Interactive cyber-security user-interface for cybersecurity components that cooperates with a set of LLMs
An interactive cyber-security user-interface for cybersecurity components can receive a voice input from a user as well as ii) a text input as a user input. The interactive cyber-security user-interface works with a set of differently trained LLMs to carry out tasks on behalf of the user input. The interactive cyber-security user-interface cooperates with the set of differently trained LLMs, which are grouped together to operate as an orchestrated system to provide different tasks. The tasks can include a collection of supplementary information, a summarization of cyber security information, translating a query in the natural human speech format into the required search syntax, how to integrate with an API, acting as a first line of support to user inquiries, a suggested response to a cyber security issue, etc. The interactive cyber-security user-interface for the cybersecurity components acts as the user interface for one or more of the cybersecurity components.
1 . An apparatus, comprising:
an interactive cyber-security user-interface for cybersecurity components that is configured to receive i) a voice input as well as ii) a text input from a user as a user input, where the interactive cyber-security user-interface for the cybersecurity components is configured to work with a set of two or more differently trained large language models (LLMs) to carry out tasks on behalf of the user input, where the interactive cyber-security user-interface for the cybersecurity components is configured to cooperate with the set of two or more differently trained LLMs, which are grouped together to operate as an orchestrated system to provide two or more different tasks;
wherein the set of two or more differently trained LLMs includes a search-syntax task dedicated LLM, where the user input is expressed in a natural human speech, where the search-syntax task dedicated LLM is trained to create corresponding pairs between a concept expressed in a formal grammar of a portion of the natural human speech to a meaning and a role level corresponding to that portion of the natural human speech, and then map the meaning and the role level of the portion of the natural human speech to a proper search syntax format utilized by at least one of i) a third-party service and ii) the cybersecurity components that corresponds to the proper search syntax format;
where the interactive cyber-security user-interface for the cybersecurity components is configured to cooperate with one or more of the cybersecurity components including i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination of these, ii) a proactive threat notification service to publicize new and ongoing cyber threats, iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat, iv) a cyberattack simulator to simulate a cyberattack, v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more minor anomalies linked to each other over a time frame of examination spanning two or more days; and
where instructions implemented in software for the cybersecurity components and the LLMs are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units.
2 . The apparatus of claim 1 , where an orchestrator LLM of the set of two or more differently trained LLMs is configured to receive the user input of voice or text, and is trained to apply a language comprehension functionality on the user input in order to generate a consistent version of a request indicated by the user input, which is then fed as an output fed to one or more of a set of task dedicated LLMs to be invoked, where an API-integration task dedicated LLM is configured to receive the request indicated by the user input and then is trained to carry out the request with one or more of the cybersecurity components, where the orchestrator LLM is further trained to orchestrate the tasks performed by the set of tasks dedicated LLMs, where the set of task dedicated LLMs are also part of the set of two or more differently trained LLMs.
3 . The apparatus of claim 1 , where a user-support task dedicated LLM is part of the set of two or more differently trained LLMs, where the user-support task dedicated LLM is trained to act as a first line of support for user queries regarding at least one of 1) troubleshooting issues with the cybersecurity components, 2) providing cyber analyst answers as a suggested response to the cyber security issue to the user, and 3) a current cyber threat landscape and current active cyber threats, while the user is waiting for an actual human cyber analyst to pick up and review their inquiry.
4 . The apparatus of claim 1 , where an API-integration task dedicated LLM is part of the set of two or more differently trained LLMs, where the API-integration task dedicated LLM is trained on a task of setting up APIs to one or more of the cybersecurity components as well as to APIs of third party services to obtain a collection of supplementary information.
5 . The apparatus of claim 1 , where a breach-summarization task dedicated LLM is part of the set of two or more differently trained LLMs, where the breach-summarization task dedicated LLM is trained to receive a history of breaches and their severity scores to produce both a summarization of cyber security information including those breaches as well as to provide recommendations to prioritize those breaches against each other to help the user.
6 . The apparatus of claim 1 , where an orchestrator LLM in the set of two or more differently trained LLMs has its training fine-tuned, where the training of the orchestrator LLM starts with selecting an already trained LLM model into performing a task and then unlocking one or more layers and parameters of the orchestrator LLM and fine tuning a machine learning of the unlocked layers and parameter on new data to perform one of the different tasks of i) the collection of supplementary information, ii) the summarization of cyber security information, or iii) the suggested response to the cyber security issue.
7 . A method to provide cybersecurity, comprising:
providing an interactive cyber-security user-interface for cybersecurity components to receive a voice input from a user as a user input;
providing the interactive cyber-security user-interface for the cybersecurity components to work with a set of two or more differently trained large language models (LLMs) to carry out tasks on behalf of the user input;
providing the interactive cyber-security user-interface for the cybersecurity components to cooperate with the set of two or more differently trained LLMs, which are grouped together to operate as an orchestrated system to provide two or more different tasks;
wherein the set of two or more differently trained LLMs includes a user-support task dedicated LLM; wherein the user-support task dedicated LLM is trained to act as a first line of support for user inquiries to provide a suggested response to a cyber security issue; wherein the user-support task dedicated LLM has been trained on a historic corpus of user inquiries submitted to an expert human cyber analyst to understand how the expert human cyber analyst would resolve the user inquiries and then supply the suggested response to the cyber security issue to the user while the user is waiting for an actual human cyber analyst to pick up and review their inquiry; and
providing the interactive cyber-security user-interface for the cybersecurity components to cooperate with one or more of the cybersecurity components including i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination of these, ii) a proactive threat notification service to publicize new and ongoing cyber threats, iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat, iv) a cyberattack simulator to simulate a cyberattack, v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more minor anomalies linked to each other over a time frame of examination spanning two or more days.
