ABSTRACT
Abstract
The cyber security training tool has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network. The cyber security training tool can then provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network. The cyber security training tool further has a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component.
Description
RELATED APPLICATION
This application claims priority under 35 USC 119 to U.S. provisional patent application No. 63/470,571, titled âCYBER SECURITY SYSTEMâ filed Jun. 2, 2023, as well as to U.S. provisional patent application No. 63/472,227, titled âCYBER SECURITY SYSTEMâ filed Jun. 9, 2023, which the disclosures of such are incorporated herein by reference in their entirety.
NOTICE OF COPYRIGHT
A portion of this disclosure contains material that is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the material subject to copyright protection as it appears in the United States Patent & Trademark Office's patent file or records, but otherwise reserves all copyright rights whatsoever.
FIELD
Cyber security and in an embodiment use of Artificial Intelligence in cyber security.
BACKGROUND
Cybersecurity attacks have become a pervasive problem for enterprises as many computing devices and other resources have been subjected to attack and compromised. A âcyberattackâ constitutes a threat to security of an enterprise (e.g., enterprise network, one or more computing devices connected to the enterprise network, or the like). As an example, the cyberattack may be a cyber threat against the enterprise network, one or more computing devices connected to the enterprise network, stored or in-flight data accessible over the enterprise network, and/or other enterprise-based resources. This cyber threat may involve malware (malicious software) introduced into a computing device or into the network. The cyber threat may originate from an external endpoint or an internal entity (e.g., a negligent or rogue authorized user). The cyber threats may represent malicious or criminal activity, ranging from theft of credential to even a nation-state attack, where the source initiating or causing the security threat is commonly referred to as a âmaliciousâ source. Conventional cybersecurity products are commonly used to detect and prioritize cybersecurity threats (hereinafter, âcyber threatsâ) against the enterprise, and to determine preventive and/or remedial actions for the enterprise in response to those cyber threats.
SUMMARY
Methods, systems, and apparatus are disclosed for an Artificial Intelligence-based cyber security system.
In an embodiment, a cyber security training tool has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network. The cyber security training tool can then provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network. The cyber security training tool further has a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component.
These and other features of the design provided herein can be better understood with reference to the drawings, description, and claims, all of which form the disclosure of this patent application.
BRIEF DESCRIPTION OF THE DRAWINGS
The drawings refer to some embodiments of the design provided herein in which:
FIG. 1 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors with a cyberattack simulator to launch a synthetic cyberattack and/or analyze both real and synthetic cyberattacks.
FIG. 2 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can cooperate with each other as well as the cyber security appliance with its cyber threat detect engine, the cyber threat autonomous response engine, the cyberattack simulator, the cyber-attack restoration engine, and the artificial intelligence-based cyber threat analyst module to train and protect against cyber threats.
FIG. 3 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors to be utilized with a cloud based war gaming virtual machine platform to allow autonomous generation of the synthetic cyberattacks and train.
FIG. 4 illustrates a block diagram of an embodiment of the AI-based cyber security appliance with example components making up a detection engine, that cooperates with the synthetic cyberattack tool and the cyber security training tool, in order to protect a system, including but not limited to a network/domain, from cyber threats.
FIG. 5 illustrates a graph of an embodiment of an example chain of unusual behavior for, in this example, the email activities and Cloud network activities deviating from a normal pattern of life in connection with the rest of the system/network under analysis.
FIG. 6 illustrates a diagram of an embodiment of the cyber-attack simulator and its Artificial Intelligence-based simulations constructing an example graph of nodes in an example network and simulating how the cyberattack might likely progress in the future tailored with an innate understanding of a normal behavior of the nodes in the system being protected and a current operational state of each node in the graph of the protected system during simulations of cyberattacks.
FIG. 7 illustrates a block diagram of an embodiment of the AI-based cyber security appliance with the cyber security restoration engine and other Artificial Intelligence-based engines plugging in as an appliance platform to protect a system.
FIG. 8 illustrates a block diagram of an embodiment of one or more computing devices that can be a part of the Artificial Intelligence-based cyber security system including the multiple Artificial Intelligence-based engines, the synthetic cyberattack tool, and the cyber security training tool discussed herein.
While the design is subject to various modifications, equivalents, and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and will now be described in detail. It should be understood that the design is not limited to the particular embodiments disclosed, butâon the contraryâthe intention is to cover all modifications, equivalents, and alternative forms using the specific embodiments.
DESCRIPTION
In the following description, numerous specific details are set forth, such as examples of specific data signals, named components, number of servers in a system, etc., in order to provide a thorough understanding of the present design. It will be apparent, however, to one of ordinary skill in the art that the present design can be practiced without these specific details. In other instances, well known components or methods have not been described in detail but rather in a block diagram in order to avoid unnecessarily obscuring the present design. Further, specific numeric references such as a first server, can be made. However, the specific numeric reference should not be interpreted as a literal sequential order but rather interpreted that the first server is different than a second server. Thus, the specific details set forth are merely exemplary. Also, the features implemented in one embodiment may be implemented in another embodiment where logically possible. The specific details can be varied from and still be contemplated to be within the spirit and scope of the present design. The term coupled is defined as meaning connected either directly to the component or indirectly to the component through another component.
The cyber security training tool has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network. The cyber security training tool can then provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network. The cyber security training tool further has a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component. The cyber security training tool can provide this training in situ to the end user and/or cyber security team member when the potential cyber threat is detected, on the computing device they are currently using, and then within the application running when the potential cyber threat was detected. The cyber security training tool can also provide the training within a wargaming exercise performed in a cyberattack simulator and/or a cloud based war gaming virtual machine platform.
FIG. 1 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors with a cyberattack simulator to launch a synthetic cyberattack and/or analyze both real and synthetic cyberattacks.
In an implementation, the synthetic cyberattack tool 125 and/or the cyber security training tool 136 can use these one or more large language models and one or more natural language processors with a cyberattack simulator 105 and/or a cloud based war gaming virtual machine platform 60 to produce the synthetic cyberattack for cyber security training. The synthetic cyberattack tool 125 utilizes natural language processing and/or generative AI technologies, such as LLMs, to generate the synthetic cyberattack, such as phishing emails, impersonation emails, advanced persistent threats including ransomware, etc., for the purpose of cyber security educational training of an end user and/or a cyber security team member. As part of the wargaming environment, the synthetic cyberattack tool 125 can cooperate with at least one of a cyberattack simulator 105 and a cloud based war gaming virtual machine platform 60 to deploy a mimic network. The mimic network can consist of one or more of the following networks of 1) an information technology network, 2) a cloud network, 3) an email network, and 4) any combinations of these networks and other networks corresponding to a portion of an architecture and policies implemented in a real world network that the end user and/or the cyber security team member interacts with. The synthetic cyberattack tool 125 can derive I) the synthetic cyberattack from real world cyberattacks and II) the wargaming cyberattack exercise from real world behaviors of the end user and/or the cyber security team member as well as the architecture and policies implemented in the real world network that the end user and/or the cyber security team member interact with. The mimic network of an organization can be implemented in i) an environment of the cyberattack simulator 105 and/or ii) as virtual machines in a cloud environment of the cloud based war gaming virtual machine platform 60 .
