IP Library Granted Patent US 12,744,793
Granted Patent B2
US 12,744,793 · App. 18/737,542 · Granted Sep 22, 2026

Cybersecurity components communicating and cooperating with one or more large language models

Inventors: John Boyer (Cambridge, GB); Justas Zaborovskis (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1416G06F40/58H04L63/1425H04L63/1441H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,793
App. No.
18/737,542
Granted
Sep 22, 2026
Kind
B2
Abstract

Cybersecurity components configured to cooperate with LLMs including i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat, ii) a proactive threat notification service, iii) a cyber threat autonomous response engine, iv) a cyberattack simulator, v) a cyber-attack restoration engine, and vi) an artificial intelligence-based cyber threat analyst module. The LLMs are configured to communicate and cooperate with the one or more cybersecurity components via one or more Application Program Interfaces (APIs) to receive cyber security information being produced by the one or more of the cybersecurity components and then to apply language generation functionality in order to assist a human in an understanding of the cyber security information being produced by the cybersecurity components, and then also to provide recommendations to prioritize breaches over other breaches in a native human friendly format for the human.

Claims (67)

1 . A cybersecurity system, comprising:

one or more cybersecurity components including

i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination thereof,

ii) a proactive threat notification service to publicize new and ongoing cyber threats,

iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat,

iv) a cyberattack simulator to simulate a cyberattack,

v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and

vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more anomalies linked to each other over a time frame of examination spanning two or more days;

one or more large language models (LLMs) implemented with 1) electronic circuit, 2) as software stored in one or more non-transitory computer storage mediums and executed by one or more processors, or 3) any combination thereof, and configured to communicate and cooperate with the one or more cybersecurity components via one or more Application Program Interfaces (APIs) to receive cyber security information being produced by the one or more of the cybersecurity components and then to apply language generation functionality in order to assist a human in an understanding of the cyber security information being produced by the cybersecurity components, and then also to provide recommendations to prioritize breaches over other breaches in a native human friendly format for the human;

where instructions implemented in software for the cybersecurity components and the large language models are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units, and

where the one or more LLMs are trained to do tasks on behalf of a user and provide human readable summaries, including

i) summarization and prioritization of breaches,

ii) launching an investigation using the one or more APIs to find out information, and then

iii) utilizing language capabilities of the LLMs to rephrase existing textual material to make the information more readily understandable to a larger audience of human end users.

2 . The cybersecurity system of claim 1 , comprising:

where a first LLM has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests and translate at least one of i) a user question and ii) a question by the LLM itself into API queries into the one or more cyber security components of the cyber security system to explain a decision process of a machine learning from within that cyber security component as well as explain a cyber security incident in the native human friendly format for that human.

3 . The cybersecurity system of claim 1 , comprising:

where a first LLM has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests to help explain both i) a decision-making process of one or more of the cyber security components as well as ii) cyber security jargon and concepts to enhance transparency and trust.

4 . The cybersecurity system of claim 1 , comprising:

where a first LLM has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests, where the training also included training on capabilities of each of the one or more of the cybersecurity components including what type of information can be found by communicating with each particular cybersecurity component as well as how to get that information through an API request.

5 . The cybersecurity system of claim 1 , comprising:

where a first LLM has been trained to take in a specification description of one or more of the APIs and turn the specification of one or more of the APIs into a set of endpoints and their associated parameters and available information that a trained deep learning model in the LLM will then use to call the cybersecurity components.

6 . The cybersecurity system of claim 1 , comprising:

where a first LLM has been trained to perform an automatic translation of the cyber security information in a first human language into a second human language of content within a user interface to be displayed on a display screen.

7 . The cybersecurity system of claim 1 , comprising:

where a first LLM has a query interface, where the first LLM of the one or more LLMs with its training on the cyber security information combined with its training to go through the APIs to obtain additional knowledge from the cyber security components creates a large cyber security knowledge base that allows the first LLM of the one or more LLMs to act as a search engine, in response to a user's query to the query interface, to obtain and provide detailed understandings of the cyber security information.

8 . The cybersecurity system of claim 1 , comprising:

where a first LLM has a user interface, where an end user is able to select at least one of a term and a phrase, displayed on the user interface, as a query input to the first LLM of the one or more LLMs in order to cause the first LLM of the one or more LLMs to explain and provide additional details on the selected term and/or phrase.

9 . The cybersecurity system of claim 1 , comprising:

where one or more of the cybersecurity components, which are configured to provide a list of all of the breaches and their severity scores as well as cyber threats trending currently in response to a first API request, to a first LLM of the one or more LLMs, and then the first LLM of the one or more LLMs is trained to provide the recommendations to prioritize the breaches over other breaches i) on a display and/or ii) in a printed report to the human.

