Artificial intelligence chatbot for data platform security analysis
In general, techniques are described that enable a computing system to execute an artificial intelligence model for data security analysis. A computing system that includes a memory and processing circuitry may be configured to implement the techniques. The memory may store a query from an end user regarding security services provided by the data platform. The processing circuitry may parse the query to identify one or more intents, and process the one or more intents to retrieve data for formulating a natural language response to the query. The processing circuitry may also process, using a large language model, the intents and the data to generate the natural language response, and output the natural language response to a user interface for display to the end user.
1 . A method comprising:
receiving, by a data platform, a query from an end user regarding security services provided by the data platform;
parsing, by the data platform, the query to identify one or more intents;
processing, by the data platform, the one or more intents to retrieve data for formulating a natural language response to the query;
processing, by the data platform, using a large language model, the intents and the data to generate the natural language response, wherein the large language model is trained based on a general knowledge base related to general knowledge of security breaches within the data platform, a specific knowledge base comprising documentation for managing security within the data platform, and an account-specific knowledge base comprising records of security breaches within a file system maintained by the data platform; and
outputting, by the data platform, the natural language response to a user interface for display to the end user.
2 . The method of claim 1 , further comprising:
executing one or more security microservices configured to analyze the file system maintained by the data platform to identify the security breaches within the file system;
storing the security breaches within the file system as the records of the security breaches;
identifying, based on the one or more intents, one or more application programming interfaces that enable interactions with the one or more security microservices; and
invoking the one or more application programming interfaces to retrieve the security breaches within the file system from the records of the security breaches, wherein the data for formulating the natural language response includes the security breaches within the file system.
3 . The method of claim 1 ,
wherein the query comprises a general query regarding the security services provided by the data platform,
wherein parsing the query comprises parsing the general query to identify a general intent of the general query,
wherein processing the one or more intents comprises accessing the general knowledge base responsive to identifying the general intent to retrieve general data responsive to the general query, and
wherein the general data relates to the security of the file system maintained by the data platform.
4 . The method of claim 1 ,
wherein the query comprises a specific query regarding the security services provided by the data platform,
wherein parsing the query comprises parsing the specific query to identify a specific intent of the specific query,
wherein processing the one or more intents comprises accessing the specific knowledge base responsive to identifying the specific intent to retrieve specific data responsive to the specific query, and
wherein the specific data comprises the documentation for managing the security within the data platform.
5 . The method of claim 1 ,
wherein the query comprises an account-specific query regarding an account maintained by the data platform for the end user,
wherein parsing the query comprises parsing the account-specific query to identify an account-specific intent of the account-specific query, and
wherein processing the one or more intents comprises accessing the account-specific knowledge base responsive to identifying the account-specific intent to retrieve security-specific data for the account responsive to the account-specific query,
wherein the security-specific data comprises the records of the security breaches within the file system maintained by the data platform.
6 . The method of claim 5 , further comprising:
executing one or more security microservices configured to analyze the file system maintained by the data platform to identify the security breaches within the file system, the file system associated with the account maintained by the data platform for the end user; and
storing the security breaches within the file system as the records of the security breaches within the file system maintained by the data platform.
7 . The method of claim 6 , wherein processing the one or more intents comprises:
identifying, based on the account-specific intent, one or more application programming interfaces that enable interactions with the one or more security microservices; and
invoking the one or more application programming interfaces to retrieve the security breaches within the file system from the records of the security breaches within the file system maintained by the data platform, wherein the data for formulating the natural language response includes the security breaches within the file system.
8 . The method of claim 5 , wherein the security breaches within the file system maintained by the data platform include one or more of a ransomware attack, a malware attack, an unauthorized data access, and a presence of malicious code.
9 . The method of claim 1 , wherein the user interface presents a chatbot user interface with which the end user interacts to enter the query as a natural language query.
