IP Library › Granted Patent US 12,547,707
Granted Patent B2
US 12,547,707 · App. 18/340,708 · Granted Feb 10, 2026

Connecting natural and security language in the embedding space for better threat hunting and incident response

Inventors: Muhammed Fatih Bulut (Cambridge, MA); Aditi Kamlesh Shah (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/552G06F16/24522G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,707
App. No.
18/340,708
Filed
Jun 23, 2023
Granted
Feb 10, 2026
Kind
B2
Art Unit
2408
USPC
726/22
Abstract

Methods and apparatuses for improving the speed, quality, and relevance of automated responses provided by a question answering system for security data are described. The question answering system may generate and utilize a large language model that is trained to combine the language of security data, such as the language found in security logs and alerts, with natural language text. Given an input prompt (or a search query) from an end user of the question answering system, the question answering system may identify relevant content from the security data and display a response based on the relevant content. The question answering system may allow the end user of the question answering system to query security logs using natural language text without requiring the end user to provide a structured query and without requiring the security data be parsed and ingested into a database system.

Claims (63)

1 . A system, comprising:

a storage device configured to store a large language model; and

at least one processor in communication with the storage device that is configured to:

receive security data, the security data includes a plurality of log lines;

map a first log line of the plurality of log lines to an event identifier associated with a type of security event;

set a window size for the first log line of the plurality of log lines based on the event identifier for the first log line;

partition the first log line based on the window size;

determine a prompt for generating a plurality of natural language descriptions corresponding with the plurality of log lines;

generate, using the prompt, the plurality of natural language descriptions corresponding with the plurality of log lines;

determine a plurality of template identifiers based on similarity between natural language descriptions of the plurality of natural language descriptions;

generate, using the plurality of template identifiers, positive pairings and negative pairings of the plurality of natural language descriptions corresponding with the plurality of log lines;

train the large language model using the positive pairings and the negative pairings;

generate, using the large language model, a response that identifies a cyber attack; and

perform a security risk mitigation action based on the response.

2 . The system of claim 1 , wherein:

the positive pairings include a first pairing of the plurality of natural language descriptions corresponding with a first log line and a second log line of the plurality of log lines;

the negative pairings include a second pairing of the plurality of natural language descriptions corresponding with a third log line and a fourth log line of the plurality of log lines; and

the at least one processor is configured to fine-tune the large language model such that the large language model generates similar embeddings with at most a first embedding distance given the first pairing and generates different embeddings with at least a second embedding distance greater than the first embedding distance given the second pairing.

3 . The system of claim 2 , wherein:

the first embedding distance corresponds with a cosine similarity distance; and

the prompt comprises natural language text that is determined based on a type of security document storing the security data.

4 . The system of claim 1 , wherein:

the positive pairings include a first pairing corresponding with a first pair of log lines of the plurality of log lines;

the negative pairings include a second pairing corresponding with a second pair of log lines of the plurality of log lines; and

the at least one processor is configured to fine-tune the large language model such that the first pairing are given similar embeddings within a first embedding distance while the second pair are given different embeddings with a second embedding distance greater than the first embedding distance.

5 . The system of claim 1 , wherein:

the at least one processor is configured to fine-tune the large language model to generate embeddings given the positive pairings and the negative pairings as inputs to the large language model.

6 . The system of claim 1 , wherein:

the at least one processor is configured to generate, using the plurality of template identifiers, a first grouping of log lines out of the plurality of log lines.

7 . The system of claim 6 , wherein:

the at least one processor is configured to generate the first grouping of log lines based on syntactic and semantic similarity between the log lines within the first grouping of log lines.

8 . The system of claim 1 , wherein:

the at least one processor is configured to detect that a second plurality of template identifiers should be used to update the positive pairings and the negative pairings; and

the at least one processor is configured to fine-tune the large language model using the updated positive pairings and the updated negative pairings.

9 . The system of claim 1 , wherein:

the at least one processor is configured to utilize a generative model to generate a first natural language description for the first log line of the plurality of log lines.

10 . The system of claim 1 , wherein:

the large language model comprises a security specific large language model; and

the at least one processor is configured to fine-tune the security specific large language model using the positive pairings and the negative pairings.

