IP Library Granted Patent US 12,592,949
Granted Patent B2
US 12,592,949 · App. 18/494,850 · Granted Mar 31, 2026

Methods and systems for categorizing cyber incident logs featuring dynamic relationships to pre-existing cyber incident reports in real-time

Inventors: Vivek Datla (McLean, VA); Isha Chaturvedi (Mountain View, CA); Anirban Das (McLean, VA)
Assignee: Capital One Services, LLC
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,949
App. No.
18/494,850
Granted
Mar 31, 2026
Kind
B2
Abstract

Systems and methods for the creation of human-readable cyber incident reports from cyber incident logs, in which the cyber incident reports may link cyber incidents recorded in a cyber incident log to the existing knowledge sources. To do so, the systems and methods overcome the technical problems of conventional systems as well as the technical problems inherent in adapting artificial intelligence solutions to the creation of cyber incident reports.

Claims (70)

1 . A system for categorizing cyber incident logs featuring dynamic relationships to pre-existing cyber incident reports in real-time, the system comprising:

one or more processors; and

one or more non-transitory, computer-readable media comprising instructions that, when executed by the one or more processors, cause operations comprising:

receiving a cyber incident log, wherein the cyber incident log relates to a recorded cyber incident, and wherein the cyber incident log includes a plurality of log sections;

determining a log section of the plurality of log sections that has a log section characteristic, wherein the log section characteristic is indicative of the log section comprising one or more cyber incident characteristics;

parsing the log section for a cyber incident characteristic and mapping data, wherein the mapping data describes a relationship of the log section to the plurality of log sections;

generating a cyber incident log map for the log section based on the mapping data;

generating a feature input based on the cyber incident log map and the cyber incident characteristic;

inputting the feature input into a first model, wherein the first model is trained to determine similarities between one or more of a plurality of historic cyber incident reports and inputted feature inputs;

determining, based on a first output of the first model, a cyber incident report type corresponding to the cyber incident log;

inputting the feature input and the cyber incident report type into a second model, wherein the second model is trained to generate cyber incident reports based on cyber incident report types;

determining, based on a second output of the second model, a cyber incident report; and

adding the cyber incident report to a plurality of cyber incident reports stored at a data source.

2 . A method for categorizing cyber incident logs featuring dynamic relationships to pre-existing cyber incident reports in real-time, the method comprising:

receiving a cyber incident log, wherein the cyber incident log includes a plurality of log sections;

determining a log section of the plurality of log sections that has a log section characteristic, wherein the log section characteristic is indicative of the log section comprising one or more cyber incident characteristics;

parsing the log section for a cyber incident characteristic and mapping data, wherein the mapping data describes a relationship of the log section to the plurality of log sections;

generating a cyber incident log map for the log section based on the mapping data;

generating a feature input based on the cyber incident log map and the cyber incident characteristic;

inputting the feature input into a model to generate an output, wherein the model is trained to determine similarities between one or more of a plurality of cyber incident reports and inputted feature inputs; and

generating for display, in a user interface of a user device of a user, based on the output of the model, a cyber incident report, wherein the cyber incident report corresponds to the cyber incident log.

3 . The method of claim 2 , further comprising:

determining a cyber incident log type for the cyber incident log; and

further generating the feature input based on the cyber incident log type.

4 . The method of claim 2 , wherein the model is trained to determine similarities between one or more of a plurality of cyber incident reports and inputted feature inputs by:

receiving a plurality of report sections; and

using an encoder-decoder model with an ensemble of loss functions to learn relationships between the plurality of report sections and the plurality of log sections.

5 . The method of claim 2 , further comprising:

determining a citation for the cyber incident report; and

linking the cyber incident log to a subset of the plurality of cyber incident reports based on the citation.

6 . The method of claim 2 , wherein generating for display, in the user interface of the user device, based on the output of the model, the cyber incident report of a plurality of cyber incident reports further comprises:

determining, based on the output, that the cyber incident report has a threshold similarity to the feature input; and

linking the cyber incident log to the cyber incident report based on determining that the cyber incident report has the threshold similarity to the feature input.

