Associating security alarms using large language models

By using a context-based insight system and a security alert generative language model, the system addresses the issues of inefficiency and inaccuracy in security incident reporting within cloud computing systems. It enables concise descriptions of detailed security incident analysis and remedial measures, thereby improving the system's flexibility and computational efficiency.

CN121753025APending Publication Date: 2026-03-27MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-09
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing cloud computing systems are inefficient, inaccurate, and lack flexibility in security incident analysis, and cannot effectively provide detailed security incident reports and remediation measures.

Method used

A context-based insight system is adopted, which uses a security alert generative language model (GLM) to generate security incident reports. By assigning security alerts to attack type buckets and using attack type templates to generate detailed and concise text descriptions, the report content is dynamically updated.

Benefits of technology

It improves the accuracy and efficiency of security incident reporting, provides a concise description of the causes of security incidents and remedial measures, and enhances the system's flexibility and computational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121753025A_ABST
    Figure CN121753025A_ABST
Patent Text Reader

Abstract

The present disclosure focuses on determining security event reports including security event insights and remedial actions based on various combinations of security alarms in a cloud computing system using a context-based insight system. A context-based insight system generates a security event report using a security alert generative language model (GLM) based on related security alerts within a security event and attack type contexts for those security alerts. By generating a security event report using a security alert GLM guided by an attack type context, a context-based insight system provides an understandable textual narration that provides clear and accurate insight into security events, including remedial measures for solving the security events as a whole, such as a security alert, a security alert, a security alert, a security alert, a security alert, and a security alert. Instead of reporting only individual security alarms of the security event. Further, the context-based insight system dynamically updates the security event report as additional relevant security alerts are detected and received.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] In recent years, significant advancements have been made in both the hardware and software of computing devices, with cloud computing systems being particularly noteworthy. Cloud computing systems provide users with a wide range of services and applications. However, occasional service incidents and outages can disrupt network systems and user experiences. Addressing the underlying causes of these incidents has become a priority for system administrators. Unfortunately, current systems fall short in providing insight into service incidents when security alerts and metrics anomalies occur. Specifically, many existing systems rely on rigid methods that tend to become outdated and struggle to adapt to the ever-changing combinations of security alerts that constitute security incidents. Furthermore, many existing systems provide users with lengthy, bulky, and generalized security incident reports. Therefore, existing systems often face challenges of inefficiency, inaccuracy, and a lack of flexibility in analyzing service incidents, providing security incident reports, insights, and remediation in cloud computing systems. Attached Figure Description

[0002] The following detailed description provides specific and detailed implementations, accompanied by accompanying drawings. Furthermore, each drawing listed below corresponds to one or more implementations discussed in this disclosure.

[0003] Figure 1 An example computing environment for implementing a context-based insight system in a cloud computing system is shown.

[0004] Figure 2 An example sequential flowchart is shown, illustrating the generation of security incident reports with context-based insights based on the type of security attack using a security alert generative language model.

[0005] Figures 3A-3B An example diagram is shown that uses a security alert generative language model to determine the attack type bucket for alerts.

[0006] Figure 4 An example diagram is shown that uses a security event correlation model to determine security events.

[0007] Figure 5 An example diagram is shown to identify the bucket identifier for the attack type of a security incident.

[0008] Figure 6 This diagram illustrates an example of generating security incident reports using a security alert generative language model based on attack type bucket identifiers for security incidents.

[0009] Figure 7 A sample sequential flowchart is shown to generate an updated security incident report based on received additional security alerts.

[0010] Figure 8This section illustrates a series of example actions for a computer implementation of a method to generate security incident reports with context-based insights in a cloud computing system.

[0011] Figure 9 Example components included within a computer system are shown. Detailed Implementation

[0012] This disclosure describes the use of a context-based insight system to accurately, flexibly, and efficiently determine security incident reports, including security incident insights and remediation actions, based on various combinations of security alerts in cloud computing systems. The context-based insight system uses a security alert generative language model (GLM) to generate security incident reports based on relevant security alerts in a security incident and the attack type context of those alerts. By generating security incident reports using a security alert GLM guided by attack type context, the context-based insight system provides an understandable textual narrative that offers clear and accurate insights into the security incident, including remediation actions to address the security incident holistically, rather than simply reporting individual security alerts related to the security incident. In effect, the context-based insight system provides a contextual understanding of why security alerts in a security incident are relevant, the security context in which they exist, and timely remediation actions. Furthermore, the context-based insight system dynamically updates the security incident reports as additional relevant security alerts are detected and received.

[0013] To illustrate, in various implementations, a context-based insight system identifies security events from a set of received and relevant security alerts. Furthermore, the context-based insight system determines the attack type of the relevant security alerts within a security event by assigning security alerts to attack type buckets. The context-based insight system then uses a generative language model (GLM), such as a large-scale language model (LLM), to generate a security event report based on the relevant security alerts and contextual information gathered from the corresponding attack types. The security event report provides a concise linguistic description of the security event, including a brief textual description of the security event and remedial actions taken.

[0014] In terms of background, cloud computing systems, including multi-cloud systems, provide users with multiple services and applications. The security of these services and applications is periodically tested and challenged. Typically, monitoring services within the cloud computing system and / or at the source of the incident detect and generate security alerts, which are then provided to a security incident management system. The security incident management system typically correlates relevant security alerts, identifies the security incident, and reports it to the appropriate parties.

[0015] Currently, security incident reports are general, lacking sufficient information and intelligence beyond simply notifying users of security incidents. In contrast, the context-based insight system disclosed in this paper uses methods and techniques to provide context-sensitive security incident reports that specifically explain the security alerts triggered during a security incident and recommend remedial actions. Furthermore, the context-based insight system provides concise, clear, and straightforward textual descriptions to minimize user confusion.

[0016] As described in this disclosure (including the following paragraphs), context-based insight systems offer several significant technical benefits in terms of computational accuracy, flexibility, and efficiency compared to existing systems. Furthermore, context-based insight systems provide several practical applications that address issues related to identifying potential threats to security incidents and clearly and concisely report the context of security attacks with corresponding remedial actions.

[0017] To illustrate, the context-based insight system implements a multi-step framework within a cloud computing system that leverages a security alert generative language model at multiple steps to efficiently, accurately, and flexibly identify and generate accurate context-based insights within reports on security incidents.

[0018] By using a security alert generative language model, a context-based insight system provides accurate and efficient textual narrative responses to a wide range of security alerts. For example, the security alert generative language model is trained on large datasets and can produce fluent, coherent, and topic-specific responses. Furthermore, the security alert generative language model has applications in natural language understanding, content generation, text summarization, dialogue systems, language translation, creative writing assistance, and image generation. Unlike existing systems that generate generic and useless reports on security incidents, the security alert generative language model can effectively process, analyze, and correlate diverse inputs (e.g., security alerts from a security incident and contextual information about the corresponding attack type) and generate accurate textual narrative responses that concisely report the cause of the security incident and suggest remedial actions.

[0019] As mentioned above, across various implementations, context-based insight systems repeatedly use the same security alert generative language model to perform different tasks (e.g., processing different types of input and generating various output types). For example, in many cases, context-based insight systems use the security alert generative language model to determine which attack type buckets an incoming security alert belongs to, including generating new attack type buckets when necessary. Additionally, context-based insight systems use the security alert generative language model to generate security incident reports for security events.

