Threat Mitigation Automation for Multi-Subsystem Security Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat mitigation systems face complexity in handling diverse security-relevant subsystems, requiring unique queries for each, which is inefficient and cumbersome.

Innovation Solution

A computer-implemented method utilizing a generative AI model and formatting script to process security event notifications, producing a summarized human-readable report and automatically executing recommended actions across multiple security-relevant subsystems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If unique queries are formulated for each security-relevant subsystem, then information can be obtained from all subsystems, but the process becomes complex and inefficient

Engineering Contradiction:
Improveinformation gathering completenessVSAvoidquery formulation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified query interface that can communicate with multiple security-relevant subsystems (SIEM, SOAR, XDR, etc.) using a single standardized query language. This eliminates the need to formulate unique queries for each subsystem while maintaining the ability to gather comprehensive information from all sources, directly resolving the contradiction between information completeness and query complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If manual processing of security event notifications is performed, then detailed analysis can be conducted, but response time increases

Engineering Contradiction:
Improvesecurity event analysis depthVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the threat mitigation system to automatically process security event notifications, generate summaries, identify recommended next steps, and execute actions without requiring continuous manual intervention. The system autonomously analyzes events from multiple subsystems, determines appropriate responses, and executes them through integrated APIs, thereby maintaining analysis depth while significantly reducing response time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining recommended next steps and action protocols for common security events. When a security event is detected, the system can immediately execute pre-planned responses rather than requiring real-time manual decision-making, thus reducing response time while maintaining thorough analysis through the structured approach of pre-defined action frameworks.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple security-relevant subsystems are integrated, then comprehensive security monitoring is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity subsystem integration capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs an intermediary approach by introducing a unified query language layer that mediates between the threat mitigation system and multiple security-relevant subsystems. This intermediary layer handles the complexity of communicating with different subsystems (SIEM, SOAR, XDR, etc.) using standardized interfaces, allowing comprehensive integration without exposing the underlying complexity to the main system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388863B2Threat mitigation system and method
Publication Date: 2025.08.12 RELIAQUEST HOLDINGS LLC
  • US12388863B2 patent drawing
  • US12388863B2 patent drawing
  • US12388863B2 patent drawing

AI summary

A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification, wherein the summarized human-readable report defines one or more recommended next steps; and automatically executing some or all of the recommended next steps to define one or more recommended actions.