IP Library Granted Patent US 12,737,460
Granted Patent B2
US 12,737,460 · App. 18/930,985 · Granted Sep 15, 2026

Geographically diversified embedding-based guided response to a security alert

Inventors: Amirhossein Gharib (Toronto, CA); Jovan Kalajdjieski (Vancouver, CA); Robert Lee Mccann (Snoqualmie, WA); Scott Alexander Freitas (Phoenix, AZ)
Assignee: Microsoft Technology Licensing, LLC
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,460
App. No.
18/930,985
Granted
Sep 15, 2026
Kind
B2
Abstract

Techniques are described herein that are capable of providing a geographically diversified embedding-based guided response to a security alert. A security alert regarding an identified security incident that is associated with an entity is received. Sets of designated security incidents, which are similar to the identified security incident, may be selected from sets of historical security incidents associated with respective geographical regions based on embeddings of the identified security incident and the historical security incidents in the sets. The identified security incident is classified into selected classes using first model(s) associated with the respective geographical regions. Security actions are selected from a plurality of possible security actions using second model(s) associated with the respective geographical regions. A security recommendation regarding the security alert is generated. The security recommendation includes representations of the sets of designated security incidents, the selected classes, and/or the security actions.

Claims (65)

1 . A system comprising:

a processor system; and

a memory that stores computer-executable instructions that are executable by the processor system to at least:

receive a security alert regarding an identified security incident associated with an entity;

classify the identified security incident into selected classes for respective geographical regions, the selected classes determined from a plurality of classes by applying a first embedding of the identified security incident to first models that are trained to map sets of second embeddings of sets of historical security incidents to corresponding sets of classes of the plurality of classes, the plurality of classes corresponding to at least one of validity of security concerns or maliciousness of actions that result in the security concerns;

select security actions to be performed with regard to the entity in the respective geographical regions by applying a third embedding of the security alert to second models that are trained to map sets of fourth embeddings of sets of historical security alerts associated with the respective geographical regions to corresponding sets of security actions; and

generate a security recommendation regarding the security alert, the security recommendation comprising a representation of the selected classes and a representation of the security actions.

2 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system to at least:

select a first set of designated security incidents from a first set of historical security incidents associated with a first geographical region by performing the following operations:

select a first number of designated security incidents from the first set of historical security incidents to be comprised in the first set of designated security incidents as a result of embeddings of the first number of designated security incidents and the first embedding being same and further as a result of the first number of designated security incidents corresponding to a common class of the plurality of classes; and

select a second number of designated security incidents from the first set of historical security incidents to be comprised in the first set of designated security incidents as a result of embeddings of the second number of designated security incidents and the first embedding being same and further as a result of the first number of designated security incidents corresponding to different classes of the plurality of classes.

3 . The system of claim 2 , wherein a number of the designated security incidents in the first set is limited to a threshold number; and

wherein the computer-executable instructions are executable by the processor system to select the first set of designated security incidents further by performing the following operation:

select a third number of designated security incidents from the first set of historical security incidents to be comprised in the first set of designated security incidents as a result of embeddings of the third number of designated security incidents being different from the first embedding and further as a result of the threshold number being equal to a sum of the first number, the second number, and the third number.

4 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

select a predefined, fixed number of embeddings from a corpus of embeddings of a specified corpus of historical security incidents associated with a specified geographical region to define a specified set of embeddings associated with the specified geographical region as a result of distances between the first embedding and the embeddings in the specified set satisfying a distance criterion.

5 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

select a representative sample of a plurality of historical security incidents associated with a specified geographical region to define a specified set of historical security incidents associated with the specified geographical region by comparing a plurality of embeddings of the plurality of historical security incidents, the representative sample comprising fewer than all of the plurality of historical security incidents.

6 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to perform at least one of the following:

train the first models to map the sets of second embeddings to the corresponding sets of classes using a random forest technique; or

train the second models to map the sets of fourth embeddings to the corresponding sets of security actions using the random forest technique.

7 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

generate a second embedding of a historical security incident in a set of historical incidents associated with a specified geographical region by arranging identifiers, which identify detectors that generate alerts that are comprised in the historical security incident, into an ordered list and hashing the ordered list.

8 . The system of claim 1 , wherein the sets of historical security alerts associated with the respective geographical regions correspond to a predefined, fixed period of time.

9 . The system of claim 1 , wherein the sets of historical security alerts associated with the respective geographical regions are limited to a predefined, fixed number of historical security alerts.

