Agent-based automation for security monitoring

JP2026142525APending Publication Date: 2026-09-07UIPATH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025250906
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-26
Filing Date
2025-12-15
Publication Date
2026-09-07

Smart Images

  • Figure 2026142525000001_ABST
    Figure 2026142525000001_ABST
Patent Text Reader

Abstract

This invention provides a system and method for evaluating computer security issues in computer systems. [Solution] The method receives an alert regarding a computer security issue in a computer system 1502, an initial AI (artificial intelligence) agent determines 1) a strategy for evaluating the computer security issue and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security issue 1504, the computer security issue is evaluated using one or more additional AI agents according to the strategy 1506, and the evaluation results of the computer security issue are output 1508.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to automation in general, and more specifically to agent-based automation for security monitoring. [Background technology]

[0002] Computer security refers to protecting computer systems, such as computers, networks, data, and software, from unauthorized access, theft, damage, or interference. Currently, robotic process automation (RPA) and script-based automation are used to monitor the computer security of computer systems. However, traditional RPA and script-based automation are deterministic, require extensive rule-based programming, and often necessitate human intervention. Therefore, traditional RPA and script-based automation increase manual work, reduce response times, and are impractical and inaccurate, especially for very large computer systems. Thus, improved and / or alternative approaches may be beneficial. [Overview of the project]

[0003] Certain embodiments of the present invention may provide alternatives or solutions to problems and needs in the art that have not yet been fully identified, recognized, or resolved by current computer security technologies, and / or may provide useful alternatives thereto. For example, some embodiments of the present invention relate to agent-based automation for security monitoring.

[0004] In one embodiment, a system and method for evaluating computer security issues in a computer system are provided. An alert regarding a computer security issue in a computer system is received. An initial AI (artificial intelligence) agent determines 1) a strategy for evaluating the computer security issue, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security issue. The computer security issue is evaluated using the one or more additional AI agents according to the strategy. The evaluation results of the computer security issue are output.

[0005] In one embodiment, the initial AI agent and the one or more additional AI agents have roles defined by role definition files provided as contextual information via one or more prompts. In one embodiment, each role definition file includes the AI ​​agent's title, background, tasks, knowledge, skills, and capabilities.

[0006] In one embodiment, the initial AI agent determines 1) the strategy and 2) the one or more additional AI agents based on a procedure provided as contextual information via one or more prompts.

[0007] In one embodiment, the alert is classified by at least one of the one or more additional AI agents.

[0008] In one embodiment, the computer security problem is mitigated by one or more of the one or more additional AI agents.

[0009] In one embodiment, the mitigation of the computer security problem is performed automatically by one or more of the one or more additional AI agents.

[0010] In one embodiment, newly arising computer security problems are identified based on news articles.

[0011] In one embodiment, the alert is received from a security monitoring / alert system. [Brief explanation of the drawing]

[0012] To facilitate understanding of the advantages of specific embodiments of the present invention, a more detailed description of the present invention, as briefly outlined above, will be made with reference to specific embodiments shown in the accompanying drawings. It should be understood that these drawings only illustrate typical embodiments of the present invention and do not limit its scope, but the present invention will be described more specifically and in detail with reference to the accompanying drawings.

[0013] [Figure 1] Figure 1 is an architectural diagram showing a hyperautomation system configured to perform agent-based automation and orchestration according to one embodiment of the present invention.

[0014] [Figure 2] Figure 2 shows some of the combined capabilities of an artificial intelligence (AI) agent and a robotic process automation (RPA) robot according to one embodiment of the present invention.

[0015] [Figure 3] Figure 3 shows an AI agent, an RPA robot, an agent-based orchestration process (AOP), and a pool of applications according to one embodiment of the present invention.

[0016] [Figure 4A] Figure 4A shows an example of an AI agent service interface according to one embodiment of the present invention. [Figure 4B] Figure 4B shows an example of an AI agent service interface according to one embodiment of the present invention.

[0017] [Figure 5] FIG. 5 is a diagram illustrating an example of an AOP development interface according to an embodiment of the present invention.

[0018] [Figure 6] FIG. 6 is a diagram illustrating an example of an RPA development interface according to an embodiment of the present invention.

[0019] [Figure 7] FIG. 7 is a diagram illustrating an end-to-end AI agent, RPA robot, and AOP development and deployment system according to an embodiment of the present invention.

[0020] [Figure 8] FIG. 8 is an architecture diagram illustrating an agent-based automation and RPA system according to an embodiment of the present invention.

[0021] [Figure 9] FIG. 9 is an architecture diagram illustrating a deployed RPA system according to an embodiment of the present invention.

[0022] [Figure 10] FIG. 10 is an architecture diagram illustrating a relationship among a designer, an activity, and a driver according to an embodiment of the present invention.

[0023] [Figure 11] FIG. 11 is an architecture diagram illustrating a computing system that can be used to implement an embodiment of the present invention.

[0024] [Figure 12A] FIG. 12A is a diagram illustrating an example of a neural network trained according to an embodiment of the present invention.

[0025] [Figure 12B]Figure 12B shows an example of a neuron according to one embodiment of the present invention.

[0026] [Figure 13] Figure 13 is an architecture diagram showing a reference architecture of a generative AI model according to one embodiment of the present invention.

[0027] [Figure 14] Figure 14 is a flowchart showing the process for training an AI / ML model according to one embodiment of the present invention.

[0028] [Figure 15] Figure 15 is a flowchart showing a method for evaluating computer security issues in a computer system according to one embodiment of the present invention.

[0029] [Figure 16] Figure 16 shows a workflow for evaluating the security of a computer system according to one or more embodiments.

[0030] [Figure 17] Figure 17 is a system diagram for receiving alerts about computer security problems according to one or more embodiments.

[0031] [Figure 18] Figure 18 shows a workflow for classifying alerts according to one or more embodiments.

[0032] [Figure 19] Figure 19 shows a workflow for investigating an alert according to one or more embodiments.

[0033] [Figure 20] Figure 20 shows a workflow for security event management according to one or more embodiments.

[0034] [Figure 21] Figure 21 shows a workflow for detecting newly occurring computer security problems according to one or more embodiments.

[0035] [Figure 22] Figure 22 shows another workflow for security event management according to one or more embodiments.

[0036] [Figure 23] Figure 23 shows a workflow for forensic acquisition according to one or more embodiments.

[0037] [Figure 24] Figure 24 shows a workflow for creating a dedicated forensic environment according to one or more embodiments.

[0038] Unless otherwise specified, identical or similar reference numerals consistently indicate the corresponding features throughout the attached drawings. [Modes for carrying out the invention]

[0039] Several embodiments relate to agent-based automation for computer security. Specific embodiments are first described with reference to Figures 1-14, and then described in further detail with reference to Figures 15-24.

[0040] Figure 1 is an architectural diagram showing a hyperautomation system 100 configured to perform agent-based automation and orchestration according to one embodiment of the present invention. As used herein, “hyperautomation” refers to an automation system that combines components of process automation, agent-based automation, integration tools, and technologies that amplify the automation capabilities of a task. Examples of these components include, but are not limited to, artificial intelligence (AI) agents, agent-based orchestration processes (AOPs), and robotic process automation (RPA) robots.

[0041] Generally, in this specification, “AI agent” refers to AI-enhanced probabilistic automation that operates independently, acts dynamically, makes decisions, performs actions, and behaves adaptively. This may be due to the use of Large-Scale Language Models (LLMs) by AI agents, which themselves are typically probabilistic. “AOP” refers to automation that enables users to describe overall business processes. AOP can be created using interfaces that enable the creation of business flowcharts described in Business Process Models and Notation (BPMN). BPMN is an extensible markup language (XML) description of business processes. See, for example, Figure 5. “RPA robot” refers to rule-based automation that operates predictably and makes deterministic decisions.

[0042] For example, in some embodiments, RPA may be used at the core of a hyperautomation system. Furthermore, in certain embodiments, automation capabilities may be extended by AI / machine learning (ML), process mining, analytics, agent-based automation, and / or other advanced tools. As the hyperautomation system learns processes, trains AI / ML models, and leverages analytics, more knowledge work can be automated, and for example, all computing systems within an organization (both those used by individuals and those operating autonomously) can become participants in the hyperautomation process. Some embodiments of hyperautomation systems enable users and organizations to efficiently and effectively discover, understand, and extend automation.

[0043] In such embodiments, the AI ​​agent "coexists" with the RPA robots that perform RPA and AOP. As described herein, the AI ​​agent is an AI-skilled automation that can operate independently, make decisions dynamically, perform actions, and adapt its performance. AI agents can dynamically leverage the tools available through these RPA robots to perform tasks such as document processing (e.g., see U.S. Patent Application Publication 2021 / 0097274), user interface (UI) automation (e.g., see U.S. Patents 10,654,166, 10,990,876, 11,080,548, 11,507,259, 11,733,668, and 11,748,069), and semantic copy-and-paste between source and target (e.g., see U.S. Patent 12,124,806 and U.S. Patent Application Publications 2023 / 0107316, 2023 / 0415338, and 2024 / 0220581). AI agents can dynamically select these tools and execute them in a pipeline format.

[0044] Generally, agent-based automation is probabilistic automation performed by one or more AI agents. Agent-based automation expands an organization's automation potential by focusing not only on individual tasks but also on the entire end-to-end process. A team of RPA robots directed by AI agents can enable a single employee to accomplish a large number of tasks. Agent-based automation via AI agents gives managers more time for guidance, physicians more time for patient care, developers the ability to fine-tune their work, engineers the freedom to innovate, and customers a seamless, personalized experience.

[0045] In some embodiments, agent-based automation can achieve a variety of technical effects, benefits, and advantages. Agent-based automation improves memory usage by reducing the storage capacity required for data storage and improves processor efficiency by reducing the number of calls and actions. Furthermore, agent-based automation can provide the processing power of gigabytes, terabytes, petabytes, or more of data that would be impossible to achieve through human, mental, or manual processes. Additionally, dynamic decision-making can enable the use of fewer triggers and models. For example, in a scenario where RPA alone requires 100 actions, agent-based automation can significantly reduce this (e.g., to 15 actions). Context grounding can also be used to tie the AI ​​agent to the desired context within the agent-based automation. Thus, context grounding "constrains" the LLM to its relevant context.

[0046] An AI agent may have agent-type memory that evolutionarily stores user interactions, feedback, corrections, and solutions (e.g., dynamic user input from human-in-the-loop operations). In this specification, “human-in-the-loop” operations may include AI agents and RPA robots collaborating with users to receive dynamic, direct user input. As agent-type memory increases, AI agents become more autonomous, reducing the need for dynamic, direct human input and improving efficiency. Furthermore, agent-type memory may allow AI agents to learn to become more efficient, if it contains or derives more efficient solutions. For example, an AI agent may periodically process agent-type memory to perform pattern analysis in order to achieve greater autonomy.

[0047] In this specification, “agent-based memory” refers to a dynamic cache (i.e., storage) system for managing escalations and tool calls. For example, if an AI agent encounters a problem during execution, it may prompt or request user interaction or feedback to overcome the problem, store / cached that interaction or feedback, and learn from it, thereby reducing the need for repeated human input. According to one or more technical effects, benefits, and advantages, agent-based memory improves efficiency by storing solutions to common problems and minimizing potentially costly tool calls. The collaborative operation of the AI ​​agent and agent-based memory makes it possible to “bend the curve” in a direction where the need for human intervention gradually decreases as the AI ​​agent continuously learns through agent-based memory.

[0048] Generally, agent-based orchestration is implemented by a conductor application that runs one or more AOPs utilizing AI agents and RPA robots. In some embodiments, agent-based orchestration orchestrates AI agents (e.g., UiPath Agents®), third-party agents, RPA robots (e.g., UiPath Robots®), AOPs, and humans executing agent-based workflows (e.g., where human approval is required). Thus, agent-based orchestration enables the automation, modeling, and monitoring of complex business processes from start to finish. Agent-based orchestration also offers a unique ability to orchestrate RPA robots, AI agents, third-party agents, and humans across an end-to-end agent-based workflow. Agent-based orchestration is beneficial for the successful scaling of agent-based automation.

[0049] AI agents for agent-based automation are, as described above, AI model-based, operate independently of humans, and enable the execution of these agent-based automations. AI agents are also goal-oriented, making probabilistic decisions using context. Furthermore, AI agents are well-suited for ad-hoc tasks that require high adaptability. AI agents learn how to perform tasks and improve over time. AI agents can use and select various tools in achieving tasks, gathering context, and executing actions (often via RPA robots that the AI ​​agent uses as tools). In some embodiments, AI agents can generate automations by building workflows that RPA robots and / or other AI agents will execute, for example, by leveraging UiPath Autopilot™ for developers or other applications that accelerate the creation and testing of automations. For example, an AI agent can use a designer application via an API to generate another AI agent or RPA workflow, and then perform human-in-the-loop operations to address problems in the generated workflow. If there are no problems, the workflow can be deployed. AI agents can also have varying degrees of autonomy controlled by agent-based orchestration.

[0050] The AI ​​agent executes an "agent loop," using the provided tools and context to generate a dynamic plan to achieve the goal according to instructions. Once the dynamic plan is generated, the AI ​​agent utilizes an efficient execution path for that plan. If the dynamic plan includes two or more steps that can be executed in parallel, the AI ​​agent executes these steps in parallel based on available resources. Upon completion of each step, the AI ​​agent retrieves the output of that step and regenerates the next step or set of steps. In this way, the agent loop continues until the goal is achieved. Executing steps in the dynamic plan in parallel, and using ecosystem tools and context grounding, are advanced features of agent-based orchestration.

[0051] As described herein, RPA robots are rule-based, operate predictably, and make deterministic decisions. RPA robots are highly reliable and efficient and are suitable for routine tasks. RPA robots, along with AI agents, may use human-in-the-loop operations for exception handling. According to some embodiments, AI agents are more flexible, abstract, and self-deterministic than RPA robots and AOP. On the other hand, RPA robots are more stable, concrete, and manageable than AI agents and AOP. AOP processes fall between AI agents and RPA robots in terms of flexibility / stability, abstraction / concreteness, and self-determinacy / manageability.

[0052] As further explained in Figure 3, AI agents and RPA robots can find and utilize each other as tools to accomplish tasks. AI agents and RPA robots can also access and utilize various applications (e.g., via Application Programming Interfaces (APIs)). Tools can be manually configured by developers for automation, or AI agents and RPA robots can discover and utilize tools at runtime.

[0053] In some embodiments, AI agents, AOPs, and RPA robots work collaboratively with users (e.g., human-in-the-loop) to enable faster, more consistent, and more informed decision-making. Furthermore, the use of AI agents, AOPs, and RPA robots increases the amount of work that humans can accomplish because they can undertake additional repetitive, monotonous, and ad-hoc tasks on a scale that would be impossible for humans to handle. If an AI agent, AOP, or RPA robot encounters an exception, humans can make the necessary decisions. Thus, humans can focus on their roles as supervisors, decision-makers, and organizational leaders.

[0054] AI models provide AI agents with the ability to reason, plan, create, and make autonomous decisions. AI models can also be used by RPA robots in task-specific activities such as document processing and data analysis. AI models can be enhanced with business-specific content and context (e.g., from a collection of corporate context repositories), which improves the accuracy and results of the AI ​​model. AI models can be applied individually or simultaneously, depending on the complexity of the task. AI model selection can be from RPA vendor model libraries, third-party models, and BYOM (Bring Your Own Model) options (see, for example, U.S. Patents 11,738,453 and 11,748,479).

[0055] The hyperautomation system 100 includes user computing systems such as a desktop computer 102, a tablet 104, and a smartphone 106. However, any user computing system, such as a smartwatch, laptop computer, server, or Internet of Things (IoT) device, can be used without departing from the scope of the present invention. Also, although three user computing systems are shown in Figure 1, any number of user computing systems can be used without departing from the scope of the present invention. For example, in some embodiments, tens, hundreds, thousands, or millions of user computing systems may be used. User computing systems may be used actively by a user or may operate automatically with little or no user input.

