Threat detection method in threat detection system and threat detection system
The threat detection system employs a controller with large language models to process inputs and convert formats, addressing configuration challenges and enhancing decision-making efficiency and transparency.
Patent Information
- Application Number
- JP2024216861
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-11
- Filing Date
- 2024-12-11
- Publication Date
- 2025-07-15
AI Technical Summary
Existing threat detection systems face challenges in maintaining and updating decision logic, requiring significant effort to configure different systems to cooperate effectively, and often rely on third-party services that raise concerns about technology dependence and privacy.
A threat detection system utilizing a threat detection controller connected to at least two threat detection elements, which includes a large language model to process and convert inputs into the required format, enabling efficient and interpretable decision-making.
Facilitates a reliable and easily configurable threat detection system that leverages large language models for flexible and transparent decision-making, reducing the complexity of maintaining and updating decision logic.
Smart Images

Figure 2025106203000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a threat detection system, a server of the threat detection system, and a threat detection method in the threat detection system.
Background Art
[0002] Security and threat detection systems for computers and computer networks are used to detect threats and anomalies in computers and computer networks. Such examples are endpoint protection platforms (EPPs), endpoint detection and response (EDR), and managed detection and response (MDR) products and services. An endpoint protection platform (EPP) is a solution deployed on endpoint devices to prevent file-based malware attacks and detect malicious activities. Also, an EDR system focuses on the detection and monitoring of defects when they occur and helps determine the best way to respond to the detected defects. An EDR system also provides the investigation and remediation capabilities required to respond to dynamic security incidents and alerts. MDR is a managed cybersecurity service for threat detection, response, and remediation. The emergence of machine learning, big data, and cloud computing has enabled the growth of efficient and robust threat detection solutions in part.
[0003] An EPP, EDR, or other corresponding system deploys a data collector or processing unit, such as an agent or sensor, on a selected network endpoint, which can be any element of the IT infrastructure. Typically, an agent of an EPP system can focus on endpoint protection and thus on data processing, while an agent of an EDR system can focus on detection capabilities and thus on data collection. The data collector observes the activities taking place at the endpoint and sends the collected data, often to a central backend system located within the cloud. When the backend receives the data, the data can be processed (e.g., aggregated and enhanced) before being analyzed and scanned by the security system provider for security flaws and signs of anomalies.
[0004] Today, the proactive and accurate detection of cyber threats requires the widespread adoption of special mechanisms that are responsible for performing various types of actions that help recognize threats in a computer or computer network. These actions can include, for example, querying reputation services and metadata lookup databases, analyzing composite objects (e.g., installer packages, emails, web pages, documents), analyzing the acquired content (executable files, process dumps, text, images, etc.), and obtaining behavioral data (e.g., via emulation and sandboxing capabilities).
[0005] The process of threat detection leading to a decision can be iterative and can include multiple steps depending on the current uncertainty and acceptable risk level, and can be continued by triggering more refined actions. The list of actions can continuously evolve and can include auxiliary mechanisms useful for tasks such as image tagging, sentiment analysis, machine translation, spell checking, and the identification of obfuscated data.
[0006] One of the problems with conventional systems is that it is difficult to develop, maintain, and keep up-to-date such decision logic, which requires a lot of work, for example, in the form of configuring different systems to cooperate with each other. Also, some actions may need to incorporate non-obvious solutions that cannot be easily formalized and thus usually rely on third-party services where technology dependence and privacy are concerns. Also, actions need to be rationally dispatched. That is, all given inputs require an appropriate processing sequence depending on the available situation, the threat situation, and the customer's preferences. Therefore, a great deal of effort is required to keep the action organization logic concise and consistent.
Summary of the Invention
Problems to be Solved by the Invention
[0007] Therefore, it is necessary to achieve a reliable and easily configurable threat detection system that can utilize different mechanisms and elements for tasks related to threat detection.
Means for Solving the Problems
[0008] The following presents a simplified overview to provide a basic understanding of some aspects of various embodiments of the invention. This overview is not an extensive overview of the invention. It is not intended to identify key or critical elements of the invention or to delineate the scope of the invention. The following overview merely presents some concepts of the invention in a simplified form as a prelude to a more detailed description of exemplary embodiments of the invention.