10 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system to at least:

generate a specified set of fourth embeddings of a specified set of historical security alerts associated with a specified geographical region by combining features of the specified set of historical security alerts that occur fewer than a threshold number of times in the specified set of historical security alerts into a common value in the specified set of fourth embeddings; and

as a result of combining the features of the specified set of historical security alerts that occur fewer than the threshold number of times in the specified set of historical security alerts into the common value in the specified set of fourth embeddings, select a first security action to be performed with regard to the entity in the specified geographical region.

11 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

generate a specified set of fourth embeddings of a specified set of historical security alerts associated with a specified geographical region by configuring the specified set of fourth embeddings to represent a predefined, fixed number of features of the specified set of historical security alerts.

12 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

provide a set of historical security alerts associated with a specified geographical region by aggregating multiple historical security alerts, which are comprised in a corpus of historical security alerts associated with the specified geographical region, into a single representative historical security alert as a result of identifiers that identify the multiple historical security alerts satisfying a similarity criterion; and

generate a set of historical security incidents associated with the specified geographical region by incorporating the representative historical security alert into the set of historical security incidents.

13 . The system of claim 1 , wherein the computer-executable instructions are executable by the processor system further to at least:

assign priorities to designated security incidents in sets of designated security incidents that are selected from the sets of historical security incidents, the priorities corresponding to likelihoods of the designated security incidents to cause damage to a system;

wherein the security recommendation comprises a representation of the sets of designated security incidents, the representation of the selected classes, and the representation of the security actions; and

wherein the representation of the sets of designated security incidents indicates the priorities.

14 . A method implemented by a computing system, the method comprising:

receiving a security alert regarding an identified security incident associated with an entity;

selecting sets of designated security incidents from sets of historical security incidents associated with respective geographical regions as a result of distances between a first embedding, which represents the identified security incident, and sets of designated embeddings, which represent the sets of designated security incidents, being less than or equal to distances between the first embedding and sets of other embeddings, which represent sets of other security incidents in the sets of historical security incidents;

classifying the identified security incident into selected classes, the selected classes determined from a plurality of classes by applying the first embedding, which represents the identified security incident, to first models that are trained to map sets of second embeddings, which represent the sets of historical security incidents associated with the respective geographical regions, to corresponding sets of classes of the plurality of classes, the plurality of classes corresponding to at least one of validity of security concerns or maliciousness of actions that result in the security concerns;

selecting security actions from a plurality of possible security actions to be performed with regard to the entity in the respective geographical regions by applying a third embedding, which represents the security alert, to second models that are trained to map sets of fourth embeddings, which represent sets of historical security alerts associated with the respective geographical regions, to corresponding sets of security actions; and

generating a security recommendation regarding the security alert, the security recommendation comprising a representation of the sets of designated security incidents, a representation of the selected classes into which the identified security incident is classified, and a representation of the security actions to be performed with regard to the entity in the respective geographical regions.

15 . The method of claim 14 , wherein the plurality of classes comprises at least a false positive class, a true positive class, and a benign positive class;

wherein the false positive class corresponds to an invalid security concern;

wherein the true positive class corresponds to a valid security concern resulting from an action that is deemed malicious;

wherein the benign positive class corresponds to a valid security concern resulting from an action that is deemed benign; and

wherein the security actions are selected from the plurality of possible security actions as a result of the selected classes being the true positive class.

16 . The method of claim 14 , wherein the sets of historical security incidents associated with the respective geographical regions correspond to a predefined, fixed period of time.

17 . The method of claim 14 , wherein the sets of historical security incidents associated with respective geographical regions are limited to a predefined, fixed number of historical security incidents.

18 . The method of claim 14 , further comprising:

generating a specified set of second embeddings that represents a specified set of historical security incidents associated with a specified geographical region by combining features of the specified set of historical security incidents that occur fewer than a threshold number of times in the specified set of historical security incidents into a common value in the specified set of second embeddings;

wherein selecting the sets of designated security incidents from the sets of historical security incidents associated with the respective geographical regions comprises:

as a result of combining the features of the specified set of historical security incidents that occur fewer than the threshold number of times in the specified set of historical security incidents into the common value in the specified set of second embeddings, selecting a first set of designated security incidents from the specified set of historical security incidents associated with the specified geographical region.