[0056] As disclosed herein, in some embodiments, there are three types of automation: (1) agent-based automation implemented by each AI agent, (2) RPA implemented by each RPA robot, and (3) composite automation where a combination of AI agents and RPA robots achieves a more complex overall task. Automations 110, 112, and 114 may include, but are not limited to, those performed by RPA robots and / or AI agents. These may be performed individually or to achieve a larger composite automation. Other processes, such as listeners, may also be implemented. These processes may be implemented as standalone applications, subprocesses of other applications, parts of an operating system, other appropriate software and / or hardware, or any combination thereof. In fact, in some embodiments, the logic of a process is partially or completely implemented by physical hardware.

[0057] Each user computing system 102, 104, and 106 runs automations 110, 112, and 114, respectively (implemented by, for example, RPA robots, AI agents, etc.). In some embodiments, automations 110, 112, and 114 can be stored remotely (for example, on a server 130 or database 140 and accessed via network 120) and loaded and executed by RPA robots and / or AI agents. Database 140 may store structured data and / or unstructured data, although RPA typically requires the former. RPA automations may exist as scripts (e.g., Extensible Markup Language (XML), Extensible Application Markup Language (XAML), etc.) or compiled as machine-readable code (e.g., dynamic link libraries). In the case of AI agents, agent-type automations may be generated based, for example, on a plain text description of a desired target.

[0058] The listener monitors and records data about user operations in each computing system and / or the operation of the unattended computing system, and transmits this data to the core hyperautomation system 120 via a network (e.g., a local area network (LAN), a mobile communication network, a satellite communication network, the internet, or any combination thereof). This data may include, but is not limited to, buttons clicked, mouse movement positions, text entered into fields, whether one window is minimized and another is opened, and applications associated with windows. In certain embodiments, data from the listener may be transmitted periodically as part of heartbeat messages. In some embodiments, data may be transmitted to the core hyperautomation system 120 after a predetermined amount of data has been collected, after a predetermined time has elapsed, or both. One or more servers, such as server 130, receive the data from the listener and store it in a database, such as database 140.

[0059] If automations 110, 112, and 114 are RPA, these automations may execute logic developed within the workflow at design time. A workflow may consist of a set of steps defined as “activities,” which are executed sequentially or in other logical flows. Each activity may include actions such as clicking a button, reading a file, or writing to a log panel. In some embodiments, workflows can be nested or embedded.

[0060] Long-running RPA workflows in several embodiments are master projects supporting service orchestration, human-in-the-loop, and long-running transactions in unattended environments. See, for example, U.S. Patent No. 10,860,905, which is incorporated herein by reference in its entirety. Human-in-the-loop is involved when a particular process requires human input (e.g., dynamic direct user input) for exception handling, approval, or verification before proceeding to the next activity. In this case, the execution of the process is paused, and the RPA robot is released until the task of the human-in-the-loop portion is completed.

[0061] Long-running workflows can support workflow fragmentation via persistence activities and, combined with invocation process activities and non-user interaction activities, can orchestrate human-in-the-loop tasks with RPA robot tasks. In some embodiments, multiple or numerous computing systems may participate in the execution of the logic of the long-running workflow. Long-running workflows may run within a session to facilitate fast execution. In some embodiments, long-running workflows can orchestrate background processes that may include activities that make API calls and operate within the long-running workflow session. These activities may be invoked by invocation process activities in some embodiments. Processes with user interaction activities operating within a user session may be invoked by starting a job from a conductor activity (conductors will be described in more detail later). In some embodiments, the user may interact with the conductor through tasks that require form completion. Activities may include causing the RPA robot to wait for the form task to complete, after which the long-running workflow can be resumed.

[0062] One or more of the automations 110, 112, and 114 communicate with the core hyperautomation system 120. In some embodiments, the core hyperautomation system 120 may run conductor applications on one or more servers, such as server 130. Although one server 130 is shown for illustrative purposes, multiple or many servers located close to each other, or multiple or many servers in a distributed architecture, can be used without departing the scope of the invention. For example, one or more servers may be provided for conductor functions, AI / ML model provisioning, authentication, governance, and / or any other appropriate functions, without departing the scope of the invention. In some embodiments, the core hyperautomation system 120 may incorporate, or be part of, a public cloud architecture, a private cloud architecture, a hybrid cloud architecture, etc. In certain embodiments, the core hyperautomation system 120 may host multiple software-based servers on one or more computing systems, such as server 130. In some embodiments, one or more servers of the core hyperautomation system 120, such as server 130, may be implemented via one or more virtual machines (VMs).

[0063] In some embodiments, one or more of the automations 110, 112, 114 may invoke one or more AI / ML models 132 that are deployed on or accessible by the core hyperautomation system 120 and trained to perform various tasks. For example, the AI / ML models 132 may include models trained to explore various application versions, models that perform computer vision (CV), models that perform optical character recognition (OCR), models that generate user interface (UI) descriptors, models that provide suggestions for the next activity or sequence of activities in an RPA workflow, models that perform semantic matching, models that perform natural language processing (NLP), and models that generate or modify code and / or RPA workflows. The AI / ML models may be trained with labeled data that includes, for example, elements from data sources (web pages, forms, scanned documents, application interfaces, screens, etc.), previously created RPA workflows, screenshots of various application screens for various versions and their corresponding UI elements, and libraries of UI objects. The AI / ML model 132 can be trained to achieve a desired confidence threshold while avoiding overfitting to a given set of training data. In general, UI elements, UI descriptors, applications, and application screens can be considered UI objects.

[0064] The AI / ML model 132 can be trained for any suitable purpose without departing from the scope of the invention, as will be described in more detail later. In some embodiments, two or more AI / ML models 132 can be chained together (e.g., in series, parallel, or a combination thereof) so that they collectively provide a collaborative output. The AI / ML model 132 can perform or assist in CV, OCR, document processing and / or document understanding, semantic learning and / or semantic analysis, analytical prediction, process discovery, task mining, testing, automated RPA workflow generation, sequence extraction, cluster detection, speech-to-text translation, NLP, semantic matching, and any combination thereof. However, any number and / or types of AI / ML models can be used without departing from the scope of the invention. By using multiple AI / ML models, for example, the system can build a whole picture of what is happening on a given computing system. For example, one AI / ML model may perform OCR, another model may detect buttons, and yet another model may compare sequences. Patterns may be determined individually by one AI / ML model or collectively by multiple AI / ML models. In certain embodiments, one or more AI / ML models are deployed locally on at least one of the computing systems 102, 104, and 106.

[0065] In some embodiments, multiple AI / ML models 132 may be used. Each AI / ML model 132 is an algorithm (or model) executed on data, and the AI / ML model itself may be, for example, a deep learning neural network (DLNN) consisting of artificial "neurons" trained on training data. In some embodiments, the AI / ML model 132 has multiple layers that perform various functions such as statistical modeling (e.g., Hidden Markov Models (HMMs)) and may utilize deep learning techniques (e.g., Long Short-Term Memory (LSTM) deep learning, encoding of previous hidden states, etc.) to perform the desired function.

[0066] In some embodiments, the hyper-automation system 100 may provide four main sets of functions: (1) discovery, (2) automation construction, (3) management, and (4) engagement. Automation (e.g., running on a user computing system, server, etc.) may, in some embodiments, be performed by, for example, an RPA robot, AOP, or AI agent, and may provide any of the functions described herein. For example, an RPA robot may include a manned robot, an unmanned robot, and / or a test robot. A manned robot assists with tasks in collaboration with a user (e.g., via UiPath Assistant®). An unmanned robot operates independently of the user, runs in the background, and may not be aware of the user. A test robot executes test cases against an application or RPA workflow. In some embodiments, test robots may run in parallel on multiple computing systems.

[0067] The discovery function can discover various opportunities for automating business processes and provide automated recommendations. This function may be implemented by one or more servers, such as server 130. In some embodiments, the discovery function may include providing an automation hub, process mining, task mining, and / or task capture. The automation hub (e.g., UiPath Automation Hub®) may provide a mechanism for managing automation deployments with visibility and control. For example, automation ideas may be crowdsourced from employees via a submission form. Feasibility and return on investment (ROI) calculations for automating these ideas may be provided, documentation for future automations may be collected, and collaboration may be provided to accelerate the process from automation discovery to build.

[0068] Process mining (e.g., via UiPath Automation Cloud® and / or UiPath AI Center®) refers to the process of collecting and analyzing data from applications (e.g., enterprise resource planning (ERP) applications, customer relationship management (CRM) applications, email applications, call center applications, etc.) to reveal what end-to-end processes exist within an organization, how to effectively automate them, and what impact such automation will have. This data may be collected, for example, by listeners from user computing systems 102, 104, and 106 and processed by servers such as server 130. In some embodiments, one or more AI / ML models 132 may be used for this purpose. This information may be exported to an automation hub to expedite implementation and avoid manual information transfer. The objective of process mining may be to increase business value by automating processes within an organization. Examples of objectives for process mining include, but are not limited to, increased profits, improved customer satisfaction, regulatory and / or contractual compliance, and improved employee efficiency.

[0069] Task mining (e.g., via UiPath Automation Cloud® and / or UiPath AI Center®) identifies and aggregates workflows (e.g., employee workflows), then applies AI to reveal patterns and variations in routine tasks, and scores such tasks in terms of ease of automation and potential savings (e.g., time and / or cost savings). One or more AI / ML models 132 may be used to reveal repetitive task patterns in the data. Repetitive tasks suitable for automation can then be identified. In some embodiments, this information may first be provided by a listener and analyzed on a server of the core hyperautomation system 120, such as a server 130. Findings from task mining (e.g., XAML process data) may be exported to process documentation or a designer application such as UiPath Studio® for faster automation creation and deployment. Task mining in some embodiments may include taking screenshots with user actions (e.g., mouse click locations, keyboard input, application windows and graphical elements the user was interacting with, timestamps of interactions, etc.), collecting statistical data (e.g., execution time, number of actions, number of text inputs, etc.), editing and annotating screenshots, and specifying the types of actions to be recorded.

[0070] Task capture (e.g., via UiPath Automation Cloud® and / or UiPath AI Center®) automatically documents human-operated processes as users work on them, or provides a framework for unattended processes. Such documentation may include automated tasks in the form of Process Definition Documents (PDDs), skeletal workflows, captures of actions for each part of the process, recordings of user actions, and automatic generation of comprehensive workflow diagrams including details for each step, as well as Microsoft Word® documents, XAML files, etc. In some embodiments, build-ready workflows can be directly exported to designer applications such as UiPath Studio®. Task capture can simplify the requirements gathering process for both subject matter experts describing processes and Center of Excellence (CoE) members providing production-quality automation.

[0071] The construction of automation can be achieved through designer applications (e.g., UiPath Studio®, UiPath StudioX®, or UiPath Studio Web®). For example, developers in the RPA development facility 150 can use the designer application 154 on the computing system 152 to build and test agent-based automation, RPA, AOP, and / or hybrid automation for various applications and environments such as web, mobile, SAP®, and virtualized desktops. Developers can also build AOP. For example, developers can create automations that are executed by RPA robots, AI agents, AOP, or combinations thereof. API integrations for various applications, technologies, and platforms can be provided. Predefined activities, drag-and-drop modeling, and workflow recorders can facilitate automation with minimal coding. Document understanding capabilities can be provided via drag-and-drop AI skills that invoke one or more AI / ML models 132 for data extraction and interpretation. Such automations can handle virtually any document type and format, including tables, checkboxes, signatures, and handwritten documents. Once the data has been validated or exceptions have been handled, this information can be used to retrain the corresponding AI / ML model, improving its accuracy over time.

[0072] The designer application 154 may be designed to invoke one or more trained AI / ML models 132 on the server 130 and / or one or more generated AI models 172 in a cloud environment via the network 120 (e.g., a local area network (LAN), a mobile communication network, a satellite communication network, the internet, or any combination thereof) to assist in the automated development process. In some embodiments, one or more AI / ML models may be packaged with the designer application 154 or stored locally on the computing system 152.

[0073] In some embodiments, one or more of the designer application 154 and the AI / ML model 132 may be configured to use an object repository stored in the database 140. See, for example, U.S. Patent No. 11,748,069, which is incorporated herein by reference in its entirety. Generally, an object repository is a storage mechanism used by automation for images, text, semantic data, taxonomic associations, ontological associations, UI objects, etc. For example, an object repository may include a library of UI objects that can be used to develop RPA workflows via the designer application 154. The object repository may be used for UI automation to add UI descriptors to activities in the workflow of the designer application 154. In some embodiments, one or more of the AI / ML model 132 may generate new UI descriptors and add them to the object repository in the database 140.

[0074] Once the automation is complete in the designer application 154, it can be exposed on the server 130 and pushed to computing systems 102, 104, 106, etc. For example, as new UI descriptors are created and / or existing UI descriptors are modified, a global repository of a shareable and collaborative UI object library can be built for all automation. Regarding the object repository, classification systems and ontologities may be used. A classification system is a hierarchical structure of subcategories. An ontology is a formal representation of a knowledge domain, including concepts, characteristics, and the relationships between them. In an ontology, the relationships between categories are not necessarily hierarchical, and their ontological relationships can span multiple screens of an application.

[0075] For example, integrated services can enable developers to seamlessly combine UI automation and API automation. Automation, such as any type of automation described herein, can be built to require APIs or to span both API and non-API applications and systems. A repository (e.g., UiPath Object Repository®) or marketplace (e.g., UiPath Marketplace®) for pre-built automation templates and solutions may be provided, enabling developers to automate a wide variety of processes more quickly. Thus, when building automation, the hyperautomation system 100 may provide a user interface, development environment, API integration, pre-built and / or custom-built AI / ML models, development templates, an integrated development environment (IDE), and advanced AI capabilities. In some embodiments, the hyperautomation system 100 may enable the development, deployment, management, configuration, monitoring, debugging, and maintenance of RPA robots and AI agents, which may provide automation for the hyperautomation system 100.

[0076] In some embodiments, components of the hyperautomation system 100, such as a designer application and / or an external rule engine, provide support for managing and enforcing governance policies to control the various functions provided by the hyperautomation system 100. Governance is the ability of an organization to set policies to prevent users from developing automations (e.g., RPA robots and / or AI agents) that can perform actions that could harm the organization, such as violating the General Data Protection Regulation (GDPR) of the European Union, the Healthcare Portability and Accountability Act (HIPAA) of the United States, or the terms of use of third-party applications. Because developers may create automations that violate privacy laws, terms of use, etc., during the execution of the automation, in some embodiments, access control and governance restrictions are implemented at the level of the robot and / or robot design application. This provides an additional level of security and compliance in the automation process development pipeline in some embodiments, which can prevent developers from relying on unauthorized software libraries that could introduce security risks or that could operate in a manner that violates policies, regulations, privacy laws and / or privacy policies. See, for example, U.S. Patent No. 11,733,668. This document is incorporated herein by reference in its entirety.

[0077] The management functions can provide management, deployment, and optimization of automation across the entire organization. In some embodiments, the management functions may include orchestration, test management, AI capabilities, and / or insights. The management functions of the hyperautomation system 100 can also serve as an integration point with third-party solutions and applications for automation applications and / or RPA robots. The management capabilities of the hyperautomation system 100 may include, but are not limited to, facilitating the provisioning, deployment, configuration, queuing, monitoring, logging, and interoperability of RPA robots and / or AI agents.

[0078] Conductor applications such as UiPath Orchestrator® (which in some embodiments may be provided as part of UiPath Automation Cloud®, or as a cloud-native single-container suite on-premises, in a VM, in a private or public cloud, in a Linux® VM, or via UiPath Automation Suite®) provide orchestration capabilities for deploying, monitoring, optimizing, scaling, and securing RPA robots and / or AI agent deployments. A test suite (e.g., UiPath Test Suite®) may provide test management for monitoring the quality of deployed automations. A test suite may facilitate test planning and execution, requirements fulfillment, and defect traceability. A test suite may include comprehensive test reporting.

