Computing Environment Threat Enrichment for Security Actions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems require manual translation and research of security alerts into actions, consuming time and resources, and lack efficient automation for determining appropriate responses to security threats in computing environments.

Innovation Solution

An advisement system that identifies security threats, obtains state and enrichment information, and determines automated or suggested security actions based on kill-state information to respond to threats, including querying internal and external databases for threat identification and behavior analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual translation and research of security alerts into actions is performed, then accuracy of security response is improved, but time consumption and resource usage increase

Engineering Contradiction:
Improveaccuracy of security responseVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes kill-chains that map security alerts to appropriate actions in advance. When a security alert is detected, the system queries the kill-chain database to retrieve pre-defined action sequences, eliminating the need for manual research and translation of alerts into actions during incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The kill-chain database serves as an intermediary between security alert detection and action execution. It stores pre-defined relationships between alert types and recommended actions, allowing the system to automatically determine appropriate responses without requiring manual intervention or research.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual research and determination of appropriate course of action is performed, then quality of security decision-making is improved, but productivity decreases

Engineering Contradiction:
Improvequality of security decision-makingVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security action sequences are pre-defined and stored in the kill-chain database during system setup. When security threats are detected, the system automatically queries and executes these pre-planned action sequences, eliminating the need for manual decision-making while maintaining consistent, high-quality responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system performs self-service by automatically determining and executing appropriate actions based on detected threats. The kill-chain database enables the system to autonomously select and implement security actions without requiring administrator intervention, thereby improving productivity while maintaining decision quality.

Inventive Principle:
Principle #25Self-service

3Productivity

If automation of security action determination is implemented, then productivity is improved, but complexity of the system increases

Engineering Contradiction:
ImproveproductivityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments security automation into distinct components: threat detection modules, a kill-chain database storing action sequences, and execution modules. This segmentation allows the system to achieve high productivity through automation while managing complexity by organizing functionality into separate, manageable parts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The kill-chain database stores pre-defined action sequences that are established during system configuration. This preliminary setup reduces operational complexity during incident response, as the automation system simply queries and executes pre-planned actions rather than requiring complex real-time decision logic.

Inventive Principle:
Principle #10Preliminary action

4Speed

If kill-chains and enrichment information are used to automate security actions, then response speed is improved, but information processing requirements increase

Engineering Contradiction:
Improveresponse speedVSAvoidinformation processing requirements
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The system extracts only the necessary action sequences from the kill-chain database based on the type of security threat detected. Rather than processing all available information, the system queries for and retrieves only the relevant pre-defined actions associated with the specific alert type, reducing information processing requirements while maintaining fast response speed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12375522B2Managing security actions in a computing environment using enrichment information
Publication Date: 2025.07.29 CISCO TECHNOLOGY INC
  • US12375522B2 patent drawing
  • US12375522B2 patent drawing
  • US12375522B2 patent drawing

AI summary

Aspects described herein provide security actions based on a current state of a security threat. In one example, a computer-implemented method includes identifying a security threat within a computing environment comprising a plurality of computing assets. The method further includes obtaining state information for the security threat within the computing environment from computing assets of the plurality of computing assets in the computing environment. The method further includes determining a current state for the security threat within the computing environment based on the state information. The method further includes obtaining enrichment information for the security threat that relates kill-state information to an identity of the security threat. The method further includes determining one or more security actions for the security threat based on the enrichment information and the current state for the security threat.