After the creation of the wargaming environment, the synthetic cyberattack tool 125 and/or the cyber security training tool 136 can work with the cyberattack simulator 105 and/or the cloud based war gaming virtual machine platform 60 to allow autonomous generation of the synthetic cyberattacks and a coordinated series of operations executed by machine learning components working together without the need of human stitching those operations together.
Note, see FIG. 3 for more details, however, generally the cloud based war gaming <figure-callout id="60" label="virtual machine platform" filenames="US20240406210A1-20241205-D00003.png,US20240406210A1-20
RELATED APPLICATION
This application claims priority under 35 USC 119 to U.S. provisional patent application No. 63/470,571, titled âCYBER SECURITY SYSTEMâ filed Jun. 2, 2023, as well as to U.S. provisional patent application No. 63/472,227, titled âCYBER SECURITY SYSTEMâ filed Jun. 9, 2023, which the disclosures of such are incorporated herein by reference in their entirety.
NOTICE OF COPYRIGHT
A portion of this disclosure contains material that is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the material subject to copyright protection as it appears in the United States Patent & Trademark Office's patent file or records, but otherwise reserves all copyright rights whatsoever.
FIELD
Cyber security and in an embodiment use of Artificial Intelligence in cyber security.
BACKGROUND
Cybersecurity attacks have become a pervasive problem for enterprises as many computing devices and other resources have been subjected to attack and compromised. A âcyberattackâ constitutes a threat to security of an enterprise (e.g., enterprise network, one or more computing devices connected to the enterprise network, or the like). As an example, the cyberattack may be a cyber threat against the enterprise network, one or more computing devices connected to the enterprise network, stored or in-flight data accessible over the enterprise network, and/or other enterprise-based resources. This cyber threat may involve malware (malicious software) introduced into a computing device or into the network. The cyber threat may originate from an external endpoint or an internal entity (e.g., a negligent or rogue authorized user). The cyber threats may represent malicious or criminal activity, ranging from theft of credential to even a nation-state attack, where the source initiating or causing the security threat is commonly referred to as a âmaliciousâ source. Conventional cybersecurity products are commonly used to detect and prioritize cybersecurity threats (hereinafter, âcyber threatsâ) against the enterprise, and to determine preventive and/or remedial actions for the enterprise in response to those cyber threats.
SUMMARY
Methods, systems, and apparatus are disclosed for an Artificial Intelligence-based cyber security system.
In an embodiment, a cyber security training tool has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network. The cyber security training tool can then provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network. The cyber security training tool further has a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component.
These and other features of the design provided herein can be better understood with reference to the drawings, description, and claims, all of which form the disclosure of this patent application.
BRIEF DESCRIPTION OF THE DRAWINGS
The drawings refer to some embodiments of the design provided herein in which:
FIG. 1 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors with a cyberattack simulator to launch a synthetic cyberattack and/or analyze both real and synthetic cyberattacks.
FIG. 2 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can cooperate with each other as well as the cyber security appliance with its cyber threat detect engine, the cyber threat autonomous response engine, the cyberattack simulator, the cyber-attack restoration engine, and the artificial intelligence-based cyber threat analyst module to train and protect against cyber threats.
FIG. 3 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors to be utilized with a cloud based war gaming virtual machine platform to allow autonomous generation of the synthetic cyberattacks and train.
FIG. 4 illustrates a block diagram of an embodiment of the AI-based cyber security appliance with example components making up a detection engine, that cooperates with the synthetic cyberattack tool and the cyber security training tool, in order to protect a system, including but not limited to a network/domain, from cyber threats.
FIG. 5 illustrates a graph of an embodiment of an example chain of unusual behavior for, in this example, the email activities and Cloud network activities deviating from a normal pattern of life in connection with the rest of the system/network under analysis.
FIG. 6 illustrates a diagram of an embodiment of the cyber-attack simulator and its Artificial Intelligence-based simulations constructing an example graph of nodes in an example network and simulating how the cyberattack might likely progress in the future tailored with an innate understanding of a normal behavior of the nodes in the system being protected and a current operational state of each node in the graph of the protected system during simulations of cyberattacks.
FIG. 7 illustrates a block diagram of an embodiment of the AI-based cyber security appliance with the cyber security restoration engine and other Artificial Intelligence-based engines plugging in as an appliance platform to protect a system.
FIG. 8 illustrates a block diagram of an embodiment of one or more computing devices that can be a part of the Artificial Intelligence-based cyber security system including the multiple Artificial Intelligence-based engines, the synthetic cyberattack tool, and the cyber security training tool discussed herein.
While the design is subject to various modifications, equivalents, and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and will now be described in detail. It should be understood that the design is not limited to the particular embodiments disclosed, butâon the contraryâthe intention is to cover all modifications, equivalents, and alternative forms using the specific embodiments.
DESCRIPTION
In the following description, numerous specific details are set forth, such as examples of specific data signals, named components, number of servers in a system, etc., in order to provide a thorough understanding of the present design. It will be apparent, however, to one of ordinary skill in the art that the present design can be practiced without these specific details. In other instances, well known components or methods have not been described in detail but rather in a block diagram in order to avoid unnecessarily obscuring the present design. Further, specific numeric references such as a first server, can be made. However, the specific numeric reference should not be interpreted as a literal sequential order but rather interpreted that the first server is different than a second server. Thus, the specific details set forth are merely exemplary. Also, the features implemented in one embodiment may be implemented in another embodiment where logically possible. The specific details can be varied from and still be contemplated to be within the spirit and scope of the present design. The term coupled is defined as meaning connected either directly to the component or indirectly to the component through another component.
The cyber security training tool has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network. The cyber security training tool can then provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network. The cyber security training tool further has a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component. The cyber security training tool can provide this training in situ to the end user and/or cyber security team member when the potential cyber threat is detected, on the computing device they are currently using, and then within the application running when the potential cyber threat was detected. The cyber security training tool can also provide the training within a wargaming exercise performed in a cyberattack simulator and/or a cloud based war gaming virtual machine platform.
FIG. 1 illustrates a block diagram of an embodiment of a synthetic cyberattack tool and a cyber security training tool that can use one or more large language models and one or more natural language processors with a cyberattack simulator to launch a synthetic cyberattack and/or analyze both real and synthetic cyberattacks.