[0009] According to a first aspect, the present invention relates to a method for threat detection in a threat detection system comprising at least one endpoint and / or at least one server, for example a computer-implemented method. The method includes using at least two threat detection elements by a threat detection system to detect cyber threats, the threat detection elements being connected to a threat detection controller that controls threat detection by assigning tasks and / or by giving commands to the threat detection elements, for example iteratively, and by following the output of the threat detection elements, the threat detection controller using at least one large language model when outputting data to the threat detection elements and / or when processing information received from the threat detection elements.
[0010] In one embodiment of the present invention, the threat detection controller is arranged in a server, or a service such as a backend service and / or a cloud service, and / or an endpoint.
[0011] In one embodiment of the present invention, inputs for the threat detection system and / or elements of the threat detection system, for example decision-making logic, analysis of executable files, incident updates and decisions, evaluated reputations and / or risk scores, are received as natural language, numbers, categories or combinations thereof, and the threat detection controller converts the information received by at least one large language model into the format required by the threat detection elements or the threat detection system.
[0012] In one embodiment of the present invention, the at least two threat detection elements comprise at least one of the following: a parser, an antivirus engine, for example an EDR and / or MDR rule-based engine, a service element such as an EDR and / or MDR AI-based engine, an EDR and / or MDR engine, an external data source such as a domain search database, a virus database, or an information source, an internal data source such as a threat intelligence information database, an incident information database, an asset information database.
[0013] In one embodiment of the present invention, the threat detection element and / or the task given to the threat detection element relate to machine translation, sentiment analysis, grammar checking, and / or identifying synonyms and semantically similar statements.
[0014] In one embodiment of the present invention, information related to decision-making logic such as in-depth analysis of executable files, incident updates and incident decisions, evaluated reputation, and / or risk scores is received as input to the threat detection controller.
[0015] In one embodiment of the present invention, the method further includes summarizing, by at least one large language model, the output from the threat detection system and / or the threat detection controller, such as a decision and / or the reason for the decision.
[0016] In one embodiment of the present invention, the at least one large language model is a generative model and / or a model for natural language processing (NLP) tasks such as text generation, language translation, sentiment analysis, text summarization, and / or question answering.
[0017] In one embodiment of the present invention, at least one endpoint collects threat detection-related data from the endpoint by a security agent module installed on the endpoint, and transmits the collected threat detection-related data to a threat detection system, such as a server of the threat detection system, for further analysis. The threat detection controller controls the analysis of the received threat detection-related data.
[0018] In one embodiment of the present invention, at least one threat detection element performs processing related to prioritizing identified threats and / or potential actions for improving the security posture. In one embodiment of the present invention, the output of the threat detection element relates to at least one of the identified vulnerabilities, identified critical assets, the priority of the identified vulnerabilities, the priority of the critical assets, the risk value for the business of the identified assets and / or vulnerabilities, the attack path mapping, the visualization, and the reporting artifacts.
[0019] According to a second aspect, the present invention relates to a server of a threat detection system, the threat detection system comprising at least one endpoint and at least one server. The server comprises at least one or a plurality of processors and is configured to utilize at least two threat detection elements when detecting cyber threats. The server comprises a threat detection controller, the threat detection elements being connected to the threat detection controller, and the threat detection controller being configured to control threat detection by assigning tasks to the threat detection elements and / or following the output of the threat detection elements, for example, by repeatedly giving instructions. The threat detection controller is configured to utilize at least one large language model when outputting data to the threat detection elements and / or when processing the input from the threat detection elements.
[0020] According to a third aspect, the present invention relates to a threat detection system comprising at least one endpoint and / or at least one server according to the present invention. In one embodiment of the present invention, the threat detection system is configured to execute the method according to any embodiment of the present invention.
[0021] According to a fourth aspect, the present invention relates to a computer program comprising instructions that, when executed by a computer, cause the computer to execute the method according to the present invention.
[0022] According to a fifth aspect, the present invention relates to a computer-readable medium comprising the computer program according to the present invention.
[0023] In the solution of the present invention, it is possible to utilize at least one large language model (LLM) in threat detection. The large language model can be used for threat detection and / or to control different elements and mechanisms that process the inputs and outputs of these different elements and mechanisms, for example, for dispatching or orchestrating. The solution of the present invention, for example, the decision-making logic (e.g., deep analysis of executable files, incident updates and decisions, reputation and risk score evaluation) can be described in natural language, and at least one large language model can translate natural language into different elements in the correct format required by the different elements. Therefore, in one embodiment of the present invention, at least one large language model can act as a script engine. In some embodiments, for example, the decision-making logic can combine the strengths of existing expert mechanisms and facilities and utilize at least one large language model where it is needed.