10 . A computing system that implements a data platform, the computing system comprising:
a memory configured to store a query from an end user regarding security services provided by the data platform; and
processing circuitry configured to:
parse the query to identify one or more intents;
process the one or more intents to retrieve data for formulating a natural language response to the query;
process, using a large language model, the intents and the data to generate the natural language response, wherein the large language model is trained based on a general knowledge base related to general knowledge of security breaches within the data platform, a specific knowledge base comprising documentation for managing security within the data platform, and an account-specific knowledge base comprising records of security breaches within a file system maintained by the data platform; and
output the natural language response to a user interface for display to the end user.
11 . The computing system of claim 10 , wherein the processing circuitry is further configured to:
execute one or more security microservices configured to analyze the file system maintained by the data platform to identify the security breaches within the file system;
store the security breaches within the file system as the records of the security breaches;
identify, based on the one or more intents, one or more application programming interfaces that enable interactions with the one or more security microservices; and
invoke the one or more application programming interfaces to retrieve the security breaches within the file system from the records of the security breaches, wherein the data for formulating the natural language response includes the security breaches within the file system.
12 . The computing system of claim 10 ,
wherein the query comprises a general query regarding the security services provided by the data platform,
wherein the processing circuitry is, when configured to parse the query, is configured to parse the general query to identify a general intent of the general query,
wherein the processing circuitry is, when configured to process the one or more intents, configured to access the general knowledge base responsive to identifying the general intent to retrieve general data responsive to the general query, and
wherein the general data relates to the security of the file system maintained by the data platform.
13 . The computing system of claim 10 ,
wherein the query comprises a specific query regarding the security services provided by the data platform,
wherein the processing circuitry is, when configured to parse the query, is configured to parse the specific query to identify a specific intent of the specific query,
wherein the processing circuitry is, when configured to process the one or more intents, configured to access the specific knowledge base responsive to identifying the specific intent to retrieve specific data responsive to the specific query, and
wherein the specific data comprises the documentation for managing the security within the data platform.
14 . The computing system of claim 10 ,
wherein the query comprises an account-specific query regarding an account maintained by the data platform for the end user,
wherein the processing circuitry is, when configured to parse the query, is configured to parse the account-specific query to identify an account-specific intent of the account-specific query, and
wherein the processing circuitry is, when configured to process the one or more intents, configured to access the account-specific knowledge base responsive to identifying the account-specific intent to retrieve security-specific data for the account responsive to the account-specific query,
wherein the security-specific data comprises the records of the security breaches within the file system maintained by the data platform.
15 . The computing system of claim 14 , wherein the processing circuitry is configured to:
execute one or more security microservices configured to analyze the file system managed by the data platform to identify the security breaches within the file system, the file system associated with the account maintained by the data platform for the end user; and
store the security breaches within the file system as the records of the security breaches.
16 . The computing system of claim 15 , wherein the processing circuitry is, when configured to process the one or more intents, is configured to:
identify, based on the account-specific intent, one or more application programming interfaces that enable interactions with the one or more security microservices; and
invoke the one or more application programming interfaces to retrieve the security breaches from the records of the security breaches, wherein the data for formulating the natural language response includes the security breaches.
17 . The computing system of claim 14 , wherein the security breaches within the file system maintained by the data platform include one or more of a ransomware attack, a malware attack, an unauthorized data access, and a presence of malicious code.
18 . Non-transitory computer-readable storage media having instructions stored thereon that, when executed, cause one or more processors to:
obtain a query from an end user regarding security services provided by a data platform;
parse the query to identify one or more intents;
process the one or more intents to retrieve data for formulating a natural language response to the query;
process, using a large language model, the intents and the data to generate the natural language response, wherein the large language model is trained based on a general knowledge base related to general knowledge of security breaches within the data platform, a specific knowledge base comprising documentation for managing security within the data platform, and an account-specific knowledge base comprising records of security breaches within a file system maintained by the data platform; and
output the natural language response to a user interface for display to the end user.