[0079] Analytics software (e.g., UiPath Insights®) can track, measure, and manage the performance of deployed automations. Analytics software can align automation operations with specific key performance indicators (KPIs) and strategic outcomes for the organization. Analytics software can present results in a dashboard format for easier understanding by human users.

[0080] A data service (e.g., UiPath Data Service®) can store data in a single, scalable, and secure location with a drag-and-drop storage interface, for example, and can ingest data in a single location. Several embodiments can provide low-code or no-code data modeling and storage for automation while ensuring seamless access to data, enterprise-grade security, and data scalability. AI functionality can be provided by an AI Center (e.g., UiPath AI Center®), which facilitates the integration of AI / ML models into automation. Pre-built AI / ML models, model templates, and various deployment options can make this functionality accessible even to non-data scientists. Deployed automations (e.g., RPA robots) can invoke AI / ML models, such as AI / ML model 132, from the AI ​​Center. The performance of AI / ML models can be monitored and trained and improved using human-validated data, such as that provided by a data review center 160. Human reviewers can provide labeled data to the core hyper-automation system 120 via a review application 164 on a computing system 162. For example, a human reviewer may verify the accuracy of predictions made by AI / ML model 132 and / or generative AI model 172, and provide corrections if necessary. The human reviewer may also provide dynamic direct user input to the AI ​​agent (e.g., within the scope of human-in-the-loop operations), and the responses and corrections provided by the human reviewer may be used to train the AI ​​agent to make the LLM used more accurate. In other words, this dynamic input may be stored as training data for retraining AI / ML model 132 and / or generative AI model 172, for example, in a database such as database 140. The AI ​​center may then schedule and execute training jobs to train a new version of the AI / ML model using the training data.Both positive and negative examples are saved and can be used to retrain the AI / ML model 132 and / or the generative AI model 172.

[0081] The engagement feature brings humans and automation together as a single team for a desired process, enabling seamless collaboration. In some embodiments, low-code applications can be built (e.g., via UiPath Apps®), which can connect browser tabs, legacy software, and even those lacking APIs. For example, applications can be quickly created via a web browser using a rich drag-and-drop control library. A single application can connect to a single automation or multiple automations.

[0082] An action center (e.g., UiPath Action Center®) provides a simple and efficient mechanism for handing over processes from automation to humans and vice versa. Humans may provide approvals or escalations, handle exceptions, etc. Automation can then perform automated functions of a given workflow.

[0083] A local assistant may be provided as a launchpad for users to initiate automations (e.g., UiPath Autopilot®). Such an assistant may also provide semantic cut-and-paste functionality (e.g., UiPath Clipboard AI®). See, for example, U.S. Patent No. 12,124,806 and U.S. Patent Application Publications 2023 / 0107316, 2023 / 0415338, and 2024 / 0220581. This functionality may be provided, for example, within a tray provided by the operating system, and may allow users to interact with RPA robots and RPA robot-driven applications on their computing system. The interface may list automations approved for a given user and allow the user to run them. These may include readily available automations from an automation marketplace, automations from an internal automation store within an automation hub, etc. When automations are executed, they may run as local instances in parallel with other processes on the computing system, so that the user can use the computing system while the automations are performing their actions. In certain embodiments, the assistant is integrated with a task capture function, allowing the user to document their processes that will soon be automated from the assistant launchpad.

[0084] In some embodiments, the hyper-automation system 100 can provide end-to-end measurement and governance of automation programs of any scale. As described above, analytics can be used to understand the performance of automation (e.g., via UiPath Insights®). Data modeling and analysis using any combination of available business metrics and operational insights can be used for various automation processes. Custom-designed and pre-built dashboards enable data visualization across desired metrics, discovery of new analytical insights, tracking of performance metrics, understanding the ROI of automation, telemetry monitoring on user computing systems, detection of errors and anomalies, and debugging of automation. An automation management console (e.g., UiPath Automation Ops®) may be provided, which allows for the management of automation throughout the entire automation lifecycle. Organizations can manage how automations are built, what users can do with them, and which automations users have access to.

[0085] In some embodiments, the hyperautomation system 100 provides an iterative platform. Processes are discovered, automation is built, tested, deployed, performance is measured, the use of automation is easily made available to users, feedback is obtained, AI / ML models are trained and retrained, and the process can be repeated. This results in a more robust and effective set of automations.

[0086] In some embodiments, generative AI models are used as described above. For example, an AI agent utilizes a generative AI model. A generative AI model can generate various types of content, such as text, images, audio, and synthetic data. Possible types of generative AI models include, but are not limited to, LLMs, generative adversarial networks (GANs), diffusion models, flow-based models, variational autoencoders (VAEs), and transformers. For example, in the case of LLMs, NLP models such as word2vec, BERT, GPT-3, and ChatGPT may be used in some embodiments to facilitate word semantic understanding and provide more accurate and human-like responses. These models may be part of an AI / ML model 132 hosted on server 130. For example, a generative AI model may be trained on a large text information corpus to perform semantic understanding, understanding the properties of things present on the screen from text, and automatic code generation. An AI agent may use such a generative AI model. In certain embodiments, generative AI models 172 provided by existing cloud ML service providers such as OpenAI®, Google®, Amazon®, Microsoft®, IBM®, Nvidia®, and Meta® may be used and trained to provide such functionality. In generative AI embodiments where the generative AI model 172 is remotely hosted, the server 130 may be configured to integrate with a third-party API that enables it to send requests containing the necessary input information to the generative AI model 172 and receive responses (e.g., semantic correspondences of fields between application versions, classification of application types on a screen, responses to natural language queries from the user). Such embodiments may provide a more advanced and sophisticated user experience and may provide access to the state-of-the-art NLP and other ML capabilities offered by these companies.

[0087] One aspect of generative AI models in some embodiments is the use of transfer learning. In transfer learning, a pre-trained generative AI model, such as a Language Language Model (LLM), is fine-tuned for a specific task or domain. This allows the LLM to leverage knowledge already learned during initial training and adapt it to its specific application. In the case of an LLM, the pre-training stage typically involves training the LLM on a large text corpus consisting of billions of words. During this stage, the LLM learns word and phrase relationships, enabling it to generate consistent, human-like responses to text-based input. The output of this pre-training stage is an LLM with a high level of understanding of fundamental patterns in natural language.

[0088] In the fine-tuning phase, a pre-trained LLM is adapted to a specific task or domain by training it on a smaller, task-specific dataset. For example, in some embodiments, the LLM may be trained to analyze specific types or combinations of data sources to improve its accuracy regarding their content. This data may include, but is not limited to, prompt tuning or instruction tuning, where the model is specifically trained to better understand and follow certain types of instructions or prompts. This improves its ability to perform a specific task when given appropriate instructions. Such information may be provided as part of the training data, and the LLM may learn to focus on these domains and more accurately identify the data elements contained within them. Fine-tuning allows the LLM to learn the nuances of the task or domain, such as specific vocabulary and syntax used in that domain, without requiring the large amount of data needed to train the LLM from scratch. By leveraging the knowledge learned in the pre-training phase, a fine-tuned LLM can achieve state-of-the-art performance on a specific task with relatively small amounts of training data.

[0089] LLM can utilize vector databases. Vector databases index, store, and provide access to structured or unstructured data (e.g., text, images, time-series data) along with their vector embeddings. Data such as text can be tokenized, in which case single characters, words, or sequences of words are parsed from text into tokens. These tokens are then "embedded" in vector embeddings, which are numerical representations of this data. Vector databases enable LLM to search and retrieve similar objects quickly and at scale in a production environment, which is not possible with manual processes.

[0090] AI and ML enable the numerical representation of unstructured data in vector embeddings without losing its semantic meaning. A vector embedding is a long sequence of numbers, each describing a feature of the data object it represents. Similar objects are grouped together in close proximity within the vector space. In other words, the more similar the objects, the closer the vector embeddings representing them are. Similar objects can be found using vector search, similarity search, or semantic search. The distance between vector embeddings can be calculated using various techniques, including, but not limited to, squared Euclidean distance or L2-squared distance, Manhattan distance or L1 distance, cosine similarity, dot product, and Hamming distance. It may be beneficial to select the same metric used to train the AI / ML model.

[0091] Vector indexing can be used to organize vector embeddings so that data can be retrieved efficiently. Calculating the distance between one vector embedding and all other vector embeddings in a vector database using the k-nearest neighbors (kNN) algorithm can be computationally expensive, as the required computation increases linearly (O(n)) with respect to the number of dimensions and data points when the number of data points is large. Finding similar objects using an approximate nearest neighbor (ANN) approach is more efficient. Since the distances between vector embeddings are calculated in advance and similar vectors are organized and stored in close proximity to each other (e.g., in clusters or graphs), similar objects can be found much faster. This process is called "vector indexing." ANN algorithms that can be used in several embodiments include, but are not limited to, clustering-based indexing, proximity-graph-based indexing, tree-structure-based indexing, hash-based indexing, and compression-based indexing.

[0092] Figure 2 shows a portion of the combined capabilities 200 of an AI agent 210 and an RPA robot 220 according to one embodiment of the present invention. The AI ​​agent 210 is configured to process natural language instructions and achieve expected goals based thereon, to execute with dynamic decision-making or dynamic flow control with self-correcting capabilities, to store information in long-term memory to evaluate its own performance, and to learn from human-in-the-loop and its own performance during execution. The RPA robot 220 may be used by the AI ​​agent 210 to respond to triggers (e.g., triggers from conductor applications such as UiPath Orchestrator®), to respond based on context (i.e., the RPA robot 220 can retrieve information from the context and perform deterministic steps such as updating a document based on the retrieved context information; alternatively, the agent 210 can use the retrieved context to update a dynamic plan and perform the next steps to achieve the goal according to the instructions), to leverage AI models (e.g., CV models, document processing models, speech-to-text models, OCR models, etc.), to leverage RPA tools (e.g., using tools available within the RPA ecosystem such as full automation, workflows within automation, integrated service connector calls for third-party and first-party services, RPA designer application activities, LLM calls, etc.), and to perform actions that the RPA robot can take based on input from the AI ​​agent (i.e., using the RPA robot as a tool). The AI ​​agent 210 can also update its own memory, update its plan to achieve goals according to instructions, self-evaluate and learn from its actions, self-repair when it encounters obstacles, and take actions to escalate to a human when help is needed.

[0093] As described above, in some embodiments, agent-based automation can achieve a variety of technical effects, benefits, and advantages. Agent-based automation improves memory usage by reducing the amount of storage required for data and improves processor efficiency by reducing the number of calls and actions. Furthermore, agent-based automation potentially offers the ability to process gigabytes, terabytes, petabytes, or more of data that would be impossible with human mental or manual processes. Additionally, dynamic decision-making can enable the use of fewer triggers and models. For example, while RPA alone might require 100 actions in a given scenario, agent-based automation can significantly reduce this (to, for example, 15 actions). Context grounding can also be used to tie AI agents to the desired context for agent-based automation. This "constrains" the LLM to the relevant context.

[0094] As used herein, “context grounding” refers to a methodology that improves models such as LLMs by integrating enterprise-specific information with pre-trained knowledge, enabling accurate responses to specialized or up-to-date queries. In some embodiments, context grounding extends LLM responses using external data to obtain responses that the LLM would not inherently know, answering queries based on the provided context. For example, because proprietary industry jargon and complex document structures can pose challenges to ensuring effective search and semantic matching, context grounding addresses this by providing precise chunking of documents so that relevant information (e.g., information derived from proprietary industry jargon and complex document structures) can be passed to the LLM without noise. As an additional example, context grounding improves LLM responses by providing enhanced extract and search techniques tailored to diverse industries and applications (e.g., techniques tailored to proprietary industry jargon and complex document structures).

[0095] Figure 3 shows a pool 300 of AOPs, AI agents, RPA robots, and applications according to one embodiment of the present invention. The AOP pool 310 includes AOPs 1, 2, ..., P which implement business processes. As described above, AOPs may be implemented as BPMNs, which are executed by an AOP execution engine such as Temporal®. AOPs may use AI agents and / or RPA robots to execute parts of business processes.

[0096] The AI ​​agent pool 320 includes AI agents 1, 2, ..., I, trained to perform various tasks such as billing investigations, problem-solving with human employees, and summarizing policies and technical specifications. The RPA robot pool 330 includes RPA robots 1, 2, ..., J, which perform various automations such as UI automation, semantic matching automation, and form entry automation. The application pool 340 includes applications 1, 2, ..., K, with which the AI ​​agents and / or RPA robots can interact. For example, these applications may include CRM applications, billing applications, payroll applications, banking applications, web applications, legacy system applications, word processor applications, spreadsheet applications, email applications, etc. The AI ​​agents, RPA robots, and applications may reside on a single computing system, or on multiple or numerous computing systems. The AOP typically resides on the cloud or other server side and, in some embodiments, may reside on the same computing system as the conductor application 350.

[0097] AOP can trigger or invoke AI agents and RPA robots via the conductor application 350. AI agents and RPA robots can also trigger or invoke each other via the conductor application. For example, to invoke an RPA robot, an AI agent may make a "Start Job" call in the conductor application 350. Note that the RPA robot is deployed as automation controlled by the conductor application 350. AI agents and RPA robots can also trigger or invoke specific applications. For example, through information obtained from human-in-the-loop actions, an AI agent may dynamically learn which RPA robots, other AI agents, and / or applications to trigger or invoke in order to accomplish a task. For example, an AI agent may learn to trigger an RPA robot via the conductor application 350 to fill out and submit a web form. The AI ​​agent may also learn to open Microsoft Excel® and enter form information into the appropriate tabs, or open and update a payroll application, etc. Furthermore, it may learn to call or trigger an email resolution AI agent via the conductor application 350 to contact a human customer service representative of the bank in the event of a problem. In some embodiments, the technical effects, benefits, and advantages may be similar to those described above with respect to Figures 1 and 2.

[0098] AI agents may belong to a tenant so that AI agents and RPA robots can find each other. A designer application may call a conductor to retrieve a list of available RPAs. In some embodiments, there are three ways to obtain the automation capability: (1) a user provides a description of what the automation will do when creating a workflow in a designer application; (2) an AI agent and ML technology generate a summary of what a given workflow will do; and (3) a developer describes what the automation will do in a designer application. A conductor application may also have a list of which applications are available for a given AI agent and RPA robot. In other words, descriptions of available AI agents, RPA robots, and / or applications are derived or provided by the AI ​​agent, ML technology, or user.

[0099] Figures 4A and 4B show an example of an agent service interface 400 according to one embodiment of the present invention. Referring to Figure 4A, the agent answers questions regarding a policy document provided within context grounding. The agent instruction pane 410 contains a user-entered natural language description of what the AI ​​agent is intended to do. The user prompt 420 allows the developer to enter the content of the user prompt in the content field 422 as needed. The tool dropdown 430 allows the developer to select the tools the AI ​​agent will use, such as using an API for the application or calling an RPA robot to perform RPA.

[0100] The context dropdown 440 allows developers to configure the context grounding for the AI ​​agent. The context configuration pane 442 allows developers to provide a description via the description field 444, and an Elastic Common Schema (ECS) index for a specific policy document containing information about contracts, regulations, and what to do, in this example, via the ECS index field 446. Developers can also add additional context 450 to further complement the context grounding. An escalation option to a human may be configured via the dropdown 460.

[0101] The query field 470 allows the user to provide queries to be responded to by the AI ​​agent. When the user clicks the execute button 480, the AI ​​agent executes the queries. Moving to Figure 4B, the results are shown in the execute pane 490 while the AI ​​agent retrieves and outputs them.

[0102] Figure 5 shows an example of an AOP development interface 500 according to one embodiment of the present invention. The AOP development interface 500 includes AOP components 510, an AI agent 520, and an RPA 530 that a user can select when developing a business process. These are selected and dragged to a canvas 540 where the user can manually develop the AOP. In this example, customer data is retrieved from a database, and the AI ​​agent is invoked to analyze the customer data to determine the customer type (e.g., very likely to pay, likely to be late on payments, frequently unemployed, etc.), thereby implementing a credit check. The type is then provided to an RPA robot that takes this information into account when performing the credit check. Alternatively, the AOP developer can enter a description of the business process in field 550 and click the generate button 560. This text is provided to the LLM, which understands the requested business process and attempts to automatically create an AOP workflow. The AOP developer can then edit the AOP workflow as desired.