10 . A method to protect against cyber threats, comprising:

providing one or more cybersecurity components including

i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination thereof,

ii) a proactive threat notification service to publicize new and ongoing cyber threats,

iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat,

iv) a cyberattack simulator to simulate a cyberattack,

v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and

vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more anomalies linked to each other over a time frame of examination spanning two or more days;

providing one or more large language models (LLMs) to communicate and cooperate with the one or more cybersecurity components via one or more Application Program Interfaces (APIs) to receive cyber security information being produced by the one or more of the cybersecurity components and then to apply language generation functionality in order to assist a human in an understanding of the cyber security information being produced by the cybersecurity components, and then also to provide recommendations to prioritize breaches over other breaches in a native human friendly format for the human; and

providing the one or more LLMs that are trained to do tasks on behalf of a user and provide human readable summaries, including

i) summarization and prioritization of breaches,

ii) launching an investigation using the one or more APIs to find out information, and then

iii) utilizing language capabilities of the LLMs to rephrase existing textual material to make the information more readily understandable to a larger audience of human end users.

11 . The method of claim 10 , comprising:

providing a first LLM that has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests and translate at least one of i) a user question and ii) a question by the LLM itself into API queries into the one or more cyber security components of the cyber security system to explain a decision process of a machine learning from within that cyber security component as well as explain a cyber security incident in the native human friendly format for that human.

12 . The method of claim 10 , comprising:

providing a first LLM that has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests to help explain both i) a decision-making process of one or more of the cyber security components as well as ii) cyber security jargon and concepts to enhance transparency and trust.

13 . The method of claim 10 , comprising:

providing a first LLM that has been trained on an API specification for one or more of the cyber security components so that the first LLM of the one or more LLMs can understand how to make API requests, where the training also included training on capabilities of each of the one or more of the cybersecurity components including what type of information can be found by communicating with each particular cybersecurity component as well as how to get that information through an API request.

14 . The method of claim 10 , comprising:

providing a first LLM that has been trained to take in a specification description of one or more of the APIs and turn the specification of one or more of the APIs into a set of endpoints and their associated parameters and available information that a trained deep learning model in the LLM will then use to call the cybersecurity components.

15 . The method of claim 10 , comprising:

providing a first LLM that has a query interface, where the first LLM of the one or more LLMs with its training on the cyber security information combined with its training to go through the APIs to obtain additional knowledge from the cyber security components creates a large cyber security knowledge base that allows the first LLM of the one or more LLMs to act as a search engine, in response to a user's query to the query interface, to obtain and provide detailed understandings of the cyber security information.

16 . The method of claim 10 , comprising:

providing a first LLM that has a user interface, where an end user is able to select at least one of a term and a phrase, displayed on the user interface, as a query input to the first LLM of the one or more LLMs in order to cause the first LLM of the one or more LLMs to explain and provide additional details on the selected term and/or phrase.

17 . The method of claim 10 , comprising:

providing one or more of the cybersecurity components, which are configured to provide a list of all of the breaches and their severity scores as well as cyber threats trending currently in response to a first API request, to a first LLM, and then the first LLM of the one or more LLMs is trained to provide the recommendations to prioritize the breaches over other breaches i) on a display and/or ii) in a printed report to the human.

18 . A non-transitory storage medium including software that, upon execution by a processor, is configured to perform operations, comprising:

using one or more large language models (LLMs) to communicate and cooperate with one or more cybersecurity components via one or more Application Program Interfaces (APIs) to receive cyber security information being produced by the one or more of the cybersecurity components and then to apply language generation functionality in order to assist a human in an understanding of the cyber security information being produced by the cybersecurity components, and then also to provide recommendations to prioritize breaches over other breaches in a native human friendly format for the human, and

where the one or more cybersecurity components configured to cooperate with the LLMs include

i) a cyber security appliance with a cyber threat detect engine to detect a cyber threat in one or more of an email system, an Information Technology network, a cloud network, and any combination thereof,

ii) a proactive threat notification service to publicize new and ongoing cyber threats,

iii) a cyber threat autonomous response engine to take one or more actions to mitigate a detected cyber threat,

iv) a cyberattack simulator to simulate a cyberattack,

v) a cyber-attack restoration engine to restore network components back to an operational state prior to the cyberattack, and

vi) an artificial intelligence-based cyber threat analyst module to investigate a chain of two or more anomalies linked to each other over a time frame of examination spanning two or more days; and

wherein the one or more LLMs are trained to do tasks on behalf of a user and provide human readable summaries, including i) summarization and prioritization of breaches, ii) launching an investigation using the one or more APIs to find out information, and then iii) utilizing language capabilities of the LLMs to rephrase existing textual material to make the information more readily understandable to a larger audience of human end users.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2026
From: BOYER, JOHN; ZABOROVSKIS, JUSTAS
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 075597/0743 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (2)
Provisional Application 63472227 · Jun 9, 2023
Related Publication 20240414211A1 · Dec 12, 2024
References Cited (6)
US 20200177612A1 · Kras · 2020 [cited by examiner]
US 20210273961A1 · Humphrey · 2021 [cited by examiner]
US 20220038489A1 · Thakur · 2022 [cited by examiner]
US 20230315856A1 · Lee · 2023 [cited by examiner]
US 20240281668A1 · Lev · 2024 [cited by examiner]
US 20240403792A1 · Goutal · 2024 [cited by examiner]