Threat Response Course of Action Builder for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-security systems require security administrators to individually code specific threat response plans for each hardware device on a network, making it time-consuming and inefficient to respond to network threats, as these plans must be tailored to the hardware and can be complex to manage and update.

Innovation Solution

A graphical user interface (GUI) based solution that allows network security administrators to create courses of action (CoA) using a CoA Builder module, which uses a workflow representation to design automated response processes that are hardware and system agnostic, enabling a common response across multiple devices regardless of brand or version, with the Orchestration Engine executing these actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security administrators individually code specific threat response plans for each hardware device, then the response plans can be tailored to specific hardware requirements, but the time and complexity required to create and manage these plans increases significantly

Engineering Contradiction:
Improvetailoring capabilityVSAvoidtime to create and manage plans
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements a universal template system where a single threat response plan template can be applied across multiple different hardware devices and platforms. The template contains parameterized fields that automatically adapt to the specific device type, allowing administrators to create one response plan that works universally for firewalls, routers, switches, and other network devices without needing to individually code each device-specific plan.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables administrators to copy and reuse proven threat response plans across multiple devices and scenarios. Once a response plan is created and validated for one device type, it can be copied and deployed to numerous other devices with the same or similar threat profiles, dramatically reducing the time and effort required to create individualized plans for each device.

Inventive Principle:
Principle #26Copying

2Speed

If preconfigured response plans are programmed for rapid implementation, then threat response speed improves, but the complexity of coding and customizing plans for each device increases

Engineering Contradiction:
Improvethreat response speedVSAvoidplan configuration complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system provides pre-configured response plan templates that have been designed and tested in advance for common threat scenarios. These templates contain pre-defined response actions, timing parameters, and device configuration settings that are prepared beforehand, allowing administrators to rapidly deploy responses without needing to code or configure each plan from scratch during an active threat event.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The template system uses parameterized variables that automatically adjust based on the specific device type and threat scenario. Administrators can quickly modify high-level parameters such as response timing, action intensity, and device selection criteria, while the system automatically handles the complex device-specific configuration parameters, reducing the perceived complexity for administrators.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If response plans are customized for each specific hardware device, then device compatibility and effectiveness improve, but the ease of creating and updating plans deteriorates

Engineering Contradiction:
Improvedevice compatibilityVSAvoidease of creating and updating plans
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system implements device-agnostic response plan templates that can be applied universally across multiple hardware platforms including firewalls, routers, switches, and servers. The templates are designed to work with different device types through parameterized configurations rather than device-specific coding, maintaining reliability across platforms while dramatically improving ease of creation and updates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer between the administrator and the diverse hardware devices. This template system acts as a mediator that translates high-level, device-agnostic response instructions into device-specific configurations automatically. Administrators interact with the simplified template interface, while the system handles the complex device-specific translation, ensuring compatibility without requiring administrators to understand device-specific complexities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If individualized threat response plans are coded for each device, then the precision and effectiveness of threat response improves, but the productivity of security administrators decreases

Engineering Contradiction:
Improveresponse precisionVSAvoidadministrator productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The template system maintains high response precision by using device-type-specific templates that are optimized for each category of hardware (firewall, router, switch, server). Each template contains precision-tuned parameters for its target device type, ensuring effective and precise threat responses while allowing administrators to efficiently manage multiple devices through a unified template approach rather than individually coding each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11063985B2Methods and apparatus for graphical user interface environment for creating threat response courses of action for computer networks
Publication Date: 2021.07.13 MAGENTA SECURITY HOLDINGS LLC
  • US11063985B2 patent drawing
  • US11063985B2 patent drawing
  • US11063985B2 patent drawing

AI summary

A graphical user interface provides network security administrators a tool to quickly and easily create one or more courses of action for automatic response to a network threat. The courses of action are hardware and system agnostic, which allows a common response task to be implemented by an underlying response engine for any or multiple similar-function devices regardless of brand or version. The course of action builder allows the administrator to use a simple, graphic-based, business modeling concept to craft and design security response processes rather than having to hard code response routines specific to each piece of hardware on the network. The graphic interface model allows the user of the threat response software incorporating the course of action builder to easily understand the overall flow and paths the response may take, as well as understand the data requirements and dependencies that will be evaluated.