System and method for generating network security remediation in computing environment

By configuring generative remediation machines and large language models (LLMs) in a cloud computing environment, the problem of slow remediation processes and high-level licensing in the prior art is solved, and efficient automated remediation is achieved.

CN120185846APending Publication Date: 2025-06-20WIZ INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411750603.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-18
Filing Date
2024-12-02
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In cloud computing environments, existing remediation solutions require a slow remediation process due to the need for high-level licensing and access, and organizations are reluctant to allow third parties to continue such access, or need to maintain expensive specialization.

Method used

By configuring a generative remediation machine in the system, using a large language model (LLM) to generate remediation actions, automating the remediation process and reducing the need for high-level permissions and access.

Benefits of technology

It realizes the generation and execution of automated remediation actions in a cloud computing environment, improves the efficiency of the remediation process, and reduces the need for professional maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185846A_ABST
    Figure CN120185846A_ABST
Patent Text Reader

Abstract

A system and method for generating remedial actions in a computing environment based on network security checks. The method comprises the following steps: checking a network security object in a computing environment; detecting a network security issue in the computing environment based on the detection of the network security object; generating an input for a generative remedial device based on the detected network security issue, where the generative remedial device is configured to generate an output comprising a remedial action based on the input; and initiating a remedial action in the computing environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to network security remediation, and more particularly to the automatic generation of remediation actions in a cloud computing environment. Background Art

[0002] Network security threats can arise in a computing environment in various ways. For example, in a cloud computing environment, some threats include vulnerabilities, misconfigurations, exposures, and exploitations, etc.

[0003] There are various solutions for monitoring network security threats in a computing environment, including threat detection and digital forensics solutions, etc. Although monitoring typically requires read-level access to the computing environment, remediation and mitigation require actions to be executed and initiated in the computing environment, and these actions generally require a higher level of permission and access than simple read-level access.

[0004] For reasons such as these, the adopted remediation solutions are slow because organizations are reluctant to allow third parties to continuously have such access. Alternatively, the remediation solutions can be maintained and provided by the organization itself in the computing environment, but this requires maintaining expensive specialization.

[0005] Therefore, it would be advantageous to provide a solution that can overcome the above challenges. Summary of the Invention

[0006] The following is an overview of several example embodiments of this disclosure. This overview is provided to facilitate a basic understanding of these embodiments by the reader and does not fully define the breadth of this disclosure. This overview is not an extensive review of all contemplated embodiments and is neither intended to identify the key or important elements of all embodiments nor to depict the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description presented later. For convenience, the term "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of this disclosure.

[0007] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or a combination thereof on the system, and the software, firmware, hardware, or a combination thereof causes the system to perform these actions during operation. One or more computer programs can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform these actions.

[0008] In one general aspect, a method may include inspecting network security objects in a computing environment. The method may also include detecting a network security issue in the computing environment based on the detection of the network security objects. The method may further include generating an input for a generative remediator based on the detected network security issue, where the generative remediator is configured to generate an output including a remediation action based on the input. The method may additionally include initiating the remediation action in the computing environment. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0009] Implementations may include one or more of the following features. The method may include: generating a prompt as an input, the prompt being provided to a large language model (LLM) of the generative remediator. The method may include: generating a representation of the computing environment in a security database, the security database including a representation schema. In the method, the prompt is generated based on any of: a predefined template, a network security issue, and the representation schema. The method may include: further generating the prompt based on a predefined remediation action. The method may include: generating multiple remediation actions, each remediation action including a priority value; and generating a visual representation of each remediation action based on the priority value. The method may include: generating multiple remediation actions, each remediation action pointing to a computing platform among multiple computing platforms of the computing environment, each computing platform being associated with the detected network security issue; and receiving a selection of a first remediation action among the multiple remediation actions, where the first remediation action remediates the network security issue when initiated. The method may include: receiving a selection of a preferred computing platform among the multiple computing platforms of the computing environment; and further configuring the generative remediator to generate an output including a remediation action based on the received selection of the preferred computing platform. Implementations of the described techniques may include hardware, a method or process, or a computer tangible medium.