[0024] Various exemplary and non-limiting embodiments of the present invention will be best understood from the following description of specific exemplary and non-limiting embodiments when read in conjunction with the accompanying drawings, with their additional objects and advantages, both with respect to structure and method of operation.
[0025] The verbs "to comprise" and "to include" are used herein as open limitations that do not exclude the presence of features not recited, nor require them. The features described in the dependent claims can be freely combined with each other unless otherwise specified.
[0026] Furthermore, throughout this specification, it should be understood that the use of "a" or "an", i.e., the singular form, does not exclude the plural form.
[0027] Embodiments of the present invention are shown by way of example and not limitation in the figures of the accompanying drawings.
Brief Description of the Drawings
[0028]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0029] A threat detection system according to an embodiment of the present invention can include at least one endpoint and a backend system including at least one backend server. In this case, information, for example, threat detection related data, can be shared between endpoints and / or between an endpoint and the backend system.
[0030] FIG. 1 illustrates an exemplary environment in which the solution of the present invention can be used. In the solution of FIG. 1, a system configuration is presented in which a local host 101 and a remote entity or server 102 are connected via a network 103. Here, the host 101 exemplifies any computer or communication system, including a single device, a network node, or a combination of devices on which malware scanning or collection of threat detection-related information is performed. Scanning and / or analysis of threat detection-related data can be performed on the host and / or the server. For example, the host 101 can include a personal computer, a personal communication device, a network-enabled device, a client, a firewall, a mail server, a proxy server, a database server, and the like. The server 102 exemplifies any computer or communication system including a single device, a network node, or a combination of devices, on which malware scanning or threat detection data analysis can be performed for the host 101, or data required to perform malware scanning or threat detection-related analysis at the host, such as risk assessment and / or reputation data, can be provided to the host 101. For example, the server 102 can include a security entity or a back-end entity of a security provider, and the server 102 can be implemented in a cloud implementation or the like.
[0031] According to an exemplary embodiment of the present invention, malware scanning and / or threat detection data analysis in host 101 and / or server 102 can be realized using a malware analysis environment such as a virtual machine or emulator environment arranged in the host and / or server. For example, a malware scanning agent or sensor, such as antivirus software, can be installed / arranged on host 101 and used for malware scanning and / or threat detection data analysis. In one embodiment of the present invention, sensors or agents in a computer are used to enable interception of files, system configuration values, and / or network operations called by an application. The sensor can be used to observe the operation of a device such as a computer, and using the information collected by the sensor, malicious behavior of an application, file, and / or process can be detected.
[0032] In one embodiment of the present invention, the malware scanning environment, service, and / or software can detect the start and end of an application and all abnormal processes, and attach monitoring to the necessary applications and processes. Also, when a service is started early, the service can detect and follow most of the user's applications. In one embodiment of the present invention, when malware scanning software or a service is started, the malware scanning software or service can execute an inventory of running applications.
[0033] Network 103 exemplifies any computer or communication network, including, for example, a (wired or wireless) local area network such as a LAN, WLAN, Ethernet (registered trademark), or a (wired or wireless) wide area network such as WiMAX, GSM (registered trademark), UMTS, LTE, etc. Thus, host 101 and server 102 can be located at different locations, but do not have to be. For example, network 103 may be any type of TCP / IP-based network. Communication between host 101 and server 102 via network 103 can be realized using any standard or proprietary protocol carried via TCP / IP. In such a protocol, the malware scanning agent at host 101 and the malware analysis sandbox or application at server 102 can be represented on / at the application layer.
[0034] FIG. 2 also schematically shows an exemplary network architecture of an embodiment of the present invention in which the solution of the present invention can be used. In FIG. 2, a part of a first local computer network 201 is schematically shown, in which a computer system, for example, an EPP or EDR system is installed. Also, any other computer system capable of implementing an embodiment of the present invention can be used instead of or in addition to the EPP or EDR system used in this example. The first local computer network is connected via a network 203 to a security service network, in one embodiment, a security backend system or server 202. The network can be similar to the network 103 in FIG. 1. The backend system or server 202 can be similar to the server 102 in FIG. 1. The backend system or server 202 can form a node on the security service computer network with respect to the first local computer network. The security service computer network can be managed by a threat detection system provider and can be separated from the network 203 by a gateway or other interface (not shown) or other network elements suitable for the backend 202. The first local computer network 201 can also be separated from the network 203 by a gateway 204 or other interface. Other network structures are also possible. In one embodiment of the present invention, the server can be provided with a threat detection controller.
