IP Library › Granted Patent US 12,621,312
Granted Patent B2
US 12,621,312 · App. 18/231,815 · Granted May 5, 2026

Incident descriptions for extended detection and response to security anomalies

Inventors: Martin Kopp (Komarov, CZ); Cenek Skarda (Praha Bechovice, CZ)
Assignee: Cisco Technology, Inc.
H04L63/1416H04L41/16H04L63/1425H04L63/20H04L63/1408H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,312
App. No.
18/231,815
Granted
May 5, 2026
Kind
B2
Abstract

Techniques described herein for extended detection and response to security anomalies in computing networks can perform automated analysis of anomalies occurring in different telemetry sources in a computer network, in order to synthesize the anomalies into analyst work units that are surfaced for further analysis by security response teams. Anomalies can initially be processed in order to identify and collect extended anomaly data. The extended anomaly data can then be used to group the anomalies according to a multi-stage grouping process which produces analyst work units. The analyst work units can be processed to produce analyst summaries that assist with analysis and response. Furthermore, the analyst work units can be prioritized for further analysis, and analyst interactions with the prioritized analyst work units can be used to influence subsequent anomaly grouping operations.

Claims (40)

1 . A method comprising:

receiving an analyst work unit, the analyst work unit comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;

identifying, within a data store comprising computing threat information, at least one similar threat that has higher similarity to the analyst work unit than one or more other threats identified in the data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search on the data store; and

generating an analyst summary of the analyst work unit, wherein generating the analyst summary comprises using a neural network-based generator to process the analyst work unit and the at least one similar threat, and wherein using the neural network-based generator comprises providing, to the neural network-based generator:

a natural language command;

one or more first events based on the analyst work unit;

one or more second events based on the at least one similar threat; and

a risk level based on the at least one similar threat.

2 . The method of claim 1 , wherein the data store further comprises threat response playbook information, and wherein generating the analyst summary further comprises generating, based on the threat response playbook information, a next action recommendation associated with the analyst work unit.

3 . The method of claim 1 , wherein at least generating the analyst summary of the analyst work unit is performed by a server coupled to a local area network, and wherein the local area network further comprises the data store comprising computing threat information.

4 . The method of claim 1 , wherein the neural network-based generator is configured to use at least one of natural language processing or a large language model.

5 . The method of claim 1 , wherein the analyst summary of the analyst work unit comprises one or more different sections corresponding to the one or more first events.

6 . A device comprising:

one or more processors;

one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving an analyst work unit, the analyst work unit comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;

identifying, within a data store comprising computing threat information, at least one similar threat that has higher similarity to the analyst work unit than one or more other threats identified in the data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search on the data store; and

generating an analyst summary of the analyst work unit, wherein generating the analyst summary comprises using a neural network-based generator to process the analyst work unit and the at least one similar threat, and wherein using the neural network-based generator comprises providing, to the neural network-based generator:

a natural language command;

one or more first events based on the analyst work unit;

one or more second events based on the at least one similar threat; and

a risk level based on the at least one similar threat.

7 . The device of claim 6 , wherein the data store further comprises threat response playbook information, and wherein generating the analyst summary further comprises generating, based on the threat response playbook information, a next action recommendation associated with the analyst work unit.

8 . The device of claim 6 , wherein at least generating the analyst summary of the analyst work unit is performed by a server coupled to a local area network, and wherein the local area network further comprises the data store comprising computing threat information.

9 . The device of claim 6 , wherein the neural network-based generator is configured to use at least one of natural language processing or a large language model.

10 . The device of claim 6 , wherein the analyst summary of the analyst work unit comprises one or more different sections corresponding to the one or more first events.

11 . A method comprising:

receiving anomaly data associated with a security threat in a network, the anomaly data comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;

identifying, within a threat intelligence data store, at least one similar threat that has higher similarity to the security threat than one or more other threats identified in the threat intelligence data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search for the security threat in the threat intelligence data store; and

generating an analyst summary of the security threat, wherein generating the analyst summary comprises using a large language model-based generator to process the security threat and the at least one similar threat, and wherein using the large language model-based generator comprises providing, to the large language model-based generator:

a natural language command;

first data based on the security threat;

second data based on the at least one similar threat; and

a risk level based on the at least one similar threat.

