IP Library Granted Patent US 12,407,712
Granted Patent B2
US 12,407,712 · App. 17/745,250 · Granted Sep 2, 2025

Artificial intelligence cyber security analyst

Inventors: Timothy Bazalgette (Knebworth, GB); Dickon Humphrey (Cambridge, GB); Carl Salji (Bedford, GB); Jack Stockdale (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1441G06F3/04842G06F3/0486G06F16/2455G06F18/23G06F18/232G06F21/36G06F21/554G06F21/556G06F40/40G06N20/00G06N20/10G06V30/10H04L41/22H04L43/045H04L51/212H04L51/224H04L51/42H04L63/0209H04L63/0428H04L63/101H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1483H04L63/20G06N20/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,712
App. No.
17/745,250
Granted
Sep 2, 2025
Kind
B2
Abstract

An analyzer module forms a hypothesis on what are a possible set of cyber threats that could include the identified abnormal behavior and/or suspicious activity with AI models trained with machine learning on possible cyber threats. The Analyzer analyzes a collection of system data, including metric data, to support or refute each of the possible cyber threat hypotheses that could include the identified abnormal behavior and/or suspicious activity data with the AI models. A formatting and ranking module outputs supported possible cyber threat hypotheses into a formalized report that is presented in 1) printable report, 2) presented digitally on a user interface, or 3) both.

Claims (50)

1. A method for tackling investigations into specific real and synthesized cyber threats, comprising:

configuring an Artificial Intelligence (AI)-based cyber-security analyst operating with a human cyber security analyst who may be facing an unidentified cyber threat for a first time;

configuring the AI-based cyber-security analyst to conduct an initial analysis and provide results of the initial analysis to supplement an investigation of a potential cyber security threat by the human cyber security analyst;

configuring an analyzer module in the AI-based cyber-security analyst to use one or more AI models are initially trained through machine-learning on behaviors or suspicious activities provided from multiple data sources to assign a probability of the potential cyber security threat, including simulations, database records, and actual monitoring of different human exemplar cases, where the one or more AI models are trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats;

configuring the AI-based cyber-security analyst to form one or more hypotheses on what are possible cyber security threats which could be caused by analyzed abnormal behavior or suspicious activity, and then to find evidence data to support or refute each possible hypothesis;

extracting data by a gatherer module on each of the possible cyber security threats;

filtering the extracted data by the gatherer module to produce relevant data that either supports or refutes each of the one or more hypotheses;

configuring the analyzer module to rank, based on the relevant data, supported candidate cyber threat hypotheses by a likelihood that this candidate cyber threat hypothesis is supported, using a confidence schema to sequentially test indicators associated with each hypothesis; and

configuring a formatting module to format, present a rank for, and output the supported cyber threat hypotheses from the analyzer module into a formalized report, from a first template, that is outputted for a human user's consumption in a medium of any of 1) printable report, 2) presented digitally on a user interface, 3) in a machine readable format for further use in machine-learning reinforcement and refinement, or 4) any combination of the three.

2. The method of claim 1 further comprising:

configuring the analyzer module to analyze the possible cyber security threats with the one or more AI models trained with machine learning on the process of the human analyzing the possible cyber security threats and one or more relevant data points human analysts examine to support or rebut their analysis of a given possible cyber threat hypothesis.

3. The method of claim 1 , wherein the multiple data sources include simulations, database records, and data associated with actual monitoring of operations by a plurality of expert human cyber security analysts analyzing a risk level regarding the one or more behaviors or suspicious activities.

4. The method of claim 1 further comprising:

configuring the AI cyber-security analyst to automate the analysis with the analyzer module and the one or more AI models trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats and the formatting module to report possible cybersecurity breaches to improve investigation efficiency and guide the human cyber security analyst; and

configuring the gatherer module to at least one of pull and retrieve some data for each possible hypothesis, where a feedback loop of cooperation is configured between the gatherer module and the analyzer module and to be used to apply the one or more AI models trained on different aspects of this process.

5. The method of claim 1 , where the cyber threat hypotheses at least include 1) a human user insider attack, 2) an inappropriate network behavior, 3) a malicious software attack, and 4) a malware attack.

6. The method of claim 1 further comprising:

configuring the gatherer module to cooperate with the analyzer module in collecting the relevant data including supporting points of data and other metrics associated with each particular possible cyber security threat, and a machine learning algorithm is configured to look at the relevant data to support or refute that particular hypothesis of what the abnormal behavior or suspicious activity relates for that cyber security threat.