[0020] Furthermore, context-based insight systems allow for greater computational flexibility through the use of generative language models for security alerts. For example, the broad scope of generative language models provides the flexibility to handle any combination of security alerts. Existing systems are often limited to general reports that are unhelpful in reporting security incidents. Sometimes, existing systems identify predefined combinations of security alerts for a specific security scenario and are able to provide curated reports for that very specific security incident. These detailed reports require significant manual processing and are impractical due to the large and ever-growing number of security alert combinations. In contrast, generative language models for security alerts can be flexibly extended to determine the cause of security incidents for most combinations of security alerts, even combinations with new security alert types.

[0021] When there is overlap and commonality between different tasks (e.g., repeated processing of security alerts and attack type contexts), using the same security alert generative language model for multiple different tasks provides computational efficiency gains. Additionally, having a single model instead of multiple models allows the same hardware resources to be used to execute the model and requires less storage (e.g., storing a single model instead of multiple models).

[0022] In one or more implementations, the context-based insight system provides contextual information about attack types within an attack type template. For example, each attack type bucket to which a security alert is assigned corresponds to an attack type template. The attack type template provides the context of the security attack to the security alert generative language model to be used when generating security incident reports. Furthermore, the description of attack types within the attack type template ensures consistency both within attack types and across different attack types.

[0023] As discussed above, this disclosure uses various terms to describe the features and advantages of one or more implementations. For illustration, this disclosure describes a context-based insight system in the context of a cloud computing system. As an example, the term "cloud computing system" refers to a network of interconnected computing devices that provide various services and applications to computing devices (e.g., server devices and client devices) inside or outside the cloud computing system. In some cases, cloud computing systems are security-based systems, such as Microsoft Defender for the Cloud. The description of cloud computing systems also includes multi-cloud systems.

[0024] In this disclosure, the term "security incident" (or "incident") refers to a specific event or series of events that potentially cause harm by compromising the confidentiality, integrity, or availability of a computer system, data, or network. Many security incidents require investigation and remediation. Typically, security incidents are identified by security alerts triggered by monitoring services and / or client devices within a cloud computing system.

[0025] The term "security alert" refers to a notification that indicates a potential security problem or breach. Security alerts are typically used as early warnings and are usually triggered by suspicious or unusual activity. Security alerts include data (e.g., alert information and / or metadata) such as alert name, alert type, alert description, entity identifiers (resource identifiers, user identifiers, service identifiers), Internet Protocol (IP) addresses, affected processes and resources, timestamps, log information, severity level, countermeasures, and / or other data.

[0026] As an example, a "generative language model" (GLM) is a large-scale artificial intelligence system that uses deep learning to produce coherent and context-sensitive text based on patterns learned from large amounts of training data. Among various implementations, GLM generative language models are multimodal generative models. In many cases, a generative model refers to a high-level computational system that uses natural language processing, machine learning, and / or image processing to generate coherent and context-sensitive human-like responses. Generative language models include large-scale language models (LLMs) based on transformer architectures for understanding, generating, and mastering human language. Examples of LLMs include generative pre-trained transformer (GPT) models such as GPT-3.5 and GPT-4, bidirectional encoder representation (BERT) models from transformers, text-to-text transfer transformer models (such as T5), conditional transformer language (CTRL) models, and Turing-NLG. Other types of generative language models include sequence-to-sequence models (Seq2Seq), vanilla recurrent neural networks (RNNs), and long short-term memory (LSTM) networks.

[0027] Generative language models are trained on large datasets and can produce fluent, coherent, and topic-specific text and images. They have applications in natural language understanding, content generation, text summarization, dialogue systems, language translation, creative writing assistance, and image generation. A single generative language model performs a wide range of tasks based on receiving diverse inputs, such as prompts (e.g., input instructions, rules, example inputs, example outputs, and / or tasks), data, and / or access to that data. In response, generative language models generate a variety of output formats, ranging from a single-word answer to long narratives, images and videos, tagged datasets, documents, tables, and presentations.

[0028] This disclosure includes a "security alert generative language model". Among various implementations, the security alert generative language model is a type of GLM that is fine-tuned based on security alerts and security events. For example, the security alert generative language model is fine-tuned using security-based literature or other security event documents. In some implementations, the security alert generative language model is an LLM specifically adapted to handle security-related queries.

[0029] Further terms are defined throughout this disclosure in various examples and contexts.

[0030] Now let's turn to the accompanying diagrams and discuss additional example implementations and details of context-based insight systems in conjunction with the diagrams. For illustration, Figure 1 An example of a computing environment 100 in which a context-based insight system is implemented is shown. The computing environment 100 includes various computing devices associated with the context-based insight system 106. The computing environment 100 may include additional devices and components not shown. Additionally, although... Figure 1 An example layout and configuration of the context-based insight system and associated components is shown, but other layouts and configurations are also possible.

[0031] As shown in the figure, computing environment 100 includes a cloud computing system 102 and client devices 140 connected via network 150. Cloud computing system 102 includes a security event system 104, an alarm monitoring service 130, and a security alarm generative language model 132. Each of these systems and / or components can be implemented on one or more computing devices, such as one or more server devices. The following is in conjunction with... Figure 9 Further details are provided regarding these and other computing devices, as well as additional details regarding networks (such as network 150 shown).

[0032] In one or more implementations, the security event system 104 manages security alerts and security events within one or more computing devices. Additionally, in various scenarios, the security event system 104 provides interfaces, tools, services, and frameworks for detecting, processing, investigating, and remediating security events.

[0033] In various implementations, the security incident system 104 communicates with the alarm monitoring service 130 to detect and report security alarms. For example, the alarm monitoring service 130 includes agents and / or services distributed across the cloud computing system 102 and / or on client devices with access to the cloud computing system 102. These agents and / or services detect security anomalies and potential breaches, generate security alarms, and provide them to the security incident system 104. The security incident system 104 can then forward the security alarms to the context-based insight system 106.

[0034] As shown in the figure, the security event system 104 implements a context-based insight system 106. In some implementations, the context-based insight system 106 resides on a different computing device than the security event system 104. In one or more implementations, some or all of the context-based insight systems 106 reside on the client device 140.

[0035] As previously described, the context-based insight system 106 generates a security incident report that provides a clear and concise textual description of the security alerts and attack types corresponding to the security incident. Furthermore, the context-based insight system 106 uses a security alert generative language model 132, which can be an LLM or another type of GLM. In various scenarios, the context-based insight system 106 queries the security alert generative language model 132 with different queries at multiple times to generate a security incident report that includes a textual description of context-based insights and remediation actions for the security incident.

[0036] As shown in the figure, the context-based insight system 106 includes various components and elements implemented in hardware and / or software. For example, the context-based insight system 106 includes a security alert manager 110, an attack type bucket manager 112, a security event correlation manager 114, a security event report manager 116, and a storage manager 118, including security alerts 120 with metadata 122, attack type buckets 124 with attack type templates 126, and security event reports 128.

[0037] As described above, the context-based insight system 106 includes a security alert manager 110. In one or more implementations, the security alert manager 110 manages security alerts 120. For example, the security alert manager 110 receives security alerts from the security event system 104 and / or the alert monitoring service 130. The security alert manager 110 may temporarily store the security alerts 120 or store them in long-term storage (e.g., via storage manager 118). In various implementations, the security alert manager 110 provides the security alerts 120 to other components of the context-based insight system 106.

