Large language model based security insights
Methods, systems, and devices for large language model (LLM) based security insights and/or recommendations at a data security system are described. A data security system may obtain event information associated with monitored computing assets and/or user accounts for a client or customer of the data security system. The data security system may filter the event information and associated computing asset and/or user account information in accordance with a security policy for the client and may generate a prompt for an LLM based on the filtered event and computing asset and/or user account information. The data security system may provide the prompt to the LLM, and the LLM may provide a natural language response to the prompt that provides a security action recommendation to resolve one or more events and/or insights such as a rationale for the security action recommendation and/or an explanation of threats associated with the event.
1 . A method, comprising:
obtaining, at a data security system, event information for a set of security or information technology events associated with a client account of the data security system;
retrieving, by the data security system and from a data store accessible to the data security system, asset or user information associated with the client account based at least in part on the event information;
filtering, by the data security system, the event information and the asset or user information in accordance with a security policy associated with the client account to generate filtered event and asset or user information;
generating, by the data security system and in accordance with the security policy, a prompt that includes the filtered event and asset or user information;
providing the prompt to a large language model; and
receiving, from the large language model in response to the prompt, a natural language response that includes a security action recommendation or insight for one or more assets or users of the client account for one or more security or information technology events of the set of security or information technology events.
2 . The method of claim 1 , further comprising:
identifying, by the data security system, one or more asset identifiers or one or more user identifiers in the event information, wherein retrieving the asset or user information is based at least in part on the asset or user information being associated with the one or more asset identifiers or the one or more user identifiers in the data store.
3 . The method of claim 1 , wherein the event information comprises a set of log files associated with the set of security or information technology events.
4 . The method of claim 3 , wherein filtering the event information comprises extracting natural language text from the set of log files.
5 . The method of claim 1 , wherein filtering the event information comprises:
selecting a subset of security or information technology events of the set of security or information technology events based at least in part on the subset of security or information technology events satisfying selection criteria associated with the security policy.
6 . The method of claim 5 , wherein:
the subset of security or information technology events are security events, and
the selection criteria comprises a threat level threshold, one or more vulnerability classes associated with the security events, an asset class of one or more assets associated with the security events, a user class of one or more users associated with the security events, or any combination thereof.
7 . The method of claim 5 , wherein:
the subset of security or information technology events are information technology events, and
the selection criteria comprises a computer processing unit usage threshold, a memory usage threshold, a latency threshold, a power threshold, an asset class of one or more assets associated with the information technology events, a user class of one or more users associated with the information technology events, or any combination thereof.
8 . The method of claim 1 , wherein filtering the asset or user information comprises:
selecting a subset of assets or a subset of users associated with the event information based at least in part on an asset class associated with the subset of assets, a type of information stored on the subset of assets, a physical location of the subset of assets, a vulnerability threshold associated with the subset of assets, a user class or role associated with the subset of users, an access level associated with the subset of users, or a physical location associated with the subset of users.
9 . The method of claim 1 , wherein obtaining the event information comprises:
receiving the event information from a security information and event management system associated with the client account.
10 . The method of claim 9 , wherein receiving the event information comprises receiving the event information in real-time based on occurrence of the set of security or information technology events.
11 . The method of claim 1 , wherein obtaining the event information comprises:
receiving a request from a computing device associated with the client account to provide the security action recommendation or insight for the event information, wherein the request comprises the event information.
12 . The method of claim 1 , further comprising:
sending, by the data security system, the natural language response that includes the security action recommendation or insight to a computing device associated with the client account.
13 . The method of claim 12 , further comprising:
obtaining, by the data security system and from the computing device or a second computing device associated with the client account, an indication of performance of the security action recommendation;
determining, by the data security system, whether performance of the security action recommendation resolved a security or information technology event of the set of security or information technology events; and
updating, by the data security system, the security policy based at least in part on the determining.
14 . The method of claim 13 , wherein the determining comprises:
identifying, by the data security system, a presence or an absence of a same security or information technology event in second event information obtained after obtention of the indication of performance of the security action recommendation.
15 . The method of claim 1 , further comprising:
obtaining, by the data security system and from one or more computing devices associated with the client account, the security policy.
16 . The method of claim 1 , further comprising:
generating, by the data security system, the security policy based at least in part on one or more security policies obtained from one or more other client accounts of the data security system.
17 . The method of claim 1 , wherein the security action recommendation comprises:
a recommendation to isolate an asset;
a recommendation to terminate a process running on an asset;
a recommendation to change an access level of one or more user accounts;
a recommendation to update one or more permissions associated with one or more user accounts;
a recommendation to update a role associated with one or more user accounts;
a recommendation to replace an asset;
a recommendation to add an asset;
a recommendation to move information from one asset to another asset;
a recommendation to perform an update on an asset; or
any combination thereof.
18 . The method of claim 1 , further comprising:
executing, by the data security system, one or more workflows to perform the security action recommendation.
19 . The method of claim 1 , wherein the natural language response comprises natural language rationale for one or more recommended actions of the security action recommendation.
20 . The method of claim 1 , further comprising:
providing, to the large language model, training data comprising respective recommended security actions for set of example security or information technology events and associated asset or user information, wherein the security action recommendation or insight is based at least in part on provision of the training data to the large language model.
21 . An apparatus, comprising:
a processing system that includes processor circuitry and memory circuitry that stores code, the processing system configured to cause the apparatus to:
obtain, at a data security system, event information for a set of security or information technology events associated with a client account of the data security system;
retrieving, by the data security system and from a data store accessible to the data security system, asset or user information associated with the client account based at least in part on the event information;
filter, by the data security system, the event information and the asset or user information in accordance with a security policy associated with the client account to generate filtered event and asset or user information;
generate, by the data security system and in accordance with the security policy, a prompt that includes the filtered event and asset or user information;
provide the prompt to a large language model; and
receive, from the large language model in response to the prompt, a natural language response that includes a security action recommendation or insight for one or more assets or users of the client account for one or more security or information technology events of the set of security or information technology events.
22 . A non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors to:
obtain, at a data security system, event information for a set of security or information technology events associated with a client account of the data security system;
retrieving, by the data security system and from a data store accessible to the data security system, asset or user information associated with the client account based at least in part on the event information;
filter, by the data security system, the event information and the asset or user information in accordance with a security policy associated with the client account to generate filtered event and asset or user information;
generate, by the data security system and in accordance with the security policy, a prompt that includes the filtered event and asset or user information;
provide the prompt to a large language model; and
receive, from the large language model in response to the prompt, a natural language response that includes a security action recommendation or insight for one or more assets or users of the client account for one or more security or information technology events of the set of security or information technology events.