Cybersecurity tools for managing anomalous security data items
This disclosure provides a filtering mechanism to manage anomalous security data items. An anomalous security data item is provided to an analysis engine (such as a Large Language Model (LLM) or another form of generative language model) for interpretation. By curating a selection of one or more relevant non-anomalous security data items to provide with the anomalous data item, the filtering mechanism enables the analysis engine to perform with increased accuracy, without requiring the analyst engine to process large numbers of data items to ascertain their relevance to the anomalous security data item.
1 . A computer system comprising:
at least one processor; and
at least one memory configured to store programming instructions for execution by the at least one processor, the programming instructions, upon execution by the at least one processor, causing the computer system to perform the following operations:
receiving an anomalous data item corresponding to an anomalous event;
identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;
generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;
providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;
receiving the output from the ML model in response to the input prompt; and
causing a security action to be performed based on the output.
2 . The computer system of claim 1 , wherein the security analysis, for which the ML model is trained, includes at least a security operations center (SOC) operation.
3 . The computer system of claim 1 , wherein the ML model is trained to summarize anomalous behavior.
4 . The computer system of claim 1 , wherein the ML model is trained to suggest remediation action(s) in response to anomalous behavior.
5 . The computer system of claim 1 , wherein the security action includes generating, at a user interface, an alert pertaining to an entity associated with the anomalous data item.
6 . The computer system of claim 1 , wherein the security action includes revoking or restricting an access privilege of an entity associated with the anomalous data item.
7 . The computer system of claim 1 , wherein the security action includes quarantining an entity associated with the anomalous data item or isolating the entity from a network or system.
8 . The computer system of claim 1 , wherein the anomalous data item and the contextual data item are both associated with a common entity.
9 . The computer system of claim 8 , wherein the common entity is a common user account or device.
10 . The computer system of claim 8 , wherein the common entity is a common application, process, service, or file.
11 . The computer system of claim 1 , wherein the property of the anomalous data item is a feature value.
12 . The computer system of claim 11 , wherein the property of the anomalous data item is a numerical feature value.
13 . The computer system of claim 11 , wherein the property of the anomalous data item is a categorical feature value.
14 . The computer system of claim 11 , wherein the property of the anomalous data item is a Boolean feature value.
15 . The computer system of claim 1 , wherein a non-anomalous feature of the contextual data item corresponds in type to an anomalous feature of the anomalous data item.
16 . The computer system of claim 15 , wherein the anomalous feature of the anomalous data item is a geolocational activity.
17 . The computer system of claim 16 , wherein the anomalous feature of the anomalous data item is an anomalous country, and wherein the non-anomalous feature of the contextual data item is a non-anomalous country that is different than the anomalous country.
18 . The computer system of claim 15 , wherein the anomalous feature of the anomalous data item is a device usage pattern or action history of a user.
19 . A method comprising:
receiving an anomalous data item corresponding to an anomalous event;
identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;
generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;
providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;
receiving the output from the ML model in response to the input prompt; and
causing a security action to be performed based on the output.
20 . A computer-readable storage medium storing programming instructions that, upon execution by a processor of a system, cause the system to perform the following operations:
receiving an anomalous data item corresponding to an anomalous event;
identifying at least a contextual data item by filtering contextual data in a database based on a property of the anomalous data item, wherein the contextual data item is non-anomalous;
generating an input prompt that includes the anomalous data item, an indication that the anomalous data item is anomalous, the contextual data item, and an indication that the contextual data item is non-anomalous;
providing the input prompt to a machine learning (ML) model trained to perform security analysis, the input prompt prompting the ML model to generate an output;
receiving the output from the ML model in response to the input prompt; and
causing a security action to be performed based on the output.