[0010] In one general aspect, a non-transitory computer-readable medium may include one or more instructions that, when executed by one or more processors of a device, cause the device to: inspect network security objects in a computing environment. The medium may also detect a network security issue in the computing environment based on the detection of the network security objects. The medium may additionally generate an input for a generative remediator based on the detected network security issue, where the generative remediator is configured to generate an output including a remediation action based on the input. The medium may also initiate the remediation action in the computing environment. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0011] In one general aspect, a system can include processing circuitry. The system can also include a memory that contains instructions that, when executed by the processing circuitry, configure the system to: inspect network security objects in a computing environment. The system can additionally detect a network security issue in the computing environment based on the detection of the network security objects. The system can also generate an input for a generative remediator based on the detected network security issue, where the generative remediator is configured to generate an output that includes remediation actions based on the input. The system can also initiate the remediation actions in the computing environment. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0012] Implementations can include one or more of the following features. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate a prompt as an input that is provided to a large language model (LLM) of the generative remediator. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate a representation of the computing environment in a security database that includes a representation schema. In the system, the prompt is generated based on any of: a predefined template, a network security issue, and a representation schema. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: further generate a prompt based on predefined remediation actions. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate multiple remediation actions, each remediation action including a priority value; and generate a visual representation of each remediation action based on the priority value. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: generate multiple remediation actions, each remediation action targeting a computing platform among a plurality of computing platforms of the computing environment, each computing platform associated with the detected network security issue; and receive a selection of a first remediation action among the multiple remediation actions, where the first remediation action remediates the network security issue when initiated. In the system, the memory contains further instructions that, when executed by the processing circuitry, further configure the system to: receive a selection of a preferred computing platform among the plurality of computing platforms of the computing environment; and further configure the generative remediator to generate an output that includes remediation actions based on the received selection of the preferred computing platform. Implementations of the described techniques can include hardware, a method or process, or a computer tangible medium. Brief Description of the Drawings

[0014] The subject matter disclosed herein is particularly pointed out and distinctly claimed in the claims of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0015] Figure 1 FIG. is an example schematic diagram of an inspection environment and a computing environment with a generative remediator implemented according to an embodiment.

[0016] Figure 2 FIG. is an example diagram of a security graph implemented according to an embodiment.

[0017] Figure 3 FIG. is an example schematic diagram of a generative remediator data flow implemented according to an embodiment.

[0018] Figure 4 FIG. is an example flowchart of a method for generating a remediation action implemented according to an embodiment.

[0019] Figure 5 FIG. is an example flowchart of a method for initiating a remediation action implemented according to an embodiment.

[0020] Figure 6 FIG. is an example schematic diagram of a generative remediator implemented according to an embodiment. DETAILED DESCRIPTION

[0021] It is important to note that the embodiments disclosed herein are merely examples of many useful applications of the innovative teachings herein. In general, statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Additionally, some statements may apply to some inventive features but not to others. In general, unless otherwise stated, without loss of generality, a singular element may be plural and vice versa. In the figures, the same numerals refer to the same parts in several views.

[0022] Figure 1 FIG. is an example schematic diagram of an inspection environment and a computing environment with a generative remediator implemented according to an embodiment.

[0023] In an embodiment, the computing environment 110 includes a plurality of entities, such as resources, subjects, etc. For example, in an embodiment, the entity is a cloud entity.

[0024] In some embodiments, the computing environment 110 is a cloud computing environment, an on-prem environment, a hybrid environment, and combinations thereof, etc. In certain embodiments, the cloud computing environment includes a virtual private cloud (VPC) and a virtual network (VNet), etc.

[0025] In some embodiments, the cloud computing environment is deployed on a cloud computing infrastructure. In an embodiment, the cloud computing infrastructure is Amazon Web Services ( Web Services, AWS), Google Cloud Platform ( CloudPlatform, GCP), and Microsoft Azure ( Azure), etc.

[0026] In some embodiments, the computing environment 110 includes multiple resources, such as virtual machines 112, software containers 114, serverless functions 116, and various combinations thereof. According to some embodiments, the virtual machine 112 is, for example The software container 114 utilizes a platform, and the serverless function 116 is Lambda.

[0027] In some embodiments, the computing environment 110 includes multiple entities, such as user accounts, service accounts, local accounts, user groups, roles, and various combinations thereof.

[0028] In an embodiment, the computing environment 110 is monitored by a network security inspection environment 120 (also referred to as the inspection environment 120). In some embodiments, the inspection environment 120 is implemented as a cloud computing environment, a hybrid environment, an on-premises environment, and combinations thereof.

[0029] In an embodiment, the inspection environment 120 includes multiple inspector workloads, such as inspector 122. In some embodiments, the inspector 122 is configured to detect network security objects. For example, in an embodiment, the inspector 122 is configured to detect network security objects on a disk associated with the virtual machine 112. In an embodiment, for example, clones, replicas, and snapshots generated based on the disk of the virtual machine 112 are used to generate an inspectable disk.