19 . The method of claim 14 , further comprising:

generating a specified set of second embeddings that represents a specified set of historical security incidents associated with a specified geographical region by configuring the specified set of second embeddings to represent a predefined, fixed number of features of the specified set of historical security incidents.

20 . The method of claim 14 , further comprising:

selecting a representative sample of a plurality of historical security alerts associated with a specified geographical region to define a specified set of historical security alerts associated with the specified geographical region by comparing a plurality of embeddings that represent the plurality of historical security alerts, the representative sample comprising fewer than all of the plurality of historical security alerts.

21 . The method of claim 14 , wherein at least one of the following:

the representation of the sets of designated security incidents in the security recommendation is an aggregation of the sets of designated security incidents that is agnostic with regard to geographical region; or

the representation of the security actions to be performed with regard to the entity in the respective geographical regions is an aggregation of the security actions that is agnostic with regard to geographical region.

22 . A computer program product comprising a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to perform operations, the operations comprising:

classifying an identified security incident associated with an entity into selected classes for respective geographical regions, the selected classes determined from a plurality of classes by applying a first embedding, which represents the identified security incident, to a first model that is trained to map sets of second embeddings, which represent sets of historical security incidents associated with the respective geographical regions, to corresponding sets of classes of the plurality of classes, the plurality of classes corresponding to at least one of validity of security concerns or maliciousness of actions that result in the security concerns;

selecting security actions from a plurality of possible security actions to be performed with regard to the entity in the respective geographical regions by applying a third embedding, which represents a security alert regarding the identified security incident, to a second model that is trained to map sets of fourth embeddings, which represent sets of historical security alerts associated with the respective geographical regions, to corresponding sets of security actions; and

