IP Library › Granted Patent US 12,462,106
Granted Patent B2
US 12,462,106 · App. 18/126,183 · Granted Nov 4, 2025

Generating security reports

Inventors: Eric Paul Douglas (Kirkland, WA); Mario Davis Goertzel (Kirkland, WA); Lloyd Geoffrey Greenwald (Murray Hill, NJ); Aditi Kamlesh Shah (Redmond, WA); Leo Moreno Betthauser (Kirkland, WA); Daniel Lee Mace (Bellevue, WA); Nicholas Becker (Boulder, CO)
Assignee: Microsoft Technology Licensing, LLC
G06F40/30G06F16/3329G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,106
App. No.
18/126,183
Granted
Nov 4, 2025
Kind
B2
Abstract

In some examples, a method of generating a security report is provided. The method includes receiving a user query and security data, and providing the user query and security data to a semantic model. The semantic model generates one or more first embeddings. The method further includes receiving, from a data model, one or more second embeddings. The data model is generated based on historical threat intelligence data. The model further includes generating an execution plan based on the one or more first embeddings and the one or more second embeddings, and returning a report that corresponds to the execution plan.

Claims (56)

1 . A method of generating security reports, the method comprising:

receiving a user query and security data corresponding to one or more security incidents associated with a computing environment;

providing the user query and security data to a semantic model, wherein the semantic model generates one or more first embeddings;

receiving, from a data model, one or more second embeddings, wherein the data model is generated based on historical threat intelligence data;

generating an execution plan based on the one or more first embeddings and the one or more second embeddings;

returning a report corresponding to the execution plan, the report comprising one or more instructions for resolving the one or more security incidents; and

causing the one or more instructions of the report corresponding to the execution plan to be executed, thereby resolving the one or more security incidents associated with the computing environment.

2 . The method of claim 1 , wherein the semantic model comprises a generative large language model (LLM) that uses one of zero-shot, one-shot, or few-shot prompting.

3 . The method of claim 1 , wherein the generating an execution plan comprises:

determining a respective similarity between the second embeddings and the first embeddings;

determining instructions based on the similarities between the second embeddings and the first embeddings; and

generating the execution plan based on the instructions.

4 . The method of claim 1 , wherein the report comprises natural language corresponding to instructions for resolving the one or more security incidents.

5 . The method of claim 1 , wherein the report comprises computer-readable instructions, and wherein the method further comprises:

executing the instructions to perform a set of operations based on the execution plan.

6 . The method of claim 1 , further comprising:

receiving user feedback based on the report;

generating one or more updated first embeddings based on the user feedback; and

updating the execution plan based on the one or more updated first embeddings and the one or more second embeddings.

7 . The method of claim 1 , wherein the security data comprises raw logs associated with the one or more security incidents.

8 . The method of claim 1 , wherein the computing environment is one or more of an endpoint, network, cloud environment, security appliance, or computer-executable application.

9 . The method of claim 1 , wherein the security data comprises network records, and wherein the one or more security incidents being resolved includes a network security incident.

10 . The method of claim 1 , further comprising:

causing a graphical user interface to be displayed;

receiving the user query via the graphical user interface; and

causing the report to be displayed via the graphical user interface, the graphical user interface comprising a button that when selected is configured to cause one or more processors to execute the one or more instructions of the report corresponding to the execution plan.

11 . A system for generating security reports, the system comprising:

a processor; and

memory comprising instructions that, when executed by the processor, cause the system to perform a set of operations, the set of operations comprising:

receiving a user query and security data corresponding to one or more security incidents associated with a computing environment;

providing the user query and security data to a semantic model, wherein the semantic model generates one or more first embeddings;

receiving, from a data model, one or more second embeddings, wherein the data model is generated based on historical threat intelligence data;

generating an execution plan based on the one or more first embeddings and the one or more second embeddings;

returning a report corresponding to the execution plan, the report comprising one or more instructions for resolving the one or more security incidents; and

causing the one or more instructions of the report corresponding to the execution plan to be executed, thereby resolving the one or more security incidents associated with the computing environment.

12 . The system of claim 11 , wherein the semantic model comprises a generative large language model (LLM) that uses one of zero-shot, one-shot, or few-shot prompting.

13 . The system of claim 11 , wherein the generating an execution plan comprises:

determining a respective similarity between the second embeddings and the first embeddings;

determining instructions based on the similarities between the second embeddings and the first embeddings; and

generating the execution plan based on the instructions.

14 . The system of claim 11 , wherein the report comprises natural language corresponding to instructions for resolving the one or more security incidents.

15 . The system of claim 11 , wherein the report comprises computer-readable instructions, and wherein the set of operations further comprise:

executing the instructions to perform a set of operations based on the execution plan.

16 . The system of claim 11 , wherein the set of operations further comprise:

receiving user feedback based on the report;

generating one or more updated first embeddings based on the user feedback; and

updating the execution plan based on the one or more updated first embeddings and the one or more second embeddings.

17 . The system of claim 11 , wherein the security data comprises raw logs associated with the one or more security incidents.

18 . The system of claim 11 , wherein the computing environment is one or more of an endpoint, network, cloud environment, security appliance, or computer-executable application.

19 . A method of generating security reports, the method comprising:

receiving a user query and security data corresponding to one or more security incidents associated with a computing environment;

providing the user query and security data to a semantic model, wherein the semantic model generates one or more first embeddings;

receiving, from a data model, one or more second embeddings;

generating an execution plan based on the one or more first embeddings and the one or more second embeddings, for resolving the one or more security incidents; and

automatically executing the execution plan via one or more processors, thereby resolving the one or more security incidents associated with the computing environment.

20 . The method of claim 19 , wherein the security data comprises raw logs corresponding to the one or more security incidents associated with a computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2023
From: DOUGLAS, ERIC PAUL; GOERTZEL, MARIO DAVIS; GREENWALD, LLOYD GEOFFREY; SHAH, ADITI KAMLESH; BETTHAUSER, LEO MORENO; MACE, DANIEL LEE; BECKER, NICHOLAS
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 064973/0001 →
Continuity (2)
Provisional Application 63441533 · Jan 27, 2023
Related Publication 20240256780A1 · Aug 1, 2024
References Cited (9)
US 20100088341A1 · Ah-Soon · 2010 [cited by examiner]
US 20180205755A1 · Kavi · 2018 [cited by examiner]
US 20220036153A1 · O'Malia · 2022 [cited by applicant]
US 20230018808A1 · Silberman · 2023 [cited by applicant]
US 20230229854A1 · McCaffery · 2023 [cited by examiner]
US 20230315766A1 · Cho · 2023 [cited by examiner]
“Long-term Memory for AI,” Vector Database for Vector Search, Pinecone Systems, Inc., retrieved from: https://www.pinecone.io/, Mar. 27, 2023, 10 pages. [cited by applicant]
Kan, “Not All Vector Databases Are Made Equal,” Towards Data Science, Oct. 2, 2021, retrieved from: https://towardsdatascience.com/milvus-pinecone-vespa-weaviate-vald-gsi-what-unites-these-buzz-words-and-what-makes-each… [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2023/085903, May 7, 2024, 13 pages. [cited by applicant]