[0038] As shown in the figure, the context-based insight system 106 includes an attack type bucket manager 112. In various implementations, the attack type bucket manager 112 uses a security alert generative language model 132 (or another model, algorithm, pre-association, or classification process) to determine the attack type buckets of security alerts 120. For example, the attack type bucket manager 112 provides security alerts and queries to the security alert generative language model 132 to determine the attack type assignments associated with attack type buckets 124.

[0039] As shown in the figure, the context-based insight system 106 includes a security event correlation manager 114. In various implementations, the security event correlation manager 114 determines security events by correlating security alerts 120. For example, the security event correlation manager 114 compares the attack type bucket assignments of security alerts 120 to determine which security alerts to include in a security event.

[0040] In some implementations, a security event correlation manager 114 (or another component such as an attack type bucket manager 112) determines the correlation between security alerts belonging to a security event and their corresponding attack types. For example, the security event correlation manager 114 identifies each attack type identified for each relevant security alert constituting a security event.

[0041] As shown in the figure, the context-based insight system 106 includes a security event report manager 116. In various implementations, the security event report manager 116 uses a security alert generative language model 132 to generate security event reports 128. For example, the security event report manager 116 provides the security alerts related to the security event and their corresponding attack type templates 126, along with a query, to the security alert generative language model 132 to generate a security event report based on the instructions and context provided by the attack type templates 126.

[0042] As shown in the figure, computing environment 100 includes client device 140 with client application 142. In various implementations, client device 140 is associated with a user, such as an administrator. Client application 142 enables the user to interact with security incident system 104 and / or context-based insight system 106 to investigate security incidents and receive security incident reports 128.

[0043] In some implementations, client application 142 is a web browser application, a mobile application, or another type of application that accesses internet-based content to retrieve and display digital content. In some implementations, client application 142 includes a plugin associated with security incident system 104 that communicates with context-based insight system 106 to generate security incident report 128.

[0044] With the foundation of the context-based insight system 106 in place, additional details regarding the various functionalities of the context-based insight system 106 will now be described. For illustration, Figure 2 A sample sequential flowchart is shown, illustrating the generation of security incident reports with context-based insights based on security attack type using a security alert generative language model. As shown in the figure, Figure 2 It also includes a series of actions 200 implemented by the context-based insight system 106 in conjunction with the alarm monitoring service 130 and the client device 140, which have been described above in conjunction with the cloud computing system.

[0045] As shown in the figure, a series of actions 200 includes action 202 where the context-based insight system 106 receives a set of security alerts from the alert monitoring service 130. For example, the alert monitoring service 130 detects various security issues throughout the cloud computing system and generates security alerts to report these events. The alert monitoring service 130 uses various security products, packages, and / or suites to monitor different parts of the cloud computing system. These security alerts are then provided to the context-based insight system 106, which can receive several security alerts corresponding to different users, resources, processes, and components of the cloud computing system.

[0046] As described above, each security alert can include data about the alert. For example, a security alert includes alert information such as the alert name, alert type, and alert description. Additionally, a security alert can include metadata such as entity identifiers (resource identifiers, user identifiers, service identifiers), Internet Protocol (IP) addresses, affected processes and resources, timestamps, log information, and other data. The context-based insight system 106 can use some or all of this information to determine security incidents and security incident reports.

[0047] As shown in the figure, action 204 involves the context-based insight system 106 using a security alert generative language model to determine the attack type bucket assignment for the security alert. For example, when the context-based insight system 106 receives a security alert, the security alert generative language model processes the alert to identify one or more attack types and assigns the alert to the corresponding attack type bucket. In some cases, the security alert generative language model determines whether the security alert should be assigned to a new attack type bucket. The following section combines... Figures 3A-3B Provides additional information on attack type bucket assignment for security alerts based on the generative language model for security alerts.

[0048] As shown in the figure, action 206 includes the context-based insight system 106 determining security events by associating a subset of security alerts with a security event alert group. For example, the context-based insight system 106 uses a security alert correlation engine to determine data correlations between some security alerts. When multiple security alerts are correlated, the context-based insight system 106 generates security events, where the security alerts form a security event alert group. The following section combines... Figure 4 Provides additional information on using the security alert correlation engine to generate security events and security event alert groups.

[0049] As shown in the figure, action 208 includes context-based insight system 106 identifying which attack type bucket corresponds to a security alarm in a security event alert group. For example, context-based insight system 106 determines which attack types correspond to security events by associating alarms in a security event alert group with their attack type bucket assignments.

[0050] Utilizing the identified attack type of the security incident, the context-based insight system 106 accesses the attack type template using an identified attack type bucket assignment, as shown in action 210. In various cases, the attack type template includes contextual information about the corresponding attack type, which the context-based insight system 106 can provide as input to the security alert generative language model when generating a security incident report. Figure 5 Additional information is provided regarding the attack types and attack type templates for identifying security incidents and / or security incident alert groups.

[0051] As shown in the figure, action 212 includes the context-based insight system 106 generating a security incident report using the Security Alert GLM based on security incident alert groups and attack type templates. For example, the context-based insight system 106 provides security incident alert groups, attack type templates (or access to attack type templates), and prompts for generating the security incident report. In response, the context-based insight system 106 generates a security incident report for the security incident, including context-based insights, based on the security attack and appropriate remediation actions. Specifically, the context-based insight system generates a security incident report including a brief, concise, and clear description, providing a contextual understanding of why the security alerts in the security incident are relevant, the security context in which they exist, and the remediation actions. Figure 6 Additional details are provided regarding the generation of security incident reports using a generative language model for security alerts.

[0052] As shown in the figure, action 214 includes the context-based insight system 106 providing a security incident report to the client device 140. The security incident report includes a concise, clear language description of the security incident and remediation steps. For example, the security incident report includes a brief, clear language description of the security incident within the context of the attack type and a concise, clear language description of the remediation steps. In some cases, the security incident report includes additional information about the security incident. The following section combines... Figure 6 Provide additional details regarding security incident reporting.

[0053] Having outlined the context-based insight system 106, the following figures provide additional details regarding the specific components, functions, features, and actions of the context-based insight system 106. For illustration, Figures 3A-3BAn example diagram is shown that uses a security alert generative language model to determine the attack type bucket for alerts.

[0054] As shown in the figure Figure 3A This includes security alerts 302, a security alert generative language model 310, and attack type buckets 312. Different implementations can have different numbers of security alerts and attack type buckets.

[0055] Attack type bucket 312 corresponds to attack type scenarios. For example, each attack type bucket represents a specific type of attack scenario. Examples of attack scenarios include suspicious users / entities, data breaches, IP entry points / suspicious IPs, ransomware, anomalous file access, password type attacks, and password mining. These attack type buckets can be thematic bucket categories based on descriptions of security alerts.

[0056] In various scenarios, the security alert generative language model 310 is a version of the aforementioned security alert generative language model 132. For example, the security alert generative language model 310 is an LLM fine-tuned to process security alerts. The security alert generative language model 310 uses training on its large dataset to process security alerts 302 and determine the attack type for each security alert. In this way, the security alert generative language model 310 processes security alerts 302 to discover the intent of the alert and assigns each alert to the appropriate attack type bucket based on the intent.

