IP Library › Granted Patent US 12,744,792
Granted Patent B1
US 12,744,792 · App. 18/409,894 · Granted Sep 22, 2026

Training machine learning models for responding to security threats

Inventor: Opal Mitchell (Pawtucket, RI)
Assignee: Rapid7, Inc.
H04L63/1416G06N20/00H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,792
App. No.
18/409,894
Granted
Sep 22, 2026
Kind
B1
Abstract

A security threat detection and response (STDR) system is disclosed capable of recommending actions for handling security events detected in a computer network. In embodiments, user actions taken via the graphical user interface of the system are recorded. The records are used as training data to train a machine learning model to recommend actions for different types of security events to subsequent users. The training may be performed online, so that the model continues to learn while it is used to make recommendations. In embodiments, the model may infer a priority of a recommended action based on observation data such as how quickly an action is taken, the order in which actions are taken, and the popularity of the action for the particular security event. In embodiments, the model may be configured to recommend actions that are new to the system or actions for new types of security events.

Claims (60)

1 . A system, comprising:

one or more computer devices that implement a security threat detection and response (STDR) system, configured to:

present, via a graphical user interface (GUI) of the STDR system, a security event detected in a computer network indicating a potential security threat;

record a sequence of actions taken via the GUI in response to the security event;

generate a feature vector that represents the security event;

generate a training record for a machine learning (ML) model based on the feature vector of the security event and the sequence of actions;

train the ML model based on the training record and using one or more ML techniques, so that the ML model is trained to output recommended actions for different types of security events; and

execute the ML model to recommend, via the GUI, the sequence of actions for a later instance of the security event.

2 . The system of claim 1 , wherein:

the STDR system is configured to monitor a plurality of client networks for security threats, including the computer network; and

the GUI is implemented at a security operations center (SOC) remote from the client networks.

3 . The system of claim 1 , wherein the STDR system is configured to:

perform online training of the ML model based on user input received via the GUI while the ML model provides recommended actions for security events.

4 . The system of claim 3 , wherein the online training changes a recommendation behavior of the ML model to cause the ML model to:

recommend a new action for a type of security event; and

change a priority of a particular action for a type of security event.

5 . The system of claim 1 , wherein the STDR system is configured to:

provide, in the GUI, one or more user control elements to start and stop recording of the action sequence.

6 . The system of claim 1 , wherein the STDR system is configured to:

enable and disable training of the ML model based on configured parameters, including one or more of:

(a) a performance criterion of the ML model,

(b) a list of users whose actions can be used to train the ML model, and

(c) a list of security events for which the ML model can be trained.

7 . The system of claim 1 , wherein the STDR system is configured to:

receive user input specifying a particular action or action sequence to recommend for a particular type of security event.

8 . The system of claim 1 , wherein:

the GUI is implemented as a web-based interface presented in a web browser; and

the sequence of actions includes interactive actions to be taken via the web-based interface.

9 . The system of claim 8 , wherein the sequence of actions includes one or more of:

(a) a web request in a Hypertext Transport Protocol (HTTP) to read or update one or more web resources,

(b) an interaction with a user control element or an area of the web-based interface,

(c) a navigation to new webpage in the web-based interface, and

(d) a change of a Document Object Model (DOM) data in a webpage in the web-based interface.

10 . The system of claim 1 , wherein the machine learned model includes a self-organizing map (SOM).

11 . A method, comprising:

performing, by a security threat detection and response (STDR) system implemented by one or more computer devices:

presenting, via a graphical user interface (GUI) of the STDR system, a security event detected in a computer network indicating a potential security threat;

recording a sequence of actions taken via the GUI in response to the security event;

generating a feature vector that represents the security event;

generating a training record for a machine learning (ML) model based on the feature vector of the security event and the sequence of actions;

training the ML model based on the training record and using one or more ML techniques, so that the ML model is trained to output recommended actions for different types of security events; and

executing the ML model to recommend, via the GUI, the sequence of actions for a later instance of the security event.

12 . The method of claim 11 , further comprising the STDR system:

recording a user annotation that indicates a description of the sequence of action or individual actions in the sequence; and

presenting the user annotation along with the recommendation of the sequence of actions via the GUI.

13 . The method of claim 11 , further comprising the STDR system:

performing online training of the ML model based on training data recorded via the GUI while the ML model provides recommended actions for security events.

14 . The method of claim 13 , wherein the training data includes a new action performed for the security event that is not generated from recorded user actions observed via the GUI.

15 . The method of claim 13 , wherein the training data includes user feedback regarding the recommended sequence of actions.

16 . The method of claim 13 , wherein the training data includes timing data associated with execution of the recommended sequence of actions.

17 . The method of claim 11 , further comprising the STDR system:

storing the ML model in a library of models, wherein different models in the library are assigned to different computer networks, different users or user groups of the STDR system, or different categories of security events.

18 . The method of claim 11 , further comprising the STDR system:

storing the sequence of actions as an action script in a library, wherein individual action scripts in the library are referenced in output of the ML model.

19 . The method of claim 18 , further comprising the STDR system:

storing a definition of a custom action in the library, wherein the custom action is composed of a plurality of primitive actions executable via the GUI.

20 . The method of claim 19 , wherein the custom action includes:

looking up a hostname or network address of a machine in the computer network;

executing a query against data about the machine using the hostname or network address; and

presenting results of the query via the GUI.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2024
From: MITCHELL, OPAL
To: RAPID7, INC.
Reel/Frame 068435/0709 →
References Cited (12)
US 10419450B2 · Muddu · 2019 [cited by examiner]
US 11544374B2 · Mitelman · 2023 [cited by applicant]
US 11562088B2 · Levy · 2023 [cited by examiner]
US 11606379B1 · Pratt · 2023 [cited by examiner]
US 11637858B2 · Wojnowicz · 2023 [cited by examiner]
US 20120240185A1 · Kapoor · 2012 [cited by examiner]
US 20180367561A1 · Givental et al. · 2018 [cited by applicant]
US 20200202184A1 · Shrestha · 2020 [cited by examiner]
US 20210273961A1 · Humphrey et al. · 2021 [cited by applicant]
US 20220253526A1 · Sanders · 2022 [cited by examiner]
US 20220407889A1 · Narigapalli · 2022 [cited by examiner]
US 20230105087A1 · Borges · 2023 [cited by examiner]