IP Library Patent Application 19075168
Patent Application
App. No. 19/075,168

Systems, Methods and Media for Canonicalizing Computer System Logs into Natural Language Processed Representations for The Purpose of Data Analysis

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/075,168
Abstract

Provided herein is an exemplary system for canonicalizing computer system logs into natural language processed representations for data analysis, the system including a real-time data collector, a cyber security purpose-based large language model communicatively coupled to the real-time data collector, a multi-dimensional vector generator communicatively coupled to the cyber security purpose-based large language model and a vectorization index and a prediction engine communicatively coupled to the multi-dimensional vector generator.

Claims (56)

1 . A method for canonicalizing computer system logs into natural language processed representations for data analysis, the method comprising:

receiving a log file;

transmitting the log file to a cyber security purpose-based large language model;

applying natural language processing by the large language model to the log file;

generating a plain English translation of the log file by the large language model;

canonicalizing the plain English translation of the log file by the large language model;

generating a multi-dimensional vector from the plain English translation of the log file by the large language model;

applying a cosine similarity calculation to the multi-dimensional vector;

generating a multi-dimensional natural language alert signature from the multi-dimensional vector;

storing the multi-dimensional natural language alert signature in a vector index data base;

applying a machine learning algorithm to the multi-dimensional natural language alert signature in the vector index data base;

associating the multi-dimensional natural language alert signature with the log file;

finger-printing the multi-dimensional natural language alert signature with the log to generate a finger print;

associating the multi-dimensional natural language alert signature with the plain English translation; and

matching the finger print to another log file.

2 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 1 , the method further comprising:

originating the received log file from a variegated assortment of tools.

3 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 1 , the method further comprising:

preserving the received log file by storing it within a database, ensuring its availability for future reference.

4 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 1 , the method further comprising:

treating the received log file as a contiguous string of text.

5 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 4 , the method further comprising:

subjecting the contiguous string of text to an embedding model.

6 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 5 , the method further comprising:

tokenizing the contiguous string of text.

7 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 6 , the method further comprising:

vectorizing the contiguous string of text into vector form.

8 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 1 , the method further comprising:

including a prompt with the transmitting of the log file to a cyber security purpose-based large language model.

9 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 8 , the method further comprising:

designing the prompt to guide the large language model in its interaction with the log file.

10 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 9 , the method further comprising:

designing the prompt as a template.

11 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 10 , the method further comprising:

designing the prompt as the template reading, “TEMPLATE: ‘Please summarize this data, using a template like this: ‘The tool, TOOLNAME, with event id EVENTID, detected an event named EVENTNAME. This event was detected on DATE. The source IP address was SOURCEIP and the source TCP port was SOURCEPORT. The destination IP address was DESTINATIONIP and the destination TCP port was TCPPORT. The protocol used was PROTOCOL. The source IP address is located in S-CITY, S-COUNTRY, and the destination IP address is located in D-CITY, D-COUNTRY. Replace the capitalized variables with their respective information. Replace EVENTID with its respective information. Replace S-CITY, S-COUNTRY, D-CITY, D-COUNTRY with their respective information. Always respond with the event creation date, in a format like: Aug. 6, 2023 at 23:24:48. Remove all underscores from event names if they exist.’”

12 . The method for canonicalizing computer system logs into natural language processed representations for data analysis of claim 11 , the method further comprising:

responding by the cyber security purpose-based large language model with information including an identity of a tool, event id, detected event, time of detection, a source IP address, a destination tcp port, a protocol used, a geographic location of the source IP address and a geographic location of a destination IP address.

13 . A system for canonicalizing computer system logs into natural language processed representations for data analysis, the system comprising:

a real-time data collector;

a cyber security purpose-based large language model communicatively coupled to the real-time data collector;

a multi-dimensional vector generator communicatively coupled to the cyber security purpose-based large language model and a vectorization index; and

a prediction engine communicatively coupled to the multi-dimensional vector generator.

14 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 13 , the system further comprising:

the real-time data collector configured to receive a log file from a variegated assortment of tools.

15 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 14 , the system further comprising:

the cyber security purpose-based large language model configured to receive the log file.

16 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 15 , the system further comprising:

the cyber security purpose-based large language model configured to apply natural language processing by the large language model to the log file.

17 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 16 , the system further comprising:

the cyber security purpose-based large language model configured to generate a plain English translation of the log file.

18 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 17 , the system further comprising:

the cyber security purpose-based large language model configured to canonicalize the plain English translation of the log file.

19 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 18 , the system further comprising:

the cyber security purpose-based large language model configured to generate a multi-dimensional vector from the plain English translation of the log file.

20 . The system for canonicalizing computer system logs into natural language processed representations for data analysis of claim 13 . the system further comprising:

the vectorization index configured to receive the multi-dimensional vector.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2025
From: PETERSON, JOHN ULISS; JESPERSEN, PAUL SOREN
To: PRE SECURITY INC.
Reel/Frame 070460/0407 →