In an implementation, the synthetic cyberattack tool 125 and/or the cyber security training tool 136 can use these one or more large language models and one or more natural language processors with a cyberattack simulator 105 and/or a cloud based war gaming virtual machine platform 60 to produce the synthetic cyberattack for cyber security training. The synthetic cyberattack tool 125 utilizes natural language processing and/or generative AI technologies, such as LLMs, to generate the synthetic cyberattack, such as phishing emails, impersonation emails, advanced persistent threats including ransomware, etc., for the purpose of cyber security educational training of an end user and/or a cyber security team member. As part of the wargaming environment, the synthetic cyberattack tool 125 can cooperate with at least one of a cyberattack simulator 105 and a cloud based war gaming virtual machine platform 60 to deploy a mimic network. The mimic network can consist of one or more of the following networks of 1) an information technology network, 2) a cloud network, 3) an email network, and 4) any combinations of these networks and other networks corresponding to a portion of an architecture and policies implemented in a real world network that the end user and/or the cyber security team member interacts with. The synthetic cyberattack tool 125 can derive I) the synthetic cyberattack from real world cyberattacks and II) the wargaming cyberattack exercise from real world behaviors of the end user and/or the cyber security team member as well as the architecture and policies implemented in the real world network that the end user and/or the cyber security team member interact with. The mimic network of an organization can be implemented in i) an environment of the cyberattack simulator 105 and/or ii) as virtual machines in a cloud environment of the cloud based war gaming virtual machine platform 60 .
After the creation of the wargaming environment, the synthetic cyberattack tool 125 and/or the cyber security training tool 136 can work with the cyberattack simulator 105 and/or the cloud based war gaming virtual machine platform 60 to allow autonomous generation of the synthetic cyberattacks and a coordinated series of operations executed by machine learning components working together without the need of human stitching those operations together.
Note, see FIG. 3 for more details, however, generally the cloud based war gaming virtual machine platform 60 can be as follows. The cloud based war gaming virtual machine platform 60 goes out and maps an entire customer's network architecture, including its cloud architecture environment, and works out what network elements connect to other network elements as well as obtains all of the information associated with each network user's account and privileges and then creates a synthetic version of that mimic network. The cloud based war gaming virtual machine platform 60 then deploys one or more autonomous software agents to act as the synthetic cyberattack on the mimic network to behave in a certain malicious way, or a normal way and then in a malicious way so that a security team member can then have a fully realistic scenario of a malicious attack going on within their virtual/simulated network, without worrying about compromising or exposing a vulnerability on their actual real network system. The cloud based war gaming virtual machine platform 60 cooperates with the cyber security training tool 136 and/or the synthetic cyberattack tool 125 to also capture and record the synthetic cyberattack information for the purpose of training non-technical end users as well as security team members.
Referring back to FIG. 1 , the cyberattack simulator 105 may be implemented and operated in more detail as discussed further below.
The synthetic cyberattack tool 125 and/or the cyber security training tool 136 can use the generative artificial intelligence component 127 , such as a large language model technique, to assist in generating one or more synthetic cyberattacks to produce one or more cybersecurity incidents and/or events within the wargaming environment, direct the steps of the synthetic cyber threat causing those cybersecurity incidents and/or events, and then to provide an analysis and an explanation of those cybersecurity incidents and/or events for a purpose of providing cyber security training to at least one of i) an end user of a network and ii) a cyber security team member for the network. The synthetic cyberattack tool 125 coordinates with the cyberattack simulator 105 and/or the cloud based war gaming virtual machine platform 60 to perform synthetic cyberattacks in the mimic network with an intention behind this synthetic cyberattack is to create realistic scenarios in the domains of, for example, email environments, cloud environments including SaaS environments, IT network environments, other on premise environments, etc. The synthetic cyberattack tool 125 uses the generative artificial intelligence component 127 to orchestrate the synthetic cyberattack, which is grounded in customized contextual data about real world attacks and real world behaviors of the end user and/or the cyber security team member based on a history of that end user and/or that cyber security team member, under analysis, and the architecture and policies implemented in the real world network that the end user and/or the cyber security team member interacts with. The synthetic cyberattack tool 125 use of the generative AI (e.g. LLMs) in, for example, the creation of phishing emails based upon historical information about inducement and/or any kind of style based training as well as the use and steps taken by these autonomous software agents in the wargaming environment is based upon the actual information from customer's environment and then the millions of training cycles of the training data for the generative artificial intelligence component 127 .
The synthetic cyberattack tool 125 can also be configured to cooperate with an email inducement text highlighting tool 139 . The email inducement text highlighting tool 139 has a natural language processor and a transformer model trained on different types of malicious inducements for email users. The natural language processor is configured to take in the text of an email, under analysis, with the natural language processor to understand both the words in the email and the structure of the fields of the email, and then feed them to the transformer model to understand an intent of the words in the email, under analysis. The email inducement text highlighting tool 139 is then configured to highlight the words and phrases which correspond to different types of inducements: redirection, offers, financial details, instructions, and threats, found in the email under analysis.
On the wargaming side, the trained email inducement text highlighting tool 139 working with generative AI, such as an LLM, may create customized inducement emails, based on the customer specific data derived from the knowledge managed by the cyber security appliance 100 , for a simulated attack scenario. The email inducement text highlighting tool 139 can create customized inducement emails for a simulated attack scenario based upon, for example, historic emails (frequency, from whom, style, etc.) for that end user and the history of the end user's interaction with historic malicious emails to generate new bad emails for the synthetic cyberattack. Thus, the synthetic cyberattack tool 125 can cooperate with the email inducement text highlighting tool 139 to create one or more phishing emails and/or any kind of style impersonation based training based upon historical information about types of emails that the end user and/or the cyber security team member, under analysis, has historically received and any inducement within those types of emails, and then to use the phishing emails as part of the synthetic cyberattack in the war gaming environment that is based upon the customer's environment and the training data examples that the machine learning in the large language model trained upon. The synthetic cyberattack tool 125 and the cyber security training tool 136 can contextualize those synthetic cyberattacks so that each one of those scenarios is contextualized to the customer's data, their users, behavior, and the realities of their own infrastructure, which makes much better training than merely on generic examples. For example, the end user may have in the past activated a particular link to make a file transfer between two devices and so the security awareness training now generates new synthetic cyberattacks that involve activating a slightly different link to make a file transfer between two devices and checks whether the end user, undergoing training, falls for the malicious link again. The synthetic cyberattack tool 125 cooperating with the cyber security training tool 136 injects this realism into all of these environments through all of these synthetic attack scenarios through a historical understanding of what is possible in their environment, but also an understanding of what the end user has seen in the previous cyber incidents and their own interactions in the past, etc.
Again, the synthetic cyberattack tool 125 uses techniques that allow for the production of synthetic data based upon a historical understanding, a contextual understanding, and a likelihood of the cyber incident occurring, which is kind of what drives all of these different approaches and the creation of synthetic attacks. The synthetic cyberattack tool 125 cooperating with the cyber security training tool 136 uses an intimate understanding of an organization and its network and/or individuals in the network, rather than just following a pre-programmed scenario.