[0103] Figure 6 shows an example of an RPA development interface 600 according to one embodiment of the present invention. The RPA development interface 600 includes RPA components 610 that a user can select when developing an RPA workflow. These can be selected and dragged onto the canvas 620. Alternatively, an RPA developer can enter a description of the RPA in the field 630 and click the generate button 640. This text is provided to the LLM, which understands the requested business process and attempts to automatically create an RPA workflow. The developer can then edit the RPA workflow as desired. Note that the functions shown and described with respect to Figures 4A, 4B, 5, and 6 may, in some embodiments, be provided in a single designer application.

[0104] Figure 7 shows an end-to-end AI agent, RPA robot, and AOP development and deployment system 700 according to one embodiment of the present invention. A designer application 710 enables developers to design AOP, AI agents, and RPA workflows. Once these are tested and validated, they are packaged and published to the automation database 720.

[0105] The conductor application 730 manages these automations, as well as the deployment of AOPs, AI agents, and RPA robots. When a human user or software process 732 requests the execution of an AOP, the conductor application 730 sends a start job command to the AOP engine 740, which then selects and starts the appropriate automation from AOP 742. When executing AOP 742, it may encounter steps implemented by an AI agent 750 or an RPA robot 760. In this case, the AOP engine 740 interrupts the AOP workflow execution and sends a request to the conductor application 730 to send a start job request to the appropriate AI agent 750 or RPA robot 760 to perform the step in question.

[0106] When an AI agent is requested, the conductor application 730 sends a start job request to the appropriate AI agent 750. This request may include natural language text or other information provided to the conductor application 730 from the AOP engine 740. The AI ​​agent 750 then performs the step by executing LLM 752 to assist in task execution. The AI ​​agent 750 then sends task-related information (e.g., requested information, an indication that the step was completed, an indication that the step failed, etc.) to the conductor 730, which then provides this information to the AOP engine 740. The AOP engine 740 then resumes its operation.

[0107] When an RPA robot is requested, the conductor application 730 sends a start job request to the appropriate RPA robot 760. The RPA robot 760 then executes the requested RPA 762. The RPA robot 760 then sends task-related information (e.g., requested information, instructions that the step was completed, instructions that the step failed, etc.) to the conductor 730, which provides this information to the AOP engine 740. The AOP engine 740 then resumes its operation.

[0108] In some cases, human intervention may be required for AOP742, AI agent 750, or RPA762. In this case, AOP engine 740, AI agent 750, or RPA robot 760 contacts human 770 for the human-in-the-loop portion of the automation. After the human completes the task, AOP engine 740, AI agent 750, or RPA robot 760 resumes the automated portion of the automation.

[0109] Figure 8 is an architectural diagram showing an agent-based automation and RPA system 800 according to one embodiment of the present invention. In some embodiments, the agent-based automation and RPA system 800 is part of the hyperautomation system 100 in Figure 1. The agent-based automation and RPA system 800 includes a designer 810 that enables developers to design automations for AI agents and RPA robots (e.g., workflows, natural language instructions for AI agents, context grounding, tool configuration, etc.). The designer 810 can provide solutions for application integration, as well as solutions for automating third-party applications, managed information technology (IT) tasks, and business IT processes. The designer 810 can facilitate the development of automation projects, which are graphical representations of business processes. In short, the designer 810 facilitates the development and deployment of automations for RPA robots and AI agents. In some embodiments, the designer 810 may be an application that runs on the user's desktop, an application that runs remotely within a VM, a web application, etc.

[0110] As described above, automation projects enable the automation of rule-based processes by giving developers control over the execution order and relationships of custom step sets, or "activities," developed within the workflow. A commercial example of one embodiment of Designer 810 is UiPath Studio®. Each activity may include actions such as clicking a button, reading a file, or writing to a log panel. In some embodiments, workflows can be nested or embedded.

[0111] Workflow types may include, but are not limited to, sequences, flowcharts, finite state machines (FSMs), and / or global exception handlers. Sequences are particularly suitable for linear processes because they allow a flow from one activity to another without complicating the workflow. Flowcharts are particularly suitable for more complex business logic because they allow for the integration of decisions and more diverse connections of activities through multiple branching logical operators. FSMs are particularly suitable for large-scale workflows. FSMs can use a finite number of states in their execution, which are triggered by conditions (i.e., transitions) or activities. Global exception handlers are particularly suitable for determining workflow behavior and debugging processes when execution errors are encountered.

[0112] Once workflows and / or other configurations for AI agents are developed in Designer 810, the execution of business processes is orchestrated by Conductor 820, which orchestrates one or more robots 830, one or more AI agents 850, and / or one or more AOPs 870 that execute the workflows developed in Designer 810. A commercial example of one embodiment of Conductor 820 is UiPath Orchestrator®. Conductor 820 facilitates the creation, monitoring, and deployment management of resources in the environment. Conductor 820 can function as an integration point with third-party solutions and applications. As described above, in some embodiments, Conductor 820 may be part of the core hyperautomation system 120 in Figure 1.

[0113] It should be noted that the RPA robot 830 can operate independently of deterministic processes. The AI ​​agent 850 and AOP 870 can also operate independently (e.g., of non-deterministic processes), or they can utilize the RPA robot 830 or other AI agent 850 as tools to achieve part of their agent-based automation. The AI ​​agent 850 can drive a composite automation that utilizes both the RPA robot 830 and the AI ​​agent 850, or vice versa, and the AOP 870 may include such a composite automation.

[0114] The conductor 820 manages a group of robots 830 and AI agents 850, and can connect and execute RPA robots 830 and AI agents 850 from a centralized point (for example, when requested by an AOP engine implementing AOP). The types of RPA robots 830 that can be managed include, but are not limited to, manned robots, unmanned robots, development robots (similar to unmanned robots but used for development and testing purposes), and non-production robots (similar to manned robots but used for development and testing purposes). Manned robots are triggered by user events and operate in parallel with humans on the same computing system. Manned robots can be used with the conductor 820 for centralized process deployment and log recording media. Manned robots can assist human users in performing various tasks and can be triggered by user events. In some embodiments, processes on these types of robots cannot be started from the conductor 820 and / or run under a locked screen. In certain embodiments, manned robots can only be started from the robot tray or command prompt. In some embodiments, the manned robot should operate under human supervision.

[0115] Unmanned robots can operate autonomously within a virtual environment and automate many processes. They can be responsible for remote execution, monitoring, scheduling, and providing support for work queues. In some embodiments, debugging for all robot types can be performed in Designer 810. Both manned and unmanned robots can automate a wide range of systems and applications, including but not limited to mainframes, web applications, VMs, enterprise applications (e.g., those provided by SAP®, Salesforce®, Oracle®, etc.), and computing system applications (e.g., desktop and laptop applications, mobile device applications, wearable computer applications, etc.).

[0116] Conductor 820 may have, but is not limited to, various capabilities, including provisioning, deployment, configuration, queuing, monitoring, logging, and / or providing interoperability. Provisioning may include creating and maintaining connections between robots 830, AI agents 850, and / or AOP 870 and Conductor 820 (e.g., web applications). Deployment may include ensuring that the correct package versions are delivered to assigned robots 830, AI agents 850, and / or AOP for execution. Configuration may include maintaining and delivering environment and process configurations for RPA robots and AI agents. Queuing may include providing management of queues and queue items. Monitoring may include tracking identification data for robots and AI agents and maintaining user privileges. Logging may include storing and indexing logs in a database (e.g., a Structured Query Language (SQL) database or a "not only" SQL (NoSQL) database) and / or other storage mechanisms (e.g., ElasticSearch®, which provides the ability to store and query large datasets at high speed). Conductor 820 can provide interoperability by acting as a centralized communication point for third-party solutions and / or applications.

[0117] Robot 830 is an execution agent that implements the workflow built in Designer 810. A commercial example of several embodiments of Robot 830 is UiPath Robots®. In some embodiments, the RPA robot 830 installs a service managed by Microsoft Windows® Service Control Manager (SCM) by default. As a result, such an RPA robot 830 can open an interactive Windows® session under the local system account and has the authority to run Windows® services.

[0118] In some embodiments, the RPA robot 830 may be installed in user mode. For such a robot 830, this means that it has the same privileges as the user on which the given RPA robot 830 is installed. This functionality may also be available for high-density (HD) robots, thereby ensuring that the capabilities of each machine are fully utilized. In some embodiments, any type of RPA robot 830 may be configured in an HD environment.

[0119] In some embodiments, the RPA robot 830 is divided into several components, each component dedicated to a specific automation task. In some embodiments, the robot components may include, but are not limited to, an SCM-managed robot service, a user-mode robot service, an executor, an agent, and a command line. The SCM-managed robot service manages and monitors Windows® sessions and acts as a proxy between the conductor 820 and the execution host (i.e., the computing system on which the robot 830 runs). These services trust and manage the credentials of the RPA robot 830. The console application is launched by the SCM under the local system.

[0120] In some embodiments, the user-mode robot service manages and monitors Windows® sessions and acts as a proxy between the conductor 820 and the execution host. The user-mode robot service can trustfully manage the credentials of the RPA robot 830. The Windows® application can be automatically started if the SCM management robot service is not installed.

[0121] An executor can execute a given job under a Windows® session (i.e., execute a workflow). An executor can be aware of per-monitor dots per inch (DPI) settings. An agent can be a Windows® Presentation Foundation (WPF) application that displays jobs available on the system in a system tray window. Note that these agents are different from AI Agent 850. An agent can be a service client and can request to start or stop jobs and change their settings. The command line is also a service client. The command line is a console application that can request to start a job and wait for its output.

[0122] By dividing the components of robot 830 as described above, developers, support users, and computing systems can more easily execute, identify, and track what each component is doing. In this way, special behavior can be configured for each component, such as setting different firewall rules for the executor and services. In some embodiments, the executor may always be aware of the DPI setting for each monitor. As a result, workflows can be executed at any DPI, regardless of the configuration of the computing system in which they were created. In some embodiments, projects from designer 810 are also independent of the browser's zoom level. For DPI-incompatible applications, or applications that are intentionally marked as incompatible, DPI can be disabled in some embodiments.

[0123] In this embodiment, the agent-based automation and RPA system 800 is part of a hyperautomation system, such as the hyperautomation system 100 in Figure 1. Developers can use the designer 810 to build and test RPA, AOP, and AI agents that utilize AI / ML models deployed in the core hyperautomation system 840 (for example, as part of its AI center). Such an RPA robot can send inputs for the execution of the AI / ML model and receive outputs from there via the core hyperautomation system 840.

[0124] One or more of the RPA robots 830 may be listeners, as described above. These listeners may provide the core hyperautomation system 840 with information about what the user is doing when using their computing system. This information can then be used by the core hyperautomation system for process mining, task mining, task capture, and the like.

[0125] To enable users to launch RPA local robots, an assistant / chatbot (not shown) may be provided on the user's computing system. The assistant / chatbot may be located, for example, in the system tray. The chatbot may have a user interface so that the user can see the text within the chatbot. Alternatively, the chatbot may not have a user interface and may run in the background, waiting for user voice input using the computing system's microphone.

[0126] In some embodiments, data labeling may be performed by a user of the computing system on which the RPA robot or AI agent is running, or on another computing system from which the robot or AI agent provides information. For example, if a robot invokes an AI / ML model to perform CV on an image for a VM user, but the AI / ML model does not correctly identify a button on the screen, the user may draw a rectangle around the misidentified or unidentified component and, if applicable, provide text indicating the correct identification. This information is provided to the core hyperautomation system 540, which can then be used later to train a new version of the AI / ML model.

[0127] Figure 9 is an architecture diagram showing a deployed RPA system 900 according to one embodiment of the present invention. In some embodiments, the RPA system 900 may be part of the agent-based automation and RPA system 800 in Figure 8 and / or the hyperautomation system 100 in Figure 1. Note that the architecture of the deployed RPA system 900 may not be used in some embodiments. The deployed RPA system 900 may be a cloud-based system, an on-premise system, a desktop-based system providing enterprise-level, user-level, or device-level automation solutions for automating different computing processes, etc.

[0128] Without departing from the scope of the present invention, it should be noted that the client side, the server side, or both may include any desired number of computing systems. On the client side, the robot application 910 includes an executor 912, an execution agent 914, and a designer 916. However, in some embodiments, the designer 916 does not have to run on the same computing system as the executor 912 and the execution agent 914. The executor 912 is a running process. Multiple business projects may be executed simultaneously. The execution agent 914 (e.g., Windows® service) is a single point of contact for all executors 912 in this embodiment. In this embodiment, all messages are recorded in the conductor 940, which further processes them via the database server 950, the AI / ML server 960, the indexer server 970, or any combination thereof. As described above with respect to Figure 8, the executor 912 may be a robot component.

[0129] In some embodiments, an RPA robot represents an association between a machine name and a username. A robot can manage multiple executors simultaneously. On a computing system that supports the simultaneous execution of multiple interactive sessions (e.g., Windows® Server 2012), multiple robots may run concurrently, each operating within a separate Windows® session using a unique username. This is referred to above as an HD robot.

[0130] The execution agent 914 is also responsible for transmitting the robot's status (for example, periodically sending "heartbeat" messages to indicate that the robot is still functioning) and for downloading the necessary versions of packages to be executed. In some embodiments, communication between the execution agent 914 and the conductor 940 is always initiated by the execution agent 914. In notification scenarios, the execution agent 914 may open a WebSocket channel which is then used by the conductor 940 to send commands (e.g., start, stop, etc.) to the robot.

[0131] To reduce the complexity of Figure 9, it is not shown here, but it should be noted that the AI ​​agent can also interact with the conductor 940, as explained above with respect to Figures 1 and 8, for example. The conductor 940 can orchestrate the operation of the AI ​​agent. The conductor 940 can also facilitate interaction between the AI ​​agent and the AI / ML models via the AI / ML server 960, which can store and / or facilitate access to the generated AI models.

[0132] The listener 930 monitors and records data relating to user interactions with the manned computing system in which the listener 930 resides and / or the operation of the unmanned computing system. Without departing from the scope of the present invention, the listener 930 may be an RPA robot, part of an operating system, a downloadable application for the computing system, or any other software and / or hardware. In fact, in some embodiments, the logic of the listener is partially or completely implemented by physical hardware.

[0133] On the server side, the presentation layer (web application 942, Open Data Protocol (oData) Representative State Transfer (REST) ​​Application Programming Interface (API) endpoint 944, and notification and monitoring 946), the service layer (API implementation / business logic 948), and the persistence layer (database server 950, AI / ML server 960, and indexer server 970) are included. The conductor 940 includes the web application 942, the oData REST API endpoint 944, notification and monitoring 946, and the API implementation / business logic 948. In some embodiments, most operations performed by the user on the conductor 940 interface (e.g., via a browser 920) are performed by calling various APIs. Such operations include, but are not limited to, starting jobs on a robot, adding / deleting data in a queue, and scheduling jobs to run unattended, without departing from the scope of the present invention. The web application 942 is the visual layer of the server platform. In this embodiment, the web application 942 uses Hypertext Markup Language (HTML) and JavaScript (JS). However, any desired markup language, scripting language, or any other form may be used without departing from the scope of the present invention. In this embodiment, the user interacts with the web pages of the web application 942 via the browser 920 and performs various actions to control the conductor 940. For example, the user may create robot groups, assign packages to robots, analyze logs per robot and / or per process, start and stop robots, and so on.

[0134] In addition to the web application 942, the conductor 940 also includes a service layer that exposes an oData REST API endpoint 944. However, other endpoints may also be included without departing the scope of the present invention. In this embodiment, the REST API is utilized by both the web application 942 and the execution agent 914. In this embodiment, the execution agent 914 is the supervisor of one or more robots on a client computer.