7. The method of claim 1 further comprising:

configuring the one or more AI models trained with machine learning on the process of the human analyzing on possible cyber threats and one or more relevant data points human analysts examine to support or rebut their analysis of a given possible cyber threat hypothesis to be trained on data sources including two or more of simulations, database records, and actual monitoring of different human exemplar cases as input to train the one or more AI models on how to make a decision.

8. The method of claim 1 further comprising:

configuring the analyzer module to utilize repetitive, iterative feedback for AI models trained with machine learning on possible cyber threats via reviewing a subsequent resulting analysis of one or more of the supported cyber security threat hypotheses and supply that information to the training of the AI models trained with machine learning on possible cyber threats in order to reinforce the model's finding as correct or inaccurate.

9. The method of claim 1 further comprising:

configuring the gatherer module to use a set of scripts to extract data on each possible cyber security threat to supply to the analyzer module, where the gatherer module is configured to use the set of scripts to walk through a step-by-step process of what to collect to filter down to the extracted data to make a decision on what is required by the analyzer module to analyze possible cyber threats with the one or more AI models trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats.

10. A non-transitory machine readable medium configured to store instructions in an executable format, where the instructions are configured to be executed by one or more processors to perform operations, comprising:

using an Artificial Intelligence (AI)-based cyber-security analyst operating with a human cyber security analyst who may be facing an unidentified cyber threat for a first time;

using the AI-based cyber-security analyst to conduct an initial analysis and then present the analysis to supplement an investigation of a potential cyber security threat by the human cyber security analyst;

using an analyzer module in the AI-based cyber-security analyst to use one or more AI models initially trained through machine-learning on behaviors or suspicious activities provided from multiple data sources to assign a probability of the potential cyber security threat, including simulations, database records, and actual monitoring of different human exemplar cases, where the one or more AI models are trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats;

using the AI-based cyber-security analyst to form one or more hypotheses on what are possible cyber security threats which could be caused by analyzed abnormal behavior or suspicious activity, and then to find evidence data to support or refute each possible hypothesis;

using a gatherer module of the AI-based cyber-security analyst to extract data on each of the possible cyber security threats;

using a gatherer module of the AI-based cyber-security analyst to filter the extracted data to relevant data that either supports or refutes each of the one or more hypotheses;

using the analyzer module to rank supported candidate cyber threat hypotheses by a likelihood that this candidate cyber threat hypothesis is supported; and

using a formatting module to format, present a rank for, and output one or more supported possible cyber threat hypotheses from the analyzer module into a formalized report, from a first template, that is outputted for a human user's consumption in a medium of any of 1) printable report, 2) presented digitally on a user interface, 3) in a machine readable format for further use in machine-learning reinforcement and refinement, or 4) any combination of the three.

11. An apparatus, comprising:

an Artificial Intelligence (AI)-based cyber-security analyst configured to operate with a human cyber security analyst who may be facing an unidentified cyber threat for a first time, where the AI-based cyber-security analyst is further configured to conduct an initial analysis and then present the analysis to supplement an investigation of a potential cyber security threat by the human cyber security analyst;

wherein an analyzer module in the AI-based cyber-security analyst is configured to use one or more AI models initially trained through machine-learning on behaviors or suspicious activities provided from multiple data sources to assign a probability of the potential cyber security threat, including simulations, database records, and actual monitoring of different human exemplar cases, where the one or more AI models are trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats,

wherein the AI-based cyber-security analyst is configured to form one or more hypotheses on what are possible cyber security threats which could be caused by analyzed abnormal behavior or suspicious activity, and then the AI Cyber Security analyst is configured to find evidence data to support or refute each possible hypothesis,

wherein a gatherer module of the AI-based cyber-security analyst is configured to extract data on each of the possible cyber security threats and to filter the extracted data to relevant data that either supports or refutes each of the one or more hypotheses,

wherein the analyzer module is configured to rank supported candidate cyber threat hypotheses by a likelihood that this candidate cyber threat hypothesis is supported; and

a formatting module configured to format, present a rank for, and output one or more supported possible cyber threat hypotheses from the analyzer module into a formalized report, from a first template, that is outputted for a human user's consumption in a medium of any of 1) printable report, 2) presented digitally on a user interface, 3) in a machine readable format for further use in machine-learning reinforcement and refinement, or 4) any combination of the three.

