organizational vulnerability, especially in large organizations with complex asset structures and varying attack categories.

Innovation Solution

An automated system for security incident analysis that ranks incidents based on the sensitivity of involved systems and historical severity, using a machine learning model integrated with reinforcement learning to provide a prioritized list, considering data asset values and organizational representation, and incorporating analyst feedback for model improvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual incident management is used with human analysts, then flexibility and adaptability in handling diverse security events are maintained, but productivity and response speed deteriorate due to manual processing limitations

Engineering Contradiction:
Improveincident processing speedVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

An automated ranking system acts as an intermediary between security incident detection and human analyst response. The system processes incidents through machine learning models that generate preliminary rankings, which then guide human analysts to focus on high-priority cases. This mediator approach accelerates overall processing while preserving human judgment for critical decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The incident management workflow is segmented into automated ranking/classification stages and human review stages. The automated system handles initial triage, scoring, and prioritization, separating these routine tasks from complex analysis requiring human expertise. This segmentation improves throughput while maintaining quality through specialized human intervention at appropriate stages.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual prioritization by security analysts is used, then contextual understanding of organizational assets is maintained, but measurement precision and ranking accuracy deteriorate due to human error and subjectivity

Engineering Contradiction:
Improveincident ranking accuracyVSAvoidautomated analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Manual subjective prioritization by analysts is replaced with automated machine learning models that objectively score incidents based on learned patterns from historical data. The system substitutes human cognitive processes with algorithmic decision-making, eliminating bias and fatigue while maintaining contextual understanding through trained models on organizational asset relationships.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated ranking system incorporates feedback loops where analyst corrections and incident outcomes are fed back into the machine learning models to continuously improve accuracy. This feedback mechanism allows the system to learn from human expertise while maintaining the precision benefits of automation, progressively reducing errors over time.

Inventive Principle:
Principle #23Feedback

3Loss of time

If comprehensive analysis of all security incidents is performed manually, then thorough assessment of incident impact is achieved, but loss of time and response delays occur due to manual processing bottlenecks

Engineering Contradiction:
Improveincident response timeVSAvoidincident assessment accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The automated system performs partial analysis by focusing computational resources on the most critical incident attributes for rapid scoring, rather than exhaustive analysis of every detail. High-priority incidents receive more thorough automated analysis, while lower-priority ones receive streamlined assessment. This partial action approach reduces overall processing time while maintaining sufficient accuracy for timely response.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10587642B1Automated security incident ranking
Publication Date: 2020.03.10 EMC IP HLDG CO LLC
  • US10587642B1 patent drawing
  • US10587642B1 patent drawing
  • US10587642B1 patent drawing

AI summary

At least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization is obtained. The at least one security incident is automatically ranked based on one or more of: (i) one or more rankings associated with one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization. The ranking of the at least one security incident is presented to an entity to make an assessment of the security event.