IP Library › Granted Patent US 12,596,811
Granted Patent B2
US 12,596,811 · App. 18/642,552 · Granted Apr 7, 2026

Threat intelligence systems

Inventors: Lior Chen (Tel Mond, IL); Amir Belgi (Ra'Anana, IL); Ron Sneh (Atlit, IL); John Eugene Neystadt (Kfar-Saba, IL)
Assignee: Varonis Systems Inc.
G06F21/577G06F40/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,811
App. No.
18/642,552
Granted
Apr 7, 2026
Kind
B2
Abstract

A threat intelligence system utilising language models to generate queries for external threat intelligence systems, receive and filter responses, and generate alerts and reports using further language models.

Claims (38)

1 . A computer-implemented threat intelligence assessment system, comprising

a data storage system comprising computer readable storage media storing identifiers based on which relevant threat intelligence information can be identified;

one or more computer readable storage media storing program instructions and one or more processors which, in response to executing the program instructions, are configured to:

generate a semantic representation of a set of rules and a text representation of the set of rules;

generate, based on the semantic and/or text representation of the set of rules, using a fine-tuned LLM, a set of requests for transmission to at least one external threat intelligence provider;

transmit the set of requests to the at least one external threat intelligence provider;

receive, from the at least one external threat intelligence provider, a set of results based on the transmitted queries;

generate and store a semantic representation of the set of results;

compare the semantic representation of the results with the semantic representation of the set of rules, and filter the results to retain the most similar results; and

process the retained results using a second fine-tuned LLM to generate actionable alerts.

2 . A system according to claim 1 , wherein the semantic representations are embedding vectors.

3 . A system according to claim 2 , wherein the embedding vectors are stored in a vector database.

4 . A system according to claim 1 , wherein the comparison of the semantic representation of the results with the semantic representation of the rules is performed as a cosine similarity.

5 . A system according to claim 1 , wherein the set of rules is generated based on user input and organisational data.

6 . A system according to claim 5 , wherein the organisational data includes names and data relating to members of the organisation and/or the organisation.

7 . A system according to claim 5 , wherein the set of rules is also generated based on context data comprising at least one of the organisation's computer system structure, security domain information, and information regarding the threat intelligence providers.

8 . A system according to claim 5 , wherein the rule generation utilises an LLM.

9 . A system according to claim 8 , wherein the LLM utilises retrieval augmented generation, based on the organisational data including names and data relating to members of the organisation and/or the organisation, and/or context data comprising at least one of the organisation's computer system structure, security domain information, and information regarding the threat intelligence providers.

10 . A system according to claim 1 , further comprising training one or more of the LLMs based on user feedback to the actionable alerts.

11 . A system according to claim 1 , wherein the retained results are retained and added to results retained from a further set of results from the at least one external threat intelligence provider.

12 . A computer-implemented method, comprising the steps of

at a data storage system comprising computer readable storage media storing identifiers based on which relevant threat intelligence information can be identified;

at a computer system comprising one or more computer readable storage media and one or more processors: —

generating a semantic representation of a set of rules and a text representation of the set of rules;

generating, based on the semantic and/or text representation of the set of rules, using a fine-tuned LLM, a set of requests for transmission to at least one external threat intelligence provider;

transmitting the set of requests to the at least one external threat intelligence provider;

receiving, from the at least one external threat intelligence provider, a set of results based on the transmitted queries;

generating and storing a semantic representation of the set of results;

comparing the semantic representation of the results with the semantic representation of the set of rules, and filter the results to retain the most similar results; and

processing the retained results using a second fine-tuned LLM to generate actionable alerts.

13 . A method according to claim 12 , wherein the semantic representations are embedding vectors.

14 . A method according to claim 12 , wherein the comparison of the semantic representation of the results with the semantic representation of the rules is performed as a cosine similarity.

15 . A method according to claim 12 , wherein the set of rules is generated based on user input and organisational data.

16 . A method according to claim 15 , wherein the organisational data includes names and data relating to members of the organisation and/or the organisation.

17 . A method according to claim 15 , wherein the set of rules is also generated based on context data comprising at least one of the organisation's computer system structure, security domain information, and information regarding the threat intelligence providers.

18 . A method according to claim 15 , wherein the rule generation utilises an LLM.

19 . A method according to claim 12 , further comprising training one or more of the LLMs based on user feedback to the actionable alerts.

20 . A method according to claim 12 , wherein the retained results are retained and added to results retained from a further set of results from the at least one external threat intelligence provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2024
From: CHEN, LIOR; BELGI, AMIR; SNEH, RON; NEYSTADT, JOHN EUGENE
To: VARONIS SYSTEMS INC.
Reel/Frame 067513/0909 →
Continuity (1)
Related Publication 20250328653A1 · Oct 23, 2025
References Cited (7)
US 10594713B2 · McLean · 2020 [cited by examiner]
US 20220004630A1 · Almukaynizi · 2022 [cited by examiner]
US 20240203404A1 · Shabat · 2024 [cited by examiner]
US 20240333765A1 · McGrew · 2024 [cited by examiner]
US 20250225328A1 · Chowdhury · 2025 [cited by examiner]
US 20250298902A1 · Palanki · 2025 [cited by examiner]
US 20250315533A1 · Glynn · 2025 [cited by examiner]