IP Library Granted Patent US 11,770,398
Granted Patent B1
US 11,770,398 · App. 18/153,270 · Granted Sep 26, 2023

Guided anomaly detection framework

Inventors: Úlfar Erlingsson (Palo Alto, CA); Jay Parikh (Redwood City, CA); Yijou Chen (Cupertino, CA)
Assignee: LACEWORK, INC.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,398
App. No.
18/153,270
Granted
Sep 26, 2023
Kind
B1
Abstract

A guided anomaly detection framework, including: gathering data describing activity associated with an anomaly detection framework monitoring a cloud deployment; generating, based on the data, a prompt describing one or more natural language inputs for a security workflow, wherein each of the one or more natural language inputs corresponds to a query for information related to the cloud deployment; and providing a selected natural language input to a natural language interface.

Claims (34)

1. A method of a guided anomaly detection framework, the method comprising:

gathering data describing activity associated with an anomaly detection framework configured for monitoring a cloud deployment;

generating, based on the data, a prompt comprising one or more natural language inputs for a security workflow, wherein each of the one or more natural language inputs corresponds to a query for information related to the cloud deployment; and

providing a selected natural language input to a natural language interface of the anomaly detection framework.

2. The method of claim 1 , further comprising providing, based on a corresponding query for the selected natural language input, a response to the selected natural language input.

3. The method of claim 1 , wherein the data describing activity associated with the anomaly detection framework comprises data describing one or more events detected in the cloud deployment, and wherein the security workflow corresponds to the one or more events.

4. The method of claim 3 , wherein the one or more events comprises one or more detected security threats.

5. The method of claim 3 , wherein the one or more events comprises one or more detected anomalies in activity associated with the cloud deployment.

6. The method of claim 1 , wherein the data describing activity associated with the anomaly detection framework comprises one or more user interactions with the anomaly detection framework.

7. The method of claim 6 , wherein the one or more interactions comprise one or more previous queries provided by a domain expert.

8. The method of claim 6 , wherein the one or more interactions comprise one or more previous natural language inputs provided by a domain expert.

9. The method of claim 6 , wherein the data describing activity associated with the anomaly detection framework comprises one or more previous interactions with a user interface of the anomaly detection framework.

10. The method of claim 1 , wherein the data describing activity associated with the anomaly detection framework comprises data describing a state of one or more assets of the cloud deployment.

11. The method of claim 1 , wherein the cloud deployment is associated with a particular customer, the method further comprising:

gathering data associated with one or more other cloud deployments of one or more other customers, wherein the prompt is further based on the data associated with the one or more other cloud deployments.

12. The method of claim 1 , wherein the security workflow comprises a plurality of related natural language inputs, and wherein the prompt comprises a prompt for a particular natural language input in a progression of the plurality of related natural language inputs.

13. The method of claim 1 , further comprising providing, to the natural language interface, data describing how the prompt was generated.

14. A computer program product for a guided anomaly detection framework, the computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions configurable to carry out the steps of:

gathering data describing activity associated with an anomaly detection framework configured for monitoring a cloud deployment;

generating, based on the data, a prompt comprising one or more natural language inputs for a security workflow, wherein each of the one or more natural language inputs corresponds to a query for information related to the cloud deployment; and

providing a selected natural language input to a natural language interface of the anomaly detection framework.

15. The computer program product of claim 14 , wherein the steps further comprise providing, based on a corresponding query for the selected natural language input, a response to the selected natural language input.

16. The computer program product of claim 14 , wherein the data describing activity associated with the anomaly detection framework comprises data describing one or more events detected in the cloud deployment, and wherein the security workflow corresponds to the one or more events.

17. The computer program product of claim 16 , wherein the one or more events comprises one or more detected security threats.

18. The computer program product of claim 17 , wherein the one or more events comprises one or more detected anomalies in activity associated with the cloud deployment.

19. The computer program product of claim 14 , wherein the data describing activity associated with the anomaly detection framework comprises one or more user interactions with the anomaly detection framework.

20. The computer program product of claim 19 , wherein the one or more interactions comprise one or more previous queries provided by a domain expert.

21. The computer program product of claim 19 , wherein the one or more interactions comprise one or more previous natural language inputs provided by a domain expert.

22. The computer program product of claim 19 , wherein the data describing activity associated with the anomaly detection framework comprises one or more previous interactions with a user interface of the anomaly detection framework.

23. The computer program product of claim 14 , wherein the data describing activity associated with the anomaly detection framework comprises data describing a state of one or more assets of the cloud deployment.

24. The computer program product of claim 14 , wherein the cloud deployment is associated with a particular customer, wherein the steps further comprise:

gathering data associated with one or more other cloud deployments of one or more other customers, wherein the prompt is further based on the data associated with the one or more other cloud deployments.

25. The computer program product of claim 14 , wherein the security workflow comprises a plurality of related natural language inputs, and wherein the prompt comprises a prompt for a particular natural language input in a progression of the plurality of related natural language inputs.

26. The computer program product of claim 14 , wherein the steps further comprise providing, to the natural language interface, data describing how the prompt was generated.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2023
From: ERLINGSSON, ÚLFAR; PARIKH, JAY; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 062349/0294 →