[0030] In some embodiments, the inspectable disk is inspected by the inspector 122. This allows, for example, static analysis to be performed on the disk without disturbing the virtual machine 112 or utilizing its resources. In an embodiment, the network security objects are files, secrets, passwords, sensitive data, code objects, hashes, keys, certificates, registry files, libraries, packages, binaries, applications, operating systems, malware, nested workloads, and combinations thereof.

[0031] In some embodiments, cybersecurity objects are used to detect cybersecurity risks. For example, in an embodiment, secrets and passwords are stored as easily accessible plaintext and clear text, etc. In such an embodiment, for example, by storing secrets in this way, the secrets are more likely to be exposed, thus presenting a higher cybersecurity risk. In some embodiments, a secret provides access to another resource, thereby creating a cybersecurity risk for the lateral movement path.

[0032] In some embodiments, the inspection controller 124 is configured to initiate the generation of an inspectable disk using a service account in the computing environment 110. In certain embodiments, the inspection controller 124 is configured to generate an inspector workload (such as the inspector 122, etc.) in response to a demand for an inspector workload. For example, in an embodiment, the inspection controller 124 is configured to have permission to instantiate a virtual instance that executes an application configured to inspect an inspectable disk for cybersecurity objects.

[0033] According to some embodiments, the inspector 122 is configured to store data, information, etc. about cybersecurity objects, inspections, etc. in the security database 126. In some embodiments, the security database 126 includes constraints and predefined data schemas, etc., which are used to represent the computing environment 110.

[0034] In some embodiments, the data schema of the security database 126 is used to represent the computing environment 110 using multiple data templates, each template describing a different entity. For example, in an embodiment, a first data template is used to describe a resource, and a second data template is used to describe a subject. In an embodiment, the first data template is used to describe any resource in the computing environment 110, that is, the first data template is used to represent the virtual machine 112, the serverless function 116, and the software container 114.

[0035] In certain embodiments, the security database 126 is implemented as a tabular database, a columnar database, an SQL database, a non - SQL database, a graph database, and various combinations thereof, etc. For example, in an embodiment, the security database 126 is a graph database, such as etc., where subjects, resources, remediation actions, cybersecurity risks, cybersecurity objects, enrichments, and endpoints, etc. are stored as nodes on the graph stored in the security database 126. The following references Figure 2 discusses in more detail an example representation of the computing environment.

[0036] According to an embodiment, the inspection environment 120 further includes a generative remediator 128. In an embodiment, the generative remediator includes a generated artificial intelligence model, such as a large language model (LLM), etc. In some embodiments, the LLM is, for example etc.

[0037] In some embodiments, the generative remediator 128 is configured to generate remediation actions. In some embodiments, the generative remediator 128 is configured to generate remediation actions in response to detecting cybersecurity threats and cybersecurity risks, etc., such as based on detecting cybersecurity objects. In embodiments, cybersecurity threats include misconfigurations, vulnerabilities, exposures, and various combinations thereof, etc.

[0038] In some embodiments, a cybersecurity threat is detected in response to detecting multiple cybersecurity objects, a cybersecurity object and an attack path (e.g., an exposure), a cybersecurity object and a vulnerability, and various combinations thereof, etc. In an implementation, such a combination is also referred to as a toxic combination.

[0039] In embodiments, the generative remediator 128 is configured to generate prompts for the LLM. In some embodiments, the prompts are generated based on the representation schema of the security database 126, discoveries (e.g., the results of cybersecurity inspections, such as the detection of cybersecurity objects), predefined actions, and combinations thereof, etc.

[0040] According to an embodiment, the generative remediator 128 is configured to generate prompts based on a predefined template. In embodiments, generating a prompt based on a predefined template includes parsing the input received by the generative remediator 128, detecting the values of data fields therein, and adjusting the predefined template based on the detected data values.

[0041] In certain embodiments, it is advantageous to provide the LLM with a prompt that includes a data schema for representation (i.e., a representation schema), as this reduces the need to fine-tune the LLM.

[0042] In some embodiments, the generative remediator 128 is further configured to initiate remediation actions. In certain embodiments, the remediation actions are: initiation of a resource, initiation of a principal, and combinations thereof, etc.

[0043] For example, according to an embodiment, the remediation actions include: revoking access to a resource, revoking access from a resource, revoking access from a principal, revoking access to a principal, updating the permissions of a principal, changing the user group of a principal, changing the role of a principal, revoking an access token, sandboxing a resource, configuring a firewall to filter traffic to a resource, configuring a firewall to filter traffic from a resource, generating an alert, installing a patch, removing a software application from a resource, updating a software package, removing a software package, and combinations thereof, etc.