Not only is the synthetic cyberattack customized in content but also customized in the steps used to carry out the attack. The synthetic cyberattack tool 125 can cooperate with the cyberattack simulator 105 , as well as the cloud based war gaming virtual machine platform 60 to autonomously generate the synthetic cyberattack incidents, which are dynamically generated to perform steps of the cyberattack based on a current status of components in the wargaming environment and counter measures taken, as current actual vulnerabilities and known behaviors of the end users at the time the decision for a step in the cyberattack is being made versus some hard coded example pre-programmed scenarios. The synthetic cyberattack tool 125 can cooperate with the generative artificial intelligence component 127 to have the ability to generate realistic synthetic cyber incidents based upon a historic understanding of real incidents seen in the wild, and an understanding of the devices within the network and the ability to interact with semi or fully autonomous software agent by the LLMs in a mimic network (e.g. mirrored with real data corresponding to the actual network environment of the customer). The synthetic cyberattack tool 125 can generate content as well as then evaluate each step taken for the wargaming cyberattack exercise, based upon actual conditions at that time the decision is being made, on a mimic network implemented in at least one of i) an environment of the cloud based war gaming virtual machine platform 60 and an environment of the cyberattack simulator 105 . The training provided to the end user and/or security team is for the purpose of preparing before a real cyberattack takes place.
The synthetic cyberattack tool 125 can include an attack engine configured to deploy a cyber threat to use an exploit that can be tested and interacted with during the wargaming cyberattack exercise in the mimic network deployed by the synthetic cyberattack tool 125 .
The synthetic cyberattack tool 125 can use the generative artificial intelligence component 127 , such as an autonomous agent large language model, as an orchestrator to collect historical data i) on cyberattack incidents within the real world network that the end user and/or cyber security team member interacts with, as well as on cyberattack incidents from one or more third party threat landscape platforms to select what type of cyberattack will be generated in the synthetic cyberattacks, ii) to correlate disparate steps taken by the synthetic cyberattack in the cyberattack simulator 105 and/or the cloud based war gaming virtual machine platform 60 based upon previous cyberattack incidents, including information about detections and model breaches, including model alerts, that have happened, as well as take in information about actions taken to mitigate the synthetic cyberattack that are currently in place, and then suggest what step to take to advance the synthetic cyberattack, and then subsequently explain cyberattack steps in the synthetic cyberattack based on vulnerabilities found and actions taken to mitigate the synthetic cyberattack in a natural language format, as well as steps that a human needs to take to mitigate and remediate to reduce risk. The LLM in the synthetic cyberattack tool 125 can make decisions on what is important and what is not, and when it should be applied in a logical way based upon its initial training from the training data trained upon and factoring in the actual history of this specific end user/security team member and the actual history of this specific network. The synthetic cyberattack tool 125 uses the autonomous agent LLM as a correlation engine because it has strong abilities to correlate, as a data transformation tool, and finally, as a form of natural language processing to turn data about breaches and vulnerabilities as well as captured meta data from the synthetic attack into information that the LLM can understand and analyze on a consistent basis. All the data need not be preformatted into a single consistent form prior to developing an understanding but rather as a natural language processor the LLM has a built in ability to understand a concept being conveyed even when the words and format types differ from each other.
Again, the generative artificial intelligence component 127 can query the cyber security appliance 100 and/or look into the data store for previous analyst incidents and types of model breaches that the network including its end users, under analysis, has observed in the past. For example, in the email behavior the cyber security training tool 136 checks history to know that this end user has received inducement emails (e.g., a lot of crypto offers). The generative artificial intelligence component 127 with the cyber security training tool 136 and/or the synthetic cyberattack tool 125 can then orchestrate and cooperate with the cyberattack simulator 105 /cloud war gaming platform 60 in order to produce the synthetic attack, for example, in the form of an inducement email sent to this end user and/or security team member, who typically received these type of emails, as well as user's who have rarely seen this type of cyberattack inducement emails, and then run the likely wargaming scenario in the simulator/virtual machine cloud environment, step by step, and then produce customized training content that highlights the factors that they need to worry about, based upon that kind of personalized profile, drawing upon all of those factors that the system drew from different parts of the cyber security appliance 100 and other engines.
Another example for training could be 1) users who have and 2) some users who have not, downloaded malicious executables (e.g., click on this link), as part of a malicious cyber threat. Another example could be whether an end user previously affected by a particular cyberattack invoked through an Office 365 document, and then the cyber security training tool 136 can present a similar cyberattack with slightly different information (e.g., previously had a cyberattack via an Office 365 document but now this time it is a Google Doc). The cyber security training tool 136 can check whether that end user will recognize a similar cyberattack the next time around as well as expose end users who have not been previously affected by that particular cyberattack. Does the end user fall for this synthetic version of cyberattack possibly again and then the cyber security training tool 136 can provide immediate on the spot visual training to that end user on why that cyber threat in the Google Doc was identified as bad.
The synthetic cyberattack tool 125 and/or the cyber security training tool 136 can cooperate with the cyberattack simulator 105 to provide attack path modeling data that is incorporated in by the synthetic cyberattack tool 125 such that a realistic likelihood is injected to an attack path route chosen corresponding to the real customer environment. The synthetic cyberattack tool 125 is configured to cooperate with the cyberattack simulator 105 to provide attack path modeling data that is incorporated in by the synthetic cyberattack to assist in choosing a particular attack path route through the mimic network based on actual vulnerabilities in the corresponding real world network. The synthetic cyberattack tool 125 can interact with one or more data stores which have information about previous emails, received information about previous AI analyst incidents, information about restoration from cyber incidents and decisions made as a result of those, information about an architecture in the network that the end user interacts with, and information about the end user and their behavior in the network under analysis in order to inject realism into the synthetic cyberattack through a historical understanding of what is possible in the network of the end user and/or the cyber security team member, but also an understanding of a context of previous cyber incidents that have actually occurred in the network of the end user and/or the cyber security team member. The data store has information about the architecture that the end user interacts with and information about the end user under analysis.
Again, the synthetic cyberattack tool 125 can use LLMs to enhance cyber security measures by simulating attack scenarios and then facilitating customized training to the receptive audience of the end user and/or security team. In another example, the synthetic cyberattack tool 125 can use LLMs trained on a user's style of email writing and formatting to generate plausible phishing emails in their âvoice.â This approach can be utilized with i) the environment of the cyberattack simulator 105 and/or ii) virtual machines in the Cloud environment engagements to create realistic phishing simulations and raise user awareness about potential threats. Additionally, the cyber security training tool 136 can employ LLMs to detect anomalies in email communication by comparing the actual emails with those predicted to be typical for a specific user. This comparison helps identify potentially malicious emails that deviate from the user's usual patterns.
The synthetic cyberattack tool 125 can cooperate with the cyber security training tool 136 to facilitate a user's style transfer for emails to generate plausible phishing. The system trains an LLM on each user's style of email writing (including the underlying formatting) and then uses the LLM to generate convincing phishing emails in their âvoiceâ as part of synthetic cyberattack engagements.
Similarly, the cyber security training tool 136 can apply this technique with a trained LLM on real world emails received by an end user as a detection approachâi.e., how much does this actual email differ from that which would be âpredictableâ for this other email user. The cyber security training tool 136 can apply this technique with a trained LLM on real world emails to identify impersonation emails on real world emails and use the email inducement text highlighting tool 139 to analyze malicious emails and identify the impersonation portions, to protect email users and train them.
