IP Library Patent Application 19652927
Patent Application
App. No. 19/652,927

Adaptive Detection of Security Threats Through Dynamic Retraining Training of Computer-Implemented Models

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/652,927
Abstract

Systems and methods for adaptive detection of security threats may include maintaining a natural language processing model trained to classify communications as attacks. The system may detect a missed attack corresponding to a communication processed by the natural language processing model, based on which the system determines to retrain the natural language processing model. The system may generate one or more training samples based on the communication processed by the natural language model, where the training samples include data corresponding to one or more behavioral dimensions from the communication. The system may retrain the natural language processing model using at least the one or more training samples, and deploy the retained natural language processing model for one or more subsequent communications, to detect an attack in at least one of the one or more subsequent communications.

Claims (46)

1 . A method, comprising:

maintaining, by one or more processors, a natural language processing model trained to classify communications as attacks;

detecting, by the one or more processors, a missed attack corresponding to a communication processed by the natural language processing model;

determining, by the one or more processors, to retrain the natural language processing model based on detection of the missed attack;

generating, by the one or more processors, one or more training samples based on the communication processed by the natural language model, the one or more training samples including data corresponding to one or more behavioral dimensions from the communication;

retraining, by the one or more processors, the natural language processing model using at least the one or more training samples, to generate a retrained natural language processing model; and

deploying, by the one or more processors, the retrained natural language processing model for one or more subsequent communications, to detect an attack in at least one of the one or more subsequent communications, based on the at least one subsequent communication having one or more traits corresponding to the one or more behavioral dimensions.

2 . The method of claim 1 , wherein generating the one or more training samples comprises generating a plurality of training samples based on the communication, each training sample being a synthetic sample generated using the communication.

3 . The method of claim 2 , wherein the synthetic samples are generated by modifying one or more of traits of the communication to generate a corresponding synthetic sample.

4 . The method of claim 3 , wherein each of the synthetic samples are a respective synthetic communication generated by augmenting one or more portions of text of the communication.

5 . The method of claim 1 , wherein the natural language processing model comprises one of a plurality of natural language processing models, and wherein retraining the natural language processing model comprises retraining each of the plurality of natural language processing model using the one or more training samples.

6 . The method of claim 1 , wherein the one or more behavioral dimensions comprise at least one of an attack type, an attack strategy, an impersonated party, an attacked party, an attack goal, or an attack vector.

7 . The method of claim 1 , wherein retraining the natural language processing model comprises:

periodically retraining, by the one or more processors, the natural language processing model responsive to generation of a defined number of training samples.

8 . The method of claim 1 , further comprising:

receiving, by the one or more processors, an indication of the communication; and

detecting, by the one or more processors, the missed attack corresponding to the communication, responsive to receipt of the indication.

9 . The method of claim 8 , wherein the indication is received from a user associated with a user account which received the communication.

10 . A system, comprising:

memory storing one or more instructions; and

one or more processors configured to execute the one or more instructions from memory to:

maintain a natural language processing model trained to classify communications as attacks;

detect a missed attack corresponding to a communication processed by the natural language processing model;

determine to retrain the natural language processing model based on detection of the missed attack;

generate one or more training samples based on the communication processed by the natural language model, the one or more training samples including data corresponding to one or more behavioral dimensions from the communication;

retrain the natural language processing model using at least the one or more training samples, to generate a retrained natural language processing model; and

deploy the retrained natural language processing model for one or more subsequent communications, to detect an attack in at least one of the one or more subsequent communications, based on the at least one subsequent communication having one or more traits corresponding to the one or more behavioral dimensions.

11 . The system of claim 10 , wherein, to generate the one or more processors, the one or more instructions cause the one or more processors to generate a plurality of training samples based on the communication, each training sample being a synthetic sample generated using the communication.

12 . The system of claim 11 , wherein the synthetic samples are generated by modifying one or more of traits of the communication to generate a corresponding synthetic sample.

13 . The system of claim 12 , wherein each of the synthetic samples are a respective synthetic communication generated by augmenting one or more portions of text of the communication.

14 . The system of claim 10 , wherein the natural language processing model comprises one of a plurality of natural language processing models, and wherein the one or more processors retrain each of the plurality of natural language processing model using the one or more training samples.

15 . The system of claim 10 , wherein the one or more behavioral dimensions comprise at least one of an attack type, an attack strategy, an impersonated party, an attacked party, an attack goal, or an attack vector.

16 . The system of claim 10 , wherein the one or more processors are configured to periodically retrain the natural language processing model responsive to generation of a defined number of training samples.

17 . The system of claim 10 , wherein the one or more processors are configured to execute the one or more instructions to:

receive an indication of the communication; and

detect the missed attack corresponding to the communication, responsive to receipt of the indication.

18 . The system of claim 17 , wherein the indication is received from a user associated with a user account which received the communication.

19 . A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

maintain a natural language processing model trained to classify communications as attacks;

detect a missed attack corresponding to a communication processed by the natural language processing model;

determine to retrain the natural language processing model based on detection of the missed attack;

generate one or more training samples based on the communication processed by the natural language model, the one or more training samples including data corresponding to one or more behavioral dimensions from the communication;

retrain the natural language processing model using at least the one or more training samples, to generate a retrained natural language processing model; and

deploy the retrained natural language processing model for one or more subsequent communications, to detect an attack in at least one of the one or more subsequent communications, based on the at least one subsequent communication having one or more traits corresponding to the one or more behavioral dimensions.

20 . The non-transitory computer readable medium of claim 19 , wherein the instructions cause the one or more processors to:

generate a plurality of training samples based on the communication, each training sample being a synthetic sample generated using the communication, the synthetic samples generated by modifying one or more of traits of the communication to generate a corresponding synthetic communication including one or more portions of text of the communication being augmented.