[0057] In one or more implementations, the context-based insight system 106 uses a security alert generative language model 310 to assign security alerts 302 to attack type buckets 312. In various implementations, the security alert generative language model 310 determines one or more attack type buckets to which the security alert is assigned based on data within the alert. As described above, a security alert includes data such as the alert's name and description. Therefore, the security alert generative language model 310 processes each security alert, determines the attack type represented by the security alert, and assigns the security alert to the corresponding attack type bucket.

[0058] In some implementations, the context-based insight system 106 provides a prompt, query, or other input to the security alert generative language model 310 along with one or more security alerts to instruct the model to determine the attack type of the alert. For example, the context-based insight system 106 provides a first prompt, such as “determine the attack type of the provided security alert.”

[0059] The security alert generative language model 310 can directly assign security alerts to the corresponding attack type bucket. In some cases, the security alert generative language model 310 outputs a determination for the security alert, and the context-based insight system 106 assigns the security alert to the corresponding attack type bucket.

[0060] Attack type bucket 312 can be a data structure, such as one or more databases, tables, or data stores. For example, each attack type bucket is a table listing each security alert that belongs to it. In some implementations, the context-based insight system 106 adds an attack type attribute to a security alert, indicating the type of attack it identifies.

[0061] exist Figure 3A In the process, based on security alert 302 processed by the security alert generative language model 310, alerts 1 and 3 are assigned to the suspicious IP address attack type bucket; alerts 2, 4, and 5 are assigned to the abnormal file access attack type bucket; and alert 4 is assigned to the data leakage attack type bucket. As shown in the figure, alert 4 is assigned to both attack type buckets. For example, the name, description, and / or other data of alert 4 determined by the security alert generative language model 310 cause alert 4 to be assigned to both the abnormal file access attack type bucket and the data leakage attack type bucket.

[0062] As further described below, each attack type bucket in attack type bucket 312 has an attack type template or is associated with an attack type template. The attack type template provides a description and contextual information about the attack type. In some implementations, the attack type template also includes hints and / or instructions when its attack type is part of a security event, as also described below. Typically, the context-based insight system 106 uses attack type templates to ensure consistency when a security event involves a corresponding attack type.

[0063] In one or more implementations, the security alert generative language model 310 determines that a security alert corresponds to an attack type that does not correspond to an attack type bucket. In these implementations, the context-based insight system 106 generates new attack type buckets via the security alert generative language model 310.

[0064] To illustrate, Figure 3B The example illustrates a context-based insight system 106 receiving additional security alerts 322, which are provided to a security alert generative language model 310. In this example, the security alert generative language model 310 determines or identifies that the additional security alerts 322 (e.g., alerts 6 and 7) are consistent with a ransomware attack. Therefore, the context-based insight system 106 generates a new attack type bucket 324 (e.g., bucket 4) named ransomware, and assigns alerts 6 and 7 to this new attack type bucket 324.

[0065] In various implementations, the context-based insight system 106 and / or the security alert generative language model 310 generate attack type buckets 312. For example, based on received security alerts, the security alert generative language model 310 determines the appropriate attack type. Based on these determinations, the context-based insight system 106 assigns security alerts to current or new attack type buckets. Furthermore, the context-based insight system 106 can remove buckets of attack types that have not been assigned for a period of time.

[0066] Similarly, the context-based insight system 106 uses a security alert generative language model 310 to automatically learn and update attack type buckets 312. For example, when a security alert changes and a new alert is created (which happens frequently), the profile of the attack type bucket may change. When the number of security alerts and attack type changes exceeds a threshold, the context-based insight system 106 automatically updates these attack type buckets and / or generates new attack type buckets. By automatically updating, adding, and maintaining attack type buckets, the context-based insight system 106 ensures the up-to-date accuracy of attack types while simplifying the maintenance of attack type buckets.

[0067] In some cases, the security alert generative language model 310 cannot determine the attack type of a security alert with an acceptable confidence value. In these cases, the context-based insight system 106 may assign the security alert to an unassigned attack type bucket. In various cases, the context-based insight system 106 may later provide the security alert to the security alert generative language model 310 to determine whether the security alert can be assigned to an attack type bucket based on other processed security alerts and / or model updates. In some cases, the context-based insight system 106 discards unassigned security alerts after a period of time.

[0068] In one or more implementations, the context-based insight system 106 also generates attack type templates for attack type buckets during bucket generation. For example, the context-based insight system 106 prompts the security alert generative language model 310 to generate attack type templates that provide descriptions and contextual information for specific attack types. The context-based insight system 106 can also add instructions and consistency elements to the attack type templates, which will be further described below.

[0069] In addition to assigning incoming security alerts to attack type buckets, the context-based insight system 106 also correlates security alerts to identify security events. To illustrate, Figure 4 An example diagram is shown illustrating the use of a security event correlation model to determine security events. As shown in the figure... Figure 4This includes security alert 302, security event correlation engine 410 with data comparator 412, and security event 414 consisting of security event alert group 416.

[0070] In various scenarios, the context-based insight system 106 uses the security event correlation engine 410 to correlate security alerts 302. In practice, the context-based insight system 106 determines that a security event 414 has occurred based on multiple related security alerts. Furthermore, when a security event 414 is generated, the security alerts constituting the security event can be referred to as a security event alert group 416.

[0071] In various implementations, the context-based insight system 106 determines security events by comparing data (e.g., metadata) within security alerts. For example, the security event correlation engine 410 uses a data comparator 412 to compare the names, entities, IP addresses, users, resources, identifiers, and / or other attributes of two security alerts to determine whether they are related to each other.

[0072] In one or more implementations, the context-based insight system 106 determines relevance when two or more security alerts have relevance scores that meet a relevance threshold. The security event relevance engine 410 may determine the relevance score based on the number of matching features and / or similarity in attribute values. Importantly, the context-based insight system 106 determines relevance and security events independently of determining attack type bucket assignments.

[0073] In some cases, the data comparator 412 generates and / or uses large tables, such as relational tables or databases, that include security alerts. Using the relational tables, the security event correlation engine 410 determines a list of alerts that are related to and / or correlated with each other for a given security event. For example, the security event correlation engine 410 determines a security event by associating shared entities in multiple security alerts by matching entity identifiers.

[0074] For each security incident, the context-based insight system 106 can determine which attack types are involved. Therefore, when determining attack type bucket assignments and security incident / security incident alarm groups, the context-based insight system 106 can identify one or more attack types corresponding to the security incident. To illustrate, Figure 5 An example diagram is shown to identify the bucket identifier for the attack type of a security incident. As shown in the figure, Figure 5 This includes security event 414, attack type bucket assignment 502, and attack type bucket identifier 504.

[0075] In various implementations, the context-based insight system 106 determines the attack type belonging to a security event by identifying the attack type of the security alert assigned to the security event. For illustration, Figure 5 Security event 414 with security event alert group 416 is shown. Security event alert group 416 includes security alerts 2, 3, and 5. Therefore, in order to determine the attack type against security event 414, the context-based insight system 106 identifies the attack type bucket assignment for these alerts.