The synthetic cyberattack tool 125 and/or the cyber security training tool 136 can truly provide a kind of wargame environment that reflects the reality of the network of the end user and/or the cyber security team member to provide incredibly valuable tailored/customized training based on stored information from the AI analyst, the cyber security appliance 100 , email system, etc. vs generic training to end up with something that's a lot more realistic and unpredictable.
In another example, the synthetic cyberattack tool 125 can use the generative artificial intelligence component 127 , such as an autonomous agent large language model trained on graphs describing a security compromise produced by a human cyber security analyst, in order to then produce a graph for the synthetic cyberattack, and then follow nodes of the graph for steps in the synthetic cyberattack in the mimic network. A cyberattack simulator 105 can use an autonomous agent LLM trained on cyber security analyst graphs describing a security compromise, that the system has either 1) ever seen or 2) at least seen within a certain time limit. In an example, the autonomous agent large language model first takes in the analyst graphs describing a security compromise produced by the cyber security analyst and then produces a graph for the synthetic cyberattack. Next, the synthetic cyberattack tool 125 can then convert those graphs to the equivalent sort of text representation. The text representation might say, for example, this device did this, then this cyber threat compromised this node initially and then migrated to this device, etc., etc. The textual sentence produced is a string of codes describing aspects of a cyber compromise. The string of codes, for example, further includes-edge type, from this node type to this node type, the indexes of those devices involved in the compromise, type of compromise. Next, the system trains the large language model on these sentences/textual representations derived from graphs describing a security compromise produced by the cyber security analyst, so that the LLM can deduce how these attacks are structured. Next, once the neural networks forming the artificial intelligence have learned how to understand graphs that describe a security compromise, then the synthetic cyberattack tool 125 can work the LLM to take the next step and train on how to generatively produce graphs that describe how to make a security compromise. Thus, cyberattack simulator 105 can use an autonomous agent LLM trained on cyber security analyst graphs describing a security compromise to then produce a graph for a proposed simulated/synthetic cyberattack and then evaluate each step in an ongoing synthetic cyberattack to the current conditions in the mimicked network.
The sentence produced is a string of codes describing an aspect of a cyber compromise, which is then what is visually represented in the produced graph. Each node and edge in the graph are then populated with the actual metadata from actual cyber incidents with can be used and referenced in the produced synthetic cyberattack.
In another example, the synthetic cyberattack tool 125 is configured to use a message passing neural network and/or an AI transformer to simulate attacks. This form of the neural net is specialized to create graph structures. Therefore, it can be successfully trained on the graph structure of AI Analyst incidents in a customer environment and then used to generate convincing synthetic incidents, using graphs generated from the LLM for the purpose of simulating an incident and response, tailored to the client environment. By training these message passing neural networks on the graph structure of AI Analyst incidents in a customer environment, synthetic incidents can be generated. These synthetic incidents simulate real-world attack scenarios tailored to the client's environment, enabling organizations to simulate incident response and test the effectiveness of their security measures.
The cyber security training tool 136 and the synthetic cyberattack tool 125 can utilize an autonomous agent large language model. Autonomous agent based large language models (LLMs), like Auto GPT, autonomously chain together tasks to achieve a big-picture goal set by the user. The autonomous agent based LLM can be leveraged to simulate attack scenarios by working together and feeding back into themselves. The autonomous agent based LLMs can work together and feed back into themselves to perform long complex tasks during a simulated cyberattack, as such, they can simulate a cyber threat in an environment. For example, an autonomous agent based LLM placed on an isolated AWS EC2 instance can execute system commands to determine the operating system, make curl requests to check connectivity, and even attempt to exfiltrate information. The autonomous agent based LLM on the AWS EC2 instance follows the situation to exfiltrate key information and then as much information to a certain endpoint. The LLM agent on the AWS EC2 instance uses system commands to work out what OS it is on, curl requests to check connectivity, if it knows it is on an AWS EC2 instance might make requests to IMDS for credentials, etc.
This simulation provides organizations with insights into potential attack vectors and helps in refining their defensive strategies.
Intelligent Customized Training Scenarios
Next, the cyber security training too
CLAIMS
Claims ( 20 )
1 . An apparatus, comprising:
a cyber security training tool is configured to have a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network, and then to provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network, where the cyber security training tool further has a user interface component configured to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component; and where instructions for the cyber security training tool are configured to be stored in one or more non-transitory machine readable mediums to be executed by one or more processing units.
2 . The apparatus of claim 1 , where the cyber security training tool is configured to use the large language model, which is trained to output a color coded visualization of i) an inducement email with a malicious inducement portion directed to an email user identified ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified, or iii) a combination of both i) and ii).
3 . The apparatus of claim 1 , where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool to analyze malicious emails based upon historical information about one or more malicious inducements as well as one or more phishing emails impersonating a style of another email user in order to provide training to the end user upon detecting the one or more malicious inducements and/or emails impersonating the style of the other email user.
4 . The apparatus of claim 1 , where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to visualize through highlighting identified malicious portions of an email under analysis for a purpose of providing training to the end user, where the user interface is configured to explain and display why this email under analysis is malicious because the email under analysis is attempting to induce the end user to do a harmful act.
5 . The apparatus of claim 1 , where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to provide immediate on the spot feedback on a display screen to the end user during their routine work activity within a software application that the end user is using on why machine learning believes that this email, under analysis, is malicious versus generating a long form written and printed report days later on why the machine learning believes that this email, under analysis, is malicious.
6 . The apparatus of claim 1 , where the cyber security training tool is configured to use a large language model trained as i) a data transformation tool to understand and transform the machine learning analysis, model breaches, and log data in their natural formats from the synthetic cyberattack and ii) apply natural language processing in order to turn data about the machine learning analysis, the model breaches, and the log data from the synthetic cyberattack into information in a natural language format in order for the end user and/or the cyber security team member to understand the analysis and the explanation as to why the machine learning identified the synthetic cyberattack and/or the real cyberattack as the cyber threat in order to train the end user and/or the cyber security team member.
7 . The apparatus of claim 1 , where the cyber security training tool is configured to use a large language model trained to generate software code that creates data visualizations, including at least one of a graph and a chart, to showcase cyber security breaches, user activity, and current cyber threat trends.
8 . The apparatus of claim 1 , where the cyber security training tool is configured to use the large language model trained to deduce a level of cyber security sophistication of the end user and/or cyber security team member out of multiple different levels of sophistication, and then tailor training and a way that the cyber security training tool is explaining things to the deduced level of sophistication of the end user or the cyber security team member.
9 . The apparatus of claim 1 , where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a natural language processor and a transformer model trained on different types of malicious inducements, where the natural language processor is configured to take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email, under analysis, and then for the email inducement text highlighting tool to highlight words and phrases which correspond to different types of malicious inducements.
10 . The apparatus of claim 1 , where the cyber security training tool is configured to have an add-in extension configured to be installed in a software application, where the software application is at least one of i) an email application, ii) a cyber security application, and iii) a browser application such that the end user can activate the add-in extension to query whether something is malicious and then have the user interface display what the understanding of the machine learning considered malicious or not malicious.
