IP Library Granted Patent US 12,542,790
Granted Patent B2
US 12,542,790 · App. 17/874,798 · Granted Feb 3, 2026

Action response framework for data security incidents

Inventors: Allen Hadden (Marlborough, MA); Kenneth Allen Rogers (Stow, MA)
Assignee: Workday, Inc.
H04L63/1416G06F3/0482G06F3/04842H04L63/1408H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,790
App. No.
17/874,798
Granted
Feb 3, 2026
Kind
B2
Abstract

An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and/or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.

Claims (40)

1 . A system comprising:

a graphical user interface configured to:

receive an indication to add an automatic action, wherein the automatic action comprises one or more conditions for satisfying the automatic action, and wherein a condition of the one or more conditions includes a message destination; and

a processor configured to:

receive an indication of an incident, wherein the indication comprises an incident object;

parse the incident object to determine an incident type associated with the incident;

perform a lookup in a decision tree to determine whether the automatic action is configured for the incident type, wherein the lookup retrieves the message destination for the incident type via the decision tree;

in response to a determination that the automatic action is configured for the incident type, determine whether the condition of the one or more conditions is satisfied by the incident object; and

in response to the condition being satisfied, send a message to the message destination, wherein the message comprises the incident object.

2 . The system of claim 1 , wherein the graphical user interface is further configured to display a button for indicating to add an automatic action.

3 . The system of claim 1 , wherein the graphical user interface is further configured to display a graphical user interface for creating an automatic action.

4 . The system of claim 3 , wherein the graphical user interface for creating the automatic action enables an indication of an associated incident type.

5 . The system of claim 3 , wherein the graphical user interface includes a create button.

6 . The system of claim 1 , wherein the automatic action comprises an instruction to quarantine a device.

7 . The system of claim 6 , wherein quarantining the device comprises segmenting network traffic.

8 . The system of claim 1 , wherein the automatic action comprises an instruction to lock a user account.

9 . The system of claim 8 , wherein the lock of the user account is associated with detection of malware.

10 . The system of claim 1 , wherein the automatic action comprises an instruction to block messages.

11 . The system of claim 10 , wherein the blocking of messages occurs associated with an IP address associated with malware.

12 . The system of claim 1 , wherein the automatic action comprises an instruction to close ports on a firewall.

13 . The system of claim 12 , wherein closing the ports on the firewall is in response to an attach incident.

14 . The system of claim 12 , wherein closing the ports on the firewall is in response to detection of a spoofed IP address.

15 . The system of claim 1 , wherein the automatic action comprises updating at least one of one or more control lists or one or more account databases to blacklist one or more user identifications.

16 . The system of claim 15 , wherein blacklisting the one or more user identifications is in response to detection of a phishing event associated with the one or more user identifications.

17 . The system of claim 1 , wherein the message destination retrieved by the lookup via the decision tree identifies a machine-readable endpoint within an enterprise network configured to receive and process the message without human intervention.

18 . The system of claim 17 , wherein the machine-readable endpoint comprises a message queue, and sending the message to the message destination is associated with enqueuing the message in the message queue.

19 . A method comprising:

receiving, using a graphical user interface, an indication to add an automatic action, wherein the automatic action comprises one or more conditions for satisfying the automatic action, and wherein a condition of the one or more conditions includes a message destination;

receiving an indication of an incident, wherein the indication comprises an incident object;

parsing, using a processor, the incident object to determine an incident type associated with the incident;

performing a lookup in a decision tree to determine whether the automatic action is configured for the incident type, wherein the lookup retrieves the message destination for the incident type via the decision tree;

in response to a determination that the automatic action is configured for the incident type, determining whether the condition of the one or more conditions is satisfied by the incident object; and

in response to the condition being satisfied, sending a message to the message destination, wherein the message comprises the incident object.

20 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, using a graphical user interface, an indication to add an automatic action, wherein the automatic action comprises one or more conditions for satisfying the automatic action, and wherein a condition of the one or more conditions includes a message destination;

receiving an indication of an incident, wherein the indication comprises an incident object;

parsing, using a processor, the incident object to determine an incident type associated with the incident;

performing a lookup in a decision tree to determine whether the automatic action is configured for the incident type, wherein the lookup retrieves the message destination for the incident type via the decision tree;

in response to a determination that the automatic action is configured for the incident type, determining whether the condition of the one or more conditions is satisfied by the incident object; and