11 . The system of claim 1 , wherein:

the at least one processor is configured to determine the plurality of template identifiers based on syntactic and semantic similarity between the natural language descriptions of the plurality of natural language descriptions; and

the at least one processor is configured to detect that the response identifies a denial-of-service attack and the security risk mitigation action comprises blocking IP traffic from sources identified in the response.

12 . A method, comprising:

receiving security data, the security data includes a plurality of log lines;

mapping a first log line of the plurality of log lines to an event identifier associated with a type of security event;

setting a window size for the first log line of the plurality of log lines based on the event identifier for the first log line;

partitioning the first log line based on the window size;

determining a prompt for generating a plurality of natural language descriptions corresponding with the plurality of log lines;

generating, using the prompt, the plurality of natural language descriptions corresponding with the plurality of log lines;

determining a plurality of template identifiers based on similarity between natural language descriptions of the plurality of natural language descriptions;

generating, using the plurality of template identifiers, positive pairings and negative pairings of the plurality of natural language descriptions;

fine-tuning a large language model using the positive pairings and the negative pairings, the fine-tuning the large language model includes fine-tuning the large language model such that the positive pairings are given similar embeddings with at most a first embedding distance while the negative pairings are given different embeddings with at least a second embedding distance greater than the first embedding distance;

storing the large language model;

generating, using the large language model, a response that identifies a cyber attack; and

performing a security risk mitigation action based on the response.

13 . The method of claim 12 , further comprising:

detecting that a second plurality of template identifiers should be used to update the positive pairings and the negative pairings;

updating, using the second plurality of template identifiers, the positive pairings and the negative pairings; and

fine-tuning the large language model using the updated positive pairings and the updated negative pairings.

14 . The method of claim 12 , wherein:

the first embedding distance corresponds with a cosine similarity distance;

the large language model is stored using a data storage device; and

the security risk mitigation action comprises blocking IP traffic from sources identified in the response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: BULUT, MUHAMMED FATIH; SHAH, ADITI KAMLESH
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 064161/0567 →
Continuity (1)
Related Publication 20240427879A1 · Dec 26, 2024
References Cited (23)
US 11444978B1 · Liao · 2022 [cited by applicant]
US 12267345B1 · Erlingsson · 2025 [cited by examiner]
US 20180248902A1 · Dãnilã-dumitrescu et al. · 2018 [cited by applicant]
US 20220279014A1 · Stokes, III · 2022 [cited by examiner]
US 20220318255A1 · Fei · 2022 [cited by applicant]
US 20230076127A1 · Yu · 2023 [cited by applicant]
US 20240330446A1 · Bulut · 2024 [cited by applicant]
US 20240404243A1 · Zhao · 2024 [cited by examiner]
US 20240406166A1 · Bell · 2024 [cited by examiner]
US 20240414048A1 · Kasap · 2024 [cited by examiner]
US 20240414211A1 · Boyer · 2024 [cited by examiner]
US 20250111238A1 · Islam · 2025 [cited by applicant]
Constantin Adam, Attack Techniques and Threat identification for Vulnerabilities, Jun. 22, 2022 (Year: 2022). [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/034647, Dec. 13, 2024, 21 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/019616, Jul. 11, 2024, 15 pages. [cited by applicant]
“Large language model”, Retrieved from the URL: https://en.wikipedia.org/w/index.php?title=Largelanguage_model&oldid=1161462207, Jun. 22, 2023, 18 Pages. [cited by applicant]
“Parsing”, Retrieved from the URL: https://en.wikipedia.org/w/index.php?title=Parsing&oldid=1153935128, May 9, 2023, 12 Pages. [cited by applicant]
Invitation to pay additional fees received for PCT Application No. PCT/US2024/034647, Oct. 22, 2024, 10 pages. [cited by applicant]
Tunstall, et al., “Natural Language Processing with Transformers, Revised Edition”, Published in O'Reilly Media Incorporation, May 2022. [cited by applicant]
Vaswani, et al., “Attention Is All You Need”, In Proceedings of 31st Conference on Neural Information Processing Systems, Dec. 4, 2017, 11 Pages. [cited by applicant]
Notice of Allowance mailed on Jun. 9, 2025, in U.S. Appl. No. 18/335,064 10 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/019616, Oct. 9, 2025, 10 pages. [cited by applicant]
Notice of Allowance mailed on Sep. 22, 2025, in U.S. Appl. No. 18/335,064 07 pages. [cited by applicant]