IP Library › Granted Patent US 12,634,190
Granted Patent B1
US 12,634,190 · App. 18/952,274 · Granted May 19, 2026

Autonomous cybersecurity operations center utilizing micro-model architecture

Inventors: Tom Findling (Dallas, TX); Alon Yotvat (Dallas, TX); Mark Kurman (Binyamina, IL)
Assignee: Conifers Technologies, Inc.
H04L41/06G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,190
App. No.
18/952,274
Filed
Nov 19, 2024
Granted
May 19, 2026
Kind
B1
Art Unit
2454
USPC
709/223
Abstract

A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.

Claims (88)

1 . A method for improving security operations center (SOC) response to cybersecurity events, comprising:

extracting data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;

receiving a plurality of data guidelines respective of the cloud computing environment;

configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;

receiving a ticket record, the ticket record generated based on an event in the cloud computing environment;

classifying the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;

processing the entire ticket record utilizing the first micro-model and the second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;

generating a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and

initiating the mitigation action, responsive to the event, in the cloud computing environment.

2 . The method of claim 1 , further comprising:

utilizing a portion of the plurality of micro-models to generate a context based on data extracted from the ticket record;

classifying the ticket record based on the generated context; and

generating the mitigation action based on the classification.

3 . The method of claim 2 , further comprising:

determining a causal event based on the classification.

4 . The method of claim 3 , further comprising:

generating the mitigation action further based on the determined causal event.

5 . The method of claim 1 , further comprising:

accessing a knowledgebase of the cloud computing environment;

accessing an issue tracking system of the cloud computing environment; and

extracting the data from the knowledgebase and from the issue tracking system, wherein the knowledgebase and the issue tracking system are data sources of the plurality of data sources.

6 . The method of claim 1 , further comprising:

receiving a plurality of exceptions respective of the cloud computing environment; and

configuring the micro-models further based on the received plurality of exceptions.

7 . The method of claim 1 , further comprising:

receiving feedback from a computing system in response to initiating the mitigation action;

generating a secondary mitigation action based on the received feedback; and

initiating the secondary mitigation action.

8 . The method of claim 7 , further comprising:

configuring a micro-model of the plurality of micro-models to generate the secondary mitigation action.

9 . The method of claim 1 , wherein a micro-model of the plurality of micro-models is any one of: a language model, a large language model, a small language model, a statistical model, a Markov model, a rule engine, a generative artificial intelligence, and any combination thereof.

10 . The method of claim 1 , further comprising:

generating a context for a language model based on the extracted data;

generating a prompt for a language model based on the received ticket record and the generated context; and

processing the prompt by the language model to generate the mitigation action.

11 . The method of claim 1 , further comprising:

generating a request for additional data from a data source of the plurality of data sources, based on a result of classifying the ticket record.

12 . The method of claim 1 , wherein the event is a single event.

13 . A non-transitory computer-readable medium storing a set of instructions for improving security operations center (SOC) response to cybersecurity events, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

extract data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;

receive a plurality of data guidelines respective of the cloud computing environment;

configure a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;

receive a ticket record, the ticket record generated based on an event in the cloud computing environment;

classify the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;

process the entire ticket record utilizing the first micro-model and a second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;

generate a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and

initiate the mitigation action, responsive to the event, in the cloud computing environment.

14 . A system for improving security operations center (SOC) response to cybersecurity events comprising:

one or more processors configured to:

extract data from a plurality of data sources of a cloud computing environment, the plurality of data sources including a structured data source and an unstructured data source;

receive a plurality of data guidelines respective of the cloud computing environment;

configure a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines;

receive a ticket record, the ticket record generated based on an event in the computing environment;

classify the ticket record into a predetermined use case, the use case associated with a first micro-model of the plurality of micro-models and a second micro-model of the plurality of micro-models;

process the entire ticket record utilizing the first micro-model and a second micro-model, wherein the first micro-model is a generative artificial intelligence (AI) model of a first type, and the second micro-model is a generative AI model of a second type;

generate a mitigation action utilizing a portion of the plurality of micro-models based on the processed ticket record; and

initiate the mitigation action, responsive to the event, in the cloud computing environment.

