Invention Grant
- Patent Title: Incident response plan based on indicators of compromise
-
Application No.: US15188281Application Date: 2016-06-21
-
Publication No.: US11785052B2Publication Date: 2023-10-10
- Inventor: Aditya Vinayak Kothekar , Kenneth Allen Rogers
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L29/06 ; H04L9/40

Abstract:
A system and method for responding to incidents in an enterprise network is disclosed. The system tracks incidents by creating, in an incident Manager, incident objects for each incident. Each incident object includes details for the incidents, also known as incident characteristics. The system also creates one or more indicators of compromise (IOCs) associated with the incident characteristics for each incident. When processing a new incident or an update to an incident, the system compares IOCs associated with the incident object for the incident being processed to stored IOCs for other incidents to determine if other incidents are related to the incident being processed. In embodiments, the system can then generate tasks for responding to new incidents based on incident characteristics of and IOCs associated with the new incidents, and can regenerate tasks for responding to incidents based on updates to incident characteristics of and IOCs associated with the incidents.
Public/Granted literature
- US20170366582A1 Incident Response Plan based on Indicators of Compromise Public/Granted day:2017-12-21
Information query