IP Library Granted Patent US 12706943
Granted Patent B2
US 12706943 · App. 18/368,392 · Granted Aug 11, 2026

Automated threat response in extended detection and response (XDR) systems

Inventors: Jaroslav Hlavac (Prague, CZ); Martin Kopp (Komarov, CZ); Michael Adam Polak (Prague, CZ)
Assignee: Cisco Technology, Inc.
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706943
App. No.
18/368,392
Granted
Aug 11, 2026
Kind
B2
Abstract

Techniques and architecture are described for automated threat response and remediation of incidents generated by single or multiple security products. The techniques and architecture provide a framework for automated threat response and remediation of incidents generated by single or multiple security products, especially for extended detection and response (XDR) systems. In particular, the techniques and architecture provide for an automated threat response that is handled by an auto-analyst engine emulating security analysts' steps during incident response and remediation. The automated threat response automatically confirms or disapproves of detection verdicts thereby reducing false positives that analysts usually have to deal with. If any actions are needed from a security analyst, a concise report of actions taken, gathered information and recommended next steps are provided by the automated threat response, significantly reducing the time and resources needed to resolve an incident.

Claims (79)

1 . A method comprising:

ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple security product vendors, and (iii) operating system logs;

based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and

based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,

wherein if the particular network alert event is not a security problem, the at least one further first step comprises:

generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and

adding the summary to an incident database, and

wherein if the particular network alert event is a security problem, the at least one further first step comprises:

adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.

2 . The method of claim 1 , further comprising:

automatically determining, by the auto-analyst engine, whether a process is monitored; and

based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:

wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.

3 . The method of claim 2 , wherein if the particular network alert event is a security problem, the method further comprises:

determining, by the auto-analyst engine, the process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.

4 . The method of claim 3 , wherein if the process is monitored, the at least one further second step comprises:

determining, by the auto-analyst engine, whether the process is still running,

wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action.

5 . The method of claim 4 , wherein if the process is still running, the method further comprises:

at least one of closing, by the auto-analyst engine, the connection to a uniform resource locator (URL), closing, by the auto-analyst engine, a port on which communication is occurring, isolating, by the auto-analyst engine, the network device, discontinuing, by the auto-analyst engine, the process running, or quarantining, by the auto-analyst engine, the network device; and

generating, by the auto-analyst engine, the summary relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.

6 . The method of claim 1 , further comprising:

obtaining, by the auto-analyst engine, information related to the particular network alert event from at least one of (i) one or more security product application programming interfaces (APIs) or (ii) the incident database.

7 . The method of claim 1 , further comprising:

suggesting, by the auto-analyst engine to a network security entity, further actions that may be taken based at least in part on a history of network alert events.

8 . The method of claim 1 , further comprising:

providing, by the auto-analyst engine to a network security entity, the summary; and

receiving, by the auto-analyst engine from the network security entity, feedback related to the summary.

9 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple product vendors, and (iii) operating system logs;

based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and

based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,

wherein if the particular network alert event is not a security problem, the at least one further first step comprises:

generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and

adding the summary to an incident database, and

wherein if the particular network alert event is a security problem, the at least one further first step comprises:

adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.

10 . The system of claim 9 , wherein the actions further comprise:

automatically determining, by the auto-analyst engine, whether a process is monitored; and

based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:

wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.

11 . The system of claim 10 , wherein if the particular network alert event is a security problem, the actions further comprise:

determining, by the auto-analyst engine, a process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.

12 . The system of claim 11 , wherein if the process is monitored, the at least one further second step comprises:

determining, by the auto-analyst engine, whether the process is still running,

wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action.

13 . The system of claim 12 , wherein if the process is still running, the actions further comprise:

at least one of closing, by the auto-analyst engine, the connection to a uniform resource locator (URL), closing, by the auto-analyst engine, a port on which communication is occurring, isolating, by the auto-analyst engine, the network device, discontinuing, by the auto-analyst engine, the process running, or quarantining, by the auto-analyst engine, the network device; and

generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.

14 . The system of claim 9 , wherein the actions further comprise:

obtaining, by the auto-analyst engine, information related to the particular network alert event from at least one of (i) one or more security product application programming interfaces (APIs) or (ii) the incident database.

15 . The system of claim 9 , further comprising:

suggesting, by the auto-analyst engine to a network security entity, further actions that may be taken based at least in part on a history of particular network alert events.

16 . The system of claim 15 , wherein the actions further comprise:

providing, by the auto-analyst engine to a network security entity, the summary; and

receiving, by the auto-analyst engine from the network security entity, feedback related to the summary.

17 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:

ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple security product vendors, and (iii) operating system logs;

based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and

based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,

wherein if the particular network alert event is not a security problem, the at least one further first step comprises:

generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and

adding the summary to an incident database, and

wherein if the particular network alert event is a security problem, the at least one further first step comprises:

adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein the actions further comprise:

automatically determining, by the auto-analyst engine, whether a process is monitored; and

based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:

wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.

19 . The one or more non-transitory computer-readable media of claim 18 , wherein if the particular network alert event is a security problem, the actions further comprise:

determining, by the auto-analyst engine, a process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.

20 . The one or more non-transitory computer-readable media of claim 19 , wherein if the process is monitored, the at least one further second step comprises:

determining, by the auto-analyst engine, whether the process is still running,

wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action, and

wherein if the process is still running, the actions further comprise:

discontinuing, by the auto-analyst engine, the process running; and

generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.