11 . A method to provide cyber security, comprising:
providing a cyber security training tool to have a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network, and then to provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network, and providing the cyber security training tool with a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component.
12 . The method of claim 11 , further comprising:
providing the cyber security training tool to use the large language model, which is trained to output a color coded visualization of i) an inducement email with a malicious inducement portion directed to an email user identified ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified, or iii) a combination of both i) and ii).
13 . The method of claim 11 , further comprising:
providing the cyber security training tool to cooperate with an email inducement text highlighting tool to analyze malicious emails based upon historical information about one or more malicious inducements as well as one or more phishing emails impersonating a style of another email user in order to provide training to the end user upon detecting the malicious inducements and/or emails impersonating the style of the other email user.
14 . The method of claim 11 , further comprising:
providing the cyber security training tool to cooperate with an email inducement text highlighting tool, and providing the email inducement text highlighting tool with a user interface to visualize through highlighting identified malicious portions of an email under analysis for a purpose of providing training to the end user, and providing the user interface to explain and display why this email under analysis is malicious because the email under analysis is attempting to induce the end user to do a harmful act.
15 . The method of claim 11 , further comprising:
providing the cyber security training tool to cooperate with an email inducement text highlighting tool, and providing the email inducement text highlighting tool with a user interface to provide immediate on the spot feedback on a display screen to the end user during their routine work activity within a software application that the end user is using on why machine learning believes that this email, under analysis, is malicious versus generating a long form written and printed report days later on why the machine learning believes that this email, under analysis, is malicious.
16 . The method of claim 11 , further comprising:
providing the cyber security training tool to use a large language model trained as i) a data transformation tool to understand and transform the machine learning analysis, model breaches, and log data in their natural formats from the synthetic cyberattack and ii) apply natural language processing in order to turn data about the machine learning analysis, the model breaches, and the log data from the synthetic cyberattack into information in a natural language format in order for the end user and/or the cyber security team member to understand the analysis and the explanation as to why the machine learning identified the synthetic cyberattack and/or the real cyberattack as the cyber threat in order to train the end user and/or the cyber security team member.
17 . The method of claim 11 , further comprising:
providing the cyber security training tool to use a Large Language Model trained to generate software code that creates data visualizations, including at least one of a graph and a chart, to showcase cyber security breaches, user activity, and current cyber threat trends.
18 . The method of claim 11 , further comprising:
providing the cyber security training tool to use the large language model trained to deduce a level of cyber security sophistication of the end user and/or cyber security team member out of multiple different levels of sophistication, and then tailor training and a way that the cyber security training tool is explaining things to the deduced level of sophistication of the end user or the cyber security team member.
19 . The method of claim 11 , further comprising:
providing the cyber security training tool to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a natural language processor and a transformer model trained on different types of inducements, where the natural language processor is configured to take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email, under analysis, and then for the email inducement text highlighting tool to highlight words and phrases which correspond to different types of inducements.
20 . A non-transitory storage medium including software that, upon execution by a processor, performs operations comprising:
using a cyber security training tool that has a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack in a mimic network corresponding to a real world network as well as ii) a real cyberattack in the real world network, and then to provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network, and using the cyber security training tool with a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component.
US18/678,461
2023-06-02
2024-05-30
Cyber security training tool that uses a large language model
Pending
US20240406210A1
( en )
Priority Applications (1)
Application Number
Priority Date
Filing Date
Title
US18/678,461
US20240406210A1
( en )
2023-06-02
2024-05-30
Cyber security training tool that uses a large language model
Applications Claiming Priority (3)
Application Number
Priority Date
Filing Date
Title
US202363470571P
2023-06-02
2023-06-02
US202363472227P
2023-06-09
2023-06-09
US18/678,461
US20240406210A1
( en )
2023-06-02
2024-05-30
Cyber security training tool that uses a large language model
Publications (1)
Publication Number
Publication Date
US20240406210A1
true
US20240406210A1 ( en )
2024-12-05
Family
ID=93651807
Family Applications (4)
Application Number
Title
Priority Date
Filing Date
US18/678,524
Pending
US20240403420A1
( en )
2023-06-02
2024-05-30
System and method for adjusting or creating ai models based on model breach alerts
US18/678,501
Pending
US20240403428A1
( en )
2023-06-02
2024-05-30
System and method for utilizing large language models and natural language processing technologies to pre-process and analyze data to improve detection of cyber threats
US18/678,451
Pending
US20240406206A1
( en )
2023-06-02
2024-05-30
Synthetic cyberattack tool that uses a generative artificial intelligence component
US18/678,461
Pending
US20240406210A1
( en )
2023-06-02
2024-05-30
Cyber security training tool that uses a large language model
Family Applications Before (3)
Application Number
Title
Priority Date
Filing Date
US18/678,524
Pending
US20240403420A1
( en )
2023-06-02
2024-05-30
System and method for adjusting or creating ai models based on model breach alerts
US18/678,501
Pending
US20240403428A1
( en )
2023-06-02
2024-05-30
System and method for utilizing large language models and natural language processing technologies to pre-process and analyze data to improve detection of cyber threats
US18/678,451
Pending
US20240406206A1
( en )
2023-06-02
2024-05-30
Synthetic cyberattack tool that uses a generative artificial intelligence component
Country Status (3)
Country
Link
US
( 4 )
US20240403420A1
( en )
EP
( 2 )
EP4720901A1
( en )
WO
( 2 )
WO2024263374A1
( en )
Cited By (13)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20220014501A1
( en )
*
2018-11-13
2022-01-13
Wenspire
Method and device for monitoring data output by a server
US20230297707A1
( en )
*
2022-03-17
2023-09-21
Bank Of America Corporation
Performing retroactive threshold reduction control review using artificial intelligence
US20250094582A1
( en )
*
2023-09-15
2025-03-20
International Business Machines Corporation
Selectively prioritizing alerts received for an advanced cybersecurity threat prioritization system
US20250133102A1
( en )
*
2023-10-19
2025-04-24
OutThink Ltd
Cyber Security Phishing Campaign
US20250168186A1
( en )
*
2023-11-17
2025-05-22
Microsoft Technology Licensing, Llc
Cybersecurity Engine in a Security Management System
US20250245327A1
( en )
*
2024-01-25
2025-07-31
Nomura Research Institute, Ltd.
Security countermeasure support system
US20250252096A1
( en )
*
2024-02-02
2025-08-07
Insight Direct Usa, Inc.
Dynamic network analysis and interactivity using a large language model
US20250258912A1
( en )
*
2023-11-29
2025-08-14
Dazz, Inc.
Techniques for cross-source alert prioritization and remediation
US12430601B2
( en )
*
2023-06-01
2025-09-30
Vade Usa Incorporated
Generation of security awareness training samples with large language models
US20250373658A1
( en )
*
2024-05-29
2025-12-04
International Business Machines Corporation
Neural networks for mitigating business email compromise (bec) events
US20250378156A1
( en )
*
2024-06-07
2025-12-11
Oracle International Corporation
Mimicry-based attack generation
US12592863B2
( en )
2023-08-08
2026-03-31
Insight Direct Usa, Inc.