generating a security recommendation regarding the security alert, the security recommendation comprising a representation of the selected classes into which the identified security incident is classified and a representation of the security actions to be performed with regard to the entity in the respective geographical regions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2024
From: GHARIB, AMIRHOSSEIN; KALAJDJIESKI, JOVAN; MCCANN, ROBERT LEE; FREITAS, SCOTT ALEXANDER
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 069064/0365 →
Continuity (2)
Provisional Application 63670097 · Jul 11, 2024
Related Publication 20260017369A1 · Jan 15, 2026
References Cited (67)
US 11423146B2 · Li · 2022 [cited by examiner]
US 11494486B1 · Kim · 2022 [cited by examiner]
US 12169512B2 · Hamilton · 2024 [cited by examiner]
US 12614037B2 · De Luis Balaguer · 2026 [cited by examiner]
US 12615267B2 · Mace · 2026 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20220321581A1 · Sood · 2022 [cited by examiner]
US 20220391198A1 · Decrop · 2022 [cited by examiner]
US 20230275907A1 · Bertiger · 2023 [cited by examiner]
US 20230275908A1 · Mace · 2023 [cited by examiner]
US 20240305491A1 · Rosenoer · 2024 [cited by examiner]
US 20240340301A1 · Thompson · 2024 [cited by examiner]
US 20240394332A1 · Roscoe · 2024 [cited by examiner]
US 20250030725A1 · Fellows · 2025 [cited by examiner]
US 20250112816A1 · Titon · 2025 [cited by examiner]
US 20250155260A1 · Fan · 2025 [cited by examiner]
US 20250156653A1 · Yuan · 2025 [cited by examiner]
US 20250217634A1 · Bono · 2025 [cited by examiner]
US 20250259075A1 · Crabtree · 2025 [cited by examiner]
US 20250392506A1 · Titon · 2025 [cited by examiner]
US 20260017369A1 · Gharib · 2026 [cited by examiner]
DE 102018202875A1 · 2018 [cited by examiner]
WO WO2022032285A1 · 2022 [cited by examiner]
WO WO2024211703A2 · 2024 [cited by examiner]
Scott Freitas, Jovan Kalajdjieski, Amir Gharib, and Robert McCann. 2025. AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security, ArXiv.org, Jul. 12, 2024, p. 1-10. (Year: 2024). [cited by examiner]
Co-pending U.S. Appl. No. 18/393,631 entitled “Hierarchical Representation Models,”, filed on Dec. 21, 2023, 64 pages. [cited by applicant]
“Microsoft Security Copilot”, Retrieved from: https://www.microsoft.com/en-in/security/business/ai-machine-learning/microsoft-security-copilot, 2024, 10 Pages. [cited by applicant]
“Triage and investigate incidents with guided responses from Microsoft Copilot in Microsoft Defender”, Retrieved from: https://learn.microsoft.com/en-us/defender-xdr/security-copilot-m365d-guided-response, Nov. 19, 2024… [cited by applicant]
“What is Microsoft Security Copilot?”, Retrieved from: https://learn.microsoft.com/en-us/copilot/security/microsoft-security-copilot, Nov. 18, 2024, 4 Pages. [cited by applicant]
Alsubhi, et al., “Alert prioritization in intrusion detection systems”, IEEE, 2008, pp. 33-40. [cited by applicant]
Alsubhi, et al., “FuzMet: a fuzzy logic based alert prioritization engine for intrusion detection systems”, International Journal of Network Management, vol. 22, No. 04, Jul. 12, 2012, pp. 263-284. [cited by applicant]
Alturkistani, et al., “Optimizing cybersecurity incident response decisions using deep reinforcement learning”, International Journal of Electrical and Computer Engineering (IJECE), Dec. 2022, vol. 12, No. 06, pp. 6768-… [cited by applicant]
Aminanto, et al., “Threat Alert Prioritization Using Isolation Forest and Stacked Auto Encoder with Day-Forward-Chaining Analysis”, IEEE, vol. 08, Dec. 2, 2020, pp. 2169-3536. [cited by applicant]
Applebaum, et al., “Playbook oriented cyber response”, In 2018 National Cyber Summit (NCS). IEEE, Jun. 2018, pp. 8-15. [cited by applicant]
Ban, et al., “Combat security alert fatigue with ai-assisted techniques”, In Proceedings of the 14th Cyber Security Experimentation and Test Workshop, Sep. 7, 2021, pp. 9-16. [cited by applicant]
Bashendy, et al., “Intrusion response systems for cyber-physical systems: A comprehensive survey”, Computers & Security, vol. 124, No. C, Jan. 2023, 102984, 9 Pages. [cited by applicant]
Duggal, et al., “HAR: Hardness Aware Reweighting for Imbalanced Datasets”, IEEE International Conference on Big Data, 2021, pp. 735-745. [cited by applicant]
Duggal, et al., “REST: Robust and Efficient Neural Networks for Sleep Monitoring in the Wild”, In Proceedings of The Web Conference 2020, Apr. 20, 2020, pp. 1704_1714. [cited by applicant]
Foo, et al., “ADEPTS: Adaptive Intrusion Response using Attack Graphs in an E-Commerce Environment”, In 2005 International Conference on Dependable Systems and Networks (DSN'05). IEEE, Jan. 2005, pp. 508_517. [cited by applicant]
Franco, et al., “SecBot: a Business-Driven Conversational Agent for Cybersecurity Planning and Management”, In 2020 16th international conference on network and service management (CNSM). IEEE, Nov. 6, 2020, 7 Pages. [cited by applicant]
Freitas, et al., “MalNet: A Large-Scale Image Database of Malicious Software”, In Proceedings of the 31st ACM International Conference on Information & Knowledge Management, Oct. 17, 2022, pp. 3948-3952. [cited by applicant]
