IP Library Granted Patent US 11,785,052
Granted Patent B2
US 11,785,052 · App. 15/188,281 · Granted Oct 10, 2023

Incident response plan based on indicators of compromise

Inventors: Aditya Vinayak Kothekar (Arlington, MA); Kenneth Allen Rogers (Stow, MA)
Assignee: International Business Machines Corporation
H04L63/205H04L63/101H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,052
App. No.
15/188,281
Granted
Oct 10, 2023
Kind
B2
Abstract

A system and method for responding to incidents in an enterprise network is disclosed. The system tracks incidents by creating, in an incident Manager, incident objects for each incident. Each incident object includes details for the incidents, also known as incident characteristics. The system also creates one or more indicators of compromise (IOCs) associated with the incident characteristics for each incident. When processing a new incident or an update to an incident, the system compares IOCs associated with the incident object for the incident being processed to stored IOCs for other incidents to determine if other incidents are related to the incident being processed. In embodiments, the system can then generate tasks for responding to new incidents based on incident characteristics of and IOCs associated with the new incidents, and can regenerate tasks for responding to incidents based on updates to incident characteristics of and IOCs associated with the incidents.

Claims (29)

1. A method for responding to data security incidents in an enterprise network, comprising:

creating, in an incident manager (IM) application and in an automated manner, one or more incident objects for respective one or more data security incidents, wherein an incident object includes an incident characteristic;

creating, in the IM application, one or more indicators of compromise (IOC), and linking the one or more indicators of compromise to the incident object;

determining tasks for the incident object, wherein one or more tasks are determined for the incident object based upon the incident characteristic of the incident object, and one or more common IOCs or common groupings of IOCs associated with the incident object, wherein common IOCs or common groupings of IOCs are determined by comparing the IOCs associated with the incident object for a data security incident to IOCs associated with one or more incident objects for other data security incidents stored within the IM application;

for a given data security incident, generating an incident response plan, wherein the incident response plan includes the tasks based upon the incident characteristic of the incident object associated with the given data security incident, and includes any tasks based upon the one or more common IOCs or common groupings of IOCs associated with the incident object;

for the given data security incident, and responsive to a determination that a given IOC is no longer correlated with the given data security incident, de-associating the given IOC from the incident object by unlinking it from the incident object in an automated manner, and responsive to the unlinking, re-generating the incident response plan; and

responsive to re-generating the incident response plan, programmatically initiate execution, in one or more computing entities in the enterprise network, of one or more tasks in the re-generated incident response plan to respond to the given data security incident.

2. The method of claim 1 , wherein determining the tasks for the incident object based upon the one or more IOCs associated with the incident object comprises:

identifying incident objects associated with the common IOCs or common groupings of IOCs as a set of correlated incident objects;

determining whether there are any common incident characteristics among the set of correlated incident objects; and

creating tasks based upon the common incident characteristics among the set of correlated incident objects.

3. The method of claim 2 , wherein determining whether there are any common incident characteristics among the set of correlated incident objects comprises:

loading a statistical analysis algorithm for analyzing the incident characteristics of the set of correlated incident objects; and

executing the statistical analysis algorithm against the incident characteristics of the incident objects within the set of correlated incident objects.

4. The method of claim 1 , further comprising:

sending a message to the IM application, the message having been generated by a Security Information and Event Manager (SIEM) of the enterprise network and including the incident characteristic of the incident object and the one or more IOCs associated with the incident object; and

creating, by the IM application, the incident object, the incident characteristic of the incident object, and the one or more IOCs associated with the incident object in response to receiving the message.

5. A system for responding to data security incidents, the system comprising:

a hardware processor;

an incident manager (IM) application executed on the hardware processor that creates, in an automated manner, one or more incident objects for one or more respective data security incidents, wherein an incident object includes an incident characteristic, and that creates one or more indicators of compromise (IOC) and links them to the incident object; and

a rules engine of the IM application that: creates one or more tasks for the incident object based upon the incident characteristic of the incident object; determines one or more tasks for the incident object based upon one or more common IOCs or common groupings of IOCs associated with the incident object, wherein common IOCs or common groupings of IOCs are determined by comparing the IOCs associated with the incident object for a data security incident to IOCs associated with one or more incident objects for other data security incidents stored within the IM application; and for a given data security incident generates an incident response plan, wherein the incident response plan for the given data security incident includes the tasks based upon the incident characteristic of the incident object associated with the given data security incident, and includes the tasks based upon the one or more common IOCs or common groupings of IOCs associated with the incident object;

wherein, responsive to a determination that a given IOC is no longer correlated with the given data security incident, the IM application de-associates the given IOC from the incident object by unlinking it from the incident object in an automated manner, and responsive to the unlinking, re-generates the incident response plan for the given data security incident; and

wherein the rules engine is further configured responsive to re-generating the incident response plan to programmatically initiate execution, in one or more computing entities, of one or more tasks in the re-generated incident plan to respond to the given security incident.

6. The system of claim 5 , wherein the IM application further comprises an inference engine that: identifies one or more incident objects associated with the common IOCs or common groupings of IOCs as a set of correlated incident objects; determines whether there are any common incident characteristics among the set of correlated incident objects; and sends the common incident characteristics to the rules engine, wherein the rules engine determines the tasks for each incident object based upon the one or more IOCs associated with each incident object in response to receiving the common incident characteristics from the inference engine.

7. The system of claim 5 , wherein the IM application includes a statistical analysis algorithm, and wherein the inference engine downloads the statistical analysis algorithm from the IM application and applies the statistical analysis algorithm to the set of correlated incident objects to determine whether there are any common incident characteristics among the set of correlated incident objects.

8. The system of claim 5 , further comprising a Security Information and Event Manager (SIEM) that includes the incident characteristics of the incident object and the one or more IOCs associated with the incident object within a message, and sends the message to the IM application, and wherein the IM application creates the incident object, the incident characteristic of the incident object, and the IOCs associated with the incident object in response to receiving the message.

9. The system of claim 5 , wherein types of the IOCs associated with the incident object include Internet Protocol (IP) addresses, hashes associated with malware, domain names, names of files, user accounts, registry keys, email addresses, and/or protocol port numbers.

10. The system of claim 5 , wherein the incident characteristic included within the incident object include an incident type, data compromise status information, data exposure status information, and time/date of incident occurrence.

11. The system of claim 5 , wherein the IM application receives updates to the tasks from a security analyst, and updates the incident response plans for the data security incidents to include the updated tasks from the security analyst.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded Jan 13, 2017
From: RESILIENT SYSTEMS, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 040973/0765 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2016
From: KOTHEKAR, ADITYA VINAYAK; ROGERS, KENNETH ALLEN
To: RESILIENT SYSTEMS, INC.
Reel/Frame 039735/0939 →
Continuity (1)
Related Publication 20170366582A1 · Dec 21, 2017
Cited By (1)
US 12,452,303