Autonomous cybersecurity operations center utilizing micro-model architecture
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
1 . A method for improving security operations center (SOC) response to cybersecurity events, comprising:
extracting data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;
receiving a plurality of data guidelines respective of the cloud computing environment;
configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;
receiving a ticket record, the ticket record generated based on an event in the cloud computing environment;
classifying the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;
processing the entire ticket record utilizing the first micro-model and the second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;
generating a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and
initiating the mitigation action, responsive to the event, in the cloud computing environment.
2 . The method of claim 1 , further comprising:
utilizing a portion of the plurality of micro-models to generate a context based on data extracted from the ticket record;
classifying the ticket record based on the generated context; and
generating the mitigation action based on the classification.
3 . The method of claim 2 , further comprising:
determining a causal event based on the classification.
4 . The method of claim 3 , further comprising:
generating the mitigation action further based on the determined causal event.
5 . The method of claim 1 , further comprising:
accessing a knowledgebase of the cloud computing environment;
accessing an issue tracking system of the cloud computing environment; and
extracting the data from the knowledgebase and from the issue tracking system, wherein the knowledgebase and the issue tracking system are data sources of the plurality of data sources.
6 . The method of claim 1 , further comprising:
receiving a plurality of exceptions respective of the cloud computing environment; and
configuring the micro-models further based on the received plurality of exceptions.
7 . The method of claim 1 , further comprising:
receiving feedback from a computing system in response to initiating the mitigation action;
generating a secondary mitigation action based on the received feedback; and
initiating the secondary mitigation action.
8 . The method of claim 7 , further comprising:
configuring a micro-model of the plurality of micro-models to generate the secondary mitigation action.
9 . The method of claim 1 , wherein a micro-model of the plurality of micro-models is any one of: a language model, a large language model, a small language model, a statistical model, a Markov model, a rule engine, a generative artificial intelligence, and any combination thereof.
10 . The method of claim 1 , further comprising:
generating a context for a language model based on the extracted data;
generating a prompt for a language model based on the received ticket record and the generated context; and
processing the prompt by the language model to generate the mitigation action.
11 . The method of claim 1 , further comprising:
generating a request for additional data from a data source of the plurality of data sources, based on a result of classifying the ticket record.
12 . The method of claim 1 , wherein the event is a single event.
13 . A non-transitory computer-readable medium storing a set of instructions for improving security operations center (SOC) response to cybersecurity events, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a device, cause the device to:
extract data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;
receive a plurality of data guidelines respective of the cloud computing environment;
configure a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;
receive a ticket record, the ticket record generated based on an event in the cloud computing environment;
classify the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;
process the entire ticket record utilizing the first micro-model and a second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;
generate a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and
initiate the mitigation action, responsive to the event, in the cloud computing environment.
14 . A system for improving security operations center (SOC) response to cybersecurity events comprising:
one or more processors configured to:
extract data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;
receive a plurality of data guidelines respective of the cloud computing environment;
configure a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;
receive a ticket record, the ticket record generated based on an event in the computing environment;
classify the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;
process the entire ticket record utilizing the first micro-model and a second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;
generate a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and
initiate the mitigation action, responsive to the event, in the cloud computing environment.
15 . The system of claim 14 , wherein the one or more processors are further configured to:
utilize a portion of the plurality of micro-models to generate a context based on data extracted from the ticket record;
classify the ticket record based on the generated context; and
generate the mitigation action based on the classification.
16 . The system of claim 15 , wherein the one or more processors are further configured to:
determine a causal event based on the classification.
17 . The system of claim 16 , wherein the one or more processors are further configured to:
generate the mitigation action further based on the determined causal event.
18 . The system of claim 14 , wherein the one or more processors are further configured to:
access a knowledgebase of the cloud computing environment;
access an issue tracking system of the cloud computing environment; and
extract the data from the knowledgebase and from the issue tracking system, wherein the knowledgebase and the issue tracking system are data sources of the plurality of data sources.
19 . The system of claim 14 , wherein the one or more processors are further configured to:
receive a plurality of exceptions respective of the cloud computing environment; and
configure the micro-models further based on the received plurality of exceptions.
20 . The system of claim 14 , wherein the one or more processors are further configured to:
receive feedback from a computing system in response to initiating the mitigation action;
generate a secondary mitigation action based on the received feedback; and
initiate the secondary mitigation action.
21 . The system of claim 20 , wherein the one or more processors are further configured to:
configure a micro-model of the plurality of micro-models to generate the secondary mitigation action.
22 . The system of claim 14 , wherein a micro-model of the plurality of micro-models is any one of:
a language model, a large language model, a small language model, a statistical model, a Markov model, a rule engine, a generative artificial intelligence, and any combination thereof.
23 . The system of claim 14 , wherein the one or more processors are further configured to:
generate a context for a language model based on the extracted data;
generate a prompt for a language model based on the received ticket record and the generated context; and
process the prompt by the language model to generate the mitigation action.
24 . The system of claim 14 , wherein the one or more processors are further configured to:
generate a request for additional data from a data source of the plurality of data sources, based on a result of classifying the ticket record.
25 . The system of claim 14 , wherein the event is a single event.