Freitas, et al., “A Large-Scale Database for Graph Representation Learning”, Retrieved from: https://arxiv.org/abs/2011.07682, Nov. 7, 2021, 13 Pages. [cited by applicant]
Freitas, et al., “AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security”, Retrieved from: https://arxiv.org/abs/2407.09017, Nov. 24, 2024, 9 Pages. [cited by applicant]
Hassan, et al., “Tactical Provenance Analysis for Endpoint Detection and Response Systems”, In 2020 IEEE Symposiumon Security and Privacy, May 2020, pp. 1172-1189. [cited by applicant]
Hassan, et al., “NODOZE: Combatting Threat Alert Fatigue with Automated Provenance Triage”, Network and Distributed Systems Security Symposium, Feb. 26, 2019, 15 Pages. [cited by applicant]
Huang, et al., “Cyber-physical system security for networked industrial processes”, International Journal of Automation and Computing, vol. 12, Nov. 6, 2015, pp. 567-578. [cited by applicant]
Inayat, et al., “Intrusion response systems: Foundations, design, and challenges”, Journal of Network and Computer Applications, vol. 62, Feb. 2016, pp. 53-74. [cited by applicant]
Jeevaprasath, “A user-centric machine learning framework for cyber security operations center”, International Research Journal of Modernization in Engineering Technology and Science, vol. 06, No. 04, Apr. 2024, 6 Pages. [cited by applicant]
Jiang, et al., “Xpert: Empowering Incident Management with Query Recommendations via Large Language Models”, Proceedings of the IEEE/ACM 46th International Conference on Software Engineering, No. 92, Apr. 12, 2024, 13 P… [cited by applicant]
Khoury, et al., “A Hybrid Game Theory and Reinforcement Learning Approach for Cyber-Physical Systems Security”, In NOMS 2020-2020 IEEE/IFIP Network Operations and Management Symposium, Apr. 2020, 9 Pages. [cited by applicant]
Kraeva, et al., “Application of the Metric Learning for Security Incident Playbook Recommendation”, IEEE 22nd International Conference of Young Professionals in Electron Devices and Materials (EDM), 2021, pp. 475-479. [cited by applicant]
Kremer, et al., “IC-SECURE: Intelligent System for Assisting Security Experts in Generating Playbooks for Automated Incident Response”, Retrieved from: https://arxiv.org/abs/2311.03825, Nov. 7, 2023, 15 Pages. [cited by applicant]
Li, et al., “A Dynamic Decision-Making Approach for Intrusion Response in Industrial Control Systems”, IEEE Transactions on Industrial Informatics, vol. 15, No. 5, Aug. 21, 2018, 11 Pages. [cited by applicant]
Lin, Tao, “A Data Triage Retrieval System for Cyber Security Operations Center”, Retrieved from: https://etda.libraries.psu.edu/catalog/14787txl78, Mar. 28, 2018, 59 Pages. [cited by applicant]
Liu, et al., “RAPID: Real-Time Alert Investigation with Context-aware Prioritization for Efficient Threat Discovery”, In Proceedings of the 38th Annual Computer Security Applications Conference, Dec. 5, 2022, pp. 827-84… [cited by applicant]
Mellen, et al., The Forrester Wave™, Extended Detection and Response Platforms, Q2, 2024, 12 Pages. [cited by applicant]
Nguyen, et al., “Human-in-the-Loop XAl-enabled Vulnerability Detection, Investigation, and Mitigation”, In 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE), Nov. 2021, pp. 1012-1212. [cited by applicant]
Oprea, et al., “MADE: Security Analytics for Enterprise Threat Detection”, In Proceedings of the 34th Annual Computer Security Applications Conference, Dec. 3, 2018, pp. 124-136. [cited by applicant]
Perera, et al., “Intelligent soc chatbot for security operation center”, In 2019 International Conference on Advancements in Computing (ICAC) IEEE, Dec. 2019, pp. 340-345. [cited by applicant]
Qin, et al., “A Risk-Based Dynamic Decision-Making Approach for Cybersecurity Protection in Industrial Control Systems”, IEEE Transactions on Systems, Man, and Cybernetics, vol. 50, No. 10, Aug. 17, 2018, pp. 3863-3870. [cited by applicant]
Shameli-Sendi, et al., “Dynamic Optimal Countermeasure Selection for Intrusion Response System”, IEEE Transactions on Dependable and Secure Computing, vol. 13, No. 09, Sep. 2014, 14 Pages. [cited by applicant]
Shameli-Sendi, et al., “Intrusion Response Systems: Survey and Taxonomy”, International Journal of Computer Science and Network Security, vol. 12, No. 01, Jan. 2012, 14 Pages. [cited by applicant]
Sopan, et al., “Building a Machine Learning Model for the SOC, by the Input from the SOC, and Analyzing it for the Soc”, IEEE Symposium on Visualization for Cyber Security, Oct. 2018, 8 Pages. [cited by applicant]
Stefanova, et al., “Off-Policy Q-learning Technique for Intrusion Response in Network Security”, World Academy of Science, Engineering and Technology, 2018, pp. 262-268. [cited by applicant]
Toth, et al., “Evaluating the impact of automated intrusion response mechanisms”, In 18th Annual Computer Security Applications Conference, IEEE, Dec. 2002, 10 Pages. [cited by applicant]
Zhong, et al., “A cyber security data triage operation retrieval system”, Computers & Security, vol. 76, Jul. 2018, pp. 12-31. [cited by applicant]
Zonouz, et al., “RRE: A Game-Theoretic Intrusion Response and Recovery Engine”, IEEE Transactions on Parallel and Distributed Systems, vol. 25, No. 02, Aug. 21, 2013, pp. 395-406. [cited by applicant]