IP Library Granted Patent US 11,463,456
Granted Patent B2
US 11,463,456 · App. 16/525,690 · Granted Oct 4, 2022

Action response framework for data security incidents

Inventors: Allen Hadden (Marlborough, MA); Kenneth Allen Rogers (Stow, MA)
H04L63/1416G06F3/0482G06F3/04842H04L63/1408H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,456
App. No.
16/525,690
Granted
Oct 4, 2022
Kind
B2
Abstract

An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and/or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.

Claims (28)

1. A method for responding to data security incidents in an enterprise network, comprising:

storing information concerning the data security incidents, the information comprising at least one incident object for at least one data security incident, and one or more incident artifacts for data resources identified within the incident object;

comparing the information to one or more action conditions of a set of action conditions to determine any action condition satisfied by the information;

combining into a message contents of any incident object and incident artifact associated with a satisfied action condition; and

providing the message that includes the contents of any incident object and incident artifact associated with the satisfied action condition to at least one message destination, wherein a message-enabled device of one or more message-enabled devices responsible for security on the enterprise network downloads the message from a message destination of the at least one message destination in response to execution of an action script on the message-enabled device, thereby facilitating a response to a data security incident associated with the satisfied action condition.

2. The method of claim 1 , wherein the at least one incident object and the one or more incident artifacts are organized as an object-oriented inheritance hierarchy and wherein an incident artifact of the one or more incident artifacts is a child object of one or more incident objects of the at least one incident object.

3. The method of claim 1 , wherein the set of action conditions includes manual action conditions selectable from a Graphical User Interface (GUI) screen of an incident manager user application.

4. The method of claim 1 , wherein the set of action conditions includes automatic action conditions.

5. The method of claim 1 , further including configuring the message-enabled device to access the message destination.

6. The method of claim 1 , wherein the response includes further executing an other action script on the message-enabled device.

7. The method of claim 6 , wherein the other action script is provided by a configuration server.

8. The method of claim 1 , further including updating the information.

9. The method of claim 1 , further including modifying the set of action conditions.

10. A system for responding to data security incidents in an enterprise network, the system comprising:

one or more message-enabled devices responsible for security on the enterprise network; and

an incident manager application, the incident manager application comprising computer program instructions executed in a hardware processor, the computer program instructions configured to perform a set of operations including:

storing information concerning the data security incidents, the information comprising at least one incident object for at least one data security incident, and one or more incident artifacts for data resources identified within the incident object;

comparing the information to one or more action conditions of a set of action conditions to determine any action condition satisfied by the information;

combining into a message contents of any incident object and incident artifact associated with a satisfied action condition; and

providing the message that includes the contents of any incident object and incident artifact associated with the satisfied action condition to at least one message destination, wherein a message-enabled device of the one or more message-enabled devices responsible for security on the enterprise network downloads the message from a message destination of the at least one message destination in response to execution of an action script on the message-enabled device, thereby facilitating a response to a data security incident associated with the satisfied action condition.

11. The system of claim 10 , wherein the at least one incident object and the one or more incident artifacts are organized as an object-oriented inheritance hierarchy and wherein an incident artifact of the one or more incident artifacts is a child object of one or more incident objects of the at least one incident object.

12. The system of claim 10 , wherein the set of action conditions includes manual action conditions selectable from a Graphical User Interface (GUI) screen of an incident manager user application executed in association with the incident manager application.

13. The system of claim 10 , wherein the set of action conditions includes automatic action conditions.

14. The system of claim 10 , wherein the set of operations further includes configuring the message-enabled device to access the message destination.

15. The system of claim 10 , wherein the response includes further executing an other action script on the message-enabled device.

16. The system of claim 15 , wherein the other action script is provided by a configuration server.

17. The system of claim 10 , wherein the set of operations further includes updating the information.

18. The system of claim 10 , wherein the set of operations further includes modifying the set of action conditions.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2022
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 058888/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2020
From: HADDEN, ALLEN; ROGERS, KENNETH ALLEN
To: RESILIENT SYSTEMS, INC.
Reel/Frame 052799/0676 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 1, 2020
From: RESILIENT SYSTEMS, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 052799/0748 →