Computing Environment Threat Enrichment for Security Actions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems require manual translation and research of security alerts into actions, consuming time and resources, and lack efficient automation for determining appropriate responses to security threats in computing environments.
Innovation Solution
An advisement system that identifies security threats, obtains state and enrichment information, and determines automated or suggested security actions based on kill-state information to respond to threats, including querying internal and external databases for threat identification and behavior analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual translation and research of security alerts into actions is performed, then accuracy of security response is improved, but time consumption and resource usage increase
Solution Approach 1:
The system pre-establishes kill-chains that map security alerts to appropriate actions in advance. When a security alert is detected, the system queries the kill-chain database to retrieve pre-defined action sequences, eliminating the need for manual research and translation of alerts into actions during incident response.
Solution Approach 2:
The kill-chain database serves as an intermediary between security alert detection and action execution. It stores pre-defined relationships between alert types and recommended actions, allowing the system to automatically determine appropriate responses without requiring manual intervention or research.
2Reliability
If manual research and determination of appropriate course of action is performed, then quality of security decision-making is improved, but productivity decreases
Solution Approach 1:
Security action sequences are pre-defined and stored in the kill-chain database during system setup. When security threats are detected, the system automatically queries and executes these pre-planned action sequences, eliminating the need for manual decision-making while maintaining consistent, high-quality responses.
Solution Approach 2:
The security system performs self-service by automatically determining and executing appropriate actions based on detected threats. The kill-chain database enables the system to autonomously select and implement security actions without requiring administrator intervention, thereby improving productivity while maintaining decision quality.
3Productivity
If automation of security action determination is implemented, then productivity is improved, but complexity of the system increases
Solution Approach 1:
The system segments security automation into distinct components: threat detection modules, a kill-chain database storing action sequences, and execution modules. This segmentation allows the system to achieve high productivity through automation while managing complexity by organizing functionality into separate, manageable parts.
Solution Approach 2:
The kill-chain database stores pre-defined action sequences that are established during system configuration. This preliminary setup reduces operational complexity during incident response, as the automation system simply queries and executes pre-planned actions rather than requiring complex real-time decision logic.
4Speed
If kill-chains and enrichment information are used to automate security actions, then response speed is improved, but information processing requirements increase
Solution Approach 1:
The system extracts only the necessary action sequences from the kill-chain database based on the type of security threat detected. Rather than processing all available information, the system queries for and retrieves only the relevant pre-defined actions associated with the specific alert type, reducing information processing requirements while maintaining fast response speed.
Data Source
AI summary
Aspects described herein provide security actions based on a current state of a security threat. In one example, a computer-implemented method includes identifying a security threat within a computing environment comprising a plurality of computing assets. The method further includes obtaining state information for the security threat within the computing environment from computing assets of the plurality of computing assets in the computing environment. The method further includes determining a current state for the security threat within the computing environment based on the state information. The method further includes obtaining enrichment information for the security threat that relates kill-state information to an identity of the security threat. The method further includes determining one or more security actions for the security threat based on the enrichment information and the current state for the security threat.