[0044] Figure 2 It is an example diagram of a security graph implemented according to an embodiment. In embodiments, for example, the cybersecurity objects of a virtual machine are inspected by an inspector discussed in more detail throughout the text.

[0045] According to an embodiment, a checker and a check controller, etc. are configured to generate a representation of a virtual machine, such as a virtual machine (VM) node 230. In an embodiment, the checker is configured to detect an application endpoint represented as an endpoint node 220. The application endpoint allows the virtual machine to connect to a public network, such as the Internet, etc. In an embodiment, the endpoint node 220 is connected to a public network node 210, which means that the application (APP) endpoint can access the public network.

[0046] In some embodiments, the checker is also configured to detect hosting technologies. For example, according to an embodiment, hosting technologies (such as databases, etc.) are represented by hosting technology nodes. In some embodiments, the database is represented by a database (DB) node 232, and the DB node 232 is connected to the VM node 230 to indicate that the DB is hosted on the VM.

[0047] According to an embodiment, the checker is configured to detect secrets on the VM. In some embodiments, a single checker is configured to detect multiple network security objects. In other embodiments, each checker is configured to detect a single network security object.

[0048] In an embodiment, the detected secret is represented by a secret node 234 connected to the VM node 230. In some embodiments, the detected secret is associated with a user account represented by a user node 240. In an embodiment, the user account is configured to assume an administrator account, represented by an administrative node 250. In an embodiment, the administrator account is configured to access resources (such as buckets, etc.) that expose the data therein. In some embodiments, the resource is represented by a resource node 260.

[0049] In certain embodiments, the checker is configured to detect a network security object that indicates the VM includes vulnerabilities, exposures, misconfigurations, etc. (e.g., represented by a CVE (common vulnerabilities and exposures) node 235). For example, in an embodiment, the CVE node 235 represents the Log4Shell vulnerability in Log4j. According to an embodiment, the CVE node 235 is connected to the VM node 230 to indicate that a vulnerability is detected on the VM.

[0050] In some embodiments, the security discovery is represented by a security discovery node 231. For example, according to an embodiment, access logs (such as network logs, cloud logs, and event logs, etc.). In some embodiments, the logs are parsed to detect the identifier of the VM.

[0051] In an embodiment, an event is detected in a log, the event corresponding to an identifier corresponding to a security finding. For example, in an embodiment, multiple unsuccessful access events indicate an attempt to brute-force a VM. In some embodiments, a security discovery node 231 is connected to a VM node 230 to indicate that a security discovery has been detected regarding the VM.

[0052] In certain embodiments, a security database is configured to detect a potential lateral movement path from a VM (VM node 230) to a resource (resource node 260) by obtaining access to the VM (e.g., by brute force), obtaining access to secrets stored thereon, and leveraging the user from there to obtain administrative access to the resource. In an embodiment, a lateral movement (LM) path and a potential lateral movement path, etc. are represented by an LM discovery node 233 connected to the VM node 230 to indicate, for example, that there is a lateral movement path between the VM node 230 and another resource.

[0053] In some embodiments, a toxic combination is defined by policies, conditions, rules, and combinations thereof, etc. For example, in the above embodiment, a vulnerability in combination with a secret has a higher cybersecurity risk compared to the presence of any one of these findings alone.

[0054] Detecting such toxic combinations is beneficial because they allow remedial actions to be initiated at multiple points (e.g., each element of the toxic combination) to address cybersecurity threats.

[0055] In certain embodiments, nodes representing findings, cybersecurity risks, and cybersecurity objects, etc. are connected to a remediation node, where the remediation node represents a remedial action. In some embodiments, for example, a generative remediator is configured to detect a remedial action based on the remediation node and adapt a remedial action template to a specific finding.

[0056] Figure 3 is an example schematic diagram of a generative remediator data flow implemented according to an embodiment. In an embodiment, a generative remediator 310 is configured to receive multiple inputs. In some embodiments, the received inputs are predefined actions 320, findings 330, representation patterns 340, and combinations thereof, etc.

[0057] In an embodiment, the predefined action 320 is a remedial action, a remedial script, an instruction, and combinations thereof, etc. In some embodiments, the predefined action 320 includes a template, predefined values, and combinations thereof, etc.

[0058] In certain embodiments, the finding 330 is generated by a security graph, an inspector, and an inspection controller, etc., for example, based on cybersecurity objects detected in a computing environment.