[0135] The REST API in this embodiment covers configuration, logging, monitoring, and queuing functions. Configuration endpoints may be used in some embodiments to define and configure application users, permissions, robots, assets, releases, and environments. Logging REST endpoints may be used to log different information, such as errors, explicit messages sent by robots, and other environment-specific information. Deployment REST endpoints may be used to query the package version that a robot should execute when a start job command is used in conductor 940. Queuing REST endpoints may be responsible for queue and queue item management, such as adding data to the queue, retrieving transactions from the queue, and setting the transaction state.

[0136] A monitoring REST endpoint may monitor the web application 942 and the execution agent 914. The notification and monitoring API 946 may be a REST endpoint used for registering the execution agent 914, delivering configuration settings to the execution agent 914, and sending and receiving notifications between the server and the execution agent 914. In some embodiments, the notification and monitoring API 946 may also use WebSocket communication.

[0137] In some embodiments, APIs within the service layer may be accessed through the configuration of appropriate API access paths. For example, access may be based on whether the conductor 940 and the entire hyperautomation system are on-premises or cloud-based deployments. The API for the conductor 940 may provide custom methods for querying statistics about various entities registered with the conductor 940. In some embodiments, each logical resource may be an oData entity. In such entities, components such as robots, processes, and queues may have characteristics, relationships, and behaviors. In some embodiments, the conductor 940's API may be utilized by the web application 942 and / or execution agent 914 in two ways: (1) by obtaining API access information from the conductor 940, or (2) by registering an external application and using the oAuth flow.

[0138] The persistence layer in this embodiment includes three servers: a database server 950 (e.g., an SQL server), an AI / ML server 960 (e.g., a server providing AI / ML model provisioning services such as AI Center functions), and an indexer server 970. In this embodiment, the database server 950 stores the configuration of robots and AI agents, groups of robots and AI agents, AOP, associated processes, users, roles, schedules, etc. This information is managed through a web application 942 in some embodiments. The database server 950 may manage queues and queue entries. In some embodiments, the database server 950 may store messages recorded by robots and AI agents (in addition to or instead of the indexer server 970). The database server 950 may also store process mining, task mining, and / or task capture-related data received, for example, from a listener 930 installed on the client side. Although no arrow is shown between the listener 930 and the database 950, it should be understood that in some embodiments, the listener 930 can communicate with the database 950, and vice versa. This data may be stored in formats such as PDDs, images, and XAML files. Note that structured and / or unstructured data may be stored. The listener 930 may be configured to intercept user activity, processes, tasks, and performance metrics on each computing system in which it resides. For example, the listener 930 may record user activity on each computing system (e.g., clicks, typed characters, location, applications, active elements, time, etc.) and then convert it into a format suitable for provision to and storage in the database server 950.

[0139] The AI / ML Server 960 facilitates the integration of AI / ML models into automation. Pre-built AI / ML models, model templates, and various deployment options make such functionality accessible even to non-data scientists. Deployed automations (e.g., RPA robots and / or AI agents) can invoke AI / ML models from the AI / ML Server 960. AI / ML model performance can be monitored and trained and improved using human-validated data. The AI / ML Server 960 can schedule and execute training jobs to train new versions of AI / ML models. The AI / ML model server can also store and / or access generated AI models.

[0140] The AI / ML server 960 may store data relating to AI / ML models and ML packages for configuring various ML skills for users during development. As used herein, "ML skill" refers to a pre-built and trained ML model for a particular process, which may be used, for example, by automation. The AI / ML server 960 may also store data relating to algorithms and software packages for various AI / ML functions, including but not limited to document understanding techniques and frameworks, intent analysis, NLP, speech analysis, and different types of AI / ML models.

[0141] An indexer server 970, which is optional in some embodiments, stores and indexes information recorded by the robot. In certain embodiments, the indexer server 970 may be disabled by configuration settings. In some embodiments, the indexer server 970 uses ElasticSearch®, an open-source full-text search engine project. Messages recorded by the robot (e.g., those recorded using activities such as log messages or write lines) are sent to the indexer server 970 via a logging REST endpoint, where they are indexed for future use.

[0142] Figure 10 is an architectural diagram showing the relationships between a designer 1010, activities 1020, 1030, 1040, 1050, a driver 1060, an API 1070, and an AI / ML model 1080 according to one embodiment of the present invention. As described above, the developer uses the designer 1010 to develop workflows and automations to be executed by RPA robots, AI agents, and an AOP engine. The developer can design and configure RPA robot workflows 1012, design and configure agent-based automation 1014 for AI agents (e.g., providing natural language description, context grounding, tools, etc. for AI agents), and design and configure AOP 1016. See, for example, Figures 4A, 4B, 5, and 6. Various types of activities may be displayed to the developer in some embodiments. The designer 1010 may be local to the user's computing system or remote to it (e.g., accessed via a VM, or via a local web browser interacting with a remote web server). A workflow for an RPA robot may include a user-defined activity 1020, an API-driven activity 1030, an AI / ML activity 1040, and / or a UI automation activity 1050. The user-defined activity 1020 and the API-driven activity 1040 interact with the application through their respective APIs. In some embodiments, the user-defined activity 1020 and / or the AI / ML activity 1040 may call one or more AI / ML models 1080, which may be located locally on the computing system in which the robot is operating, and / or remotely from it.

[0143] Some embodiments can identify non-textual visual elements within an image, which are referred to herein as CV. However, it should be noted that in some embodiments, CV incorporates OCR. CV may be performed, at least in part, by the AI / ML model 1080. Some CV activities relating to such elements include, but are not limited to, text extraction from segmented label data using OCR, fuzzy text matching, extraction of segmented label data using ML, and comparison of extracted text within label data with ground truth data. In some embodiments, hundreds, or even thousands, of activities may be implemented in the user-defined activity 1020. However, any number and / or types of activities may be used without departing the scope of the present invention.

[0144] The UI automation activity 1050 is a subset of specialized low-level activities written in lower-level code that facilitates interaction with the screen. The UI automation activity 1050 facilitates these interactions via drivers 1060 that enable the robot to interact with desired software. For example, drivers 1060 may include operating system (OS) drivers 1062, browser drivers 1064, VM ​​drivers 1066, enterprise application drivers 1068, etc. In some embodiments, one or more AI / ML models 1080 may be used by the UI automation activity 1050 to perform interactions with computing systems. In certain embodiments, the AI / ML models 1080 may complement or completely replace the drivers 1060. In fact, in certain embodiments, drivers 1060 are not included.

[0145] Driver 1060 can interact with the OS at a low level via OS driver 1062, performing tasks such as hook discovery and key monitoring. Driver 1060 can facilitate integration with applications such as Chrome®, IE®, Citrix®, and SAP®. For example, a "click" activity can perform the same role in these different applications via driver 1060.

[0146] Figure 11 is an architectural diagram showing a computing system 1100 configured to implement embodiments of the present invention. In some embodiments, the computing system 1100 may be one or more computing systems illustrated and / or described herein. In certain embodiments, the computing system 1100 may be part of a hyperautomation system as shown in Figures 1 and 8. The computing system 1100 includes a bus 1105 or other communication mechanism for transmitting information and a processor 1110 coupled to the bus 1105 for processing information. The processor 1110 may be any kind of general-purpose or purpose-specific processor, including a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a graphics processing unit (GPU), multiple instances thereof, and / or any combination thereof. The processor 1110 may also have multiple processing cores, at least some of which may be configured to perform specific functions. In some embodiments, multiple parallel processing may be used. In certain embodiments, at least one of the processors 1110 may be a neuromorphic circuit including processing elements that mimic biological neurons. In some embodiments, neuromorphic circuits may not require the typical components of a von Neumann computing architecture.

[0147] The computing system 1100 further includes memory 1115 for storing information and instructions executed by the processor 1110. Memory 1115 may consist of random access memory (RAM), read-only memory (ROM), flash memory, cache, static storage devices such as magnetic disks or optical disks, or any other type of non-temporary computer-readable medium, or any combination thereof. The non-temporary computer-readable medium may be any available medium accessible by the processor 1110, and may include volatile media, non-volatile media, or both. The medium may also be removable, non-removable, or both. The computing system 1100 includes communication devices 1120, such as transceivers, for providing access to a communication network via wireless and / or wired connections. In some embodiments, the communication devices 1120 may include one or more antennas in single, arrayed, phase-controlled, switchable, beamforming, beam-steering, combinations thereof, or any other antenna configuration that does not depart from the scope of the present invention.

[0148] The processor 1110 is further coupled to the display 1125 via the bus 1105. Any suitable display device and haptic I / O may be used without departing from the scope of the invention. A keyboard 1130 and a cursor control device 1135, such as a computer mouse or touchpad, are further coupled to the bus 1105 to allow the user to interact with the computing system 1100. However, in certain embodiments, there may be no physical keyboard and mouse, and the user may interact with the device only via the display 1125 and / or touchpad (not shown). Any type and combination of input devices may be used as a design choice. In certain embodiments, there may be no physical input device and / or display. For example, the user may remotely interact with the computing system 1100 via another computing system communicating with it, or the computing system 1100 may operate autonomously.

[0149] Memory 1115 stores software modules that provide functionality when executed by processor 1110. These modules include an operating system 1140 for the computing system 1100. The modules further include a computer security module 1145 configured to execute all or part of the processes described herein, or derivatives thereof. The computing system 1100 may include one or more additional functionality modules 1150 that provide additional functionality.

[0150] Those skilled in the art will understand that “computing system” can be embodied as a server, embedded computing system, personal computer, console, personal digital assistant (PDA), mobile phone, tablet computing device, smartwatch, quantum computing system, or any other suitable computing device, or any combination thereof without departing from the scope of the present invention. The use of “system” to describe the above functions is not intended to limit the scope of the present invention in any sense, but rather to provide an example of many embodiments of the present invention. Indeed, the methods, systems, and devices disclosed herein can be implemented in localized and distributed forms that are consistent with computing technologies, including cloud computing systems. A computing system may be part of, or accessible by, a LAN, mobile communication network, satellite communication network, the Internet, a public or private cloud, a hybrid cloud, a server farm, or any combination thereof. Any localized or distributed architecture may be used without departing from the scope of the present invention.

[0151] It should be noted that some of the system functions described herein are presented as modules to more clearly emphasize their implementation independence. For example, modules may be implemented as hardware circuits including custom very large-scale integrated (VLSI) circuits or gate arrays, or commercially available semiconductors (e.g., logic chips, transistors, or other discrete components). Modules may also be implemented as field-programmable gate arrays, programmable array logic, programmable logic devices, graphics processing units, or similar programmable hardware devices.

[0152] Modules can also be implemented, at least partially, as software executed by various types of processors. For example, a specified unit of executable code may include one or more physical or logical computer instruction blocks, which may be composed of, for example, objects, procedures, or functions. Nevertheless, the executable code of a specified module does not need to be physically located in one place, and may include various instructions stored in different locations, which, when logically combined, constitute the module and achieve the purpose stated for that module. Furthermore, modules may be stored on computer-readable media such as, for example, hard disk drives, flash devices, RAM, tape, and / or other non-temporary computer-readable media used to store data without departing from the scope of the present invention.

[0153] In fact, a module of executable code may be a single instruction, a number of instructions, or even distributed across multiple different code segments, different programs, and multiple memory devices. Similarly, operational data may be identified and illustrated within a module herein, embodied in any suitable form, and organized within any suitable type of data structure. Operational data may be collected as a single data set, distributed in different locations including across different storage devices, or exist at least in part as mere electronic signals on a system or network.

[0154] Without departing from the scope of the present invention, various types of AI / ML models can be trained and deployed. For example, Figure 12A shows an example of a neural network 1200 trained according to one embodiment of the present invention. The neural network 1200 includes a number of hidden layers. Both deep learning neural networks (DLNNs) and shallow learning neural networks (SLNNs) typically have multiple layers, although SLNNs may have only one or two layers in some cases, and usually fewer than DLNNs. Typically, a neural network architecture includes an input layer, multiple hidden layers, and an output layer, and the neural network 1200 is no exception.

[0155] DLNNs often have many layers (e.g., 10, 50, 200), and subsequent layers typically reuse features from previous layers to compute more complex and general functions. SLNNs, on the other hand, usually have fewer layers and tend to be trained relatively quickly because expert features are pre-generated from raw data samples. However, feature extraction is time-consuming. DLNNs, on the other hand, usually do not require expert features, but training takes longer and they tend to have more layers.

[0156] In both approaches, layers are trained simultaneously on the training set, and overfitting is typically detected on an independent cross-validation set. Both techniques can yield excellent results, and there are high expectations for both approaches. The optimal size, shape, and number of individual layers vary depending on the problem each neural network addresses.

[0157] Returning to Figure 12A, inputs 1, 2, 3, 4, etc., are provided as the input layer and supplied as inputs to J neurons in hidden layer 1. Various other inputs are also possible and may include, but are not limited to, computing system state information, published automations, business rules, information about which RPA workflow and / or task it is, initial definitions of automations, process automation documents, etc. In this example, all of these inputs are supplied to each neuron, but without departing from the scope of the present invention, various architectures are possible that use, alone or in combination, feedforward networks, radial basis networks, deep feedforward networks, deep convolutional inverse graphics networks, convolutional neural networks, recurrent neural networks, artificial neural networks, long short-term memory networks, gated recurrent unit networks, generative adversarial networks, liquid state machines, autoencoders, variational autoencoders, denoising autoencoders, sparse autoencoders, extreme learning machines, echo state networks, Markov chains, Hopfield networks, Boltzmann machines, restricted Boltzmann machines, deep residual networks, Kohonen networks, deep belief networks, deep convolutional networks, support vector machines, neural Turing machines, or any other suitable type or combination of neural networks.

[0158] Hidden layer 2 receives input from hidden layer 1, hidden layer 3 receives input from hidden layer 2, and so on for all hidden layers until the last hidden layer provides its output as input to the output layer. Although multiple candidates are shown as outputs here, in some embodiments only a single output candidate is provided. In certain embodiments, the candidates are ranked based on confidence scores. In this embodiment, the outputs are output 1, output 2, output 3, output 4, and so on.

[0159] It should be noted that the number of neurons I, J, K, and L are not necessarily equal. Therefore, any desired number of layers can be used for a given layer of the neural network 1200 without departing from the scope of the present invention. In fact, in certain embodiments, the types of neurons within a given layer do not all need to be the same.

[0160] The neural network 1200 is trained to assign confidence scores to appropriate outputs. To reduce inaccurate predictions, in some embodiments, only results whose confidence scores meet or exceed a confidence threshold may be provided. For example, if the confidence threshold is 80%, outputs with confidence scores exceeding this value may be used, and the rest may be ignored.

[0161] Neural networks are typically probabilistic configurations that have confidence scores. These can be scores learned by an AI / ML model based on how correctly it identified similar inputs during training. Common types of confidence scores include decimals between 0 and 1 (which can also be interpreted as confidence percentages), numbers between negative infinity and positive infinity, and sets of representations such as "low," "medium," and "high." Various post-processing calibration techniques, such as temperature scaling, batch normalization, weight decay, and negative log-likelihood (NLL), may also be used in attempts to obtain more accurate confidence scores.

[0162] In a neural network, "neurons" are typically implemented algorithmically as mathematical functions based on the functions of biological neurons. A neuron receives weighted inputs and has a summing function and an activation function that controls whether or not to pass the output to the next layer. This activation function can be a non-linear thresholded activity function (i.e., modified linear unit (ReLU) nonlinearity) where nothing happens if the value is below a threshold, but the function responds linearly above the threshold. The summing function and ReLU function are used in deep learning because real neurons can generally have similar activity functions. Linear transformations allow information to be subtracted, added, etc. In short, a neuron acts as a gating function that passes the output to the next layer according to its underlying mathematical function. In some embodiments, different functions may be used for at least some of the neurons.