[0076] As shown in the figure, alerts 2 and 5 are assigned to attack type bucket 2 (e.g., abnormal file access), and alert 3 is assigned to attack type bucket 1 (e.g., suspicious IP address). Therefore, the context-based insight system 106 can associate these two attack types with security event 414 based on the security alerts in security event alert group 416 being assigned to these attack types.

[0077] As part of associating attack types with security events, the context-based insight system 106 can access and associate corresponding attack type templates with security events. As mentioned in this disclosure, attack type templates provide descriptions, contextual information, hints, and / or instructions for the corresponding attack type. Therefore, in the provided example, the context-based insight system 106 identifies attack type template 1 and attack type template 2 as linked to security event 414. For illustration, the attack type bucket identifier 504 includes an attack type template set 506 that includes these attack type templates.

[0078] By associating security events with attack types and / or attack type templates, the context-based insight system 106 can utilize attack type descriptions and contextual information when generating security event reports. Specifically, utilizing attack type information allows the context-based insight system 106 to generate targeted security event reports that provide a comprehensive picture of the attack behind the security event, rather than offering a general response to one or more security alerts included in the security event.

[0079] To illustrate, Figure 6 This diagram illustrates an example of generating security incident reports using a security alert generative language model based on attack type bucket identifiers targeting security incidents. As shown in the figure, Figure 6 It includes a security alert generative language model 310, a security event 414, an attack type bucket identifier 504, and a security event report 604, which has a concise language description of the security event constructed in the context of the relevant attack type.

[0080] In many implementations, the security alert generative language model 310 is the same as the generative language model used to determine attack types, as described above. For example, the context-based insight system 106 uses the same security alert LLM to determine attack type bucket assignments and generate security incident reports. Because the security alert generative language model 310 is trained and tuned on a wide variety of tasks, it is able to perform both tasks. Furthermore, because the security alert generative language model 310 can be fine-tuned to handle security alerts, it can perform both security alert-based tasks with increased accuracy compared to other generative language models. In some cases, the context-based insight system 106 uses different models for the two tasks.

[0081] As shown in the figure, the context-based insight system 106 uses a security alert generative language model 310 to generate a security event report 604 based on a security event 414 and an attack type template set 506. In conjunction with providing the security event 414 and / or security event alert group 416 to the security alert generative language model 310, the context-based insight system 106 also provides a bucket identifier 504 for attack types and / or a template set 506 for attack types.

[0082] When attack type bucket identifier 504 is provided or supplied, the context-based insight system 106 enables the security alert generative language model 310 to access the attack type template set 506 even when it is not directly provided. For example, the security alert generative language model 310 accesses the attack type template set 506 from an attack type template repository. In any case, the context-based insight system 106 provides the security alert generative language model 310 with the attack type template corresponding to security event 414, either directly or indirectly.

[0083] As shown in the figure, the security alert generative language model 310 generates a security incident report 604. For example, the security alert generative language model 310 generates a security incident report that includes a brief textual description of the security incident. For example, the security incident report 604 includes an incident description 606 and a remedial action description 608. In many implementations, these descriptions are brief (e.g., 1-2 sentences) and provide a context-based summary of the security incident and remedial actions or steps. In some cases, the security incident report 604 includes additional brief descriptions and / or supplementary information about the security incident.

[0084] In various implementations, the security alert generative language model 310 uses descriptions and data of relevant security alerts in the security event alert group 416, along with contextual information about the attack types, to generate a security event report 604. For example, the relevant security alerts in the security event alert group 416 provide a first set of information, including when the alert was triggered, which entities were involved, and what functions were affected. Then, one or more templates in the attack type template set 506 provide a second set of information, including background and contextual information about one or more attack types involved in the security event.

[0085] By processing two sets of information, the security alert generative language model 310 is able to identify key fields from each alert for aggregation, map alert and attack type information together, and generate a comprehensive description of the security incident as a whole, rather than providing fragmented reports for individual security alerts. Furthermore, the security alert generative language model 310 is able to generate a remedial action description 608 for the entire security incident, rather than a list of fragmented remedial actions.

[0086] Typically, by including the attack type template set 506, the security alert generative language model 310 can report why a security incident occurred and effective and accurate remediation steps. For example, by combining background and contextual information about the attack type used for the security incident, the security alert generative language model 310 can more accurately piece together the full picture of the security incident, including why the security alerts in the security incident alert group 416 are relevant. In other words, the attack type template set 506 allows the security alert generative language model 310 to integrate the attack intent and / or root cause of the security incident.

[0087] As described above, in various implementations, the attack type template provides prompts, parameters, and / or instructions to the security alert generative language model 310 to generate a security incident report. For example, the attack type template includes prompts to generate a security incident report 414 given one or more attack types. The attack type template may also include parameters and / or instructions for generating a concise, brief, and non-verbal language description in the security incident report 604 (e.g., incident description 606 and remedial action description 608). Furthermore, the attack type template ensures consistent and comprehensive reporting.

[0088] Just as attack type templates can provide output instructions for generating security incident reports with a single attack type, attack type templates can also provide instructions for generating security incident reports when multiple attack type templates are provided. For example, an attack type template for one attack type indicates the hierarchy of other attack type templates, how to combine or incorporate multiple attack types into a single narrative, and / or how to reduce the length of the text narrative for each attack type to keep the incident description narrative 606 (e.g., security incident insight) and remediation action narrative 608 concise. In these cases, the attack type template set 506 ensures that the security incident report 604 is not excessively verbose or lengthy when multiple attack types are involved in a security incident.

[0089] In some cases, the context-based insight system 106 provides a security incident report 604 within an interactive interface. Upon receiving the security incident report 604 at a client device, the context-based insight system 106 allows the client device to request additional information about any provided narrative. In response, the context-based insight system 106 uses a security alert generative language model 310 to provide longer and / or more detailed responses, explanations, and / or guidance to understand or correct the security incident. For example, the security alert generative language model 310 can provide a detailed timeline of the security incident's occurrence or step-by-step instructions for performing remedial actions (or confirmation of automated remedial actions).

[0090] In addition to generating security incident reports that include context-sensitive security incident insights and remediation actions for cloud computing systems, the context-based insight system 106 also provides a framework for dynamically and automatically updating security incident reports when new security alerts are received. To illustrate, Figure 7 A sample sequential flowchart is shown to generate an updated security incident report based on received additional security alerts. As shown in the figure... Figure 7 It also includes a series of actions 700 implemented by the context-based insight system 106 in conjunction with the alarm monitoring service 130 and the client device 140, which have been described above in the context of cloud computing systems.

[0091] Figure 7 Follows the context-based insight system 106 for generating security incident reports. For the context, a series of actions 700 includes the above... Figure 2 The action 214 provided in the system provides a security incident report to the client device 140, which includes a brief, concise language description of the security incident and remediation steps. As described above, the context-based insight system 106 generates a security incident report that includes a brief, concise language description of the security incident in the context of the attack type and a brief, concise language description of the remediation steps.

[0092] As shown in the figure, a series of actions 700 includes the action 702 of the context-based insight system 106 receiving additional security alerts. For example, after providing a security incident report to the client device 140, the alert monitoring service 130 provides one or more security alerts to the context-based insight system 106. In some implementations, the context-based insight system 106 receives additional security alerts after a threshold duration has elapsed since receiving the previous security alert included in the security incident report and / or after generating its own security incident report. In various cases, the length of the time threshold is based on the type and / or severity of the security incident to balance consuming processing resources with accurately reporting security incidents.