[0059] In some embodiments, 330 is found to be security discovery, lateral movement discovery, CVE discovery, privilege escalation discovery, and various combinations thereof. In some embodiments, security discovery indicates network security issues and toxic combinations of network security issues. For example, in an embodiment, the network security issues are vulnerabilities, misconfigurations, exposures, attack paths, and combinations thereof.

[0060] In an embodiment, for example, security discoveries are generated based on events in detection logs. For example, a security discovery is the detection of a brute-force attack (e.g., multiple failed login attempts). According to an embodiment, lateral movement discovery includes detecting a lateral movement path between a first resource and a second resource, such as by traversing a security graph in a security database to detect potential lateral movement paths. In an embodiment, lateral movement discovery includes secrets, keys, and principals that connect a first resource to a second resource.

[0061] According to an embodiment, the representation schema includes database schemas and constraints, etc., which are used to represent a computing environment, its discoveries, its enrichments, remediation actions, network security risks, network security threats, and network security objects, etc. in a security database.

[0062] In an embodiment, the generative remediator 310 is configured to receive user input as further input. For example, in an embodiment, the user input indicates a platform preference for remediating network security issues.

[0063] In certain embodiments, the computing environment includes multiple platforms, such as CLI (command line interface), cloud computing consoles, infrastructure as code (IaC) platforms, and various combinations thereof. Additionally, in some embodiments, various remediation actions can be deployed in a production environment, such as by instructing an admission controller and sensors, etc. to initiate the remediation actions.

[0064] Thus, according to an embodiment, network security issues can be remediated from multiple points in the environment. For example, the network security issue can be the detection of an exposure due to a misconfiguration (e.g., a database with sensitive data not protected by a password, hosted on a virtual machine on which a sensor is deployed).

[0065] In an embodiment, remediating the above network security issues includes any of the following: configuring a sensor to set a password for the database, updating code objects in an IaC file (e.g., file), deploying a VM with a hosted database from the file to include password protection, etc. In certain embodiments, user preferences are determined corresponding to the platform for remediating network security issues. In some embodiments, multiple preferred platforms are selected.

[0066] According to an embodiment, the generative remediator 310 is configured to generate a remediation action 350. In some embodiments, the remediation action 350 includes a remediation script, such as multiple lines of code that remediate a cybersecurity issue when executed in a computing environment.

[0067] In certain embodiments, the generative remediator 310 is configured to generate multiple remediation actions. In some embodiments, the generative remediator 310 is configured to generate a priority value for each of the multiple remediation actions. For example, in an embodiment, the priority value is generated based on past success indicators. This is advantageous because remediation actions that have been found to be effective in remediating cybersecurity issues in the past may be effective for current cybersecurity threats.

[0068] Figure 4 is an example flowchart of a method for generating a remediation action implemented according to an embodiment.

[0069] In S410, the computing environment is checked for cybersecurity objects. In an embodiment, checking the computing environment for cybersecurity objects includes: detecting a plurality of resources deployed in the computing environment.

[0070] In certain embodiments, detecting the plurality of resources includes, for example, entity discovery. In an embodiment, entity discovery includes querying an application programming interface (API) of the computing environment (such as a cloud computing environment) to determine which resources and workloads are deployed therein.

[0071] For example, according to an embodiment, the cloud API is accessed to determine which virtual machines, software containers, serverless functions, microservices, buckets, storage, and software repositories are deployed in the computing environment.

[0072] In an embodiment, the resources are checked to detect nested resources therein. For example, in an embodiment, a virtual machine is configured to host a software container platform (such as Kubernetes), and each virtual machine and the software containers deployed thereon are separately checked for cybersecurity objects.

[0073] In some embodiments, checking the computing environment includes generating an inspectable disk based on the raw disks deployed in the computing environment. In certain embodiments, generating the inspectable disk includes generating a clone, copy, snapshot, and combinations thereof of the raw disk.

[0074] According to an embodiment, in response to a request to initiate a raw disk check, the inspectable disk is generated on demand, and in response to determining that the check is complete, the resources allocated to the inspectable disk are released.

[0075] In some embodiments, multiple inspectors are allocated to inspect network security objects of an inspectable disk, and each inspector is configured to inspect different network security objects. For example, in an embodiment, a first inspector is configured to inspect nested workloads, while a second inspector is configured to inspect secrets.

[0076] In embodiments, network security objects are files, secrets, passwords, sensitive data, code objects, hashes, keys, certificates, registry files, libraries, packages, binaries, applications, operating systems, malware, nested workloads, and combinations thereof, etc.

