Automatic incident generator

US12170678B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12170678-B2
Application numberUS-202217804830-A
CountryUS
Kind codeB2
Filing dateMay 31, 2022
Priority dateMay 31, 2022
Publication dateDec 17, 2024
Grant dateDec 17, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for automatic recognition of security incidents includes a processor coupled to a memory storing instructions, the processor being configured to implement the instructions for an automatic incident generator (AIG) with at least one type of events related to the system, and access to a repository of information about previously recorded incidents with the events related to these previously recorded incidents, to monitor a plurality of events, identify sequences of events including suspected signatures that are capable of constituting an incident, calculate a degree of variance (DoV) of the suspected signatures and at least one signature related to a previously recorded incident, compare the DoV to at least one threshold and, if the DoV is less (or less or equal) to the threshold, identify the incident and optionally initiate the workflow related to the identified incident.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for automatic detection of security incidents in a computer system with access to a database of previously recorded security incidents comprising incident signatures based on a sequence of at least three events related to the security incidents, the method comprising: monitoring an event stream comprising a sequence of at least three system events in the computer system; calculating an incident signature based on the sequence of at least three system events; calculating a degree of variance (DoV) of the monitored sequence of events from the incident signature, wherein the DoV is the distance between the incident signature and an incident signature based on previously recorded security incidents; comparing the calculated DoV to a predetermined variance threshold; determining that the monitored sequence of events is a security incident associated with the incident signature of the previously recorded activities when the calculated DoV is less than or equal the threshold; determining that the monitored sequence of events is not a security incident associated with the incident signature of the previously recorded activities when the calculated DoV is greater than the threshold; executing instructions on the computer system based on the calculated DoV, wherein the instructions add the determined security incident to the database of previously recorded security incidents when the calculated DoV is less than or equal to the threshold and wherein the instructions do not add the monitored sequence of events to the database of previously recorded security incidents when the calculated DoV is greater than the threshold; and when the calculated DoV is less than or equal to the threshold, apply the security incident to a security policy which prevents sending a message to a receiver. 2. The method of claim 1 , wherein the instructions further comprise raising the security incident by associating a security classification with a computer user associated with the security incident. 3. The method of claim 1 , wherein the instructions further comprise communicating predetermined information about the security incident to a user of the computer system. 4. The method of claim 1 , wherein the instructions further comprise communicating predetermined information about the security incident to a trouble tracking system. 5. The method of claim 1 , wherein the instructions further comprise communicating predetermined information about the security incident to a system administrator. 6. The method of claim 1 , wherein the instructions further comprise identifying controls in the computing system related to the security incident. 7. The system of claim 6 , wherein the instructions further comprise applying controls in the computer system related to the security incident. 8. The method of claim 1 , wherein a determined security incident is further analyzed and classified using pre-programmed heuristic rules, statistical analysis, a neural network, or support vector machines. 9. The method of claim 1 , wherein the at least one incident signature comprises information about a sequence of four or more events. 10. The method of claim 1 , wherein the security incident comprises a sequence of three or more events comprising failed attempts at transmitting digital data followed by a successful transmission of digital data to one or more receivers or one or more devices outside the computer system. 11. A system for automatic detection of security incidents in a computer system, the system comprising: a database of previously recorded security incidents comprising incident signatures based on a sequence of at least three events related to the security incidents; a microprocessor in communication with the database and coupled to a memory storing instructions, the microprocessor being configured to implement the instructions for automatic incident generation and access the database of previously recorded security incidents with the events related to these incidents, to: monitor an event stream comprising a sequence of at least three system events in the computer system; calculating an incident signature based on a sequence of the at least three system events; compare the calculated DoV to a predetermined variance threshold; calculate a degree of variance (DoV) of the monitored sequence of events from the incident signature wherein the DoV is the distance between the incident signature and an incident signature based on previously recorded security incidents; determine that the monitored sequence of events is a security incident associated with the incident signature of the previously recorded activities when the calculated DoV is less than or equal the threshold; determine that the monitored sequence of events is not a security incident associated with the incident signature of the previously recorded activities when the calculated DoV is greater than the threshold; execute instructions on the computer system based on the calculated DoV, wherein the instructions add the identified security incident to the database of previously recorded security incidents when the calculated DoV is less than or equal to the threshold and wherein the instructions do not add the monitored sequence of events to the database of previously recorded security incidents when the calculated DoV is greater than the threshold; and when the calculated DoV is less than or equal to the threshold, apply the security incident to a security policy which prevents sending a message to a receiver. 12. The system of claim 11 , wherein the AIG instructions raise the security incident by associating a security classification with a computer user associated with the security incident. 13. The system of claim 11 , wherein the instructions cause communication of predetermined information about the security incident to a user of the computer system. 14. The system of claim 11 , wherein the instructions cause communication of predetermined information about the security incident to an incident management, trouble tracking, or workflow management system. 15. The system of claim 11 , wherein the instructions cause communication of predetermined information about the security incident to a system administrator. 16. The system of claim 11 , wherein the instructions cause identification of controls related to the security incident. 17. The system of claim 16 , wherein the instructions apply controls in the computer system related to the security incident. 18. The system of claim 11 , wherein the microprocessor is further configured to analyze and classify a determined security incident by performing analysis using pre-programmed heuristic rules, statistical analysis, a neural network, or support vector machines. 19. The system of claim 11 , wherein the at least one incident signature comprises information about a sequence of four or more events. 20. The system of claim 11 , wherein the security incident comprises a sequence of three or more events comprising failed attempts to transmit digital data followed by a successful transmission of digital data to one or more receivers or one or more devices outside the computer system.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12170678B2 cover?
A system for automatic recognition of security incidents includes a processor coupled to a memory storing instructions, the processor being configured to implement the instructions for an automatic incident generator (AIG) with at least one type of events related to the system, and access to a repository of information about previously recorded incidents with the events related to these previou…
Who is the assignee on this patent?
Acronis Int Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 17 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).