7 . The method of claim 2 , wherein generating for display, in the user interface of the user device, based on the output of the model, the cyber incident report of a plurality of cyber incident reports further comprises:

determining, using an ensemble of loss functions, a report section corresponding to the log section; and

generating the cyber incident report based on the report section.

8 . The method of claim 2 , further comprising:

retrieving the plurality of cyber incident reports from a data source; and

adding the cyber incident report to the data source.

9 . The method of claim 2 , wherein determining the log section of the plurality of log sections that has the log section characteristic further comprises:

determining a plurality of log section characteristics in the log section; and

comparing each of the plurality of log section characteristics to cyber incident characteristics in a cyber incident profile to determine a correspondence.

10 . The method of claim 2 , wherein the cyber incident characteristic is textual data, and wherein the cyber incident report comprises an alternative cyber incident characteristic that is different textual data.

11 . The method of claim 2 , wherein the cyber incident characteristic is textual data, wherein the cyber incident report comprises an alternative cyber incident characteristic that is image data, and wherein the model is trained to translate the textual data into the image data.

12 . The method of claim 2 , wherein the cyber incident characteristic is an alphanumeric text string and the mapping data, and wherein the mapping data describing a relationship of the log section to the plurality of log sections comprises a cross-reference of an object corresponding to the alphanumeric text string.

13 . The method of claim 2 , wherein the model is further trained to generate an additional output of an additional cyber incident report, and wherein the additional cyber incident report is simultaneously displayed with the cyber incident report.

14 . The method of claim 2 , wherein the model further comprises an autoregressive language model that performs natural language processing using pre-trained language representations.

15 . The method of claim 2 , wherein parsing the log section for the cyber incident characteristic further comprises:

retrieving a list of cyber incident characteristics;

comparing objects in the log section to the list of cyber incident characteristics; and

determining the cyber incident characteristic based on matching an object of the objects to a listed cyber incident characteristic.

16 . One or more non-transitory, computer-readable media comprising instructions that, when executed by one or more processors, cause operations comprising:

receiving a cyber incident log, wherein the cyber incident log includes a plurality of log sections;

determining a log section of the plurality of log sections that has a log section characteristic, wherein the log section characteristic is indicative of the log section comprising one or more cyber incident characteristics;

parsing the log section for a cyber incident characteristic and mapping data, wherein the mapping data describes a relationship of the log section to the plurality of log sections;

generating a cyber incident log map for the log section based on the mapping data;

inputting the cyber incident log map and the cyber incident characteristic into a model to generate an output, wherein the model is trained to determine similarities between one or more of a plurality of cyber incident reports and inputted feature inputs; and

generating, based on the output, a cyber incident report, wherein the cyber incident report corresponds to the cyber incident log.

17 . The one or more non-transitory, computer-readable media of claim 16 , further comprising:

determining a cyber incident log type for the cyber incident log; and

further generating the feature inputs based on the cyber incident log type.

18 . The one or more non-transitory, computer-readable media of claim 16 , wherein the model is trained to determine similarities between one or more of a plurality of cyber incident reports and inputted feature inputs by:

receiving a plurality of report sections; and

using an encoder-decoder model with an ensemble of loss functions to learn relationships between the plurality of report sections and the plurality of log sections.

19 . The one or more non-transitory, computer-readable media of claim 16 , further comprising:

determining a citation for the cyber incident report; and

linking the cyber incident log to a subset of the plurality of cyber incident reports based on the citation.

20 . The one or more non-transitory, computer-readable media of claim 16 , wherein generating, based on the output of the model, the cyber incident report of a plurality of cyber incident reports further comprises:

determining, based on the output, that the cyber incident report has a threshold similarity to the feature inputs; and

linking the cyber incident log to the cyber incident report based on determining that the cyber incident report has the threshold similarity to the feature inputs.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2023
From: DATLA, VIVEK; CHATURVEDI, ISHA; DAS, ANIRBAN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 065352/0563 →
Continuity (1)
Related Publication 20250141895A1 · May 1, 2025
References Cited (3)
US 11606379B1 · Pratt · 2023 [cited by examiner]
US 11627162B2 · Brurok · 2023 [cited by examiner]
US 20230117120A1 · Johnson · 2023 [cited by examiner]