[0077] In S420, network security issues are detected. In embodiments, network security issues are detected based on the detection of network security objects. In some embodiments, network security issues are detected based on a combination of the detection of network security objects and findings. For example, in an embodiment, findings are security findings, lateral movement findings, privilege escalation findings, vulnerabilities, exposures, misconfigurations, malware, attack paths, and various combinations thereof, etc.

[0078] As an example, a combination (also referred to as a toxic combination) includes detecting vulnerabilities, such as running an application with a known vulnerability and managed technologies of endpoints (e.g., indicating public network access), where the managed technologies are configured to employ a service account with high permissions.

[0079] In certain embodiments, detecting a toxic combination includes imposing policies, rules, conditions, etc. on a representation of a computing environment. In some embodiments, a security database is queried based on, for example, a pre-existing query that is configured to detect a toxic combination. For example, in some embodiments, a security graph is traversed to detect nodes corresponding to a query directed to the security graph, such as the graph discussed in more detail above with respect to Figure 2 the graph discussed in more detail above.

[0080] In certain embodiments, multiple network security issues are detected. In some embodiments, each network security issue includes a priority score, a severity score, and combinations thereof, etc. For example, in an embodiment, the scores are qualitative scores (e.g., low, medium, high), quantitative scores (e.g., from 1 to 10), and combinations thereof, etc.

[0081] In S430, a remediation action is generated. In embodiments, the remediation action is generated by a generative remediator configured to generate the remediation action. In some embodiments, the remediation action is generated based on the network security issue.

[0082] In embodiments, the generative remediator is configured to receive the network security issue, including, for example, identifiers of resources (e.g., names in a namespace and IP addresses, etc.) and data about network security objects, etc., and generate a remediation action based on the received input.

[0083] In some embodiments, the remediation action is generated based on a template, such as including a code template. In an embodiment, the code template includes machine-readable instructions that, when executed in a computing environment (such as a cloud computing environment, etc.), cause the remediation action to be initiated.

[0084] In some embodiments, the generative remediator is configured to generate prompts for a large language model (LLM), which is configured to generate remediation actions. In an embodiment, the prompts are generated based on a template (such as based on a code template).

[0085] In some embodiments, a first LLM is used to generate prompts and a second LLM is used to generate remediation actions. In an embodiment, the first LLM and the second LLM are the same model.

[0086] In an embodiment, when provided to the LLM model, the prompt configures the LLM model to generate an output that includes a remediation action. In an embodiment, the remediation action includes a remediation script and multiple remediation scripts, etc. In an embodiment, the remediation script includes code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is a script.

[0087] Figure 5 is an example flowchart of a method for initiating a remediation action according to an embodiment. In an embodiment, the initiated remediation action is generated by the generative remediator, as discussed in more detail above regarding Figure 4 more detailed discussion.

[0088] In S510, an input is received. In an embodiment, the received input is provided to the generative remediator. In some embodiments, the received input includes a cybersecurity issue, a cybersecurity alert, a predefined action, a discovery, a representation pattern, and combinations thereof, etc.

[0089] In an embodiment, the predefined action is a remediation action, a remediation script, an instruction, and combinations thereof, etc. In some embodiments, the predefined action includes a template, a predefined value, and combinations thereof, etc.

[0090] In certain embodiments, for example, based on a cybersecurity object detected in a computing environment, a discovery is generated by a security graph, an inspector, and an inspection controller, etc.

[0091] In some embodiments, the discovery is a security discovery, a lateral movement discovery, a CVE discovery, a privilege escalation discovery, and various combinations thereof, etc. In some embodiments, the security discovery indicates a cybersecurity issue and a toxic combination of cybersecurity issues, etc. For example, in an embodiment, the cybersecurity issue is a vulnerability, a misconfiguration, an exposure, an attack path, and combinations thereof, etc.

[0092] In an embodiment, for example, security findings are generated based on events in a detection log. For example, a security finding is the detection of a brute-force attack (e.g., multiple failed login attempts). According to an embodiment, lateral movement discovery includes detecting a lateral movement path between a first resource and a second resource, e.g., by traversing a security graph in a security database to detect potential lateral movement paths. In an embodiment, lateral movement discovery includes secrets, keys, principals, etc., that connect the first resource to the second resource.

[0093] According to an embodiment, a representation schema includes a database schema, constraints, etc., for representing a computing environment, its findings, its enrichment, remediation actions, cybersecurity risks, cybersecurity threats, cybersecurity objects, etc. in a security database.

