IP Library Patent Application 19206307
Patent Application
App. No. 19/206,307

AUTOMATED SUMMARIZATION OF NETWORK SECURITY INVESTIGATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/206,307
Abstract

In some implementations, a cybersecurity system is provided for summarizing network security investigations. The system receives a request to summarize an investigation sequence performed in response to a computer security incident, retrieves tokenized elements that correspond to the investigation sequence, and provides the tokenized elements to a large language model (LLM) for translation into a data operation format. The system receives, from the LLM, and for each tokenized element, a corresponding translated data operation. For each translated data operation, the system submits the translated data operation for execution by a data source, and receives a corresponding data operation response. The system performs a summarization process of the investigation sequence, and outputs a natural language summarization.

Claims (48)

1 . A cybersecurity system for summarizing network security investigations, comprising:

at least one processor; and

memory storing instructions, that, when executed by the at least one processor, cause the system to perform operations comprising:

receiving a request to summarize an investigation sequence performed in response to a computer security incident;

retrieving a set of tokenized elements that correspond to the investigation sequence;

providing each tokenized element in the set of tokenized elements to a large language model (LLM) for translation into a data operation format;

receiving, from the LLM, and for each tokenized element in the set of tokenized elements, a corresponding translated data operation;

for each translated data operation in a set of translated data operations, (i) submitting the translated data operation for execution by a data source, and (ii) receiving a corresponding data operation response;

performing a summarization process of the investigation sequence, based at least in part on the set of tokenized elements and on a set of corresponding data operation responses; and

outputting a natural language summarization of the investigation sequence, based on the summarization process.

2 . The system of claim 1 , the operations further comprising:

refining the LLM such that the LLM is configured to translate natural language commands into the data operation format, wherein the refining is based at least in part on (i) a data schema of security incident data maintained by the data source, (ii) a data operation syntax employed by the data source, and (iii) data that represents historical security investigations and their associated data operations.

3 . The system of claim 1 , wherein the set of tokenized elements includes natural language questions and/or natural language actions.

4 . The system of claim 3 , wherein the summarization process comprises:

providing each data operation response in the set of data operation responses to the LLM for translation into a corresponding natural language response;

aggregating the set of tokenized elements and a corresponding set of natural language responses;

providing the aggregated tokenized elements and corresponding natural language responses to the LLM for summarization; and

receiving, from the LLM, the natural language summarization of the investigation sequence.

5 . The system of claim 4 , wherein a technical complexity of the natural language summarization of the investigation sequence is adaptively adjusted by the LLM to reflect a technical expertise and/or security privileges of a user from whom the request to summarize an investigation sequence is received.

6 . The system of claim 1 , wherein the request to summarize the investigation sequence performed in response to the computer security incident is received through a visual interface, and the natural language summarization of the investigation sequence is returned through the visual interface.

7 . The system of claim 6 , wherein the visual interface is a text service that supports multi-turn conversations about the computer security incident.

8 . The system of claim 1 , the operations further comprising:

mapping the corresponding data operation response to a corresponding security insight.

9 . The system of claim 1 , the operations further comprising storing the natural language summarization of the investigation sequence, along with information that pertains to a case type of the investigation sequence.

10 . The system of claim 9 , wherein the information that pertains to the case type of the investigation sequence comprises a typical predicted analysis pattern for the case type.

11 . A computer-implemented method for summarizing network security investigations, the method comprising:

receiving a request to summarize an investigation sequence performed in response to a computer security incident;

retrieving a set of tokenized elements that correspond to the investigation sequence;

providing each tokenized element in the set of tokenized elements to a large language model (LLM) for translation into a data operation format;

receiving, from the LLM, and for each tokenized element in the set of tokenized elements, a corresponding translated data operation;

for each translated data operation in a set of translated data operations, (i) submitting the translated data operation for execution by a data source, and (ii) receiving a corresponding data operation response;

performing a summarization process of the investigation sequence, based at least in part on the set of tokenized elements and on a set of corresponding data operation responses; and

outputting a natural language summarization of the investigation sequence, based on the summarization process.

12 . The computer-implemented method of claim 11 , further comprising:

refining the LLM such that the LLM is configured to translate natural language commands into the data operation format, wherein the refining is based at least in part on (i) a data schema of security incident data maintained by the data source, (ii) a data operation syntax employed by the data source, and (iii) data that represents historical security investigations and their associated data operations.

13 . The computer-implemented method of claim 11 , wherein the set of tokenized elements includes natural language questions and/or natural language actions.

14 . The computer-implemented method of claim 13 , wherein the summarization process comprises:

providing each data operation response in the set of data operation responses to the LLM for translation into a corresponding natural language response;

aggregating the set of tokenized elements and a corresponding set of natural language responses;

providing the aggregated tokenized elements and corresponding natural language responses to the LLM for summarization; and

receiving, from the LLM, the natural language summarization of the investigation sequence.

15 . The computer-implemented method of claim 14 , wherein a technical complexity of the natural language summarization of the investigation sequence is adaptively adjusted by the LLM to reflect a technical expertise and/or security privileges of a user from whom the request to summarize an investigation sequence is received.

16 . The computer-implemented method of claim 11 , wherein the request to summarize the investigation sequence performed in response to the computer security incident is received through a visual interface, and the natural language summarization of the investigation sequence is returned through the visual interface.

17 . The computer-implemented method of claim 16 , wherein the visual interface is a text service that supports multi-turn conversations about the computer security incident.

18 . The computer-implemented method of claim 11 , further comprising:

mapping the corresponding data operation response to a corresponding security insight.

19 . The computer-implemented method of claim 11 , further comprising storing the natural language summarization of the investigation sequence, along with information that pertains to a case type of the investigation sequence.

20 . The computer-implemented method of claim 19 , wherein the information that pertains to the case type of the investigation sequence comprises a typical predicted analysis pattern for the case type.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2025
From: SOLIMAN, HAZEM MOHAMED AHMED; KRAFT, CHRIS DOUGLAS; LARROYD, MARCIO LOPES; RAY, KENNETH D.; HUSSAIN, SYED AZFAR; SCHIAPPA, DANIEL; MYLREA, MICHAEL ELLIOTT
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 071467/0823 →