in response to the condition being satisfied, sending a message to the message destination, wherein the message comprises the incident object.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
Continuity (4)
Continuation 16525690 · Jul 30, 2019
Continuation 14792129 · Jul 6, 2015
Provisional Application 62072829 · Oct 30, 2014
Related Publication 20220385679A1 · Dec 1, 2022
References Cited (117)
US 6125408A · McGee · 2000 [cited by applicant]
US 6378607B1 · Ryan · 2002 [cited by applicant]
US 6678827B1 · Rothermel · 2004 [cited by applicant]
US 7013395B1 · Swiler · 2006 [cited by applicant]
US 7376969B1 · Njemanze · 2008 [cited by applicant]
US 7472422B1 · Agbabian · 2008 [cited by examiner]
US 7873717B1 · Woolway · 2011 [cited by applicant]
US 7877804B2 · Khanolkar · 2011 [cited by applicant]
US 7996374B1 · Jones · 2011 [cited by examiner]
US 8032557B1 · Sudhir · 2011 [cited by applicant]
US 8056130B1 · Njemanze · 2011 [cited by examiner]
US 8141157B2 · Farley · 2012 [cited by applicant]
US 8176561B1 · Hurst · 2012 [cited by examiner]
US 8225407B1 · Thrower · 2012 [cited by examiner]
US 8244777B1 · Sudhir · 2012 [cited by applicant]
US 8365278B1 · Njemanze · 2013 [cited by examiner]
US 8661062B1 · Jamail · 2014 [cited by applicant]
US 8707445B2 · Sher-Jan · 2014 [cited by applicant]
US 8763133B2 · Sher-Jan · 2014 [cited by applicant]
US 8782784B1 · Bruskin · 2014 [cited by applicant]
US 8880682B2 · Bishop · 2014 [cited by applicant]
US 9002384B1 · Hallenbeck · 2015 [cited by examiner]
US 9069930B1 · Hart · 2015 [cited by applicant]
US 9075668B1 · Hushon · 2015 [cited by applicant]
US 9083734B1 · Bishop · 2015 [cited by applicant]
US 9152706B1 · Claudatos · 2015 [cited by applicant]
US 9215270B2 · Mohaban · 2015 [cited by applicant]
US 9258321B2 · Amsler · 2016 [cited by applicant]
US 11030579B1 · Campbell · 2021 [cited by examiner]
US 11997129B1 · Aloisio · 2024 [cited by examiner]
US 20020169644A1 · Greene · 2002 [cited by examiner]
US 20030023476A1 · Gainey · 2003 [cited by examiner]
US 20030105976A1 · Copeland, III · 2003 [cited by examiner]
US 20040267729A1 · Swaminathan · 2004 [cited by examiner]
US 20050039144A1 · Wada · 2005 [cited by examiner]
US 20050182722A1 · Meyer · 2005 [cited by examiner]
US 20050193269A1 · Haswell · 2005 [cited by examiner]
US 20050245232A1 · Jakober · 2005 [cited by examiner]
US 20060031938A1 · Choi · 2006 [cited by applicant]
US 20060101517A1 · Banzhof · 2006 [cited by applicant]
US 20060211404A1 · Cromp · 2006 [cited by examiner]
US 20070103294A1 · Bonecutter · 2007 [cited by examiner]
US 20070164849A1 · Haeberle · 2007 [cited by examiner]
US 20070180107A1 · Newton · 2007 [cited by examiner]
US 20080016569A1 · Hammer · 2008 [cited by examiner]
US 20080040191A1 · Chakravarty · 2008 [cited by examiner]
US 20080133300A1 · Jalinous · 2008 [cited by examiner]
US 20090063234A1 · Refsland · 2009 [cited by examiner]
US 20090103524A1 · Mantripragada · 2009 [cited by examiner]
US 20090199120A1 · Baxter · 2009 [cited by examiner]
US 20090200021A1 · Pinto · 2009 [cited by applicant]
US 20090217381A1 · Helman · 2009 [cited by examiner]
US 20090254392A1 · Zander · 2009 [cited by examiner]
US 20090271504A1 · Ginter · 2009 [cited by applicant]
US 20090328222A1 · Helman · 2009 [cited by examiner]
US 20100131533A1 · Ortiz · 2010 [cited by applicant]
US 20100242106A1 · Harris · 2010 [cited by applicant]
US 20100306179A1 · Lim · 2010 [cited by examiner]
US 20110106558A1 · Solito · 2011 [cited by applicant]
US 20110145711A1 · Njemanze · 2011 [cited by examiner]
US 20120131185A1 · Petersen · 2012 [cited by applicant]
US 20120205154A1 · Lozinsky · 2012 [cited by applicant]
US 20120232947A1 · McLachlan · 2012 [cited by examiner]
US 20120324377A1 · Allington · 2012 [cited by examiner]
