IP Library Granted Patent US 12706948
Granted Patent B2
US 12706948 · App. 18/488,481 · Granted Aug 11, 2026

Methods, systems, and devices for recommending mitigation of internet of things (IoT) cyber threats using generative artificial intelligence

Inventors: Yaron Koral (Cherry Hill, NJ); Hasit Dani (Hillsborough, NJ)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/145H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706948
App. No.
18/488,481
Granted
Aug 11, 2026
Kind
B2
Abstract

Aspects of the subject disclosure may include, for example, obtaining a group of threat research reports, obtaining a group of indicators of compromise (IOCs), and monitoring a network of Internet of Things (IoT) devices. Further embodiments can include determining a group of possible malware on the network based on the monitoring of the network and generating a network security recommendation based on the group of threat research reports, the group of IOCs, and the group of possible malware. Other embodiments are disclosed.

Claims (43)

1 . A device, comprising:

a processing system including a processor; and

a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:

obtaining a group of threat research reports comprising unstructured data;

extracting cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier;

obtaining a group of indicators of compromise (IOCs);

monitoring, based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;

determining a group of possible malware on the network based on the monitoring of the network;

generating an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and

generating a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification.

2 . The device of claim 1 , wherein the operations further comprise implementing the network security recommendation.

3 . The device of claim 1 , wherein the generating of the network security recommendation comprises generating the network security recommendation utilizing generative artificial intelligence.

4 . The device of claim 1 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.

5 . The device of claim 4 , wherein the IoT environment classification includes automotive, healthcare, retail, utilities, government, malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.

6 . The device of claim 4 , wherein the IoT environment classification includes malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.

7 . The device of claim 4 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on a generative artificial intelligence threat classification.

8 . The device of claim 7 , wherein the generative artificial intelligence threat classification comprises malware names, tool names for initial access, threat group names, threat names, or a combination thereof.

9 . The device of claim 7 , wherein the generative artificial intelligence threat classification comprises malware type, operating system, initial access technique, campaign type, geographical region, or a combination thereof.

10 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:

obtaining a group of threat research reports;

extracting cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier, wherein the cyber threat properties comprise threat names and synonyms thereof;

obtaining a group of indicators of compromise (IOCs);

monitoring, based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;

determining a group of possible malware on the network based on the monitoring of the network;

generating an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and

generating a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification, wherein the network security recommendation comprises a determination that at least one possible malware among the group of possible malware is irrelevant and should be ignored.

11 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on the group of IOCs.

12 . The non-transitory machine-readable medium of claim 10 , wherein the operations further comprise implementing the network security recommendation.

13 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation utilizing generative artificial intelligence.

14 . The non-transitory machine-readable medium of claim 10 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.

15 . The non-transitory machine-readable medium of claim 10 , wherein the generating of the network security recommendation comprises generating the network security recommendation based on a generative artificial intelligence threat classification.

16 . A method, comprising:

obtaining, by a processing system including a processor, a group of threat research reports comprising unstructured data;

extracting, by the processing system, cyber threat properties from the group of threat research reports using a generative artificial intelligence (AI) threat classifier;

obtaining, by the processing system, a group of indicators of compromise (IOCs);

monitoring, by the processing system and based on the group of IOCs, a network of Internet of Things (IoT) devices associated with one or more IoT environments;

determining, by the processing system, a group of possible malware on the network based on the monitoring of the network;

generating, by the processing system, an IoT environment classification that associates a respective relevance of each of a plurality of cyber threat characteristics in relation to the one or more IoT environments; and

generating, by the processing system, a network security recommendation based on the cyber threat properties, the group of possible malware, and the IoT environment classification, wherein the network security recommendation comprises a determination that at least one possible malware among the group of possible malware is irrelevant and should be ignored.

17 . The method of claim 16 , wherein the generating of the network security recommendation comprises generating, by the processing system, the network security recommendation based on the group of threat research reports.

18 . The method of claim 16 , further comprising implementing the network security recommendation.

19 . The method of claim 16 , wherein the generating of the network security recommendation comprises generating, by the processing system, the network security recommendation utilizing generative artificial intelligence.

20 . The method of claim 16 , wherein the IoT environment classification includes the relevance or severity of one or more cyber threat characteristics in relation to properties of the IoT environment.