Security threat mitigation
The present disclosure provides methods, systems and computer readable media for training and implementing a generative machine learning model for identifying and mitigating security threats. Certain examples relate to generative model training, in which a training image is provided to a generative machine learning (ML) model in a training prompt, with an Indicator of Compromise (IoC) prediction instruction pertaining to the first security image. The model generates a predicted IoC and a parameter of the model is updated based on a loss function that quantifies error between a ground truth IoC and the predicted IoC. Other examples relate to the use of trained generative models for cybersecurity. A mitigation prompt comprising a second security image and an associated mitigation instruction is provided to a trained generative model. The model outputs an indication of a cybersecurity mitigation action based on the mitigation prompt, and the cybersecurity mitigation action is performed on the system. Certain example embodiments identify and automatically mitigate security issues using a multimodal generative model (MGM) though appropriate prompt engineering.
1 . A computer-implemented method, comprising:
receiving, from a training set, a first security image and a ground truth indicator of compromise (IoC) associated with the first security image, wherein:
the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;
the first security image comprises a first visual representation of a first cybersecurity threat; and
the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;
inputting, to a generative machine learning (ML) model, at least one training prompt comprising the first security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity;
receiving a predicted IoC generated by the generative ML model based on the at least one training prompt;
updating a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;
receiving a second security image pertaining to a system, wherein:
the second security image comprises a visual incident graph that visualizes a second cybersecurity threat and is generated or collected in response to detection of the second cybersecurity threat; and
the visual incident graph comprises an alert node representing the second cybersecurity threat and an entity node representing an entity associated with the alert node;
inputting, to the updated generative ML model, at least one mitigation prompt comprising:
the second security image;
an extraction instruction requesting extraction of a security insight from the visual incident graph; and
a mitigation instruction to determine a cybersecurity mitigation action based on the security insight;
receiving an indication of the cybersecurity mitigation action generated by the updated generative ML model based on the at least one mitigation prompt; and
causing the cybersecurity mitigation action to be performed on the system.
2 . The computer-implemented method of claim 1 , wherein:
the generative ML model is multi-modal;
the at least one training prompt comprises first text associated with the first security image; and
the at least one mitigation prompt comprises second text associated with the second security image.
3 . The computer-implemented method of claim 1 , wherein:
the second security image is received from a cybersecurity detector deployed in the system; and
the second security image is generated by the cybersecurity detector in response to the second cybersecurity threat.
4 . The computer-implemented method of claim 1 , wherein:
the at least one training prompt comprises both the first security image and text associated with the first security image; and
the generative ML model is configured to jointly process visual features extracted from the first security image and textual features extracted from the text associated with the first security image to identify the predicted IoC.
5 . The computer-implemented method of claim 1 , wherein the security insight is based on a connection between the entity node and the alert node in the second security image.
6 . The computer-implemented method of claim 5 , wherein:
the generative ML model is multi-modal;
the at least one mitigation prompt comprises third text associated with the second cybersecurity threat; and
the extraction instruction instructs the updated generative ML model to extract the security insight based on the third text.
7 . The computer-implemented method of claim 5 , wherein the security insight identifies a compromised entity, and the cybersecurity mitigation action comprises blocking, quarantining or isolating the compromised entity.
8 . The computer-implemented method of claim 1 , wherein:
the at least one mitigation prompt comprises a code generation instruction;
the indication of the cybersecurity mitigation action comprises computer-readable code embodying the cybersecurity mitigation action; and
the causing of the cybersecurity mitigation action to be performed comprises executing the computer-readable code.
9 . The computer-implemented method of claim 8 , wherein the mitigation instruction instructs the updated generative ML model to generate a report comprising generated text data and generated image data indicating the cybersecurity mitigation action, wherein the generated image data comprises at least one of: a security incident diagram, a visual mitigation workflow, or a graphical representation of one or more compromised components; and
the code generation instruction instructs the updated generative ML model to generate the computer-readable code based on the generated text data and the generated image data.
10 . The computer-implemented method of claim 8 , wherein the at least one mitigation prompt comprises:
a first mitigation prompt comprising the extraction instruction, and
a second mitigation prompt comprising the mitigation instruction and the code generation instruction.
11 . The computer-implemented method of claim 10 , wherein the first mitigation prompt is input to the updated generative ML model in a first chat session, and the second mitigation prompt is input to the updated generative ML model in a second chat session.
