THREAT MITIGATION SYSTEM AND METHOD
A computer-implemented method, computer program product and computing system for monitoring activity within a computing platform, thus defining monitored activity; associating the monitored activity with a user of the computing platform, thus defining an associated user; and assigning a risk level to the monitored activity to determine if such monitored activity is indicative of a security event, wherein the assigned risk level is based, at least in part, upon the associated user.
1 . A computer-implemented method executed on a computing device comprising:
monitoring activity within a computing platform, thus defining monitored activity;
associating the monitored activity with a user of the computing platform, thus defining an associated user; and
assigning a risk level to the monitored activity to determine if such monitored activity is indicative of a security event, wherein the assigned risk level is based, at least in part, upon the associated user.
2 . The computer-implemented method of claim 1 further comprising:
if such monitored activity is indicative of a security event, generating an initial notification of the security event, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event.
3 . The computer-implemented method of claim 2 further comprising:
iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.
4 . The computer-implemented method of claim 1 wherein the computing platform includes a plurality of security-relevant subsystems.
5 . The computer-implemented method of claim 4 wherein monitoring activity within a computing platform includes;
monitoring activity within one or more of the plurality of security-relevant subsystems of the computing platform.
6 . The computer-implemented method of claim 1 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using the generative AI model, the formatting script and/or one or more tools to produce the summarized human-readable report for the initial notification.
7 . The computer-implemented method of claim 6 wherein the one or more tools includes one or more of:
a decoding tool to decode an encoded initial notification;
a decompression tool to decompress a compressed initial notification; and
an identification tool to identify an owner of a domain associated with the initial notification.
8 . The computer-implemented method of claim 1 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using a large language model.
9 . The computer-implemented method of claim 1 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing prompt engineering to produce the summarized human-readable report for the initial notification.
10 . The computer-implemented method of claim 1 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing several loops and/or nested loops to produce the summarized human-readable report for the initial notification.
11 . A computer program product residing on a computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:
monitoring activity within a computing platform, thus defining monitored activity;
associating the monitored activity with a user of the computing platform, thus defining an associated user; and
assigning a risk level to the monitored activity to determine if such monitored activity is indicative of a security event, wherein the assigned risk level is based, at least in part, upon the associated user.
12 . The computer program product of claim 11 further comprising:
if such monitored activity is indicative of a security event, generating an initial notification of the security event, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event.
13 . The computer program product of claim 12 further comprising:
iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.
14 . The computer program product of claim 11 wherein the computing platform includes a plurality of security-relevant subsystems.
15 . The computer program product of claim 14 wherein monitoring activity within a computing platform includes;
monitoring activity within one or more of the plurality of security-relevant subsystems of the computing platform.
16 . The computer program product of claim 11 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using the generative AI model, the formatting script and/or one or more tools to produce the summarized human-readable report for the initial notification.
17 . The computer program product of claim 16 wherein the one or more tools includes one or more of:
a decoding tool to decode an encoded initial notification;
a decompression tool to decompress a compressed initial notification; and
an identification tool to identify an owner of a domain associated with the initial notification.
18 . The computer program product of claim 11 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using a large language model.
19 . The computer program product of claim 11 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing prompt engineering to produce the summarized human-readable report for the initial notification.
20 . The computer program product of claim 11 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing several loops and/or nested loops to produce the summarized human-readable report for the initial notification.
21 . A computing system including a processor and memory configured to perform operations comprising:
monitoring activity within a computing platform, thus defining monitored activity;
associating the monitored activity with a user of the computing platform, thus defining an associated user; and
assigning a risk level to the monitored activity to determine if such monitored activity is indicative of a security event, wherein the assigned risk level is based, at least in part, upon the associated user.
22 . The computing system of claim 21 further comprising:
if such monitored activity is indicative of a security event, generating an initial notification of the security event, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event.
23 . The computing system of claim 22 further comprising:
iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.
24 . The computing system of claim 21 wherein the computing platform includes a plurality of security-relevant subsystems.
25 . The computing system of claim 24 wherein monitoring activity within a computing platform includes;
monitoring activity within one or more of the plurality of security-relevant subsystems of the computing platform.
26 . The computing system of claim 21 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using the generative AI model, the formatting script and/or one or more tools to produce the summarized human-readable report for the initial notification.
27 . The computing system of claim 26 wherein the one or more tools includes one or more of:
a decoding tool to decode an encoded initial notification;
a decompression tool to decompress a compressed initial notification; and
an identification tool to identify an owner of a domain associated with the initial notification.
28 . The computing system of claim 21 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
iteratively processing the initial notification using a large language model.
29 . The computing system of claim 21 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing prompt engineering to produce the summarized human-readable report for the initial notification.
30 . The computing system of claim 21 wherein iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification includes:
utilizing several loops and/or nested loops to produce the summarized human-readable report for the initial notification.