IP Library › Granted Patent US 12,001,550
Granted Patent B1
US 12,001,550 · App. 18/466,882 · Granted Jun 4, 2024

Cybersecurity incident response techniques utilizing artificial intelligence

Inventors: Alon Schindel (Tel Aviv, IL); Barak Sharoni (Tel Aviv, IL); Amitai Cohen (Kfar Saba, IL); Ami Luttwak (Binyamina, IL); Roy Reznik (Tel Aviv, IL); Yinon Costica (Tel Aviv, IL)
Assignee: WIZ, INC.
G06F21/552G06F16/24522
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,550
App. No.
18/466,882
Filed
Sep 14, 2023
Granted
Jun 4, 2024
Kind
B1
Art Unit
2435
USPC
726/22
Abstract

A system and method for providing cybersecurity incident response utilizing a large language model. The method includes: mapping a received incident input into a scenario of a plurality of scenarios, each scenario including a plurality of sub-scenarios; generating a query based on the received incident input and a selection of a sub-scenario of the plurality of sub-scenarios; executing the query on a security database, the security database including a representation of the computing environment; and initiating a mitigation action based on a result of the executed query.

Claims (60)

1. A method for providing cybersecurity incident response, comprising:

providing a received incident input into a large language model (LLM);

mapping the received incident input into a scenario of a plurality of scenarios, each scenario including a plurality of sub-scenarios, based on an output of the LLM;

receiving a user input through a user interface, the user interface configured to render a graphical representation of a group of sub-scenarios of the plurality of sub-scenarios;

selecting a sub-scenario based on the received user input;

generating a query based on the received incident input and a selection of a sub-scenario of the plurality of sub-scenarios;

executing the query on a security database, the security database including a representation of a computing environment; and

initiating a mitigation action based on a result of the executed query.

2. The method of claim 1 , wherein the incident input includes any one of: a query, a statement, and a combination thereof.

3. The method of claim 1 , wherein the LLM is trained on: a data schema utilized in representing the computing environment, incident data classified to a scenario, the plurality of scenarios, and any combination thereof.

4. The method of claim 1 , further comprising:

generating the query further using the LLM.

5. The method of claim 1 , further comprising:

training the LLM on a plurality of database queries, each database query executable on the security database.

6. The method of claim 1 , further comprising:

generating a prompt for the LLM based on the received user input, the prompt, when executed configuring the LLM to output a sub-scenario selection.

7. The method of claim 1 , further comprising:

receiving a user input through a component of a graphical user interface to initiate generation of an explanation of a security finding;

utilizing the LLM to generate an explanation of a security finding, the explanation including any one of: a base observation regarding the security finding, an analysis of a symptomatic nature of the security finding, and a combination thereof; and

rendering for display the generated explanation of the security finding.

8. The method of claim 1 , further comprising:

processing a user input through a component of a graphical user interface to initiate investigation of a custom incident; and

generating a request to receive additional contextual information wherein the custom incident is unrelated to any specific resource.

9. A non-transitory computer-readable medium storing a set of instructions for providing cybersecurity incident response, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

provide a received incident input into a large language model (LLM);

map the received incident input into a scenario of a plurality of scenarios, each scenario including a plurality of sub-scenarios, based on an output of the LLM;

receive a user input through a user interface; the user interface configured to render a graphical representation of a group of sub-scenarios of the plurality of sub-scenarios;

selecting a sub-scenario based on the received user input;

generate a query based on the received incident input and a selection of a sub-scenario of the plurality of sub-scenarios;

execute the query on a security database, the security database including a representation of a computing environment; and

initiate a mitigation action based on a result of the executed query.

10. A system for providing cybersecurity incident response comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

provide a received incident input into a large language model (LLM);

map the received incident input into a scenario of a plurality of scenarios, each scenario including a plurality of sub-scenarios, based on an output of the LLM;

receive a user input through a user interface; the user interface configured to render a graphical representation of a group of sub-scenarios of the plurality of sub-scenarios;

selecting a sub-scenario based on the received user input;

generate a query based on the received incident input and a selection of a sub-scenario of the plurality of sub-scenarios;

execute the query on a security database, the security database including a representation of a computing environment; and

initiate a mitigation action based on a result of the executed query.

11. The system of claim 10 , wherein the incident input includes any one of:

a query, a statement, and a combination thereof.

12. The system of claim 10 , wherein the LLM is trained on:

a data schema utilized in representing the computing environment, incident data classified to a scenario, the plurality of scenarios, and any combination thereof.

13. The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the query further using the LLM.

14. The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

train the LLM on a plurality of database queries, each database query executable on the security database.

15. The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a prompt for the LLM based on the received user input, the prompt, when executed configuring the LLM to output a sub-scenario selection.

16. The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

receive a user input through a component of a graphical user interface to initiate generation of an explanation of a security finding;

utilize the LLM to generate an explanation of a security finding, the explanation including any one of:

a base observation regard the security finding, an analysis of a symptomatic nature of the security finding, and a combination thereof; and

render for display the generated explanation of the security finding.

17. The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

process a user input through a component of a graphical user interface to initiate investigation of a custom incident; and

generate a request to receive additional contextual information wherein the custom incident is unrelated to any specific resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2024
From: SCHINDEL, ALON; SHARONI, BARAK; COHEN, AMITAI; LUTTWAK, AMI; REZNIK, ROY; COSTICA, YINON
To: WIZ, INC.
Reel/Frame 066169/0755 →
Continuity (1)
Continuation In Part 18457054 · Aug 28, 2023
Cited By (4)
US 12,199,936 US 12,493,615 US 12,608,370 US 12,675,470