8 . The method of claim 7 , further comprising:
providing an orchestrator LLM of the set of two or more differently trained LLMs to receive the user input of voice or text, and is trained to apply a language comprehension functionality on the user input in order to generate a consistent version of a request indicated by the user input, which is then fed as an output fed to one or more of a set of task dedicated LLMs to be invoked; and
providing an API-integration task dedicated LLM to receive the request indicated by the user input, which is trained to carry out the request with one or more of the cybersecurity components, where the orchestrator LLM is further trained to orchestrate the tasks performed by the set of tasks dedicated LLMs, where the set of task dedicated LLMs are also part of the set of two or more differently trained LLMs.
9 . The method of claim 7 , further comprising:
providing a set of task dedicated LLMs as part of the set of two or more differently trained LLMs; and
providing the set of task dedicated LLMs to include two or more of a following 1) an API-integration task dedicated LLM trained to act as an assistant that submits data to at least one of i) a third-party service and ii) the cybersecurity components using training on how to integrate with an API of that third party service or cybersecurity component to obtain a collection of the supplementary information, 2) a search-syntax task dedicated LLM trained on a search syntax required by at least one of i) the third-party service and ii) the cybersecurity components to allow users to query in natural human speech, and the second task dedicated LLM trained to translate the query in the natural human speech into the search syntax required, 3) a breach-summarization task dedicated LLM trained to be fed a history of model breaches and their severity scores and then the breach-summarization task dedicated LLM produces both a summarization of the cyber security information including the model breaches as well as provides recommendations, and 4) a user-support task dedicated LLM trained to act as a first line of support for user inquiries to provide a suggested response to the cyber security issue.
10 . The method of claim 7 , further comprising:
providing an API-integration task dedicated LLM as part of the set of two or more differently trained LLMs; and
providing the API-integration task dedicated LLM, which is trained on a task of setting up APIs to one or more of the cybersecurity components as well as to APIs of third party services to obtain a collection of supplementary information.
11 . The method of claim 7 , further comprising:
providing a search-syntax task dedicated LLM as part of the set of two or more differently trained LLMs; and
providing the search-syntax task dedicated LLM, which is trained on a task of formatting a query from the user input into a search syntax utilized by at least one of i) a third-party service and ii) the cybersecurity components to go out and find whatever the user is asking for in the user input made in a natural human speech but the search-syntax task dedicated LLM has translated the query from the user input into the search syntax utilized by the third-party service or the cybersecurity components.
12 . The method of claim 7 , further comprising:
providing a breach-summarization task dedicated LLM as part of the set of two or more differently trained LLMs; and
providing the breach-summarization task dedicated LLM, which is trained to receive a history of breaches and their severity scores to produce both a summarization of cyber security information including those breaches as well as to provide recommendations to prioritize those breaches against each other to help the user.
13 . A non-transitory storage medium including software that, upon execution by a processor, is configured to perform operations, comprising:
using an interactive cyber-security user-interface for cybersecurity components to receive a voice input from a user as a user input;
using the interactive cyber-security user-interface for the cybersecurity components to work with a set of two or more differently trained large language models (LLMs) to carry out tasks on behalf of the user input;
using the interactive cyber-security user-interface for the cybersecurity components to cooperate with the set of two or more differently trained LLMs, which are grouped together to operate as an orchestrated system to provide two or more different tasks wherein the set of two or more differently trained LLMs comprises at least two of the following task-dedicated LLMs:
(a) an API-integration task dedicated LLM trained to act as an assistant that submits data to at least one of i) a third-party service and ii) the cybersecurity components using training on how to integrate with an API of that third party service or cybersecurity component to obtain a collection of supplementary information;
(b) a search-syntax task dedicated LLM trained on a search syntax required by at least one of i) the third-party service and ii) the cybersecurity components to allow users to query in natural human speech via the search-syntax task dedicated LLM being trained to translate the query in the natural human speech into the search syntax required;
(c) a breach-summarization task dedicated LLM trained to be fed a history of model breaches and their severity scores and then the breach-summarization task dedicated LLM produces both a summarization of cyber security information including the model breaches as well as provides recommendations; and
(d) a user-support task dedicated LLM trained to act as a first line of support for user inquiries to provide a suggested response to a cyber security issue; and
using the interactive cyber-security user-interface for the cybersecurity components to cooperate with one or more of the cybersecurity components including i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination of these, ii) a proactive threat notification service to publicize new and ongoing cyber threats, iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat, iv) a cyberattack simulator to simulate a cyberattack, v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more minor anomalies linked to each other over a time frame of examination spanning two or more days.
14 . The non-transitory storage medium of claim 13 , wherein the set of two or more differently trained LLMs includes an orchestrator LLM; wherein the operations further comprise using the orchestrator LLM to receive the user input of voice or text, and apply a language comprehension functionality on the user input to generate a consistent version of a request indicated by the user input; and feeding the consistent version of the request as an output to one or more of the task-dedicated LLMs to be invoked; wherein the orchestrator LLM is further trained to orchestrate the tasks performed by the task-dedicated LLMs.
15 . The non-transitory storage medium of claim 14 , wherein the orchestrator LLM has fine-tuned training; wherein the training of the orchestrator LLM starts with selecting an already trained LLM model into performing a task and then unlocking one or more layers and parameters of the orchestrator LLM and fine tuning a machine learning of the unlocked layers and parameter on new data to perform one of the different tasks.