IP Library Granted Patent US 11,805,148
Granted Patent B2
US 11,805,148 · App. 17/513,595 · Granted Oct 31, 2023

Modifying incident response time periods based on incident volume

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA)
Assignee: Splunk Inc.
H04L63/1441G06F16/285G06F21/554H04L63/0236H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L47/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,148
App. No.
17/513,595
Granted
Oct 31, 2023
Kind
B2
Abstract

Systems, methods, and software described herein provide for managing service level agreements (SLAs) for security incidents in a computing environment. In one example, an advisement system identifies a rule set for a security incident based on enrichment information obtained for the security incident, wherein the rule set is associated with action recommendations to be taken against the incident. The advisement system further identifies a default SLA for the security incident based on the rule set, and obtains environmental characteristics related to the security incident. Based on the environmental characteristics, the advisement system determines a modified SLA for the security incident.

Claims (44)

1. A computer-implemented method, comprising:

obtaining, by an advisement system coupled to a networked computing environment, data indicating a plurality of occurrences of an incident in the networked computing environment;

identifying an action recommendation for responding to an occurrence of the plurality of occurrences of the incident, wherein the action recommendation is associated with a defined time period for receiving input from an administrator of the advisement system;

modifying, based on a number of the plurality of occurrences of the incident, the defined time period for receiving input from the administrator of the advisement system to obtain a modified defined time period; and

causing display of the action recommendation and of an indication of the modified defined time period for receiving input from the administrator of the advisement system.

2. The method of claim 1 , further comprising identifying a criticality rating associated with a computing asset affected by the incident, wherein the defined time period for receiving input is further modified based on the criticality rating.

3. The method of claim 1 , wherein the defined time period is further modified based on a time window in which the incident occurred.

4. The method of claim 1 , further comprising identifying a severity level associated with the incident, and wherein the defined time period is further modified based on the severity level.

5. The method of claim 1 , further comprising identifying a criticality rating associated with a computing asset affected by the incident, wherein the action recommendation is identified based at least in part on the criticality rating.

6. The method of claim 1 , further comprising identifying a rate of the plurality of occurrences of the incident, wherein the action recommendation is identified based at least in part on the rate of the plurality of occurrences of the incident.

7. The method of claim 1 , wherein modifying the defined time period includes reducing the defined time period.

8. The method of claim 1 , further comprising:

obtaining enrichment information associated with the incident, wherein identifying the action recommendation is based at least in part on the enrichment information; and

modifying a default hierarchy of administrators to be used to respond to the incident based on the enrichment information.

9. The method of claim 1 , further comprising obtaining enrichment information associated with the incident from one of: a database, or a website based on information associated with the incident.

10. The method of claim 1 , further comprising:

receiving input associated with the administrator to implement the action recommendation; and

implementing the action recommendation.

11. The method of claim 1 , further comprising:

receiving input to modify the action recommendation to obtain a modified action recommendation; and

implementing the modified action recommendation.

12. The method of claim 1 , further comprising receiving input deferring selection of the action recommendation to another administrator.

13. The method of claim 1 , further comprising:

obtaining environmental characteristics associated with the incident; and

modifying the defined time period based at least in part on the environmental characteristics.

14. The method of claim 1 , further comprising:

determining that the action recommendation is not selected by an administrator within the defined time period; and

initiating an automated response to respond to the incident.

15. A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors, cause performance of operations comprising:

obtaining, by an advisement system coupled to a networked computing environment, data indicating a plurality of occurrences of an incident in the networked computing environment;

identifying an action recommendation for responding to an occurrence of the plurality of occurrences of the incident, wherein the action recommendation is associated with a defined time period for receiving input from an administrator of the advisement system;

modifying, based on a number of the plurality of occurrences of the incident, the defined time period for receiving input from the administrator of the advisement system to obtain a modified defined time period; and

causing display of the action recommendation and of an indication of the modified defined time period for receiving input from the administrator of the advisement system.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause performance of operations comprising identifying a criticality rating associated with a computing asset affected by the incident, wherein the defined time period for receiving input is further modified based on the criticality rating.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the defined time period is further modified based on a time window in which the incident occurred.

18. An apparatus comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions which, when executed by the one or more processors, causes the apparatus to:

obtain data indicating a plurality of occurrences of an incident in a networked computing environment;

identify an action recommendation for responding to an occurrence of the plurality of occurrences of the incident, wherein the action recommendation is associated with a defined time period for receiving input from an administrator of an advisement system;

modify, based on a number of the plurality of occurrences of the incident, the defined time period for receiving input from the administrator of the advisement system to obtain a modified defined time period; and

cause display of the action recommendation and of an indication of the modified defined time period for receiving input from the administrator of the advisement system.

19. The apparatus of claim 18 , wherein the instructions, when executed by the one or more processors, further cause the apparatus to identify a criticality rating associated with a computing asset affected by the incident, wherein the defined time period for receiving input is further modified based on the criticality rating.

20. The apparatus of claim 18 , wherein the defined time period is further modified based on a time window in which the incident occurred.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2021
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND
To: PHANTOM CYBER CORPORATION
Reel/Frame 057965/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2021
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 057965/0715 →
Continuity (8)
Continuation 16699299 · Nov 29, 2019
Continuation 16142913 · Sep 26, 2018
Continuation 15845963 · Dec 18, 2017
Continuation 14689926 · Apr 17, 2015
Provisional Application 62106830 · Jan 23, 2015
Provisional Application 62106837 · Jan 23, 2015
Provisional Application 62087025 · Dec 3, 2014
Related Publication 20220053017A1 · Feb 17, 2022