×

Incident triage engine

  • US 8,732,840 B2
  • Filed: 10/07/2011
  • Issued: 05/20/2014
  • Est. Priority Date: 10/07/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method of prioritizing responses to a plurality of incidents, the method being performed by a computer processor connected to a memory, the method comprising:

  • receiving, by the computer processor, attributes of a plurality of linked assets within a system;

    receiving, by the computer processor, attributes of a plurality of incidents, each incident of the plurality of incidents being initially associated with an initial asset at an initial time;

    generating, by the computer processor, for each incident, a cumulative loss forecast for the incident by;

    calculating, by the computer processor, a first loss forecast for the incident with respect to the corresponding initial asset, the first loss forecast calculations being based on the attributes of the incidents, the attributes of the assets, and an incident impact over time on an asset confidentiality loss model, an incident impact over time on an asset integrity loss model, and an incident impact over time on an asset availability loss model;

    calculating, by the computer processor, additional loss forecasts for the incident with respect to each of the remaining assets of the plurality of assets, the additional loss forecasts being based on the attributes of the incidents, the attributes of the assets, and a time duration from the initial time to a time of incident inception at each of the remaining assets; and

    calculating, by the computer processor, the cumulative loss forecast by combining the first loss forecast and the additional loss forecasts for the incident; and

    prioritizing, by the computer processor, the responses to the plurality of incidents based on the cumulative loss forecasts generated for each of the plurality of incidents.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×