Automated Threat Intelligence Workflow for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growing complexity and volume of cybersecurity threats in cloud-based services pose challenges for security operations to scale detection and response capabilities efficiently, leading to potential technical inefficiencies and delayed threat mitigation.

Innovation Solution

A method that involves identifying cybersecurity threats through event data streams, automatically initializing relevant threat intelligence workflows, deriving threat intelligence data via API calls, and routing threats based on severity for effective mitigation, utilizing machine learning models and workflows to classify and prioritize threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the volume of security threats increases, then the need for scaling security operations services grows, but technical inefficiencies and detection delays occur

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidthreat detection time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the monolithic security operations service into multiple specialized agents (detection agents, investigation agents, response agents) that can independently process different aspects of threat detection and response. This segmentation enables parallel processing of threats, improving productivity while maintaining rapid detection response times even as threat volume increases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated investigation and response dimension that operates alongside traditional detection capabilities. By adding this new dimension with machine learning models and automated workflows, the system handles increased threat volumes through intelligent automation rather than simply scaling human analysts, thus maintaining detection speed.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If more security services are scaled to protect against increasing threats, then protection coverage improves, but technical inefficiencies increase

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidsecurity operations complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security operations platform where a single integrated system performs multiple functions: threat detection, automated investigation, intelligence gathering, and response execution. This multi-functional approach improves protection coverage without proportionally increasing operational complexity, as one system handles what would otherwise require multiple separate services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities through automated investigation agents and machine learning models that independently analyze threats, gather intelligence, and execute responses without human intervention. This automation reduces operational complexity by eliminating manual processes while maintaining comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If automated investigative tasks are executed for each threat, then threat intelligence accuracy improves, but processing time increases

Engineering Contradiction:
Improvethreat intelligence accuracyVSAvoidthreat processing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by selectively executing automated investigative tasks based on threat severity, type, and confidence levels. Not every threat receives the full investigation workflow - instead, the system applies appropriate levels of analysis, maintaining high intelligence accuracy for critical threats while processing lower-priority threats more efficiently to preserve overall throughput.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary classification and triage of threats using machine learning models before initiating full automated investigations. This preliminary action filters threats to identify which ones require extensive investigative resources, ensuring accurate intelligence gathering for high-priority threats while maintaining high processing throughput by quickly handling lower-priority items.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240414194A1Systems and methods for intelligent cyber security threat detection and mitigation through an extensible automated investigations and threat mitigation platform
Publication Date: 2024.12.12 EXPEL INC
  • US20240414194A1 patent drawing
  • US20240414194A1 patent drawing
  • US20240414194A1 patent drawing

AI summary

A cybersecurity system and method for handling a cybersecurity event includes identifying a cybersecurity alert; selectively initializing automated threat intelligence workflows based on computing a cybersecurity alert type, wherein the automated threat intelligence workflows include a plurality of automated investigative tasks that, when executed by one or more computers, derive cybersecurity alert intelligence data; and executing the plurality of automated investigative tasks includes automatically sourcing a corpus of investigative data; deriving the cybersecurity alert intelligence data based on extracting selective pieces of data from the corpus of investigative data, wherein the cybersecurity alert intelligence data informs an inference of a cybersecurity alert severity of the cybersecurity alert; and automatically routing the cybersecurity alert to one of a plurality of distinct threat mitigation or threat disposal routes based on the cybersecurity alert severity of the cybersecurity alert.