[0093] As shown in the figure, action 704 involves the context-based insight system 106 using a security alert GLM to determine the attack type bucket assignment for additional security alerts. For example, the security alert GLM processes additional alerts to identify one or more attack types and assigns the additional alerts to the corresponding attack type buckets, as described above. In some implementations, a security alert generative language model determines which new attack type bucket to assign the additional alerts to.

[0094] As shown in the figure, action 706 includes the context-based insight system 106 determining that an additional security alert is part of the current security event. For example, the context-based insight system 106 associates the additional security alert with a security event that is the subject of a previously generated security event report. Therefore, in various cases, the context-based insight system 106 adds an additional security alert to a security event alert group for a security event based on the additional security alert that is associated with one or more security alerts in the security event alert group.

[0095] As shown in the figure, action 708 includes the context-based insight system 106 generating an updated security incident report using the Security Alert GLM based on the additional security alert and the attack type template associated with the additional security alert. For example, the Security Alert GLM determines a current or new attack type template for the additional security alert. In some implementations, the attack type template is an updated version. The context-based insight system 106 provides the Security Alert GLM with the attack type template associated with the additional security alert to generate the updated security incident report.

[0096] In various implementations, the context-based insight system 106 also provides access to additional security alerts within the security incident alert group and / or to other attack type templates corresponding to those security alerts (e.g., attack type templates associated with the security incident). Based on the name, description, and data of the security alerts combined with information from the attack type templates (including those added from additional security alerts), the security alert GLM generates an updated security incident report. The context-based insight system 106 ensures that all contextual information, including newly added alerts, is reflected in the updated description and remediation steps of the updated security incident report.

[0097] In some implementations, the Security Alert GLM generates new security incident reports. In some cases, the Security Alert GLM modifies, rewrites, and / or appends previously generated security incident reports. In any case, the context-based insight system 106 uses appended security alerts and the Security Alert GLM to provide updated information about the security incident. In some cases, this includes providing updated incident descriptions (e.g., updated explanations or a complete picture of the security incident) and / or updated remedial action descriptions (e.g., new or additional remedial steps).

[0098] When additional security alerts are received, the context-based insight system 106 presents a more complete picture of the attack types involved in a security incident, as well as the methods used to remediate the attacks and prevent future incidents related to the security incident. Furthermore, by using the Security Alert GLM within the context of attack types, the context-based insight system 106 is able to connect security risk patterns and seemingly disparate attacks into a single security incident, where existing systems might report these attacks as separate, unrelated events.

[0099] As shown in the figure, action 710 includes the context-based insight system 106 providing an updated security incident report to the client device 140, which includes a brief, concise description of the security incident and remediation steps. The context-based insight system 106 can continue to provide updated security incident reports as additional security alerts are received and associated with the security incident, until the security incident is resolved or closed.

[0100] Turn now Figure 8 The diagram illustrates an example flowchart of a series of actions 800 for leveraging a context-based insight system, based on one or more implementations. Specifically, Figure 8 This document illustrates a series of example actions for reporting security incidents in cloud computing systems, based on various implementations.

[0101] Although Figure 8Actions are shown according to one or more implementations, but alternative implementations may omit, add, reorder, and / or modify any of the actions shown. Furthermore, Figure 8 The action can be performed as part of a method (e.g., a computer-implemented method). Alternatively, the computer-readable medium can include actions that cause a computing device to execute when executed by a processing system having a processor. Figure 8 The instructions for the action.

[0102] In some implementations, the system (e.g., a processing system including a processor) can execute... Figure 8 Actions. For example, actions include systems for reporting security alerts in cloud computing systems. In some cases, the system includes a processing system and computer memory containing instructions that, when executed by the processing system, cause the system to perform various actions or steps. In various implementations, the system includes a security alert generative language model (GLM).

[0103] As shown in the figure, a series of actions 800 includes action 810, which uses a security alert model to determine the attack type allocation for the alerts. For example, in an example implementation, action 810 involves using a security alert generative language model to determine the attack type bucket allocation for security alerts in a received security alert set. In various implementations, action 810 includes receiving the received security alert set from a security monitoring agent or service.

[0104] In some implementations, action 810 includes determining, based on the alarm name and alarm description of the first security alarm, to assign the first security alarm to a first attack type bucket using a security alarm generative language model, wherein the first attack type bucket belongs to an attack type bucket set. In various implementations, action 810 includes determining, based on the alarm name and alarm description of the first security alarm, to assign the first security alarm to a second attack type bucket using a security alarm generative language model, wherein the second attack type bucket belongs to that attack type bucket set. In some implementations, action 810 includes determining, based on the determination that the first security alarm does not correspond to any existing attack type bucket within the attack type bucket set, to assign the first security alarm to a new attack type bucket using a security alarm generative language model.

[0105] As further illustrated, a series of actions 800 includes action 820 of generating a security event by correlating a subset of received alerts. For example, in an example implementation, action 820 involves generating a security event by determining the correlation between subsets of security alerts from the received security alert set. In some implementations, action 820 includes determining that a fallback response threshold is activated. In one or more implementations, action 810 includes utilizing a correlation engine to determine the correlation between subsets of security alerts. In one or more implementations, action 810 includes determining that data between alerts in the subset of security alerts satisfies a correlation threshold. In one or more implementations, the data includes a security alert, a security alert name, a security alert description, and a computed address for a user identifier.

[0106] As further shown, the series of actions 800 includes action 830 identifying the attack type of an alert from a security event. For example, in an example implementation, action 830 involves identifying one or more attack type buckets for a security event based on an attack type bucket assignment determined for a subset of security alerts. In some implementations, the subset of security alerts includes security alerts assigned to different attack type bucket assignments.

[0107] As further illustrated, a series of actions 800 includes action 840: generating a security incident report using a security alert model based on contextual information from alerts and attack types related to the security incident. For example, in an example implementation, action 840 involves generating a security incident report using a security alert generative language model based on contextual information from a subset of data from security alerts and one or more attack type buckets, where the security incident report provides a concise, plain language description of the security incident. In some cases, the concise language description includes a short textual description of the security incident and a textual description of remedial steps for the security incident.

[0108] In one or more implementations, action 840 includes providing an attack type bucket identifier for one or more attack type buckets to the security alert generative language model. In some implementations, the security alert generative language model accesses contextual information for one or more attack type buckets based on the attack type bucket identifier. In some implementations, action 840 includes providing the security alert generative language model with access to an attack type template based on the attack type bucket identifier. In some implementations, a first attack type template provides the security alert generative language model with a description of a first attack type for a first attack type bucket. In various implementations, the first attack type template provides instructions for generating a concise language description constructed within the context of the first attack type.

[0109] In some cases, the series of actions 800 includes additional actions. For example, the series of actions 800 includes the following actions: receiving additional security alerts after generating a security incident report and / or further generating an updated security incident report using the security alert generative language model based on contextual information about the attack type bucket assignment of the additional security alerts and the additional security alerts generated by the security alert generative language model. In some implementations, the updated security incident report includes a concise language description of the security incident rewritten and / or the updated security incident report includes additional remedial steps for resolving the security incident.

