Threat Mitigation Automation for Multi-Subsystem Security Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Threat mitigation systems face complexity in handling diverse security-relevant subsystems, requiring unique queries for each, which is inefficient and cumbersome.
Innovation Solution
A computer-implemented method utilizing a generative AI model and formatting script to process security event notifications, producing a summarized human-readable report and automatically executing recommended actions across multiple security-relevant subsystems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If unique queries are formulated for each security-relevant subsystem, then information can be obtained from all subsystems, but the process becomes complex and inefficient
Solution Approach 1:
The patent applies universality by creating a unified query interface that can communicate with multiple security-relevant subsystems (SIEM, SOAR, XDR, etc.) using a single standardized query language. This eliminates the need to formulate unique queries for each subsystem while maintaining the ability to gather comprehensive information from all sources, directly resolving the contradiction between information completeness and query complexity.
2Measurement precision
If manual processing of security event notifications is performed, then detailed analysis can be conducted, but response time increases
Solution Approach 1:
The patent implements self-service by enabling the threat mitigation system to automatically process security event notifications, generate summaries, identify recommended next steps, and execute actions without requiring continuous manual intervention. The system autonomously analyzes events from multiple subsystems, determines appropriate responses, and executes them through integrated APIs, thereby maintaining analysis depth while significantly reducing response time.
Solution Approach 2:
The system performs preliminary actions by pre-defining recommended next steps and action protocols for common security events. When a security event is detected, the system can immediately execute pre-planned responses rather than requiring real-time manual decision-making, thus reducing response time while maintaining thorough analysis through the structured approach of pre-defined action frameworks.
3Adaptability or versatility
If multiple security-relevant subsystems are integrated, then comprehensive security monitoring is achieved, but system complexity increases
Solution Approach 1:
The patent employs an intermediary approach by introducing a unified query language layer that mediates between the threat mitigation system and multiple security-relevant subsystems. This intermediary layer handles the complexity of communicating with different subsystems (SIEM, SOAR, XDR, etc.) using standardized interfaces, allowing comprehensive integration without exposing the underlying complexity to the main system architecture.
Data Source
AI summary
A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification, wherein the summarized human-readable report defines one or more recommended next steps; and automatically executing some or all of the recommended next steps to define one or more recommended actions.