[0163] Figure 12B shows an example of neuron 1210. Inputs x1, x2, ..., xn from the preceding layer are assigned weights w1, w2, ..., wn, respectively. Therefore, the total input from preceding neuron 1 is w1x1. These weighted inputs are used in the sum function of the biased neurons, for example, as shown in the following equation.

number

[0164] This sum is compared to the activation function f(x) to determine whether or not the neuron "fires". For example, f(x) can be given by the following equation:

number

[0165] Therefore, the output y of neuron 1210 can be given by the following equation.

number

[0166] In this case, neuron 1210 is a single-layer perceptron. However, any suitable type of neuron or combination of neuron types may be used without departing from the scope of the present invention. It should also be noted that in some embodiments, the range of weight values ​​and / or the range of activation function output values ​​may differ without departing from the scope of the present invention.

[0167] A goal, or "reward function," is often used. The reward function guides the exploration of the state space by searching for intermediate transitions and steps that involve both short-term and long-term rewards, aiming to achieve the goal (e.g., finding the most accurate answer to a user query based on relevant metrics). During training, various labeled data are passed through the neural network. Successful classifications strengthen the weights of the inputs to the neurons, while failed classifications weaken them. A cost function, such as mean squared error (MSE) or gradient descent, may be used to punish slightly wrong predictions much less severely than very wrong predictions. If the performance of the AI / ML model does not improve after a given number of training iterations, data scientists may modify the reward function, providing corrections for wrong predictions, etc.

[0168] Backpropagation is a technique for optimizing synaptic weights in a feedforward neural network. Backpropagation can be used to examine the hidden layers of a neural network to determine how much of the loss each node is responsible for, and then update the weights to minimize the loss by assigning lower weights to nodes with higher error rates, and vice versa. In other words, backpropagation allows data scientists to iteratively adjust weights to minimize the difference between the actual output and the desired output.

[0169] The backpropagation algorithm has its mathematical foundation in optimization theory. In supervised learning, training data with known outputs is passed through a neural network, an error is calculated from the known target outputs using a cost function, and this error is used for backpropagation. The error is calculated at the output, and this error is converted into corrections to network weights that minimize the error.

[0170] In the case of supervised learning, an example of the backpropagation method is shown below. A column vector input x is processed through a series of N non-linear activation functions f arranged between each layer i=1,…,N of the network i , and the output at a given layer is first multiplied by the synaptic matrix W i , then the bias vector b i is added. The network output o is

Mathematical Expression

[0171] In some embodiments, o is compared to a target output t, resulting in an error

Mathematical Expression

[0172] Optimization in the form of a gradient descent procedure may be used to minimize the error by modifying the synaptic weights W of each layer j . The gradient descent procedure requires computation of the output o given the input x corresponding to the known target output t, and generation of the error o−t. This global error is then propagated backwards to give local errors for weight update using calculations that are similar, but not identical, to those used for forward propagation. In particular, the backpropagation step typically requires an activation function of the form p j (n j )=f j '(n j ), where n j is the network activity at layer j (that is, n j =Wj o j-1 +b j ) and here o j =f j (n j ) and the apostrophe ' indicates the derivative of the activity function f.

[0173] Weight updates can be calculated using the following formula:

number

[0174] Here, o represents the Hadamard product (i.e., the element-wise product of two vectors), T This shows the matrix transpose, o j is f j (W j o j-1 +b j ) shows that o0 = x. Here, the learning rate η is chosen with respect to machine learning considerations. Below, η is associated with the neural Hebb learning mechanism used in the neural implementation. Note that synapses W and b can be coupled into one large synaptic matrix. In this case, it is assumed that the input vector is appended with 1, and the additional column representing the b synapse is included in W.

[0175] AI / ML models can be trained over multiple epochs until a good level of accuracy is achieved (e.g., 97% or higher after approximately 2,000 epochs using an F2 or F4 threshold for detection). This level of accuracy can be determined in some embodiments using an F1 score, F2 score, F4 score, or any other suitable technique that does not depart from the scope of the invention. After being trained on training data, the AI / ML model can be tested on an evaluation data set that it has not encountered before. This helps prevent the AI / ML model from "overfitting," where it performs well on the training data but not on other data.

[0176] In some embodiments, it may be unclear what level of accuracy an AI / ML model can achieve. Therefore, if the accuracy of the AI / ML model begins to decline when analyzing evaluation data (i.e., the model performs well on training data but begins to perform poorly on evaluation data), the AI / ML model can undergo more training epochs on the training data (and / or new training data). In some embodiments, the AI / ML model is deployed only when its accuracy reaches a predetermined level, or when the accuracy of the trained AI / ML model is better than that of an existing deployed AI / ML model. In certain embodiments, a set of trained AI / ML models may be used to accomplish a task. For example, one AI / ML model may be trained for image recognition, another for text recognition, and yet another for semantic and / or ontological association recognition.

[0177] It should be noted that, in addition to or instead of neural networks, transformer networks such as SentenceTransformers™ may be used in some embodiments. This is a state-of-the-art Python™ framework for sentence, text, and image embedding. Such transformer networks learn the associations of words and phrases that have both high and low scores. This trains the AI / ML model to determine, respectively, which are close to the input and which are not. Transformer networks may also use field lengths and field types, not just word / phrase pairs.

[0178] As described above, NLP models such as word2vec, BERT, GPT-3, ChatGPT, and other LLMs can be used in several embodiments to facilitate semantic comprehension and provide more accurate and human-like responses. Other techniques, such as clustering algorithms, can also be used to find similarities between groups of elements. Clustering algorithms include, but are not limited to, density-based, distribution-based, centroid-based, and hierarchy-based algorithms. Examples include K-means clustering, DBSCAN clustering, Gaussian mixture model (GMM) algorithms, and Bircean balanced iterative reduction clustering (BIRCH) algorithm with hierarchy. Such techniques can also assist in classification.

[0179] Figure 13 is an architecture diagram showing a reference architecture 1300 for a generative AI model according to one embodiment of the present invention. This architecture consists of multiple layers, namely an API plugin, a prompt library, vector data source ingestion, access processing control, a model training pipeline, an evaluation layer for evaluating hallucination / telemetry / evaluation, a BYOM embedding layer, and an LLM orchestration layer. Furthermore, there are also search plugins, access control plugins, and API plugins that are integrated into enterprise systems.

[0180] This embodiment has three main flows.

[0181] Data Ingestion and Training Flow: Data is read from multiple data stores, preprocessed, chunked, and trained through an embedding model (e.g., Search Enhancement Generation (RAG)) and training pipeline (i.e., fine-tuning). A vector database stores chunked document embeddings, enabling better semantic-based and similarity-based data retrieval.

[0182] Prompt extension using data retrieval: When a user query reaches the API layer, a prompt is selected, and then, before the prompt is passed to the LLM layer, a data retrieval is performed via a vector database or API plugin to obtain the appropriate contextual data.

[0183] LLM Inference: Here, there is a choice between using a general-purpose foundational model or a self-hosted foundational model. Fine-tuned models tailored to specific tasks or use cases may be used. Responses are evaluated for accuracy, including hallucination, and other metrics.

[0184] It should be noted that in some embodiments, generative AI models having multiple "heads" may be used. A head refers to the output layer of the generative AI model. A generative AI model, such as generative AI model 172 in Figure 1, typically has a series of layers, and each head often shares the first few layers of the model before branching off into its own unique layers.

[0185] Figure 14 is a flowchart of process 1400 for training an AI / ML model according to one embodiment of the present invention. In some embodiments, the AI / ML model may be a generative AI model, as described above. In the case of a neural network, the architecture typically includes multiple neuron layers, including an input layer, an output layer, and hidden layers. See, for example, Figures 12A and 12B. The hidden layers in between process the input data and generate an intermediate representation of the input used to produce the output. These hidden layers may include various types of neurons, such as convolutional neurons, recursive neurons, and / or transformer neurons. A generative AI model may also have various layers.

[0186] In some embodiments, the training process begins in 1410 with providing training data, whether labeled or unlabeled. For generative AI models, they are often already trained, so the training process can be omitted unless a fine-tuning model is desired, as described later. The AI / ML model is then trained over multiple epochs in 1420, and the results are reviewed in 1430. While various types of AI / ML models can be used, LLMs and other generative AI models are typically trained (fine-tuned) using a process called "supervised learning," which was also explained above. Supervised learning involves providing the model with a large dataset, which the model uses to learn the relationship between inputs and outputs. During the training process, the model adjusts the weights and biases of neurons in the neural network to minimize the difference between the predicted output and the actual output in the training dataset.

[0187] One aspect of the model in some embodiments is the use of transfer learning. For example, transfer learning can utilize a pre-trained model such as ChatGPT, which is fine-tuned for a specific task or domain over 1420 steps. This allows the model to leverage knowledge already learned in the pre-training phase and adapt to a specific application through the 1420 training phases.

[0188] The pre-training phase involves training the model on an initial set of training data, which may be more general. During this phase, the model learns relationships within the data. In the fine-tuning phase (performed in some embodiments in addition to or instead of the initial training phase, for example, during step 1420, if the pre-trained model is used as the initial foundation for the final model), the pre-trained model is adapted to a specific task or domain by training the model on a smaller dataset specific to that task. For example, in some embodiments, the model may focus on a particular type of data source. This may help it to more accurately identify data elements within them than a simply pre-trained generative AI model. Fine-tuning allows the model to learn the nuances of the source, such as specific vocabulary and syntax, specific graphical properties, or specific data formats, without requiring as much data as would be needed to train the model from scratch. By leveraging the knowledge learned in the pre-training phase, the fine-tuned model may achieve state-of-the-art performance on a particular task with relatively little additional training data.

[0189] In some embodiments, if the AI / ML model does not meet the desired confidence threshold at 1440, the training data is supplemented and / or the reward function is modified at 1450 so that the AI / ML model can better achieve its objective, and the process returns to step 1420. If the AI / ML model meets the confidence threshold at 14140, the AI / ML model is tested on evaluation data at 1460 to confirm that the AI / ML model generalizes well and does not overfit to the training data. The evaluation data contains information that the AI / ML model has not previously processed. If the confidence threshold is met on the evaluation data at 1470, the AI / ML model is expanded at 1480. Otherwise, the process returns to step 1450, and the AI / ML model is further trained.

[0190] Embodiments described herein provide agent-based automation for computer security. Agent-based automation is implemented by an AI agent for evaluating computer security issues in a computer system. Such an AI agent is implemented using AI / ML models to make probabilistic decisions independently and autonomously in a non-deterministic manner. Such an AI agent cognitively monitors the computing environment to ensure robust security based on probe and trigger analysis. The AI ​​agent receives computer security data as input from various sources and uses automated processes, tools, etc., to evaluate the relevance and impact of newly arising problems. Advantageously, the AI ​​agent enables the processing of extremely large amounts of computer security data (e.g., gigabytes, terabytes, petabytes, or more) that would be impossible with human mental or manual processes, while improving accuracy and response time, in order to evaluate computer security issues in a computer system. Furthermore, agent-based automation with AI agents improves memory usage by reducing the amount of data required for storage and improves processor efficiency by reducing the number of calls and actions involved in computer security, compared to conventional approaches.

[0191] Figure 15 shows a method 1500 for evaluating computer security issues in a computer system, according to one or more embodiments. Method 1500 can be performed by one or more computing systems, such as the computing system 1100 in Figure 11. Figure 16 shows a workflow 1600 for evaluating the security of a computer system, according to one or more embodiments. Method 1500 in Figure 15 and workflow 1600 in Figure 16 will be described together.

[0192] In step 1502 of Figure 15, an alert regarding a computer security issue in the computer system is received. For example, the alert is alert 1602, as shown in workflow 1600 of Figure 16. The computer system may include, for example, one or more computing devices (e.g., personal computers, laptop computers, servers, mobile phones, tablet computing devices, smartwatches, IoT devices) or a network of such computing devices. For example, the computer system may include computing system 1100 in Figure 11.

[0193] In one embodiment, alerts are generated and received from a computer security monitoring / alert system, such as a SIEM (security information and event management) system. The computer security monitoring system collects and analyzes computer security data from the computer system to detect computer security issues (e.g., threats) and generates alerts for the detected computer security issues.

[0194] Figure 17 shows a system diagram 1700 for receiving alerts on computer security issues according to one or more embodiments. In system diagram 1700, a SIEM system 1702 generates alerts. A connector 1706 receives alerts from the SIEM system 1702 via one or more APIs (Application Programming Interfaces). The connector 1706 is integrated with an integration service 1704, which is an API service that connects various services and systems. The connector 1706 listens for alerts triggered by the SIEM system 1702, retrieves data related to the alerts, and moves this data to a triage workflow 1708 for determining strategies to mitigate security issues and for determining one or more additional AI agents from a pool of AI agents to mitigate computer security issues (in step 1504 of Figure 15). In one embodiment, the alert-related data retrieved by the connector 1706 includes: • Alert ID: An identifier assigned to the computer security alert by the SIEM system 1702. This is a unique identifier that helps in identifying and tracking computer security alerts during triage. • Alert URL: For example, a URL (uniform resource locator) that allows a user to directly connect to a computer security alert. • Alert connection string: The connection used by connector 1706 within API and integration service 1704. • Alert Title: The title of the computer security alert created by SIEM system 1702. • Detection Rule ID: An identifier for the detection analysis rule that contains the logic that generated the computer security alert. • Detection Rule Name: The name of the detection and analysis rule that contains the logic that generated the computer security alert. • Key Artifacts: A dictionary of the key artifacts that triggered the computer security alert. • Alert Context: A multi-line string of the computer security alert. This includes an alert summary and relevant activities involved in the computer security alert. • Alert Source: The source of the data analyzed to trigger a computer security alert. ·

[0195] Alert Severity: The severity level of the computer security alert. Returning to step 1502 in Figure 15, in one embodiment, the alert is received from one or more probes and / or one or more triggers that monitor computer security data. The alert may be received by a connector from the one or more probes and / or the one or more triggers that monitor computer security data, for example, via one or more APIs.

[0196] A probe is a tool, device, or software component for continuously acquiring, monitoring, and / or collecting data about the activity and security events of a computer system. A probe functions as a sensor or monitoring agent to collect information at various points within a computer system. Probes may include, for example, 1) network probes (e.g., simple network management protocol probes) for monitoring network traffic, bandwidth usage, packet flow, etc., 2) host-based probes (e.g., endpoint detection and response tools) for monitoring local activity on a computer or server, 3) application probes (e.g., web application monitoring tools) for monitoring specific applications running on a computing device, and / or 4) intrusion detection system probes (e.g., Snort sensors) for acquiring and analyzing packets for signs of malicious activity.

[0197] A trigger is a predefined condition that, when met, initiates an alert, action, or response, enabling automated responses to suspicious or abnormal activity in a computer system. Triggers may include, for example, 1) threshold-based triggers that activate when an indicator (e.g., processor usage or packet loss) exceeds a predefined threshold; 2) anomaly-based triggers that activate when actual behavior deviates significantly from expected behavior; 3) signature-based triggers that activate when computer system activity matches a known malicious behavior pattern; 4) event-based triggers that activate due to a specific event or action; and / or 5) time-based triggers that activate based on the timing or frequency of an event.

[0198] In one embodiment, alerts may be received by a user manually triggering an alert based on computer security data.

[0199] Computer security data (which triggers computer security alerts) may include any appropriate data relating to the security of a computer system. For example, computer security data may include logs from firewalls, services, applications, and computer processes (e.g., RPA processes). In another example, computer security data may include news articles. News articles may contain information about newly emerging computer security issues. For example, news articles may include reports of security breaches in operating systems. Computer security data may also include any other appropriate data relating to the security of a computer system (e.g., computer system policies, source code of applications on the computer system, etc.).

[0200] Computer security alerts can be received, for example, by receiving them from a computer system such as a SIEM (e.g., via the display 1125, keyboard 1130, or cursor control device 1135 in Figure 11), by loading them from the storage device or memory of the computer system (e.g., from memory 1115 in Figure 11), or by receiving them from a remote computer system (e.g., via the communication device 1120 in Figure 11). Computer security alerts can also be received via one or more APIs.