[0035] The first local computer network 201 can be formed from a plurality of interconnected network nodes 205a - 205h, each representing an element within the first local computer network 201 such as a computer, smartphone, tablet, laptop, or other network - enabled hardware. In one embodiment of the present invention, a node is any device on the network but not a gateway. Each of the network nodes 205a - 205h shown in the first local computer network can also represent an endpoint, such as an EDR endpoint or an EPP endpoint, on which malware scan agent or sensor security agent modules 206a - 206h, which may include a data collector or a sensor, are installed. The network nodes 205a - 205h can be similar to the local host 101 in FIG. 1, and the malware scan agent or sensor can correspond to the agents presented in relation to FIG. 1. In some embodiments of the present invention, the malware scan agent or sensor can also be installed on any other element of the computer network, such as on a gateway or other interface. In the example of FIG. 2, the security agent module 204a is installed on the gateway 204. The malware scan agent, or sensors 206a - 206h, 204a collect various types of data at the nodes 205a - 205h or the gateway 204, including, for example, program or file hashes, files stored at the nodes 205a - 205h, logs of network traffic, process logs, binaries or files cut out from memory (e.g., DLL, EXE, or memory forensic artifacts), and / or logs from monitoring actions (e.g., TCP dump) performed by programs or scripts executed on the nodes 205a - 205h or the gateway 204. The collected data can be stored in a database or similar model for information storage for further use and / or sent for further analysis.Any type of threat detection model can be further constructed in the backend / server 202 and / or in the second server and stored in the database. Nodes 205a - 205h and server 202 typically comprise a hard drive, a processor, and RAM.
[0036] Any type of data that can assist in detecting and monitoring security threats, such as security breaches or intrusions into the system, can be collected by malware scanning agents or sensors 206a - 206h, 204a during their life cycles, and the types of data to be monitored and collected can be set according to rules defined by the threat detection system provider at the time of installation of the threat detection system and / or when distributing elements of the threat detection model. In one embodiment, one or more detection mechanisms can detect suspicious or malicious events among the monitored events. In one embodiment, the detection mechanisms used to detect suspicious or malicious events can include using machine learning models, scanning engines, discovery rules, statistical anomaly detection, fuzzy logic - based models, and using predetermined rules.
[0037] In one embodiment of the present invention, at least some of the malware scanning agents or sensors 206a - 206h can also have the ability to make decisions regarding the types of data observed and collected by themselves. For example, the malware scanning agents or malware scanning sensors 206a - 206h, 204a can collect data regarding the behavior of programs running on the endpoints and can observe when new programs are started. When appropriate resources are available, the collected data can be permanently or temporarily stored by the malware scanning agents or sensors 206a - 206h, 204a at their respective network nodes or in appropriate storage locations on the first local computer network 201 and / or further transmitted.
[0038] The malware scanning agents or sensors 206a - 206h, 204a are configured to transmit and receive information such as data they have collected or transmitted to / from the threat detection system backend 202 via a network 203 such as the Internet. This enables the system to be remotely managed without the need for a certain human presence in an organization where the threat detection system provider manages the first local computer network 201.
[0039] In one embodiment of the present invention, the malware scanning agents or sensors 206a - 206h, 204a can also be configured to establish an internal network, such as an internal swarm intelligence network, that includes malware scanning agents or sensors for a plurality of interconnected network nodes 205a - 205h of the local computer network 201. Since the malware scanning agents or sensors 206a - 206h, 204a collect data related to their respective network nodes 205a - 205h of each malware scanning agent or sensor 206a - 206h, 204a, they are further configured to share information based on the collected data within the established internal network. In one embodiment, the swarm intelligence network is composed of a plurality of semi - independent security nodes (security agent modules) that can function similarly by themselves. Thus, the number of instances in the swarm intelligence network can vary sufficiently. Also, there may be two or more connected swarm intelligence networks that cooperate with each other within one local computer network.
[0040] The malware scanning agents or sensors 206a - 206h, 204a and / or the backend system can be further configured to use the collected data and information received from the internal network to generate and adapt models related to their respective network nodes 205a - 205h and / or their users.