12. The apparatus of claim 11 , wherein the analyzer module is configured to analyze the possible cyber security threats with the one or more AI models trained with machine learning on the process of a human analyzing on possible cyber threats and one or more relevant data points human analysts examine to support or rebut their analysis of a given possible cyber threat hypothesis.

13. The apparatus of claim 11 , wherein the analyzer module is configured to form the one or more hypotheses on what are the possible cyber threats that could include the analyzed abnormal behavior or suspicious activity with the one or more AI models trained with machine learning on the possible cyber security threats, and then the analyzer module is configured to request the relevant data from the gatherer module to perform the analysis of a possible set of activities including cyber threats that could include the analyzed abnormal behavior or suspicious activity.

14. The apparatus of claim 11 , wherein the AI cyber-security analyst is configured to automate the analysis with the analyzer module and the one or more AI models trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats and the formatting module to report possible cybersecurity breaches to improve investigation efficiency and guide the human cyber security analyst, and

wherein the gatherer module is configured to at least one of pull and retrieve some data for each possible hypothesis, where a feedback loop of cooperation is configured between the gatherer module and the analyzer module and to be used to apply the one or more AI models trained on different aspects of this process.

15. The apparatus of claim 11 , wherein the gatherer module is configured to cooperate with the analyzer module in collecting the relevant data including supporting points of data and other metrics associated with each particular possible cyber security threat, and a machine learning algorithm is configured to look at the relevant data to support or refute that particular hypothesis of what the suspicious activity or abnormal behavior relates for that cyber security threat.

16. The apparatus of claim 11 , wherein the one or more AI models trained with machine learning on the process of the human analyzing on possible cyber threats and one or more relevant data points human analysts examine to support or rebut their analysis of a given possible cyber threat hypothesis are trained on data sources including two or more of simulations, database records, and actual monitoring of different human exemplar cases as input to train the one or more AI models on how to make a decision.

17. The apparatus of claim 11 , wherein the analyzer module is configured to utilize repetitive feedback for AI models trained with machine learning on possible cyber threats via reviewing a subsequent resulting analysis of one or more of the supported cyber security threat hypotheses and supply that information to the training of the AI models trained with machine learning on possible cyber threats in order to reinforce the model's finding as correct or inaccurate.

18. The apparatus of claim 11 , wherein the gatherer module is configured to use a set of scripts to extract data on each possible cyber security threat to supply to the analyzer module, where a gatherer module is configured to use the set of scripts to walk through a step-by-step process of what to collect to filter down to the extracted data to make a decision on what is required by the analyzer module to analyze possible cyber threats with the one or more AI models trained to learn how the expert human cyber security analysts tackle investigations into specific real and synthesized cyber threats.

19. The apparatus of claim 11 , wherein an assessment module is configured to assign at least one of i) a probability of or ii) a confidence level that a given cyber threat hypothesis is supported and a threat level posed by that cyber threat hypothesis, which includes the abnormal behavior or suspicious activity forming a chain of unusual behavior or suspicious activity and causal links between the chain, with the one or more AI models trained on possible cyber threats, where the assessment module is configured to receive an input from the analyzer module.

20. The apparatus of claim 11 , wherein the possible hypotheses of cyber security threats at least include 1) a human user insider attack, 2) an inappropriate network behavior, 3) a malicious software attack, and 4) a malware attack.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (3)
Continuation 16278918 · Feb 19, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20220353286A1 · Nov 3, 2022
References Cited (111)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10268821B2 · Stockdale et al. · 2019 [cited by applicant]
US 10419466B2 · Ferguson et al. · 2019 [cited by applicant]
US 10516693B2 · Stockdale et al. · 2019 [cited by applicant]
US 10701093B2 · Dean et al. · 2020 [cited by applicant]
US 11336669B2 · Bazalgette et al. · 2022 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140201836A1 · Amsler · 2014 [cited by examiner]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20140359761A1 · Altman et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150332054A1 · Eck et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170054745A1 · Zhang et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170118236A1 · Devi Reddy et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170262633A1 · Miserendino et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180048661A1 · Bird · 2018 [cited by examiner]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180367561A1 · Givental · 2018 [cited by examiner]
US 20190190945A1 · Jang · 2019 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, May 10, 2021. [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts, ” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
Massimiliano Albanese et al., “Computer-Aided Human Centric Cyber Situation Awareness,” International Conference on Computer Analysis of Images and Patters, CAIP 2017: Computer Analysis of Images and Patterns, pp. 3-25. [cited by applicant]
Cited By (3)
US 12,621,325 US 12,671,706 US 12,695,769