[0094] In an embodiment, a generative remediator is configured to receive user input as further input. For example, in an embodiment, the user input indicates a platform preference for remediating a cybersecurity issue.

[0095] In S520, a prompt is generated. In an embodiment, the prompt is generated by a first LLM and provided as input to a second LLM. In some embodiments, the first LLM is the second LLM.

[0096] In some embodiments, the generative remediator is configured to generate a prompt for a large language model (LLM) that is configured to generate remediation actions. In an embodiment, the prompt is generated based on a template (e.g., based on a code template).

[0097] In an embodiment, when provided to the LLM model, the prompt configures the LLM model to generate an output that includes remediation actions. In an embodiment, the remediation actions include remediation scripts and multiple remediation scripts, etc. In an embodiment, the remediation script includes code, such as high-level code, etc. In some embodiments, the high-level code script, for example, is a script.

[0098] In S530, a remediation action is initiated. In an embodiment, the remediation action is generated based on the output of the LLM. For example, according to an embodiment, the prompt generated in S520 is provided to the LLM, and the LLM is configured to generate an output that includes the remediation action.

[0099] In an embodiment, initiating the remediation action includes executing one instruction and multiple instructions, etc. in the computing environment. In certain embodiments, the initiated remediation action is initiated with respect to a computing platform among multiple computing platforms deployed in the computing environment. For example, according to an embodiment, the computing environment is a command line interface (CLI), an infrastructure as code (IaC) platform, a console, a sensor, an admission controller, and combinations thereof, etc.

[0100] Figure 6 FIG. 1 is an exemplary schematic diagram of a generative remediator 128 according to an embodiment. The generative remediator 128 includes a processing circuit 610 that is coupled to a memory 620, a storage device 630, and a network interface 640. In an embodiment, the components of the generative remediator 128 may be communicatively connected via a bus 650.

[0101] The processing circuit 610 may be understood as one or more hardware logic components and circuits. By way of example and not limitation, illustrative types of hardware logic components that may be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-a-chip systems (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general purpose microprocessors, microcontrollers, and digital signal processors (DSPs), among others, or any other hardware logic component that can perform computational or other information operations.

[0102] The memory 620 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read only memory, flash memory, etc.), or a combination thereof. In an embodiment, the memory 620 is on-chip memory, off-chip memory, and combinations thereof, etc. In certain embodiments, the memory 620 is a scratchpad memory for the processing circuit 610.

[0103] In one configuration, software for implementing one or more embodiments disclosed herein may be stored in the storage device 630, the memory 620, and combinations thereof, etc. Software should be construed broadly as any type of instructions, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. The instructions may include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by the processing circuit 610, the instructions cause the processing circuit 610 to perform the various processes described herein.

[0104] The storage device 630 is a magnetic storage device, an optical storage device, a solid state storage device, and combinations thereof, etc. According to an embodiment, the storage device 630 is implemented as a flash memory, a hard disk drive, or other memory technology, or any other medium that can be used to store the desired information.

[0105] The network interface 640 is configured to provide communication to the generative remediator 128 with, for example, the inspector 122, the inspection controller 124, the security database 126, etc.

[0106] It should be understood that the embodiments described herein are not limited to Figure 6 the specific architecture shown, and other architectures may be equally used without departing from the scope of the disclosed embodiments.

[0107] In addition, in certain embodiments, the inspector 122, the inspection controller 124, and the security database 126 may be implemented in the Figure 6 architecture shown. In other embodiments, other architectures may be equally used without departing from the scope of the disclosed embodiments.

[0108] The various embodiments disclosed herein may be implemented as hardware, firmware, software, or any combination thereof. In addition, the software is preferably implemented as an application tangibly embodied on a program storage unit or a computer-readable medium, which program storage unit or computer-readable medium consists of a part or certain devices and / or combinations of devices. The application may be uploaded to a machine including any suitable architecture and executed by the machine. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (“CPUs”), a memory, and an input / output interface. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code or part of the application, or any combination thereof, and they may be executed by the CPU, whether or not such a computer or processor is explicitly shown. In addition, various other peripheral units may be connected to the computer platform, such as additional data storage units and printing units, etc. In addition, a non-transitory computer-readable medium is any computer-readable medium other than a transitory propagated signal.