[0201] In step 1504 of Figure 15, the initial AI agent determines 1) a strategy for evaluating computer security issues, and 2) one or more additional AI agents from a pool of AI agents for evaluating computer security issues. For example, as shown in workflow 1600 of Figure 16, the initial AI agent is LLM1 1604, and the one or more additional AI agents are LLM2 1614-A, LLM3 1614-B, ..., LLMn 1614-n.

[0202] AI agents (i.e., the initial AI agent and one or more additional AI agents) are implemented to make probabilistic decisions independently and autonomously in a non-deterministic manner using AI / ML models. In one or more examples, the AI ​​agents may be AI agent 210 in Figure 2, the AI ​​agent in AI agent pool 320 in Figure 3, AI agent 520 in Figure 5, AI agent 750 in Figure 7, or AI agent 850 in Figure 8. In one embodiment, the AI ​​agent is implemented using a pre-trained language model. For example, the AI ​​agent may be implemented using an LLM such as word2vec, BERT, GPT-3, or ChatGPT. However, the AI ​​agent may also be implemented using a small language model with relatively fewer parameters than an LLM. Any other suitable type of language model, such as a recurrent neural network (RNN) based model or a transformer-based model, can also be used to implement the AI ​​agent. The language model can be fine-tuned for the computer security domain.

[0203] The AI ​​agent is configured, for example, using a designer application. The designer application could be designer application 154 in Figure 1, agent service interface 400 in Figures 4A and 4B, designer application 710 in Figure 7, designer 810 in Figure 8, or designer 1010 in Figure 10. The user (e.g., a developer) interacts with the designer application to provide the AI ​​agent with instructions and context for context-grounding to define the roles and tasks the AI ​​agent should perform, and to define the tools (e.g., other AI agents, RPA robots, automation, applications, etc.) that the AI ​​agent can use to perform the tasks.

[0204] Once configured, the AI ​​agent is executed to perform step 1404 in Figure 14 for agent-based automation. The execution of the AI ​​agent is managed by a conductor (also called an orchestrator). In one or more examples, the conductor may be conductor 350 in Figure 3, conductor application 730, conductor 820 in Figure 8, or conductor 940 in Figure 9. In one embodiment, the conductor executes the AI ​​agent in response to user input (e.g., via a designer application) indicating that the AI ​​agent should be executed. For example, as shown in Figure 4A, the conductor may execute the AI ​​agent in response to the user selecting the execute button 480. In another embodiment, the conductor executes the AI ​​agent according to a predefined schedule (e.g., at a predetermined time each day). In yet another embodiment, the conductor executes the AI ​​agent (e.g., in response to user input), and the AI ​​agent operates continuously to continuously assess the security of the computer system.

[0205] As shown in workflow 1600 in Figure 16, LLM1 1604 (i.e., the initial AI agent) functions as the SOCC (security operations center commander). LLM1 1604 retrieves its persona via context grounding from the role definition file 1608 stored in the context grounding database (CG1) 1606. The role definition file 1608 provides the expertise, skills, and capabilities of that role. As defined in the role definition file 1608, the role of LLM1 1604 as the SOCC is to evaluate incoming alerts 1602, determine strategies for evaluating computer security issues, select one or more AI agents (i.e., LLM2 1614-A, LLM3 1614-B, ..., LLMn 1614-n) from a pool of AI agents for evaluating computer security issues, and continue orchestrating the workflow. LLM1 1604 thinks and acts autonomously based on alert 1602, but also utilizes predefined operational procedures 1612 to apply additional frameworks and guidelines for SOCC decisions. Predefined operational procedures 1612 are stored in context grounding database (CG2) 1610. Role definition file 1608 and operational procedures 1612 are stored in context grounding database CG1 1606 and context grounding database CG2 1610, respectively, but it should be understood that role definition file 1608 and operational procedures 1612 may be stored in any number of databases.

[0206] Different alerts utilize different roles with expertise, skills, and capabilities to assess computer security issues. LLM1 1604 has a pool of AI agents including LLM2 1614-A, LLM3 1614-B, ..., LLMn 1614-n, which obtain their personas from role definition file 1608. Role definition file 1608 and predefined operational procedures 1612 are provided to the AI ​​agents as contextual information through one or more prompts for context grounding.

[0207] By having a context grounding database CG1 1606 for role definition file 1608, consistent operation by different agents can be achieved at scale. By utilizing file-based resources within the context grounding database CG1 1606, rapid modification of files in a central source outside of the code becomes possible and can be used at scale. Modifications to the centralized role definition file 1608 adapt all usage of that role to the changes.

[0208] In one embodiment, the role definition file 1608 includes the following components: 1) Title: The name of the role. 2) Description: A summary of the role that enables other agents to understand the context of the role and therefore determine when and how to use that role. 3) Background: The background of the role that defines its work experience and history. 4) Tasks: A list of specific tasks that the role is aware of and effective at, without limiting its capabilities. 5) Knowledge: A list of specific knowledge that the role possesses. 6) Skills: A list of specific skills that the role possesses. 7) Abilities: A list of specific abilities that the role possesses.

[0209] The following is a list of exemplary AI agents, shown according to one embodiment, along with their roles, the tools they may have available, the tasks they perform, and other AI agents they may have available. Other types of AI agents may also be available, and the number of AI agents used may increase or decrease based on, for example, the needs of a particular alert, reception source, or a specific desired workflow. • SOCC Agent: ○Role: Conductor and orchestrator for evaluating security issues (e.g., from alerts to security events, on-demand intelligence, and threat hunting requests). ○Tools: Alert History, Alert Processor, Internal Documentation Tool, Messager, Email Message, Ticket creator, Write to Confluence. Tasks: Initialize agents for event triage, ensure agents do not deviate from their tasks, summarize analysis and recommend actions, and communicate with internal employees to support the analysis. ○Available agents: Incident (Security Event) Commander, SSA, IAM analyst, STH, Insider Risk Analyst. • Incident (Security Event) Commander Agent: ○Role: A senior security engineer specializing in orchestrating and managing time-constrained security investigations. ○Tools: Write to Confluence, Ticket creator, Email Message, Messager, Start Security Event, Alert Update, Alert History, Internal Documentation Tool. Tasks: Event start, event scheduling, event summary, event announcements. ○Available agents: STH, TIA, MA, CSFE, NFE. • SSA (Senior Security Operations Analyst) Agent: ○Role: A general analyst with extensive experience in security operations. Initiate the implementation of the playbook and collaborate with SCCC. ○ Tools: Data Lake Execute Query, Enrichments Services, Internal Documentation Tool, Alert Processor, Query Builder, Log Analyzer, Alert History, Alert Investigator, Alert Update, Alert Escalation, Identify Procedure. Tasks: Investigate alerts and events, recommend assistance from other agents, document findings from alert or event investigations, and document and analyze IoCs. ○Available agents: TIA, CTI OSINT Analyst, IAM Analyst, Insider Risk Analyst, Incident (Security Event) Commander. • NFE (Network Forensics Expert) Agent: ○Role: A specialist who analyzes network traffic data. ○Tools: Query Builder, Log Analyzer, Data Lake Execute Query, Internal Documentation Tool. ○Available Agent: Senior TIA. • CSFE (Computing Systems Forensics Expert) Agent: ○Role: Expert in forensic operations and activity analysis on computing systems (personal computing, virtual machines, cloud systems). ○Tools: Create Dedicated Forensics Environment, Endpoint Forensics Acquisition, Cloud Forensics Acquisition. ○Available Agent: Senior TIA. • IAM (Identity and Access Management) Analyst Agent: ○Role: Experts who analyze identity information, authorization analytics, and access analytics. ○Tools: Data Lake Execute Query, Internal Documentation Tool, Query Builder, Log Analyze, Enrichments Services. • MA (Malware Analyst) Agent: ○Role: Malware analysis expert. ○Available agents: MRE. • Malware Reverse Engineer (MRE) Agent: ○Role: Experts who investigate malware and reverse engineer its code. • Senior TIA (Threat Intelligence Analyst) Agent: ○Role: A threat intelligence expert who receives indicators or tactics, techniques, and procedures and helps provide context for events. ○Tools: Enrichments Services, Internal CTI for indicators, Data Lake Execute Query, Internal CTI reports, Internet query, Intelligence Report Processor, Query Builder, Log Analyzer, Alert CTI Model, Log Analyzer. • STH (Senior Threat Hunger) Agent: ○Role: A threat hunting expert who receives indicators or tactics, techniques, and procedures to search for artifacts or evidence of compromise within the organization. ○Tools: Data Lake Execute Query, Internal CTI reports, Internet query, Intelligence Report Processor, Query Builder, Log Analyzer, Log Analyzer, Alert History, Write to Confluence, Ticket creator. Available agents: Senior TIA, Senior SSA. • CTI (Cyber ​​Threat Intelligence) OSINT (Open Source Intelligence) Analyst Agent: ○Role: Senior security engineer with a strong background in cyber threat intelligence. Continuously monitor open source intelligence or news feeds to identify threats relevant to the organization. ○Tools: Enrichments Services, Internet query, Intelligence Report Processor, Internal Documentation Tool, Alert CTI Model. ○Available agent: STH. • Insider Risk Analyst Agent: ○Role: Security analyst handling alerts, including PII and other sensitive corporate data. ○Tools: Log Analyzer, Query Builder, Data Lake Execute Query, Enrichments Services, Internal Documentation Tool. ○Available agent: Incident (Security Event) Commander.

[0210] The following is a list of exemplary tools that the AI ​​agent may use, along with a description of each tool and the components it uses. Tools are defined in role definition file 1608. Other types of tools may also be used, and the number of tools used may increase or decrease. • Data Lake Execute Query: ○Description: A tool that allows you to execute specific queries against a data lake. The purpose of this tool is to bring more context to alerts, enabling analyst tools or users to understand the chain of events and classify those events appropriately. ○Components: HTTP requests, Data Lake. Enrichments Services: ○Description: A tool that can provide enrichment (more cyber threat-specific context) for evidence fragments. This tool has a dual structure: an API-based component for third-party services and an LLM component that provides a human-readable summary of the enrichment and appropriate conclusions about its impact. ○Components: HTTP request, LLM, third-party service (e.g., CTI provider). ·Internal CTI for Indicators: ○Description: A tool with the ability to query internal cyber threat intelligence data stores to bring more context to the evidence. ○ Components: HTTP request, LLM. • Internal CTI Reports: ○Description: A tool with the ability to identify relevant context from a wide range of cyber threat intelligence reports. This tool can help classify alerts, identify other related threats or clues, and retrieve relevant content that can suggest appropriate next steps for this alert. ○Components: LLM, Context Grounding. ·Internal Documentation Tool: ○Description: A tool that uses internal data to provide enrichment and relevant context search for LLM use. ○Components: LLM, Context Grounding. Internet Query: ○Description: A tool that can perform internet searches for specific indicators or pieces of evidence. Its scope is to provide enrichment to alerts based on alert-specific elements that are not present in the CTI feed. ○Components: HTTP requests, RPA (web-based applications), LLM. ·Intelligence Report Processor: ○Description: This tool is based on LLM and prompt engineering and has the ability to process intelligence and security news reports to extract correlations with relevant data, indicators, related vulnerabilities, and other internal data points. ○Component: LLM. • Alert Processor: ○Description: A tool for processing alerts to extract core entities such as users, machines, and indicators. This tool uses LLM to identify and classify each entity fragment into its appropriate class. ○Component: LLM. • Query Builder: ○Description: An LLM tool that allows you to build appropriate queries for use in investigations. Starting with a template / sample query, the query builder tool uses entities extracted and categorized from the alert processor tool to generate appropriate investigation queries. ○Components: LLM, Context Grounding. • Log Analyzer: ○Description: Based on a specific profile of the system message (analyst role), the log analyzer tool uses the data provided by the original alert and the execution query tool (queries provided by the query builder tool) as input to identify correlations between the data set and the original alert. Furthermore, the tool evaluates whether there is relevant information that brings more context to the security connection or alert. ○Component: LLM. • Alert History: ○Description: The scope of this tool is to use information about previously investigated alerts to identify whether there is a strong correlation with the alert currently being processed. This tool identifies patterns, as well as previous solutions and processing steps for the alert in question. To this end, this tool uses a context grounding mechanism with an index built on previously reviewed alerts. ○Components: LLM, Context Grounding. • Alert Investigator: ○Description: The scope of this tool is to receive output from all enrichment tools (enrichment, queries, context grounding, etc.) and provide a summary of the study, a classification of the study, and a set of follow-up elements where required by the classification. ○Component: LLM. • Alert Update: ○Description: The scope of this tool is to perform simple actions on alerts based on results from the alert investigator (e.g., closing or assigning alerts to users, changing classifications, leaving analysis summaries in comments, etc.). ○Components: HTTP Requests, LLM. • Alert Escalation: ○Description: If an alert is classified as a true positive by the Alert Investigator tool, this tool identifies an on-call human analyst, generates a complete summary of the alert, alert status, and investigation, and submits it to the on-call person via the on-call mechanism. ○Components: HTTP Requests, LLM. • Alert CTI Model: ○Description: The scope of this tool is to extract relevant CTI information from alerts. To do this, the tool uses a context-grounding approach with relevant CTI information to perform appropriate mapping. ○Components: LLM, Context Grounding. Identify Procedure: ○Description: This tool uses a contextual grounding index based on all procedures associated with the internal security operations team. When an alert is given, this tool returns the details of the procedure associated with that alert. ○Components: LLM, Context Grounding. ·Cloud Forensics Acquisition: ○Description: Given a specific identifier for a compromised cloud computing platform, this tool can perform tasks such as 1) taking snapshots of computing unit disks and 2) memory dumps of computing unit RAM (random access memory) allocations. ○Components: Cloud Computing Platform APIs. ·Endpoint Forensics Acquisition: ○Description: Given a specific identifier for a compromised endpoint, this tool can perform tasks such as 1) performing a memory dump of the computing unit, 2) extracting memory from the computing unit, 3) extracting forensic (log) acquisition capabilities, and 4) sharing artifacts with the response team via a cloud service (uploading to a storage account). ○Components: Endpoint APIs. ·Created Dedicated Forensics Environment ○Description: A dedicated forensic environment is created for each security incident being processed. ○Components: Cloud Computing Platform API. ·Start Security Event: ○Description: This tool allows you to initiate an incident response / security event management process, performing tasks such as 1) extracting information from escalated alerts, 2) creating a dedicated security event Confluence page, 3) creating a shared dedicated space, 4) creating tickets for action management, 5) creating a collaborative messenger channel, and 6) maintaining an updated timeline within the created Confluence page. ○Components: Messenger API, Share Space API. Messenger: ○Description: A tool that allows you to send custom messages to users or channels (those that the bot participates in). ○Components: Messenger API. Email Message: ○Description: A tool that allows you to send emails to individuals or groups. ○Component: Email API. Ticket Creator: ○Description: A tool that allows you to create custom tickets for different projects and issues. ○Components: Ticket API. • Write to Confluence: ○Description: A collaborative tool that allows you to write new pages or update existing pages. ○Components: Collaboration Tool API.

[0211] In one embodiment, a strategy for evaluating computer security issues includes a threat management assessment to classify alerts by one or more additional AI agents. The additional AI agent orchestrating the threat management assessment is an SSA agent. The scope of the SSA agent is to properly classify alerts by collecting all possible evidence regarding alerts and alert elements and correlating that evidence with alert details. The SSA agent identifies computer security issues that do not pose a threat but may occupy up to 80% of user time.

[0212] In one embodiment, a strategy for evaluating computer security issues includes security event management by one or more additional AI agents. Security event management may be triggered, for example, based on the classification of alerts made by an SSA agent during a threat management evaluation, or it may be manually triggered by a user. The additional AI agent orchestrating security event management is an Incident (Security Event) Commander agent, which 1) handles incident management reception to mitigate computer security issues (by creating documentation, tracking, and orchestration infrastructure for the incident), and 2) handles artifact acquisition and forensic processes.