Digital network simulation and graph database formulation for use with a large language model
US20260099597A1
( en )
*
2024-10-04
2026-04-09
International Business Machines Corporation
Creating and extracting training data from storage systems to train machine learning models for ransomware detection
Families Citing this family (38)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US12621331B2
( en )
*
2020-11-13
2026-05-05
Cyberark Software Ltd.
Detection of security risks based on secretless connection data
US12596813B2
( en )
2023-01-19
2026-04-07
Citibank, N.A
Autonomous agent observation and control
US12475235B2
( en )
2023-01-19
2025-11-18
Citibank, N.A.
Generative cybersecurity exploit discovery and evaluation
US11874934B1
( en )
2023-01-19
2024-01-16
Citibank, N.A.
Providing user-induced variable identification of end-to-end computing system security impact information systems and methods
US12608486B2
( en )
2023-01-19
2026-04-21
Citibank, N.A.
Generating predicted end-to-end cyber-security attack characteristics via bifurcated machine learning-based processing of multi-modal data systems and methods
US12314406B1
( en )
2023-01-19
2025-05-27
Citibank, N.A.
Generative cybersecurity exploit discovery and evaluation
US12282565B2
( en )
*
2023-01-19
2025-04-22
Citibank, N.A.
Generative cybersecurity exploit synthesis and mitigation
US12271491B2
( en )
2023-01-19
2025-04-08
Citibank, N.A.
Detection and mitigation of machine learning model adversarial attacks
US20240330443A1
( en )
*
2023-03-30
2024-10-03
Dell Products L.P.
Method and system for user authentication and data prioritization during data migration
US20240338458A1
( en )
*
2023-04-06
2024-10-10
The Trustees Of The Stevens Institute Of Technology
Amplification of formal method and fuzz testing to enable scalable assurance for communication system
US12568095B2
( en )
*
2023-06-14
2026-03-03
Micro Focus Llc
Using machine learning to identify phishing, vishing, and deep fake attacks
US20250016183A1
( en )
*
2023-07-06
2025-01-09
AO Kaspersky Lab
System and method for using large language models to respond to information security incidents
US12541346B2
( en )
*
2023-07-31
2026-02-03
Dependable AI, Inc.
Utility system for automated code generation and execution
US20250055865A1
( en )
*
2023-08-07
2025-02-13
Capital One Services, Llc
Systems and methods for detecting unauthorized access
US12001550B1
( en )
*
2023-08-28
2024-06-04
Wiz, Inc.
Cybersecurity incident response techniques utilizing artificial intelligence
US12608370B2
( en )
2023-08-28
2026-04-21
Wiz, Inc.
System and method for natural language query processing utilizing language model techniques
US12493615B2
( en )
2023-08-28
2025-12-09
Wiz, Inc.
System and method for improving efficiency in natural language query processing utilizing language model
US12418558B1
( en )
*
2023-09-29
2025-09-16
Amazon Technologies, Inc.
Detection of malicious domains
US20250173436A1
( en )
*
2023-11-28
2025-05-29
Palo Alto Networks, Inc.
Context-based cyberattack signature generation with large language models
US12602624B2
( en )
2023-12-11
2026-04-14
Citibank, N.A.
Anomaly detection method for model outputs
GB2636382A
( en )
*
2023-12-11
2025-06-18
Withsecure Corp
A method for threat detection in a threat detection system and a threat detection system
US12542795B2
( en )
*
2024-02-05
2026-02-03
S&P Global Inc.
Ai-driven multi-faceted cyber threat classification and categorization
US20250280019A1
( en )
*
2024-03-01
2025-09-04
Honeywell International Inc.
Anomaly detection in operational technology environment
US12596738B2
( en )
2024-04-11
2026-04-07
Citibank, N.A.
Explainable large language model routing with immutable audit trails
US12602418B2
( en )
2024-04-11
2026-04-14
Citibank, N.A.
Intelligent query decomposition, specialized model routing, and hierarchical aggregation with conflict resolution
US12346820B1
( en )
2024-04-11
2025-07-01
Citibank, N. A.
Identifying and remediating gaps in artificial intelligence use cases using a generative artificial intelligence model
US20250371159A1
( en )
*
2024-05-28
2025-12-04
Bank Of America Corporation
System and method for generating artificial intelligence based visualizations of computing device security and stability
US20260075070A1
( en )
*
2024-09-06
2026-03-12
Culminate, Inc.
Automatically investigating security alerts for Security Operations Center (SOC)
US20260100973A1
( en )
*
2024-10-03
2026-04-09
Truist Bank
Learning access permissions to computing resources
US20260099601A1
( en )
*
2024-10-08
2026-04-09
Simbian, Inc.
Autonomous threat operation system
US20260119554A1
( en )
*
2024-10-24
2026-04-30
Nomura Research Institute, Ltd.
Security countermeasure support system
US20260119622A1
( en )
*
2024-10-29
2026-04-30
American Express Travel Related Services Company, Inc.
Long-term, context-based, small language model aided authentication
CN119544363B
( en )
*
2024-12-09
2025-11-25
å京ç«å±±å¼æç§ææéå ¬å¸
Methods, media, electronic devices, and software products for processing network attack logs
CN119788400B
( en )
*
2025-01-07
2025-10-24
ä¸å½å·¥åé¶è¡è¡ä»½æéå ¬å¸
Network data processing methods, devices, equipment, media and products
CN119577139B
( en )
*
2025-02-05
2025-05-13
ä¸å½çµåç§æéå¢å ¬å¸ç¬¬ä¸åç ç©¶æ
Event association analysis method and system based on large language model
CN120263461A
( en )
*
2025-03-28
2025-07-04
åç»´åæºï¼å京ï¼ç§æå屿éå ¬å¸
Network attack and defense confrontation and penetration testing system, method, device, equipment and media
US12518318B1
( en )
*
2025-06-13
2026-01-06
Trayport Limited
System and method for enhancing user experience of user of computing application
CN120632894B
( en )
*
2025-08-11
2025-10-28
æå·åéç§ææéå ¬å¸
Automatic repair suggestion generation method and system based on AI security vulnerabilities
Citations (12)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US9749360B1
( en )
*
2017-01-05
2017-08-29
KnowBe4, Inc.
Systems and methods for performing simulated phishing attacks using social engineering indicators
US11599838B2
( en )
*
2017-06-20
2023-03-07
KnowBe4, Inc.
Systems and methods for creating and commissioning a security awareness program
US20230259861A1
( en )
*
2022-02-17
2023-08-17
KnowBe4, Inc.
Methods and systems for security maturity determination
US20230351120A1
( en )
*
2022-04-28
2023-11-02
Theai, Inc.
Observation-based training of artificial intelligence character models
US20230396641A1
( en )
*
2022-06-03
2023-12-07
Netenrich, Inc.
