IP Library Granted Patent US 12,418,546
Granted Patent B2
US 12,418,546 · App. 17/657,689 · Granted Sep 16, 2025

System and method for predicting investigation queries based on prior investigations

Inventors: Gary A. Bushey (Youngsville, NC); Hrisheek Radhakrishnan (Atlanta, GA); Tarun Sondhi (Ashburn, VA)
Assignee: KPMG LLP
H04L63/1416G06F16/9538
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,546
App. No.
17/657,689
Granted
Sep 16, 2025
Kind
B2
Abstract

An embodiment of the present invention is directed to predicting investigation queries based on prior investigations. An embodiment of the present invention leverages the knowledge of the existing experienced analysts to assist and guide newer or less experienced analysts through incident investigations. By analyzing queries that have been run previously, and utilizing machine learning, an embodiment of the present invention may mimic the knowledge of experienced and/or existing analysts by automatically running those queries against similar incidents.

Claims (43)

1. A computer-implemented system for predicting investigation queries based on prior investigations, the system comprising:

an interactive user interface that is configured to receive one or more inputs;

an interface that communicates with a security information and event management (SIEM) system; and

a computer processor executing on a computer server and coupled to the interactive user interface and the interface, the computer processor further configured to perform the steps of:

receiving, via an input interface, a new alert relating to an incident event wherein the incident event comprises one or more data items that are classifiable into a plurality of category types;

determining a category type for each data item;

determining, via the computer processor, whether the new alert is similar to a prior investigation into a security incident in SIEM, based on a comparison of the category type for each data item with a set of category types associated with a prior query for the prior investigation;

responsive to the new alert having the set of category types that match the one or more category types, identify one or more parsed queries from the prior investigation;

identifying one or more associated factors for each of the one or more parsed queries;

based on the new alert, updating one or more variables associated with the parsed query;

ranking the one or more parsed queries based on the one or more associated factors;

initiating execution of the one or more parsed queries based on the ranking with updated one or variables via the SIEM system;

receiving and storing results of the executed parsed query; and

displaying, via the interactive user interface, the executed parsed query and corresponding results of the parsed query.

2. The system of claim 1 , wherein the set of category types match a single category type.

3. The system of claim 1 , wherein the set of category types match multiple category types.

4. The system of claim 1 , wherein the parsed query comprises at least one static parameter and at least one variable.

5. The system of claim 1 , wherein the parsed query is associated with analyst data comprising analyst level and experience.

6. The system of claim 1 , wherein the parsed query is associated with mean time to closure data.

7. The system of claim 1 , wherein the one or more category types comprise account, file, host and IP address.

8. The system of claim 1 , wherein the parsed query comprises a set of queries wherein each query is saved and displayed on the interactive user interface.

9. The system of claim 1 , wherein the interface communicates with additional sources of security information.

10. The system of claim 1 , wherein the parsed query comprises comments data.

11. A computer-implemented method for predicting investigation queries based on prior investigations, the method comprising the steps of:

receiving, via an input interface, a new alert relating to an incident event wherein the incident event comprises one or more data items that are classifiable into a plurality of category types;

determining a category type for each data item;

determining, via a computer processor, whether the new alert is similar to a prior investigation into a security incident in SIEM, based on a comparison of the category type for each data item with a set of category types associated with a prior query for the prior investigation;

responsive to the new alert having the set of category types that match the one or more category types, identify one or more parsed queries from the prior investigation;

identifying one or more associated factors for each of the one or more parsed queries;

based on the new alert, updating one or more variables associated with the parsed query;

ranking the one or more parsed queries based on the one or more associated factors;

initiating execution of the one or more parsed queries based on the ranking with updated one or variables via a security information and event management (SIEM) system;

receiving and storing results of the executed parsed query; and

displaying, via an interactive user interface, the executed parsed query and corresponding results of the parsed query.

12. The method of claim 11 , wherein the set of category types match a single category type.

13. The method of claim 11 , wherein the set of category types match multiple category types.

14. The method of claim 11 , wherein the parsed query comprises at least one static parameter and at least one variable.

15. The method of claim 11 , wherein the parsed query is associated with analyst data comprising analyst level and experience.

16. The method of claim 11 , wherein the parsed query is associated with mean time to closure data.

17. The method of claim 11 , wherein the one or more category types comprise account, file, host and IP address.

18. The method of claim 11 , wherein the parsed query comprises a set of queries wherein each query is saved and displayed on the interactive user interface.

19. The method of claim 11 , wherein the interface communicates with additional sources of security information.

20. The method of claim 11 , wherein the parsed query comprises comments data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2025
From: BUSHEY, GARY A.; RADHAKRISHNAN, HRISHEEK; SONDHI, TARUN
To: KPMG LLP
Reel/Frame 072083/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: BUSHEY, GARY A.; RADHAKRISHNAN, HRISHEEK; SONDHI, TARUN
To: KPMG LLP
Reel/Frame 059475/0202 →
Continuity (1)
Related Publication 20230319062A1 · Oct 5, 2023
References Cited (5)
US 8874550B1 · Soubramanien · 2014 [cited by examiner]
US 20180089258A1 · Bhattacharjee et al. · 2018 [cited by applicant]
US 20200042648A1 · Rao · 2020 [cited by examiner]
US 20210281583A1 · Okunlola · 2021 [cited by examiner]
International Searching Authority, PCT International Search Report and Written Opinion, International Application No. PCT/US23/15632, Jun. 21, 2023, pp. 1-15. [cited by applicant]