15 . The system of claim 14 , wherein the one or more processors are further configured to:

utilize a portion of the plurality of micro-models to generate a context based on data extracted from the ticket record;

classify the ticket record based on the generated context; and

generate the mitigation action based on the classification.

16 . The system of claim 15 , wherein the one or more processors are further configured to:

determine a causal event based on the classification.

17 . The system of claim 16 , wherein the one or more processors are further configured to:

generate the mitigation action further based on the determined causal event.

18 . The system of claim 14 , wherein the one or more processors are further configured to:

access a knowledgebase of the cloud computing environment;

access an issue tracking system of the cloud computing environment; and

extract the data from the knowledgebase and from the issue tracking system, wherein the knowledgebase and the issue tracking system are data sources of the plurality of data sources.

19 . The system of claim 14 , wherein the one or more processors are further configured to:

receive a plurality of exceptions respective of the cloud computing environment; and

configure the micro-models further based on the received plurality of exceptions.

20 . The system of claim 14 , wherein the one or more processors are further configured to:

receive feedback from a computing system in response to initiating the mitigation action;

generate a secondary mitigation action based on the received feedback; and

initiate the secondary mitigation action.

21 . The system of claim 20 , wherein the one or more processors are further configured to:

configure a micro-model of the plurality of micro-models to generate the secondary mitigation action.

22 . The system of claim 14 , wherein a micro-model of the plurality of micro-models is any one of:

a language model, a large language model, a small language model, a statistical model, a Markov model, a rule engine, a generative artificial intelligence, and any combination thereof.

23 . The system of claim 14 , wherein the one or more processors are further configured to:

generate a context for a language model based on the extracted data;

generate a prompt for a language model based on the received ticket record and the generated context; and

process the prompt by the language model to generate the mitigation action.

24 . The system of claim 14 , wherein the one or more processors are further configured to:

generate a request for additional data from a data source of the plurality of data sources, based on a result of classifying the ticket record.

25 . The system of claim 14 , wherein the event is a single event.

References Cited (18)
US 10270644B1 · Valsecchi · 2019 [cited by examiner]
US 10681061B2 · Jang et al. · 2020 [cited by applicant]
US 10685293B1 · Heimann et al. · 2020 [cited by applicant]
US 10938678B2 · Ghosh · 2021 [cited by examiner]
US 11729204B1 · Coull et al. · 2023 [cited by applicant]
US 11909757B2 · Kibler et al. · 2024 [cited by applicant]
US 12309185B1 · Skarphedinsson · 2025 [cited by examiner]
US 20080189788A1 · Bahl · 2008 [cited by examiner]
US 20200201989A1 · Shu · 2020 [cited by examiner]
US 20210012239A1 · Arzani · 2021 [cited by examiner]
US 20230291755A1 · Siebel et al. · 2023 [cited by applicant]
US 20240242154A1 · Jindal · 2024 [cited by examiner]
US 20240430289A1 · Engelberg · 2024 [cited by examiner]
Arici, Nicola, et al. “LLM-based Approaches for Automatic Ticket Assignment: A Real-world Italian Application.” NL4AI@ AI* IA. (Year: 2023). [cited by examiner]
McCoy, R. Thomas, et al. “How much do language models copy from their training data? evaluating linguistic novelty in text generation using raven.” Transactions of the Association for Computational Linguistics 11: 652-6… [cited by examiner]
Maatouk, Ali, et al. “Large language models for telecom: Forthcoming impact on the industry.” IEEE Communications Magazine. Jul. (Year: 2024). [cited by examiner]
Remil, Youcef, et al. “Aiops solutions for incident management: Technical guidelines and a comprehensive literature review.” arXiv preprint arXiv:2404.01363. Apr. (Year: 2024). [cited by examiner]
Forbes, Bernard Marr, “The Vital Difference Between Machine Learning and Generative AI,” Jun. 25, 2024, retrieved from the Internet on Dec. 12, 2025. [cited by applicant]