IP Library Granted Patent US 12,407,713
Granted Patent B2
US 12,407,713 · App. 18/213,128 · Granted Sep 2, 2025

Autonomous report composer

Inventors: Dickon Humphrey (Cambridge, GB); Timothy Bazalgette (Knebworth, GB); David Palmer (Cheltenham, GB)
Assignee: Darktrace Holdings Limited
H04L63/1441G06F3/04842G06F40/40H04L43/045H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,713
App. No.
18/213,128
Granted
Sep 2, 2025
Kind
B2
Abstract

An autonomous report composer composes a type of report on cyber threats that is composed in a human-readable format with natural language prose, terminology, and level of detail on the cyber threats aimed at a target audience. The autonomous report composer cooperates with libraries with prewritten text templates with i) standard pre-written sentences written in the natural language prose and ii) prewritten text templates with fillable blanks that are populated with data for the cyber threats specific for a current report being composed, where a template for the type of report contains two or more sections in that template. Each section having different standard pre-written sentences written in the natural language prose.

Claims (50)

1. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a computing device, to cause the computing device to perform operations as follows, comprising:

providing a formatting module to at least have an autonomous report composer and a set of one or more libraries,

providing the autonomous report composer to compose a type of report on cyber threats that is composed in a human-readable format with natural language prose, terminology, and a level of detail on the cyber threats aimed at a target audience, where the autonomous report composer is configured to select a first type of report from different types of possible reports,

providing the autonomous report composer to cooperate with the set of one or more libraries of sets of prewritten text templates derived from at least one of i) one or more standard pre-written sentences written in the natural language prose derived from previously generated reports of the first type of reports as well as ii) one or more of the prewritten text templates with fillable blanks, also derived from previously generated reports of the first type, but have fillable blanks that are populated with data for the cyber threats specific for a current report being composed, and

providing the autonomous report composer to also cooperate with one or more machine learning models trained on composing reports on cyber threats, where the autonomous report composer cooperating with the one or more machine learning models compose the first type of report by 1) initially choosing the first type of report from a category of the different types of possible reports to be generated, 2) where each different type of possible report is created to convey relevant information to a different level of intended target audience and then 3) each type of report will have a corresponding template of that report type with multiple sections making up that report type, 4) where each section will have its own set of i) prewritten text templates, ii) graphs, iii) charts and iv) any combination of these, that are routinely presented in each of those sections making up that type of report.

2. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

where the intended target audience for the first type of report is an executive and the relevant information is phrased in language the executive should understand.

3. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

where the intended target audience for the first type of report is a cyber professional and the relevant information is phrased in language the cyber professional should understand.

4. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing a template for the first type of report that contains two or more sections in that template, where each section has different standard pre-written sentences written in the natural language prose as well as one or more of the prewritten sentences having fillable blanks for that section of the first type of report on cyber threats.

5. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the formatting module and the autonomous report composer to cooperate with one or more Artificial Intelligence models trained with machine learning on a normal behavior of entities in a network, where a breach of the Artificial Intelligence models trained with the machine learning on the normal behavior of entities with its data and description is used to map specific incidents to portions in the first type of report.

6. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the first type of report on the cyber threats as a threat assessment drafted by the autonomous report composer with natural language prose, terminology, and the level of detail on the cyber threats aimed at the intended target audience with details on and data from making, testing, and refining a series of successive hypotheses on potential cyber threats and salient points to support or refute each hypothesis, which are assessed using a combination of supervised machine learning and unsupervised machine learning, which is formatted and written at a level to capture relevant details and the language of the intended target audience.

7. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with the one or more machine learning models trained on composing the reports on cyber threats to further compose the first type of report so that each section has standard sentences and charts or graphs for that section that are found in similar reports.

8. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with the one or more machine learning models trained on composing the reports on cyber threats to further compose the first type of report so that a first section has standard sentences written in the natural language prose selected for that section, where a lookup occurs on specifics for each incident being textually conveyed or graph being generated.

9. The non-transitory computer readable medium storing computer readable code operable of claim 8 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

where salient points that need to be conveyed can be looked up and grabbed from machine data collected from one or more cyber threat incidents on the cyber threats being conveyed, and then populated with the grabbed data into the selected prewritten standard sentences with fillable blanks, which will now contain the specifics for this report.

10. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with a library of suggested actionable actions to take in light of the cyber threats in the first type of report, and then populate suggested actionable actions to take into the first type of report.

11. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the first type of report on the cyber threats aimed at an audience of a business executive reading a level threat-landscape drafted by the autonomous report composer with natural language prose, terminology, and the level of detail on the cyber threats aimed at the business executive audience that summarizes the cyber threats encountered by an organization with individual incidents mapped to overall incident categories over a defined time period with an analysis and explanation of the summarized cyber threats.

12. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with a natural language processing engine, where after the autonomous report composer composes the first type of report on cyber threats that is composed in the human-readable format with the natural language prose, terminology, and the level of detail on the cyber threats aimed at the intended audience of a cyber professional, then the autonomous report composer sends a draft of that report to the natural language processing engine to identify any sections of text that do not have a level of confidence equal to or above a set threshold value, in a meaning of a generated sentence in light of a rest of the sentences in that section.

13. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a computing device, to cause the computing device to perform operations as follows, comprising:

providing an Artificial Intelligence (AI) cyber-security analyst to protect a network from cyber threats, where the AI cyber-security analyst cooperates with a formatting module that has an autonomous report composer and a set of one or more libraries,

providing the autonomous report composer to compose a type of report on cyber threats that is composed in a human-readable format with natural language prose, terminology, and a level of detail on the cyber threats aimed at a target audience,

providing the autonomous report composer to cooperate with the set of one or more libraries of sets of prewritten text templates derived from at least one of i) one or more standard pre-written sentences written in the natural language prose derived from previously generated reports of a first type of report as well as ii) one or more of the prewritten text templates with fillable blanks, also derived from previously generated reports of the first type of report, but have fillable blanks that are populated with data for the cyber threats specific for a current report being composed, and

providing a second type of report on the cyber threats to be an executive level threat-landscape drafted by the autonomous report composer with natural language prose, terminology, and the level of detail on the cyber threats aimed at a business executive audience that summarizes the cyber threats encountered by an organization with individual incidents mapped to overall incident categories over a defined time period with an analysis and explanation of the summarized cyber threats, where the natural language prose and terminology are selected by the autonomous report composer from a set of libraries corresponding to the second type of report template.

14. The non-transitory computer readable medium storing computer readable code operable of claim 13 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing a template for the first type of report that contains two or more sections in that template, where a first section has different standard pre-written sentences written in the natural language prose as well as one or more of the prewritten sentences have fillable blanks for that section of the first type of report on cyber threats.

15. The non-transitory computer readable medium storing computer readable code operable of claim 13 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the formatting module and the autonomous report composer to cooperate with one or more Artificial Intelligence models trained with machine learning on a normal behavior of entities in the network, where a breach of the Artificial Intelligence models trained with the machine learning on the normal behavior of entities with its data and description is used to map specific incidents to portions in the first type of report.

16. The non-transitory computer readable medium storing computer readable code operable in claim 13 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to supply suggested actionable actions to take in light of the cyber threats in the first type of report, and then populate suggested actionable actions to take into the first type of report.

17. The non-transitory computer readable medium storing computer readable code operable in claim 13 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with one or more machine learning models trained on composing the reports on cyber threats to further compose the first type of report so that a first section has standard sentences written in the natural language prose selected for that section, where a lookup occurs on the specifics for each incident being textually conveyed or graph being generated.

18. The non-transitory computer readable medium storing computer readable code operable in claim 13 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

where the target audience for the first type of report is a cyber professional and the prose, the terminology, and the level of detail on the cyber threats is phrased in language that the cyber professional should understand.

19. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a computing device, to cause the computing device to perform operations as follows, comprising:

providing a formatting module to at least have an autonomous report composer and a set of one or more libraries,

providing the autonomous report composer to compose a type of report on cyber threats that is composed in a human-readable format with natural language prose, terminology, and a level of detail on the cyber threats aimed at a target audience,

providing the autonomous report composer to cooperate with the set of one or more libraries of sets of prewritten text templates derived from at least one of i) one or more standard pre-written sentences written in the natural language prose derived from previously generated reports of a first type of report as well as ii) one or more of the prewritten text templates with fillable blanks, also derived from previously generated reports of the first type of report, but have fillable blanks that are populated with data for the cyber threats specific for a current report being composed,

providing the formatting module and the autonomous report composer to cooperate with one or more Artificial Intelligence models trained with machine learning on a normal behavior of entities in a network to provide some data and description to map specific incidents into related sentences, and

providing the autonomous report composer to select the first type of report from different types of possible reports, where the first type of report on the cyber threats is a threat assessment drafted by the autonomous report composer with natural language prose, terminology, and the level of detail on the cyber threats aimed at the target audience with details on and data from making, testing, and refining a series of successive hypotheses on potential cyber threats and salient points to support or refute each hypothesis, which are assessed using a combination of supervised machine learning and unsupervised machine learning, which is formatted and written at a level to capture relevant details and the language of the target audience.

20. The non-transitory computer readable medium storing computer readable code operable in claim 19 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

providing the autonomous report composer to cooperate with a natural language processing engine, where after the autonomous report composer composes the first type of report on cyber threats that is composed in the human-readable format with the natural language prose, terminology, and the level of detail on the cyber threats aimed at the target audience of a cyber professional.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (3)
Continuation 16279022 · Feb 19, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20240121263A1 · Apr 11, 2024
References Cited (105)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20060271571A1 · Brookler · 2006 [cited by examiner]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070169021A1 · Huynh · 2007 [cited by examiner]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100043066A1 · Miliefsky · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100121929A1 · Lin · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130055399A1 · Zaitsev · 2013 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160241581A1 · Watters et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20170353477A1 · Faigon et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20190155877A1 · Sharma · 2019 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Jun. 14, 2021, 26 pages, US. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Aug. 17, 2022, 8 pages, US. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, Feb. 18, 2023, 7 pages, US. [cited by applicant]