US 20130055399A1 · Zaitsev · 2013 [cited by examiner]
US 20130091574A1 · Howes · 2013 [cited by applicant]
US 20130124223A1 · Gregg · 2013 [cited by applicant]
US 20130179936A1 · Choi · 2013 [cited by examiner]
US 20130246925A1 · Ahuja · 2013 [cited by examiner]
US 20130297364A1 · Putra · 2013 [cited by examiner]
US 20130329522A1 · Skinner · 2013 [cited by applicant]
US 20130332590A1 · Mohaban · 2013 [cited by applicant]
US 20130346440A1 · Alon · 2013 [cited by examiner]
US 20140058730A1 · Costa · 2014 [cited by examiner]
US 20140089039A1 · McClellan · 2014 [cited by examiner]
US 20140208843A1 · Godfrey · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by examiner]
US 20140278664A1 · Loomis · 2014 [cited by examiner]
US 20140304822A1 · Sher-Jan · 2014 [cited by applicant]
US 20150033351A1 · Oliphant · 2015 [cited by examiner]
US 20150113663A1 · Sher-Jan · 2015 [cited by applicant]
US 20150143504A1 · Desai · 2015 [cited by examiner]
US 20150180891A1 · Seward · 2015 [cited by examiner]
US 20150235164A1 · Key · 2015 [cited by applicant]
US 20150242625A1 · Cassidy · 2015 [cited by applicant]
US 20150244732A1 · Golshan · 2015 [cited by examiner]
US 20150312266A1 · Thomas · 2015 [cited by examiner]
US 20150312267A1 · Thomas · 2015 [cited by examiner]
US 20150356301A1 · Diehl · 2015 [cited by applicant]
US 20160021133A1 · Sher-Jan · 2016 [cited by applicant]
US 20160028771A1 · Jacobsen · 2016 [cited by applicant]
US 20160036837A1 · Jain · 2016 [cited by applicant]
US 20160072836A1 · Hadden · 2016 [cited by examiner]
US 20160119379A1 · Nadkarni · 2016 [cited by examiner]
US 20160164890A1 · Haugsnes · 2016 [cited by examiner]
US 20160192166A1 · deCharms · 2016 [cited by examiner]
US 20160205142A1 · Arkin · 2016 [cited by examiner]
US 20160308910A1 · Carver · 2016 [cited by examiner]
US 20160321452A1 · Richardson · 2016 [cited by examiner]
US 20160373469A1 · Howard · 2016 [cited by examiner]
US 20170048273A1 · Bach · 2017 [cited by examiner]
US 20170070480A1 · Blumenfeld · 2017 [cited by examiner]
US 20170230412A1 · Thomas · 2017 [cited by examiner]
US 20200304999A1 · Hernoud · 2020 [cited by examiner]
WO 2004104793 · 2004 [cited by applicant]
QRadar Users Guide, http://www.q1labs.com, May 2012. 396 pages. [cited by applicant]
BlackStratus SIEMStorm, “Rapidly identify and resolve threats, . . . ” www.blackstratus.com, 2012. Four pages. [cited by applicant]
D. Swift, “A Practical Application of SIM/SEM/SIEM Automating Threat Identification,” 2006, SANS Institute 2007. Forty-one pages. [cited by applicant]
Domino Project Management, “Track and Control Projects with Lotus Notes,” www.trackersuite.com/index, 2013. Two pages. [cited by applicant]
HP ArcSight Express, “World-Class Protection for the Mid-Size Organization,” www.arcsight.com, 2010. Six pages. [cited by applicant]
J. Jarocki, “Orion Incident Response Live CD,” 2010, Sans Institute, https://www.sans.org. Forty-five pages. [cited by applicant]
Janet Csirt, “RTIR incident handling work-flow,” Janet (UK) WI/JCSIRT/002, jisc.ac.uk, 2011. Eighteen pages. [cited by applicant]
Khurana et al., “Palantir: A Framework for Collaborative Incident Response and Investigation,” IDtrust, 2009. Fourteen pages. [cited by applicant]
M. West-Brown et al., “Handbook for Computer Security Incident Response Teams (CSIRTs),” 2nd Edition, Apr. 2003. 223 pages. [cited by applicant]
PCT/US15/48469 International Search Report and Written Opinion of the International Searching Authority, mailed Nov. 27, 2015. [cited by applicant]
QRadar Administration Guide, http://www.q1labs.com, May 2012. 318 pages. [cited by applicant]
Reddy et al., “The architecture of a digital forensic readiness management system,” Computers & Security 32 (2013) 73-89. Seventeen pages. [cited by applicant]