Adaptive system for network and security management
US20240330165A1
( en )
*
2023-04-03
2024-10-03
Microsoft Technology Licensing, Llc
Quality assurance for digital technologies using large language models
US20240354403A1
( en )
*
2023-04-24
2024-10-24
Vade Usa, Incorporated
Detection of synthetic text in emails in an organization inbound email traffic
US20240372876A1
( en )
*
2023-05-01
2024-11-07
Skyhawk Security
Security Posture Management Methods and Systems Using Threat Detection and Response Data
US20240370570A1
( en )
*
2023-05-04
2024-11-07
Microsoft Technology Licensing, Llc
Ad-hoc graph processing for security explainability
US20240403792A1
( en )
*
2023-06-01
2024-12-05
Vade Usa, Incorporated
Generation of security awareness training samples with large language models
US20250175446A1
( en )
*
2022-02-25
2025-05-29
WELDSECURE Limited
Electronic Messaging Systems
US20250299402A1
( en )
*
2024-03-19
2025-09-25
Robert Bosch Gmbh
Method and device for generating synthetic video data from a text prompt
Family Cites Families (25)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
WO2016064919A1
( en )
*
2014-10-21
2016-04-28
Abramowitz Marc Lauren
Dynamic security rating for cyber insurance products
US20220210200A1
( en )
*
2015-10-28
2022-06-30
Qomplx, Inc.
Ai-driven defensive cybersecurity strategy analysis and recommendation system
GB2547201B
( en )
*
2016-02-09
2022-08-31
Darktrace Holdings Ltd
Cyber security
US10469526B2
( en )
*
2016-06-06
2019-11-05
Paypal, Inc.
Cyberattack prevention system
US10009375B1
( en )
*
2017-12-01
2018-06-26
KnowBe4, Inc.
Systems and methods for artificial model building techniques
US10785258B2
( en )
*
2017-12-01
2020-09-22
At&T Intellectual Property I, L.P.
Counter intelligence bot
US11385633B2
( en )
*
2018-04-09
2022-07-12
Diveplane Corporation
Model reduction and training efficiency in computer-based reasoning and artificial intelligence systems
US11275841B2
( en )
*
2018-09-12
2022-03-15
Adversa Ai Ltd
Combination of protection measures for artificial intelligence applications against artificial intelligence attacks
US12034767B2
( en )
*
2019-08-29
2024-07-09
Darktrace Holdings Limited
Artificial intelligence adversary red team
US11316875B2
( en )
*
2020-01-31
2022-04-26
Threatology, Inc.
Method and system for analyzing cybersecurity threats and improving defensive intelligence
CA3129245A1
( en )
*
2020-08-27
2022-02-27
Royal Bank Of Canada
System and method for anomalous database access monitoring
CN114443556A
( en )
*
2020-11-05
2022-05-06
è±ç¹å°å ¬å¸
Device and method for man-machine interaction of AI/ML training host
US11687954B2
( en )
*
2020-12-07
2023-06-27
Capital One Services, Llc
Linking physical locations and online channels in a database
US20220279015A1
( en )
*
2021-02-26
2022-09-01
ArmorBlox, Inc.
Method for detecting financial attacks in emails
US12003535B2
( en )
*
2021-03-01
2024-06-04
Microsoft Technology Licensing, Llc
Phishing URL detection using transformers
EP4340416A4
( en )
*
2021-05-14
2024-07-10
Guangdong Oppo Mobile Telecommunications Corp., Ltd.
EARLY WARNING INFORMATION TRANSMISSION METHODS AND RECEPTION METHODS, DEVICES, APPARATUS AND MEDIUM
US20220398055A1
( en )
*
2021-06-11
2022-12-15
The Procter & Gamble Company
Artificial intelligence based multi-application systems and methods for predicting user-specific events and/or characteristics and generating user-specific recommendations based on app usage
US11240266B1
( en )
*
2021-07-16
2022-02-01
Social Safeguard, Inc.
System, device and method for detecting social engineering attacks in digital communications
US12556555B2
( en )
*
2021-11-22
2026-02-17
Darktrace Holdings Limited
Artificial intelligence based cybersecurity system monitoring telecommunications networks
JP2025508358A
( en )
*
2022-02-09
2025-03-26
ã¢ã¦ã°ãªã¢ï¼ã¤ã³ã³ã¼ãã¬ã¤ããã
Method and system for identifying anomalous computer events to detect security incidents - Patents.com
US20230273982A1
( en )
*
2022-02-28
2023-08-31
Intuit Inc.
Login classification with sequential machine learning model
US12619726B2
( en )
*
2022-03-29
2026-05-05
Intelligent Fusion Technology, Inc.
Cyber resilience integrated security inspection system (CRISIS) against false data injection attacks
WO2024035745A1
( en )
*
2022-08-08
2024-02-15
Darktrace Holdings Limited
An interactive cyber security user interface
US20240143776A1
( en )
*
2022-10-28
2024-05-02
Vmware, Inc.
Vulnerability management for distributed software systems
US12524678B2
( en )
*
2023-03-27
2026-01-13
Microsoft Technology Licensing, Llc
Finding semantically related security information
2024
2024-05-30
US
US18/678,524
patent/US20240403420A1/en
active
Pending
2024-05-30
US
US18/678,501
patent/US20240403428A1/en
active
Pending
2024-05-30
US
US18/678,451
patent/US20240406206A1/en
active
Pending
2024-05-30
US
US18/678,461
patent/US20240406210A1/en
active
Pending
2024-06-03
WO
PCT/US2024/032229
patent/WO2024263374A1/en
not_active
Ceased
2024-06-03
WO
PCT/US2024/032228
patent/WO2024249989A1/en
not_active
Ceased
2024-06-03
EP
EP24816650.6A
patent/EP4720901A1/en
active
Pending
2024-06-03
EP
EP24826447.5A
patent/EP4721346A1/en
active
Pending
Patent Citations (12)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US9749360B1
( en )
*
2017-01-05
2017-08-29
KnowBe4, Inc.
Systems and methods for performing simulated phishing attacks using social engineering indicators
US11599838B2
( en )
*
2017-06-20
2023-03-07
KnowBe4, Inc.
Systems and methods for creating and commissioning a security awareness program
US20230259861A1
( en )
*
2022-02-17
2023-08-17
KnowBe4, Inc.
Methods and systems for security maturity determination
US20250175446A1
( en )
*
2022-02-25
2025-05-29
WELDSECURE Limited
Electronic Messaging Systems
US20230351120A1
( en )
*
2022-04-28
2023-11-02
Theai, Inc.
Observation-based training of artificial intelligence character models
US20230396641A1
( en )
*
2022-06-03
2023-12-07
Netenrich, Inc.
Adaptive system for network and security management
US20240330165A1
( en )
*
2023-04-03
2024-10-03
Microsoft Technology Licensing, Llc
Quality assurance for digital technologies using large language models
US20240354403A1
( en )
*
2023-04-24
2024-10-24
Vade Usa, Incorporated
Detection of synthetic text in emails in an organization inbound email traffic
US20240372876A1
( en )
*
2023-05-01
2024-11-07
Skyhawk Security
Security Posture Management Methods and Systems Using Threat Detection and Response Data
<span item