Threat Response System Automating Security Incident Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in effectively responding to the high volume and variability of cyber threats due to the limitations of existing security threat response systems, which often result in unresolved threats and the need for manual intervention that cannot keep pace with the frequency and severity of attacks.

Innovation Solution

A system that automates the response to security threats by generating records and populating forms with threat characteristics, using a customizable workflow to execute actions and integrate threat intelligence, allowing for self-learning and enhanced security without user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual security analysis is used to investigate threats, then investigation accuracy is improved, but productivity deteriorates due to the high volume of threats that cannot be addressed

Engineering Contradiction:
Improvethreat investigation accuracyVSAvoidthreat response volume
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments the threat response process into distinct phases: automated initial assessment, triage, enrichment, and investigator review. This segmentation allows routine threats to be handled automatically while preserving human expertise for complex cases, thereby increasing overall productivity without sacrificing investigation accuracy for serious threats

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service through automated threat assessment, enrichment with contextual intelligence, and triage capabilities that operate without human intervention. This allows the system to handle high volumes of threats autonomously, freeing investigators to focus on high-value cases and thus improving both productivity and resource allocation

Inventive Principle:
Principle #25Self-service

2Reliability

If security analysts manually review each threat, then threat detection quality is improved, but loss of time increases due to the sheer volume of incidents

Engineering Contradiction:
Improvethreat detection qualityVSAvoidtime to address threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically enriching threats with contextual intelligence, assessing their validity, and prioritizing them before human review. This preliminary processing ensures that when analysts do review threats, they are focusing on validated, high-priority cases with complete contextual information, thereby maintaining detection quality while dramatically reducing the time spent on each threat

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where threat intelligence is continuously updated based on automated analysis results and investigator actions. This feedback mechanism improves threat detection quality over time by learning from patterns and updating enrichment data, while the automated nature of the feedback process prevents time loss

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If threat intelligence databases are used, then adaptability to new threats is improved, but device complexity increases due to integration requirements

Engineering Contradiction:
Improvethreat intelligence integrationVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal threat intelligence platform that can ingest and process data from multiple sources (internal logs, external feeds, threat databases) through a single integrated architecture. This multi-functional design allows the system to adapt to various threat types and sources without requiring separate integration systems for each, thereby improving adaptability while managing complexity through standardization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11550921B2Threat response systems and methods
Publication Date: 2023.01.10 SWIMLANE INC
  • US11550921B2 patent drawing
  • US11550921B2 patent drawing
  • US11550921B2 patent drawing

AI summary

A security operations system may receive an alarm in response to a detected threat. The alarm may include characteristics of the threat. The system may then generate a record in response to the alarm and populate a form with the characteristics of the threat. The form may be associated with the record and selected in response to a type of the threat. The system may further generate a workflow including at least one but potentially multiple actions. The system also receives security contextual information in response to a request including the characteristics of the threat or associated indicators of the threat and then updates the form to include the security contextual information. The security operations system can evaluate contextual information and request additional information, as well as leverage workflow to take iterative changes to rulesets and configurations, to provide additional security protection or garner additional information on a threat.