IP Library › Granted Patent US 12,651,061
Granted Patent B2
US 12,651,061 · App. 18/651,246 · Granted Jun 9, 2026

Cybersecurity tools for managing anomalous security data items

Inventors: Raz Marom (Haifa, IL); Dror Cohen (Tel-Aviv, IL); Jonatan Zukerman (Matan, IL)
Assignee: Microsoft Technology Licensing, LLC.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,061
App. No.
18/651,246
Filed
Apr 30, 2024
Granted
Jun 9, 2026
Kind
B2
Art Unit
2407
USPC
726/23
Abstract

This disclosure provides a filtering mechanism to manage anomalous security data items. An anomalous security data item is provided to an analysis engine (such as a Large Language Model (LLM) or another form of generative language model) for interpretation. By curating a selection of one or more relevant non-anomalous security data items to provide with the anomalous data item, the filtering mechanism enables the analysis engine to perform with increased accuracy, without requiring the analyst engine to process large numbers of data items to ascertain their relevance to the anomalous security data item.

Claims (40)

1 . A computer system comprising:

at least one processor; and

at least one memory configured to store programming instructions for execution by the at least one processor, the programming instructions, upon execution by the at least one processor, causing the computer system to perform the following operations:

receiving an anomalous data item corresponding to an anomalous event;

identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;

generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;

providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;

receiving the output from the ML model in response to the input prompt; and

causing a security action to be performed based on the output.

2 . The computer system of claim 1 , wherein the security analysis, for which the ML model is trained, includes at least a security operations center (SOC) operation.

3 . The computer system of claim 1 , wherein the ML model is trained to summarize anomalous behavior.

4 . The computer system of claim 1 , wherein the ML model is trained to suggest remediation action(s) in response to anomalous behavior.

5 . The computer system of claim 1 , wherein the security action includes generating, at a user interface, an alert pertaining to an entity associated with the anomalous data item.

6 . The computer system of claim 1 , wherein the security action includes revoking or restricting an access privilege of an entity associated with the anomalous data item.

7 . The computer system of claim 1 , wherein the security action includes quarantining an entity associated with the anomalous data item or isolating the entity from a network or system.

8 . The computer system of claim 1 , wherein the anomalous data item and the contextual data item are both associated with a common entity.

9 . The computer system of claim 8 , wherein the common entity is a common user account or device.

10 . The computer system of claim 8 , wherein the common entity is a common application, process, service, or file.

11 . The computer system of claim 1 , wherein the property of the anomalous data item is a feature value.

12 . The computer system of claim 11 , wherein the property of the anomalous data item is a numerical feature value.

13 . The computer system of claim 11 , wherein the property of the anomalous data item is a categorical feature value.

14 . The computer system of claim 11 , wherein the property of the anomalous data item is a Boolean feature value.

15 . The computer system of claim 1 , wherein a non-anomalous feature of the contextual data item corresponds in type to an anomalous feature of the anomalous data item.

16 . The computer system of claim 15 , wherein the anomalous feature of the anomalous data item is a geolocational activity.

17 . The computer system of claim 16 , wherein the anomalous feature of the anomalous data item is an anomalous country, and wherein the non-anomalous feature of the contextual data item is a non-anomalous country that is different than the anomalous country.

18 . The computer system of claim 15 , wherein the anomalous feature of the anomalous data item is a device usage pattern or action history of a user.

19 . A method comprising:

receiving an anomalous data item corresponding to an anomalous event;

identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;

generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;

providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;

receiving the output from the ML model in response to the input prompt; and

causing a security action to be performed based on the output.