12 . The method of claim 11 , wherein the analyst summary comprises one or more different sections corresponding to the second data.

13 . The method of claim 11 , wherein generating the analyst summary further comprises generating a next action recommendation associated with the security threat.

14 . The method of claim 11 , wherein the analyst summary comprises a risk level associated with the security threat.

15 . The method of claim 14 , wherein the risk level associated with the security threat is based at least in part of the risk level associated with the at least one similar threat.

16 . The method of claim 1 , wherein the multiple detected anomalies comprise anomalies detected from at least two different telemetry sources.

17 . The method of claim 1 , wherein the multiple detected anomalies comprise anomalies detected by multiple anomaly detection systems.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2023
From: KOPP, MARTIN; SKARDA, CENEK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064531/0007 →
Continuity (2)
Provisional Application 63461374 · Apr 24, 2023
Related Publication 20240356942A1 · Oct 24, 2024
References Cited (32)
US 10873596B1 · Bourget et al. · 2020 [cited by applicant]
US 11290483B1 · Kannan et al. · 2022 [cited by applicant]
US 20150261963A1 · Ukil et al. · 2015 [cited by applicant]
US 20170243009A1 · Sejpal · 2017 [cited by examiner]
US 20190362278A1 · Saraf et al. · 2019 [cited by applicant]
US 20200272741A1 · Bhatia et al. · 2020 [cited by applicant]
US 20220038490A1 · Thakur et al. · 2022 [cited by applicant]
US 20220070209A1 · Lantuh et al. · 2022 [cited by applicant]
US 20220103590A1 · Steimberg et al. · 2022 [cited by applicant]
US 20220210195A1 · Parekh et al. · 2022 [cited by applicant]
US 20220224721A1 · Bertiger et al. · 2022 [cited by applicant]
US 20220294817A1 · Parekh et al. · 2022 [cited by applicant]
US 20220329630A1 · Li · 2022 [cited by applicant]
US 20220337621A1 · Peters et al. · 2022 [cited by applicant]
US 20220345469A1 · Domagalski et al. · 2022 [cited by applicant]
US 20230009127A1 · Boyer · 2023 [cited by applicant]
US 20230018808A1 · Silberman et al. · 2023 [cited by applicant]
US 20230110056A1 · Gullikson et al. · 2023 [cited by applicant]
US 20230113375A1 · Thomas et al. · 2023 [cited by applicant]
US 20230135590A1 · Pearcy et al. · 2023 [cited by applicant]
US 20230146804A1 · Narula et al. · 2023 [cited by applicant]
US 20240137375A1 · Srivatsa et al. · 2024 [cited by applicant]
US 20240303530A1 · Ru et al. · 2024 [cited by applicant]
US 20240356934A1 · Skarda et al. · 2024 [cited by applicant]
US 20240356943A1 · Kopp et al. · 2024 [cited by applicant]
US 20250103713A1 · Oba · 2025 [cited by examiner]
WO WO2023090864A1 · 2023 [cited by applicant]
George, D. A. S., George, A. H., Baskar, T., & Pandey, D. (2021). XDR: The Evolution of Endpoint Security Solutions-Superior Extensibility and Analytics to Satisfy the Organizational Needs of the Future. International J… [cited by applicant]
Svoboda,Michal “Security Detection with XDR” Jun. 13, 2022 Cisco pp. 1-18. [cited by applicant]
Search Report and Written Opinion for International Application No. PCT/US2024/024881, Dated Jul. 1, 2024, 15 pages. [cited by applicant]
Search Report and Written Opinion for International Application No. PCT/US2024/024871, Dated Jul. 16, 2024, 15 pages. [cited by applicant]
Search Report and Written Opinion for International Application No. PCT/US2024/024887, Dated Jul. 3, 2024, 19 pages. [cited by applicant]