[0110] In one or more implementations, a series of actions 800 includes the following actions: receiving additional security alerts; determining the attack type bucket assignment for the additional security alerts using a security alert generative language model; adding the additional security alerts to a subset of security alerts and security events; and further generating an updated security event report using the security alert generative language model based on the contextual information of the additional security alerts and the attack type bucket assignment for the additional security alerts.

[0111] Figure 9 Some components that may be included within a computer system 900 are shown. The computer system 900 can be used to implement the various computing devices, components, and systems described herein (e.g., by executing computer-implemented instructions). As used herein, a “computing device” means an electronic component that performs a set of operations based on a set of programmed instructions. Computing devices include groups of electronic components, client devices, server devices, etc.

[0112] In various implementations, computer system 900 refers to one or more of a client device, a server device, or other computing devices described above. For example, computer system 900 can refer to various types of network devices capable of accessing data on a network, a cloud computing system, or another system. For example, a client device can refer to a mobile device, such as a mobile phone, smartphone, personal digital assistant (PDA), tablet computer, laptop computer, or wearable computing device (e.g., headphones or smartwatch). A client device can also refer to a non-mobile device, such as a desktop computer, a server node (e.g., from another cloud computing system), or another non-portable device.

[0113] Computer system 900 includes a processing system, which includes a processor 901. Processor 901 may be a general-purpose single-chip or multi-chip microprocessor (e.g., an Advanced Reduced Instruction Set Computer (RISC) machine (ARM)), a special-purpose microprocessor (e.g., a Digital Signal Processor (DSP)), a microcontroller, a programmable gate array, etc.). Processor 901 may be referred to as a Central Processing Unit (CPU) and enables the execution of computer-implemented instructions. Although the processor 901 shown is only a... Figure 9 The computer system 900 uses a single processor, but in alternative configurations, a combination of processors (e.g., ARM and DSP) can be used.

[0114] The computer system 900 also includes a memory 903 that communicates electronically with the processor 901. The memory 903 can be any electronic component capable of storing electronic information. For example, the memory 903 can be embodied as random access memory (RAM), read-only memory (ROM), disk storage media, optical storage media, flash memory devices in RAM, onboard memory integrated with the processor, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, etc., including combinations thereof.

[0115] Instruction 905 and data 907 may be stored in memory 903. Instruction 905 may be executed by processor 901 to implement some or all of the functions disclosed herein. Execution of instruction 905 may involve using data 907 stored in memory 903. Any of the various examples of modules and components described herein may be implemented in part or in whole as instruction 905 stored in memory 903 and executed by processor 901. Any of the various instances of data described herein may be in data 907 stored in memory 903 and used during the execution of instruction 905 by processor 901.

[0116] The computer system 900 may also include one or more communication interfaces 909 for communicating with other electronic devices. The one or more communication interfaces 909 may be based on wired communication technology, wireless communication technology, or both. Some examples of the one or more communication interfaces 909 include Universal Serial Bus (USB), Ethernet adapters, wireless adapters operating according to the Institute of Electrical and Electronics Engineers (IEEE) 902.11 wireless communication protocol, Bluetooth® wireless communication adapters, and infrared (IR) communication ports.

[0117] Computer system 900 may also include one or more input devices 911 and one or more output devices 913. Some examples of one or more input devices 911 include a keyboard, mouse, microphone, remote control device, button, joystick, trackball, touchpad, and light pen. Some examples of one or more output devices 913 include speakers and printers. A particular type of output device typically included in computer system 900 is a display device 915. The display device 915 used with the implementations disclosed herein may use any suitable image projection technology, such as liquid crystal display (LCD), light-emitting diode (LED), gas plasma, electroluminescence, etc. A display controller 917 may also be provided for converting data 907 stored in memory 903 into text, graphics, and / or moving images (as applicable) displayed on display device 915.

[0118] The various components of a computer system 900 can be coupled together via one or more buses, which may include power buses, control signal buses, status signal buses, data buses, etc. For clarity, the various buses are... Figure 9 It is described as a bus system 919.

[0119] This disclosure describes a subjective data application system within a network framework. In this disclosure, "network" refers to one or more data links that enable electronic data transmission between computer systems, modules, and other electronic devices. A network can include public networks such as the Internet as well as private networks. When information is transmitted or provided via a network or another communication connection (hardwired, wireless, or both), the computer correctly treats the connection as a transmission medium. The transmission medium can include networks and / or data links carrying desired program code in the form of computer-executable instructions or data structures, which can be accessed by general-purpose or special-purpose computers.

[0120] Furthermore, the network described herein can refer to a network or combination of networks through which one or more computing devices can access the various systems described in this disclosure (such as the Internet, corporate intranets, virtual private networks (VPNs), local area networks (LANs), wireless local area networks (WLANs), cellular networks, wide area networks (WANs), metropolitan area networks (MANs), or combinations of two or more such networks). In practice, the network described herein can include one or more networks that use one or more communication platforms or technologies to transmit data. For example, a network can include the Internet or other data links that enable the transmission of electronic data between corresponding client devices and components (e.g., server devices and / or virtual machines) of a cloud computing system.

[0121] Furthermore, upon arrival at various computer system components, program code in the form of computer-executable instructions or data structures can be automatically transferred from a transmission medium to a non-transitory computer-readable storage medium (device) and vice versa. For example, computer-executable instructions or data structures received via a network or data link can be buffered in random access memory (RAM) within a network interface module (NIC) and then ultimately transferred to the computer system RAM and / or a less volatile computer storage medium (device) at the computer system. Therefore, it should be understood that computer-readable storage media (devices) can be included in computer system components that also (or even primarily) use transmission media.

[0122] Computer-executable instructions include instructions and data that, when executed by a processor, cause a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform a particular function or group of functions. In some implementations, the computer-executable and / or computer-implemented instructions are executed by a general-purpose computer to turn the general-purpose computer into a special-purpose computer that implements the elements of this disclosure. Computer-executable instructions may include, for example, binary files, intermediate format instructions (such as assembly language), or even source code. Although the subject matter has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the features or actions described above. Rather, the described features and actions are disclosed as exemplary forms for implementing the claims.

[0123] Those skilled in the art will understand that this disclosure can be practiced in networked computing environments with many types of computer system configurations, including personal computers, desktop computers, laptop computers, message processors, handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframes, mobile phones, PDAs, tablets, pagers, routers, switches, etc. This disclosure can also be practiced in distributed system environments, where both local and remote computer systems, linked via a network (via a hardwired data link, a wireless data link, or a combination of hardwired and wireless data links), perform tasks. In a distributed system environment, program modules can reside in both local and remote memory storage devices.

[0124] The techniques described herein can be implemented in hardware, software, firmware, or any combination thereof, unless specifically described as being implemented in a particular manner. Any features described as modules, components, etc., can also be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques can be implemented at least in part by a non-transitory processor-readable storage medium comprising instructions that, when executed by at least one processor, perform one or more of the methods described herein (including computer-implemented methods). Instructions can be organized into routines, programs, objects, components, data structures, etc., which can perform specific tasks and / or implement specific data types, and can be combined or distributed as needed in various implementations.

[0125] Computer-readable media can be any available medium accessible by a general-purpose or special-purpose computer system. A computer-readable medium storing computer-executable instructions is a non-transitory computer-readable storage medium (device). A computer-readable medium carrying computer-executable instructions is a transmission medium. Therefore, by way of example, implementations of this disclosure may include at least two distinctly different kinds of computer-readable media: non-transitory computer-readable storage media (devices) and transmission media.