[0109] All of the examples and conditional language recited herein are intended for pedagogical purposes to help the reader understand the principles of the disclosed embodiments and the concepts contributed by the inventor to advance the art, and should be construed as not limited to these specifically recited examples and conditions. In addition, all statements of the principles, aspects, and embodiments of the disclosed embodiments described herein, as well as the specific examples thereof, are intended to cover their structural and functional equivalents. Additionally, it is intended that such equivalents include both currently known equivalents and equivalents developed in the future, i.e., any elements developed to perform the same function regardless of structure.

[0110] It should be understood that any reference in this text to an element using terms such as "first", "second", etc. generally does not limit the number or order of these elements. Instead, these terms are generally used herein as a convenient way to distinguish between two or more elements or instances of an element. Thus, a reference to a first and a second element does not mean that only two elements may be used there, or that the first element must somehow precede the second element. In addition, unless otherwise specified, a group of elements includes one or more elements.

[0111] As used herein, the phrase "at least one" followed by a list of items means that any of the listed items can be used individually, or any combination of two or more of the listed items can be used. For example, if a system is described as including "at least one of A, B, and C", the system can include only A; only B; only C; two A's; two B's; two C's; three A's; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of two A's and C; a combination of A, three B's, and two C's, and so on.

Claims

1. A method for generating remediation actions in a computing environment based on a network security check, comprising: Examine cybersecurity objects in computing environments; Detecting a network security issue in the computing environment based on detecting the network security object; generating a representation of the computing environment in a secure database, the secure database comprising a representation schema; generating a prompt based on the detected cybersecurity issue as an input to a large language model (LLM) of a generative remediator, wherein the generative remediator is configured to generate an output including a remediation action based on the input; as well as The remedial action is initiated in the computing environment.

2. The method according to claim 1, wherein: The prompt is generated based on any of: a predefined template, the network security issue, and the presentation mode.

3. The method according to claim 1, further comprising: The prompt is further generated based on a predefined remedial action.

4. The method according to claim 1, further comprising: generating a plurality of remedial actions, each remedial action including a priority value; and A visual representation of each remedial action is generated based on the priority value.

5. The method according to claim 1, further comprising: generating a plurality of remediation actions, each remediation action directed to a computing platform of a plurality of computing platforms of the computing environment, each computing platform associated with the detected network security issue; as well as A selection of a first remedial action among the plurality of remedial actions is received, wherein the first remedial action remediates the network security issue when initiated.

6. The method according to claim 1, further comprising: receiving a selection of a preferred computing platform from among a plurality of computing platforms of the computing environment; Further based on the received selection of the preferred computing platform, the generative remediator is configured to generate an output including the remedial action.

7. A non-transitory computer-readable medium storing a set of instructions for generating a remediation action in a computing environment based on a network security check, the set of instructions comprising: one or more instructions which, when executed by one or more processors of a device, cause the device to: Examine cybersecurity objects in computing environments; Detecting a network security issue in the computing environment based on detecting the network security object; generating a representation of the computing environment in a secure database, the secure database comprising a representation schema; generating a prompt based on the detected cybersecurity issue as an input to a large language model (LLM) of a generative remediator, wherein the generative remediator is configured to generate an output including a remediation action based on the input; as well as The remedial action is initiated in the computing environment.

8. A system for generating remediation actions in a computing environment based on a network security check, comprising: Processing circuit; a memory comprising instructions that, when executed by the processing circuit, configure the system to: Examine cybersecurity objects in computing environments; Detecting a network security issue in the computing environment based on detecting the network security object; generating a representation of the computing environment in a secure database, the secure database comprising a representation schema; generating a prompt based on the detected cybersecurity issue as an input to a large language model (LLM) of a generative remediator, wherein the generative remediator is configured to generate an output including a remediation action based on the input; as well as The remedial action is initiated in the computing environment.

9. The system according to claim 8, wherein: The prompt is generated based on any of: a predefined template, the network security issue, and the presentation mode.

10. The system according to claim 8, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: The prompt is further generated based on a predefined remedial action.

11. The system according to claim 8, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: generating a plurality of remedial actions, each remedial action including a priority value; and A visual representation of each remedial action is generated based on the priority value.

12. The system according to claim 8, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: generating a plurality of remediation actions, each remediation action directed to a computing platform of a plurality of computing platforms of the computing environment, each computing platform associated with the detected network security issue; as well as A selection of a first remedial action among the plurality of remedial actions is received, wherein the first remedial action remediates the network security issue when initiated.

13. The system according to claim 8, wherein: The memory contains further instructions which, when executed by the processing circuit, further configure the system to: receiving a selection of a preferred computing platform from among a plurality of computing platforms of the computing environment; and Further based on the received selection of the preferred computing platform, the generative remediator is configured to generate an output including the remedial action.