Threat Mitigation System with Universal Queries and AI-Guided Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Threat mitigation systems face challenges in efficiently obtaining and processing information from multiple security-relevant subsystems, often requiring unique queries for each subsystem, which is cumbersome and inefficient.
Innovation Solution
A computer-implemented method that establishes connectivity with multiple security-relevant subsystems, processes initial notifications using a generative AI model and formatting script to produce human-readable reports, and automatically executes recommended actions to address security events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a unique query is formulated for each security-relevant subsystem, then information can be obtained from each subsystem, but the process becomes cumbersome and inefficient
Solution Approach 1:
The patent applies universality by creating a universal query language that can interface with multiple different security-relevant subsystems through a standardized protocol. Instead of requiring separate query formulations for each subsystem, the system uses a single unified query language (such as JSON) that can be processed by all subsystems, thereby reducing query formulation time while maintaining information completeness across diverse security subsystems
2Adaptability or versatility
If multiple security-relevant subsystems are integrated, then comprehensive security monitoring is achieved, but system complexity increases
Solution Approach 1:
The patent employs an intermediary approach by introducing a universal query language as a mediator between the threat mitigation system and multiple security subsystems. This universal query language acts as a standardized interface layer that translates high-level security queries into subsystem-specific protocols, allowing comprehensive subsystem integration while simplifying the query formulation process for users
3Speed
If automated action execution is implemented, then response speed to security events improves, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-defining recommended actions within the universal query language response structure. When security events are detected, the system automatically executes pre-planned actions rather than requiring real-time decision-making, thereby achieving fast response speeds while keeping the automation mechanism relatively simple and maintainable
Data Source
AI summary
A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification, wherein the summarized human-readable report defines one or more recommended actions; and automatically executing some or all of the recommended actions to address the security event.