[0126] As used herein, a computer-readable storage medium (device) may include RAM, ROM, EPROM, CD ROM, solid-state drive (SSD) (e.g., RAM-based), flash memory, phase-change memory (PCM), other types of memory, other optical disc storage, disk storage or other magnetic storage devices, or any other medium that may be used to store desired program code components in the form of computer-executable instructions or data structures and that may be accessed by a general-purpose or special-purpose computer.

[0127] Without departing from the scope of the claims, the steps and / or actions of the methods described herein may be interchanged with each other. In other words, unless the correct operation of the described methods requires a specific order of steps or actions, the order and / or use of specific steps and / or actions may be modified without departing from the scope of the claims.

[0128] The term "determine" encompasses a wide variety of actions, and therefore, "determine" can include calculation, computation, processing, derivation, investigation, lookup (e.g., searching in a table, database, or other data structure), ascertainment, etc. Furthermore, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in memory), etc. Additionally, "determine" can include parsing, selecting, picking, building, etc.

[0129] The terms “comprising,” “including,” and “having” are intended to be inclusive and mean that additional elements may exist in addition to those listed. Furthermore, it should be understood that references to “one implementation” or “implementation” in this disclosure are not intended to exclude the existence of additional implementations that also include the described features. For example, where compatible, any element or feature described with respect to an implementation herein may be combined with any element or feature of any other implementation described herein.

[0130] This disclosure may be embodied in other specific forms without departing from the spirit or characteristics thereof. The described implementations should be considered illustrative rather than restrictive. The scope of this disclosure is indicated by the appended claims rather than by the foregoing description. Variations in the meaning and scope of equivalents of the claims will be included within their scope.

Claims

1. A computer-implemented method for reporting security incidents in a cloud computing system (102), the computer-implemented method comprising: Determine the attack type bucket assignment (502) for security alerts in the received security alert (102) (320) set; A security event (414) is generated by determining the correlation between subsets (416) of security alerts from the received security alert (102) (320) set; Based on the attack type bucket assignment (502) determined for a subset (416) of the security alerts, identify one or more attack type buckets (112)(324) for the security event (414); and Based on data from a subset (416) of the security alerts and contextual information associated with the one or more attack type buckets (112)(324), a security incident report (604) is generated using a security alert generative language model (132)(310), which provides a concise language description of the security incident (414).

2. The computer-implemented method according to claim 1 further includes: Based on the alarm name and alarm description of the first security alarm, the security alarm generative language model is used to determine whether to assign the first security alarm to a first attack type bucket, wherein the first attack type bucket belongs to a set of attack type buckets associated with different types of security events.

3. The computer-implemented method according to claim 2 further includes: Based on the alarm name and alarm description of the first security alarm, the security alarm generative language model is used to determine whether to assign the first security alarm to a second attack type bucket, wherein the second attack type bucket belongs to the attack type bucket set, and wherein the second attack type bucket and the first attack type bucket are associated with different types of security events.

4. The computer-implemented method according to claim 3 further includes: Receive additional security alerts; The attack type bucket assignment for the additional security alert is determined using the security alert generative language model. Add the additional security alert to the subset of security alerts and the security event; as well as Further, based on the additional security alert and the context information assigned to the attack type bucket for the additional security alert, an updated security incident report is generated using the security alert generative language model.

5. The computer-implemented method of claim 4, wherein the updated security incident report includes a rewritten, concise language description of the security incident.

6. The computer-implemented method of claim 5, wherein the updated security incident report includes additional remedial steps for resolving the security incident.

7. The computer-implemented method according to claim 1, further comprising: Based on the determination that the first security alert does not correspond to any existing attack type bucket within the attack type bucket set, the security alert generative language model is used to determine whether to assign the first security alert to a new attack type bucket.

8. The computer-implemented method of claim 1 further includes providing an attack type bucket identifier of the one or more attack type buckets to the security alert generative language model, wherein the security alert generative language model accesses the context information of the one or more attack type buckets based on the attack type bucket identifier of the one or more attack type buckets.

9. The computer-implemented method according to claim 8, further comprising: Based on the attack type bucket identifier, the security alert generative language model is provided with access to multiple attack type templates.

10. The computer-implemented method of claim 9, wherein a first attack type template from the plurality of attack type templates provides the security alert generative language model with a description of a first type of security event associated with the first attack type bucket.

11. The computer-implemented method of claim 10, wherein the first attack type template provides instructions for generating the concise language description within the context of a security event of the first type.

12. A system for reporting security incidents in a cloud computing system (102), the system comprising: Generative language model for security alerts (132)(310); Processing system; as well as Computer memory (903) includes instructions (905) that, when executed by the processing system, cause the system to perform the following operations: Determine the attack type bucket assignment (502) for the security alerts (102)(320) in the received security alert (102)(320) set; A security event (414) is generated by determining the correlation between subsets of security alerts (416) from the received security alert (102) (320) set; Based on the attack type bucket assignment (502) determined for a subset (416) of the security alerts, identify one or more attack type buckets (112)(324) for the security event (414); and Based on data from a subset (416) of the security alerts and contextual information associated with the one or more attack type buckets (112)(324), a security incident report (604) is generated using the security alert generative language model (132)(310), which provides a concise language description of the security incident (414).

13. The system of claim 12, wherein the subset of security alerts includes security alerts assigned to buckets of different attack types.

14. The system of claim 12, wherein the concise language description comprises a short textual description of the security incident and a textual description of remedial steps for the security incident.

15. The system of claim 12, wherein the operation further comprises using a correlation engine to determine the correlation between the subsets of security alerts.

16. The system of claim 12, wherein determining the correlation between the subsets of security alerts comprises determining that the data between the alerts in the subsets of security alerts satisfy a correlation threshold.

17. The system of claim 16, wherein the data includes the computation address of the security alarm, the security alarm name, the security alarm description, and the user identifier.

18. A computer-implemented method for reporting security incidents in a cloud computing system (102), the computer-implemented method comprising: Determine the attack type bucket assignment (502) for the security alerts (102)(320) in the received security alert (102)(320) set; A security event (414) is generated by determining the correlation between subsets (416) of security alerts from the received security alert (102) (320) set; Based on the attack type bucket assignment (502) determined for a subset (416) of the security alerts, one or more attack type buckets (112)(324) for the security event (414) are identified; Based on data from a subset (416) of the security alerts and contextual information associated with the one or more attack type buckets (112)(324), a security incident report (604) is generated using a security alert generative language model (132)(310), which provides a concise language description of the security incident (414). Receive additional security alerts after generating the security incident report (604); as well as Further, based on the additional security alert and the context information of the attack type bucket assignment for the additional security alert generated by the security alert generative language model (132)(310), an updated security incident report (604) is generated using the security alert generative language model (132)(310).

19. The computer-implemented method according to claim 18, wherein: The updated security incident report includes a rewritten, concise description of the security incident; as well as The updated security incident report includes additional remedial steps for resolving the security incident.

20. The computer-implemented method of claim 18, further comprising receiving the received security alert set from one or more security monitoring agents implemented on one or more network devices on the cloud computing system.