20 . A computer-readable storage medium storing programming instructions that, upon execution by a processor of a system, cause the system to perform the following operations:

receiving an anomalous data item corresponding to an anomalous event;

identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;

generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;

providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;

receiving the output from the ML model in response to the input prompt; and

causing a security action to be performed based on the output.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2024
From: COHEN, DROR; MAROM, RAZ; ZUKERMAN, JONATAN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 067491/0851 →
Continuity (1)
Related Publication 20250335584A1 · Oct 30, 2025
References Cited (27)
US 10270788B2 · Faigon · 2019 [cited by examiner]
US 10462173B1 · Aziz · 2019 [cited by examiner]
US 10848519B2 · Howard · 2020 [cited by examiner]
US 11743286B2 · Du · 2023 [cited by examiner]
US 11973784B1 · Erlingsson · 2024 [cited by examiner]
US 12107872B2 · Neupane · 2024 [cited by examiner]
US 20180262529A1 · Allen · 2018 [cited by examiner]
US 20200028871A1 · Thayer et al. · 2020 [cited by applicant]
US 20220156372A1 · Harang · 2022 [cited by examiner]
US 20240056458A1 · Lee · 2024 [cited by applicant]
US 20240250968A1 · Kaleli · 2024 [cited by examiner]
US 20250086271A1 · Achary · 2025 [cited by examiner]
US 20250317455A1 · Agron · 2025 [cited by examiner]
WO WO2022251462A1 · 2022 [cited by examiner]
WO WO2025193532A1 · 2025 [cited by examiner]
Extended European Search Report Received in European Application No. 25173472.9, mailed on Aug. 27, 2025, 11 Pages. [cited by applicant]
“5 Approaches to Solve LLM Token Limits”, accessed on: https://deepchecks.com/5-approaches-to-solve-llm-token-limits/, DeepChecks, Oct. 2, 2023, 6 pages. [cited by applicant]
“Medium: Ai'nt That Easy #2: 4 Approaches to Solve LLM Token Limit and Rate Limit Issues”, accessed on URL: https://aint-that-easy.medium.com/aint-that-easy-2-4-approaches-to-solve-llm-token-limit-and-rate-limit-issues-… [cited by applicant]
“Understanding Your SIEM Options”, accessed on URL: https://gurucul.com/blog/understanding-your-siem-options, Jan. 30, 2024, 10 pages. [cited by applicant]
“What is UEBA?”, accessed on URL: https://www.fortinet.com/resources/cyberglossary/what-is-ueba, Apr. 6, 2024, 10 pages. [cited by applicant]
“What is user and entity behavior analytics (UEBA)?”, accessed on URL: https://www.ibm.com/topics/ueba, Apr. 6, 2024, 10 pages. [cited by applicant]
Aparna, Dhinakaran, “The Guide to LLM Evals: How to Build and Benchmark Your Evals”, accessed on URL: https://towardsdatascience.com/llm-evals-setup-and-the-metrics-that-matter-2cc27e8e35f3, Oct. 13, 2023, 24 pages. [cited by applicant]
Chu, Lan, “Medium: Workarounds Large language model's token limit issues”, accessed on URL: https://medium. com/the-data-perspectives/workarounds-openai-models-token-limit-issues-3ea52a60d937, Nov. 22, 2023, 8 pages. [cited by applicant]
Poduska, Josh, “LLM Monitoring and Observability—A Summary of Techniques and Approaches for Responsible AI”, accessed on: https://towardsdatascience.com/llm-monitoring-and-observability-c28121e75c2f, Sep. 15, 2023, 15 p… [cited by applicant]
Wilson, Steve, “Integrating, Instead of Disrupting: How AI Will Impact Security”, accessed on URL: https://www.exabeam.com/information-security/integrating-instead-of-disrupting-how-ai-will-impact-security/, Jan. 31, 20… [cited by applicant]
Yelevin, et al., “Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel”, accessed on: https://learn.microsoft.com/en-us/azure/sentinel/identify-threats-with-entity-behavior-anal… [cited by applicant]
Yelevin, et al., “Microsoft Sentinel UEBA reference”, accessed on URL: https://learn.microsoft.com/en-us/azure/sentinel/ueba-reference, Apr. 3, 2024, 17 pages. [cited by applicant]