Invention Grant
- Patent Title: Action response framework for data security incidents
-
Application No.: US14792129Application Date: 2015-07-06
-
Publication No.: US10367828B2Publication Date: 2019-07-30
- Inventor: Allen Hadden , Kenneth Allen Rogers
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F3/0484 ; G06F3/0482

Abstract:
An incident manager application (IM) for responding to data security incidents in enterprise networks is disclosed. An IM tracks the incidents in an enterprise network by storing incident objects and incident artifact (IA) metadata created for the incidents, where the incident objects and IAs include information concerning the incidents. Incident response team (IRT) personnel of the enterprise networks can define action conditions within the IM that are associated with the incident objects. When the information within the incident objects and/or IAs meets the defined action conditions, the IM includes the objects that cause the action conditions to be satisfied in messages. Devices such as user account databases and configuration servers within the enterprise network can then download the messages and execute actions that reference the objects extracted from the downloaded messages to implement a response to the incidents.
Public/Granted literature
- US20160127394A1 Action Response Framework for Data Security Incidents Public/Granted day:2016-05-05
Information query