[0213] In one embodiment, a strategy for evaluating computer security issues includes the identification of emerging computer security issues by one or more additional AI agents. The additional AI agents that orchestrate the identification of emerging threats are STH agents, TIA agents, and CTI OSINT analyst agents. During the emerging threat identification workflow, the additional AI agents extract relevant information from news articles and other data related to the emerging threat and identify computer security issues related to the emerging threat.

[0214] In step 1506 of Figure 15, the computer security problem is evaluated using the one or more additional AI agents according to the strategy.

[0215] In one embodiment, a strategy for evaluating computer security issues includes a threat management assessment for classifying alerts. In this embodiment, the one or more additional AI agents include an SSA agent.

[0216] Figure 18 shows a workflow 1800 for classifying an alert according to one or more embodiments. The steps and substeps of workflow 1800 are performed by the SSA agent. In workflow 1800, an alert investigation 1806 is performed based on extracted alert information 1804, enrichment 1808, identified relevant logs 1810, past alert history 1812, and intelligence service 1814. The extracted alert information 1804 is extracted from a new alert 1802. In one example, this alert is the alert received in step 1506 of Figure 15. The alert classification 1816 is determined based on the alert investigation 1806 to classify the alert, and the alert is updated 1818. For example, the alert status may be classified as false positive, true positive, conclusion unknown, or doubtful. In another embodiment, the urgency of the alert may be classified as low, medium, high, and critical. The alert classification 1816 may also output an investigation summary. If the updated alert is true positive or suspicious, the alert is escalated 1822. For example, for medium, high, and critical level alerts, the updated alert may be escalated to the user for manual review. If the updated alert is critical 1824, security event management procedure 1826 is initiated by the incident (security event) commander agent. Security event management procedure 1826 may be performed according to Figure 20.

[0217] Figure 19 shows a workflow 1900 for investigating an alert, according to one or more embodiments. Workflow 1900 may be performed in the alert investigation 1806 of Figure 18. For each entity type extracted from the alert, and for each entity of a certain type X, the query builder 1902 constructs one or more queries. For each query for indicator Y of type X, the query is executed 1904, and if the result is greater than 0 in block 1906, the log analyzer 1908 analyzes the execution log and alert 1910 to generate a log investigation summary 1912. The log investigation summary 1912 is added to the full investigation in block 1914, the investigation is updated 1916, and similar alerts previously processed for that entity are retrieved in block 1918. If the result is greater than 0 in block 1920, the previously processed alerts are added to the full investigation in block 1922. Furthermore, Enrichment Services 1924, Threat Intelligence Indicators 1926, Threat Intelligence Reports 1928, and RPA Internet Queries 1930 were added to the full investigation in block 1932, and the investigation was updated in 1934.

[0218] Returning to step 1506 in Figure 15, in one embodiment, the strategy for evaluating computer security issues includes security event management. Security event management may be triggered, for example, based on alert classification by an SSA agent determined according to Figure 18, or it may be manually triggered by a user. In this embodiment, the one or more additional AI agents include an incident (security event) commander agent.

[0219] FIG. 20 illustrates a workflow 2000 for security event management, in accordance with one or more embodiments. Steps and sub-steps of the workflow 2000 are performed by an incident (security event) commander agent. The incident (security event) commander agent may optionally invoke one or more additional artificial intelligence (AI) agents, such as an NFE agent, a CSFE agent, an MA agent, an MRE agent, and / or an STH agent. These agents may utilize tools such as creation of a dedicated forensic environment, cloud forensic acquisition, and endpoint forensic acquisition. An intake 2002 receives an escalated alert, an analysis / investigation 2004 is performed to generate a recommendation 2006 of one or more actions for mitigating a security issue. At block 2008, a determination is made whether to proceed with the one or more actions, which may involve input from a human 2010. At block 2012, the one or more actions are performed to mitigate the computer security issue. The workflow 2000 may return to the analysis / investigation 2004 to ensure successful mitigation of the computer security issue. A post-mortem analysis 2014 is performed to analyze the mitigation result of the computer security issue, a call may be scheduled at block 2016, and a ticket and tracking are created at block 2018. The workflow ends at block 2020.

[0220] Returning to step 1506 in Figure 15, in one embodiment, a strategy for assessing computer security issues includes the identification of newly emerging threats by one or more additional AI agents. In this embodiment, the one or more additional AI agents may include an STH agent, a TIA agent, and a CTI OSINT analyst agent. The CTI OSINT analyst agent may run at predefined intervals (e.g., 1 hour) and may use the following tools: Alert CTI Model, Internet query, Internal Documentation Tool, Intelligence Report process, and Ticket creator. The TIA agent may be invoked by the CTI OSINT analyst agent or the STH agent, or manually invoked by the user. The TIA agent may use the following tools: Alert CTI Model, Internet query, Enrichments Services, Internal CTI for indicators, Internal CTI reports, Data Lake Execute Query, Query Builder, and Log Analyzer. The STH agent may be invoked by the CTI OSINT analyst agent, or manually invoked by the user. The purpose of the STH agent is to gather all evidence on a given topic and generate a comprehensive report on a given claim or issue. The STH agent can use the following tools: engage TIA agent, Data Lake Execute Query, Query Builder, Log Analyzer, Write to Confluence, Alert Processor, and Alert CTI Model.

[0221] Figure 21 illustrates a workflow 2100 for detecting emerging computer security issues in accordance with one or more embodiments. The steps and sub-steps of workflow 2100 are executed by a CTI OSINT agent. In workflow 2100, a new security report is received at block 2102. The security report may include, for example, news articles, social media posts, emails or messages, alerts, audio / video recordings, or any other data related to computer security. At block 2104, features such as content, title, date, and links are extracted from the security-related news. At block 2106, relevant internal documents are identified, and if the news article is determined to be relevant at decision block 2108, information about the computer security issue, such as indicators, summaries, techniques, vulnerabilities, affected packages, etc., is extracted from the news article, and the urgency is classified. A ticket for the emerging computer security issue is created at block 2112 for human review.

[0222] In one embodiment, evaluating the security of a computer system includes evaluating the exploitability of a vulnerability in an executable file. Often, vulnerabilities exist in files that are part of a package installed within a virtual machine. However, application code may not have an execution path to call such a file. An AI agent evaluates the computer system to determine whether the vulnerable file has an execution path and is callable. The one or more additional AI agents receive, as input together with an alert, computer security data (e.g., the source code of the file), understand the stack trace of the code flow, analyze the source code to determine whether the file has an execution path, and generate a result of the source code analysis as output.

[0223] In step 1508 of Figure 15, the results of the computer security problem evaluation are output. For example, the results of the computer security problem evaluation can be output by displaying the results on a display device of the computer system (e.g., the display 1125 of the computing system 1100 in Figure 11), by storing the results in the memory or storage device of the computer system (e.g., the memory 1115 of the computing system 1100 in Figure 11), or by transmitting the results to a remote computer system (e.g., the computing system 1100 via a communication device 1120).

[0224] Figure 22 shows a workflow 2200 for security event management according to one or more embodiments. Workflow 2200 shows a high-level workflow performed by an Incident (Security Event) Commander Agent using various tools. In workflow 2200, the incident confirmation step 2202 is performed by ingesting external incident reports 2212 and alerts 2222, incident tracking 2204 is performed by the tracker tool 2214, task tracking 2206 is performed by the ticketing tool 2216, evidence handling 2208 is performed by the shared environment tool 2218, and incident coordination 2210 is performed by the messenger tool 2220.

[0225] Figure 23 shows a workflow 2300 for forensic acquisition according to one or more embodiments. Workflow 2300 may be performed by one or more tools, such as cloud forensic acquisition or endpoint forensic acquisition. In workflow 2300, for each virtual machine, virtual machine details are acquired in step 2303. For each virtual disk of a virtual machine, disk snapshots 2304 and 2312 are taken and copied to forensic databases 2306 and 2314. A command to perform a memory dump is executed in step 2308, and the memory dump is performed in step 2310. The forensic acquisition is coordinated by tracker 2316.

[0226] Figure 24 shows a workflow 2400 for creating a dedicated forensics environment according to one or more embodiments. Workflow 2400 can be performed by one or more tools, such as the create dedicated forensics environment tool. The forensics server is created from a template in step 2402. The forensics server is created within a virtual server 2412 on a workstation. SSH (secure shell) access to the virtual server 2412 is obtained in step 2404. For each snapshot, the snapshot is saved to disk in step 2406, and the disk is attached to a virtual machine 2408 within the virtual server 2412. The disk is mounted within the virtual server 2412 in step 2410.

[0227] The steps disclosed herein (including the steps and substeps of Figures 14 to 24) may be executed by a computer program encoding instructions that direct a processor to perform at least some of the steps disclosed herein, in accordance with embodiments of the present invention. The computer program may be embodied on a non-temporary computer-readable medium. The computer-readable medium may include, but is not limited to, a hard disk drive, a flash device, RAM, tape, and / or other such medium or combination of mediums used to store data. The computer program may include encoded instructions for controlling a processor of a computing system (e.g., processor 1110 of computing system 1100 in Figure 11) to implement all or some of the steps disclosed herein, and these instructions may also be stored on a computer-readable medium.

[0228] Computer programs can be implemented in hardware, software, or a hybrid implementation. Computer programs may consist of modules designed to communicate with each other in an operable manner and to pass information or instructions to a display. Computer programs may be configured to run on a general-purpose computer, an ASIC, or any other suitable device.

[0229] It will be readily apparent that the components of various embodiments of the present invention can be arranged and designed in a wide variety of different configurations, as generally described and illustrated in the drawings herein. Therefore, the detailed description of embodiments of the present invention shown in the accompanying drawings is not intended to limit the claimed scope of the invention, but merely to represent selected embodiments of the invention.

[0230] The features, structures, or characteristics of the present invention described throughout this specification may be combined in any suitable way in one or more embodiments. For example, any reference throughout this specification to “a particular embodiment,” “some embodiments,” or similar phrases means that the particular features, structures, or characteristics described in relation to that embodiment are included in at least one embodiment of the present invention. Therefore, the occurrence of “a particular embodiment,” “some embodiments,” “other embodiments,” or similar phrases throughout this specification does not necessarily refer to the same group of embodiments, and the described features, structures, or characteristics may be combined in any suitable way in one or more embodiments.

[0231] Furthermore, it should be noted that throughout this specification, references to features, advantages, or similar terms do not imply that all features and advantages that can be realized by the present invention should or must be included in any single embodiment of the invention. Rather, terms referring to features and advantages should be understood to mean that certain features, advantages, or characteristics described in relation to embodiments are included in at least one embodiment of the invention. Accordingly, discussions of features and advantages, and similar terms throughout this specification may, but not necessarily, refer to the same embodiment.

[0232] Furthermore, the features, advantages, and characteristics of the present invention described herein can be combined in any suitable manner in one or more embodiments. Those skilled in the art will recognize that the present invention may be implemented without one or more specific features or advantages of a particular embodiment. In other cases, additional features and advantages not present in all embodiments of the present invention may be recognized in a particular embodiment.

[0233] Those skilled in the art will readily understand that the present invention, as described above, can be implemented in a different sequence of steps and / or with hardware elements of a different configuration than those disclosed. Therefore, although the present invention has been described based on these preferred embodiments, it is obvious that certain modifications, changes, and alternative configurations will be apparent to those skilled in the art, while remaining within the spirit and scope of the invention. Accordingly, to define the technical scope of the invention, one should refer to the appended claims.

Claims

1. A computer implementation method, Receiving alerts regarding computer security issues in computer systems, The initial AI (artificial intelligence) agent determines: 1) a strategy for evaluating the computer security problem, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security problem. Using the one or more additional AI agents, evaluate the computer security problem in accordance with the strategy, To output the evaluation results of the aforementioned computer security problem, Computer implementation methods, including those mentioned above.

2. The computer implementation method according to claim 1, wherein the initial AI agent and the one or more additional AI agents have roles defined by a role definition file provided as contextual information via one or more prompts.

3. The computer implementation method according to claim 2, wherein each of the role definition files includes a title, background, tasks, knowledge, skills, and capabilities for an AI agent.

4. The initial AI (artificial intelligence) agent determines: 1) a strategy for evaluating the computer security problem, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security problem. The computer implementation method according to claim 1, comprising determining 1) the strategy and 2) the one or more additional AI agents based on a procedure provided as contextual information via one or more prompts by the initial AI agent.

5. The strategy for evaluating the aforementioned computer security problem is, The computer implementation method according to claim 1, comprising classifying the alerts by at least one of the one or more additional AI agents.

6. The strategy for evaluating the aforementioned computer security problem is, The computer implementation method according to claim 1, further comprising mitigating the computer security problem with one or more of the one or more additional AI agents.

7. Using the one or more additional AI agents described above, the computer security problem can be evaluated according to the strategy described above. The computer implementation method according to claim 6, further comprising automatically performing the mitigation of the computer security problem using one or more of the one or more additional AI agents.

8. The strategy for evaluating the aforementioned computer security problem is, The computer implementation method according to claim 1, comprising identifying newly occurring computer security issues based on a security report.

9. Receiving an alert regarding a computer security issue in the aforementioned computer system, The computer implementation method according to claim 1, comprising receiving the alert from a security monitoring / alert system.

10. It is a system, At least one processor, Memory that stores computer instructions, The computer instruction is provided and, when executed by the at least one processor, the system Receiving alerts regarding computer security issues in computer systems, The initial AI (artificial intelligence) agent determines: 1) a strategy for evaluating the computer security problem, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security problem. Using the one or more additional AI agents, evaluate the computer security problem in accordance with the strategy, To output the evaluation results of the aforementioned computer security problem, A system that performs actions including those mentioned above.

11. The system according to claim 10, wherein the initial AI agent and the one or more additional AI agents have roles defined by a role definition file provided as contextual information via one or more prompts.

12. The system according to claim 11, wherein each of the role definition files includes a title, background, tasks, knowledge, skills, and capabilities for an AI agent.

13. The initial AI (artificial intelligence) agent determines: 1) a strategy for evaluating the computer security problem, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security problem. The system according to claim 10, comprising the initial AI agent determining 1) the strategy and 2) the one or more additional AI agents based on procedures provided as contextual information via one or more prompts.

14. The strategy for evaluating the aforementioned computer security problem is, The system according to claim 10, further comprising classifying the alerts by at least one of the one or more additional AI agents.

15. A non-temporary computer-readable medium for storing computer program instructions for developing RPA (Robotic Process Automation) workflows, wherein, when the computer program instructions are executed on at least one processor, the at least one processor... Receiving alerts regarding computer security issues in computer systems, The initial AI (artificial intelligence) agent determines: 1) a strategy for evaluating the computer security problem, and 2) one or more additional AI agents from a pool of AI agents for evaluating the computer security problem. Using the one or more additional AI agents, evaluate the computer security problem in accordance with the strategy, To output the evaluation results of the aforementioned computer security problem, A non-temporary computer-readable medium that enables the execution of actions including [specific actions].

16. The non-temporary computer-readable medium according to claim 15, wherein the initial AI agent and the one or more additional AI agents have roles defined by a role definition file provided as contextual information via one or more prompts.

17. The strategy for evaluating the aforementioned computer security problem is, The non-temporary computer-readable medium according to claim 15, comprising mitigating the computer security problem with one or more of the aforementioned additional AI agents.

18. Using the one or more additional AI agents described above, the computer security problem can be evaluated according to the strategy described above. The non-temporary computer-readable medium according to claim 17, comprising automatically performing the mitigation of the computer security problem by one or more of the one or more additional AI agents.

19. The strategy for evaluating the aforementioned computer security problem is, A non-temporary computer-readable medium according to claim 15, comprising identifying newly emerging computer security issues based on news articles.

20. Receiving an alert regarding a computer security issue in the aforementioned computer system, A non-temporary computer-readable medium according to claim 15, comprising receiving the alert from a security monitoring / alert system.