INCIDENT TRIAGE ENGINE
0 Assignments
0 Petitions
Accused Products
Abstract
An incident triage engine performs incident triage in a system by prioritizing responses to incidents within the system. One prioritization method may include receiving attributes of incidents and assets in the system, generating cumulative loss forecasts for the incidents, and prioritizing the responses to the incidents based on the cumulative loss forecasts for the incidents. Another prioritization method may include determining different arrangements of incidents within a response queue, calculating cumulative queue loss forecasts for the different arrangements of incidents within the response queue, and arranging the incidents in the response queue based on the arrangement of incidents that minimizes the total loss to the system over the resolution of all of the incidents present in the response queue.
16 Citations
42 Claims
-
1-5. -5. (canceled)
-
6. A method of prioritizing responses to a plurality of incidents within a system, the method being performed by a processor connected to a memory, the method comprising:
-
determining a plurality of different arrangements of the incidents within a response queue; calculating, for each of the plurality of different arrangements of the incidents within the response queue, a cumulative queue loss forecast based on the arrangement of the incidents within the response queue; and arranging the order of the incidents within the response queue according to the arrangement of the incidents within the response queue with the smallest cumulative queue loss forecast. - View Dependent Claims (7, 8, 9, 10, 11, 12, 13, 14)
-
-
15-19. -19. (canceled)
-
20. A non-transitory computer-readable storage medium storing computer program instructions for prioritizing responses to a plurality of incidents within a system according to a method, the method comprising:
-
determining a plurality of different arrangements of the incidents within a response queue; calculating, for each of the plurality of different arrangements of the incidents within the response queue, a cumulative queue loss forecast based on the arrangement of the incidents within the response queue; and arranging the order of the incidents within the response queue according to the arrangement of the incidents within the response queue with the smallest cumulative queue loss forecast. - View Dependent Claims (21, 22, 23, 24, 25, 26, 27, 28)
-
-
29-33. -33. (canceled)
-
34. A system including a processor and a memory, the memory storing instructions operable with the processor for prioritizing responses to a plurality of incidents within an environment, the instructions associated with a plurality of devices, the devices comprising:
-
a determining device that determines a plurality of different arrangements of the incidents within a response queue; a calculating device that calculates, for each of the plurality of different arrangements of the incidents within the response queue, a cumulative queue loss forecast based on the arrangement of the incidents within the response queue; and an arranging device that arranges the order of the incidents within the response queue according to the arrangement of the incidents within the response queue with the smallest cumulative queue loss forecast. - View Dependent Claims (35, 36, 37, 38, 39, 40, 41, 42)
-
Specification