US 12,335,316 B2
Methods and systems for processing cyber incidents in cyber incident management systems using dynamic processing hierarchies
Brian Brurok, Leesburg, VA (US); Mario Cotom, Arlington, VA (US); Christopher Euerle, Arlington, VA (US); Matthew Anderson, Mountain View, CA (US); Margo Chanin, Washington, DC (US); and Sean Spaniol, Fairfax, VA (US)
Assigned to Capital One Services, LLC, McLean, VA (US)
Filed by Capital One Services, LLC, McLean, VA (US)
Filed on Oct. 9, 2023, as Appl. No. 18/483,337.
Application 18/483,337 is a continuation of application No. 18/176,349, filed on Feb. 28, 2023, granted, now 11,818,177.
Application 18/176,349 is a continuation of application No. 16/929,061, filed on Jul. 14, 2020, granted, now 11,627,162, issued on Apr. 11, 2023.
Prior Publication US 2024/0121274 A1, Apr. 11, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); G06F 3/0484 (2022.01); G06F 16/22 (2019.01); G06F 16/245 (2019.01)
CPC H04L 63/20 (2013.01) [G06F 3/0484 (2013.01); G06F 16/2246 (2019.01); G06F 16/245 (2019.01)] 20 Claims
OG exemplary drawing
 
1. A system for processing cyber incidents in cyber incident management systems using dynamic processing hierarchies, comprising:
cloud-based memory configured to:
store a first structure for a cyber incident management system, wherein the first structure is associated with first-hierarchical automatic processing of tasks;
store a second structure for the cyber incident management system, wherein the second structure is associated with second-hierarchical processing of tasks using user inputs in response to user queries; and
cloud-based control circuitry configured to:
receive, via a user interface, a request to process a cyber incident through an integrated cyber incident management system, wherein the cyber incident includes an incident characteristic;
process the cyber incident through an integrated structure, wherein the integrated structure is generated by combining the first structure and the second structure, and wherein the incident characteristic is used to determine a shared structure node for transitioning from the first structure to the second structure; and
generate for display, on the user interface, a user query comprising native data, for the cyber incident, and integration data that describes a relationship of the native data to the integrated structure.