12 . The computer-implemented method of claim 1 , wherein:
responsive to the mitigation instruction, the updated generative ML model generates a report comprising generated text data and generated image data, wherein:
the report indicates the cybersecurity mitigation action; and
the generated image data comprises at least one of a security incident diagram, a visual mitigation workflow, or a graphical representation of one or more compromised components.
13 . A computer system comprising:
a memory configured to store computer-readable instructions; and
a hardware processor coupled to the memory, wherein the computer-readable instructions are configured to cause the hardware processor to:
receive a training security image and a ground truth indicator of compromise (IoC) associated with the training security image, wherein:
the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;
the training security image comprises a first visual representation of a first cybersecurity threat; and
the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;
input, to a multi-modal generative machine learning (ML) model, a training prompt comprising the training security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity associated with the alert;
receive a predicted IoC generated by the generative ML model based on the training prompt; and
update a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;
receive a security image pertaining to a system, wherein:
the security image comprises a visual incident graph that visualizes a cybersecurity threat and is generated or collected in response to detection of the cybersecurity threat; and
the visual incident graph comprises an alert node representing the cybersecurity threat and an entity node representing an entity associated with the cybersecurity threat;
submit, to the updated generative ML model, a mitigation prompt comprising:
the security image;
an extraction instruction requesting extraction of a security insight from the visual incident graph; and
a mitigation instruction to determine a cybersecurity mitigation action based on the security insight; and
a code generation instruction that instructs the updated generative ML model to generate computer-readable code based on the cybersecurity mitigation action;
receive, from the updated generative ML model and based on the mitigation prompt, the computer-readable code, the computer-readable code embodying the cybersecurity mitigation action; and
execute the computer-readable code whereby the cybersecurity mitigation action is performed on the system.
14 . The system of claim 13 , wherein the training prompt comprises training text associated with the training security image.
15 . The system of claim 13 , wherein the security image is received from a cybersecurity detector deployed in the system, the security image having been generated by the cybersecurity detector in response to a cyberthreat detected in the system.
16 . The system of claim 13 , wherein:
the security insight identifies a compromised entity; and
the cybersecurity mitigation action includes blocking, quarantining, or isolating a compromised entity.
17 . The system of claim 13 , wherein the mitigation prompt comprises:
a first mitigation prompt comprising the extraction instruction, and
a second mitigation prompt comprising the mitigation instruction and the code generation instruction.
18 . The system of claim 17 , wherein the computer-readable instructions are further configured to cause the hardware processor to submit the first mitigation prompt as input to the updated generative ML model in a first chat session, and to submit the second mitigation prompt as input to the updated generative ML model in a second chat session.
19 . A non-transitory computer storage medium embodying computer-readable instructions, the computer-readable instructions configured upon execution on a hardware processor to cause the hardware processor to:
receive from a training set a first security image and a ground truth indicator of compromise (IoC) associated with the first security image, wherein:
the ground truth IoC is a true reference IoC relating to a particular type or category of cyberthreat;
the first security image comprises a first visual representation of a first cybersecurity threat; and
the first visual representation depicts a relationship between an alert corresponding to the first cybersecurity threat and an entity associated with the alert;
input, to a generative machine learning (ML) model, a training prompt comprising the first security image and an IoC prediction instruction that requests identification of an IoC based on the depicted relationship between the alert and the entity;
receive a predicted IoC generated by the generative ML model based on the training prompt;
update a parameter of the generative ML model based on a training loss function that quantifies error between the ground truth IoC and the predicted IoC, wherein the updating produces an updated generative ML model;
receive a second security image pertaining to a system, wherein:
the second security image comprises a visual incident graph that visualizes a second cybersecurity threat and is generated or collected in response to detection of the second cybersecurity threat;
the visual incident graph comprises an alert node representing the second cybersecurity threat and an entity node representing an entity associated with the alert node;
input, to the updated generative ML model, a mitigation prompt comprising:
the second security image;
an extraction instruction requesting extraction of a security insight from the visual incident graph; and
a mitigation instruction to determine a cybersecurity mitigation action based on the security insight;
receive an indication of the cybersecurity mitigation action generated by the updated generative ML model based on the mitigation prompt; and
cause the cybersecurity mitigation action to be performed on the system.