[0041] In the solution of the present invention, at least two threat detection elements are utilized for a threat detection system to detect cyber threats or to assist in the detection of cyber threats. The threat detection elements are connected to a threat detection controller that controls threat detection by assigning tasks and / or giving instructions to the threat detection elements and by following the output of the threat detection elements. The process can be iterative, for example, tasks are assigned to the threat detection elements and / or instructions are given as long as a specific high-level task is completed or a predetermined certainty level is achieved. An example of the elements and their interoperability with the threat detection controller is shown in FIG. 3. The threat detection elements can include, for example, processing or analysis services, external data sources, and / or internal data sources. The processing or analysis services can comprise at least one of a static parser, a dynamic parser, an antivirus engine, an EDR / MDR rule engine, an EDR / MDR AI-based engine. The external data sources can include at least one of a domain search database, a virus database, a virus information source. The internal data sources can include at least one of a threat intelligence information source, an incident information source, an asset information source. The threat detection elements can comprise (in addition to or instead of the previous elements) at least one of the following elements, namely, a data source, a data collection agent, a data aggregation and normalization element, namely, a data storage, an analysis engine, a warning and notification element, a user interface element, a reporting and logging element, an incident response tool, an integration tool, a machine learning algorithm, and an AI algorithm, a rule engine, a scalability and / or redundancy unit, a threat intelligence feed.
[0042] In one embodiment of the present invention, the threat detection controller may be arranged in a server or service such as a backend service and / or a cloud service. In one embodiment, the threat detection controller may be arranged in an endpoint or a host.
[0043] The threat detection controller can manage the threat detection process of a threat detection system, for example, by instructing different threat detection elements to perform the tasks of the threat detection system. The threat detection controller can process and provide threat detection related tasks for the threat detection elements using at least one large language model, and / or can process the data provided as input to the elements using at least one large language model. The elements can perform different types of actions, including (but not limited to) querying reputation services and metadata lookup databases, analyzing composite objects (such as installer packages, emails, web pages, documents), analyzing the acquired content (executable files, process dumps, text, images, etc.), obtaining behavioral data (e.g., via emulation and sandboxing functions), and making decisions about the collected facts, identifying threat landscape information, image tagging, sentiment analysis, machine translation, spell checking, and obfuscated data that summarizes the results of the analysis. The elements can provide, for example, specialized, well-formulated tasks when the use of a large language model is not feasible.
[0044] The large language models (LLMs) utilized in the solution of the present invention are typically based on a transformer architecture, although other architectures such as recurrent neural networks are also possible. LLMs belong to a broader class of models called foundation models. These models can be trained on a large scale with extensive data and can be adapted to a wide range of downstream tasks. LLMs are trained to predict the next word or token in a sequence based on the preceding context and can effectively generate text that follows the patterns and structures of natural language. LLMs can be specialized for text generation and NLP tasks, but they can share basic generative modeling principles with other generative models that create different types of data such as images (e.g., diffusion models or general-purpose adversarial networks) or audio (e.g., WaveGAN).
[0045] Large language models can demonstrate powerful capabilities to understand natural language and tackle complex tasks using text generation. They can, for example, perform few-shot tasks using in-context learning. For instance, when the model is given a series of instructions or task demonstrations in natural language, it can generate the expected results for test instances by completing the word sequence in the input text. This can be done without the need for additional training or gradient updates. Large language models can also exhibit capabilities beyond natural language processing such as understanding programming languages.
[0046] One of the main advantages of large language models is their flexibility in input and ability to adapt to input. By this means, these models are not limited to a given type of input. Large language models can process arrays of various inputs and can accommodate even structured data such as tables, unstructured data such as text or images, and abstract data structures such as graphs. Furthermore, large language models offer considerable adaptability with respect to output. The models can generate a variety of output formats ranging from simple numerical values to text summaries, classification results, or various types of data structures. The flexibility in interpreting instructions given in natural language facilitates the ability of cybersecurity analysts to focus on important areas of their expertise and responsibility (the detection rules and definitions of the predicted output itself can be expressed in natural language).
[0047] Another advantage lies in the interpretability of large language models. They can provide results with reasonable explanations, which helps users understand how the model arrived at the conclusions. This is beneficial in situations where transparent decision-making is essential. Thus, for customers of cybersecurity services, the final output and the inference chain can be summarized to make interpretable decisions.
[0048] Large language models also have the ability to handle tasks that are often difficult to express in traditional coding languages. They demonstrate proficiency in pattern recognition and inferential assignment and are skilled at adapting to variations and learning from previous data. Large language models have unique characteristics to support various use cases related to handling natural language such as machine translation, sentiment analysis, grammar checking, identification of synonyms, and semantically similar statements. Such use cases are in line with the auxiliary operations of detection logic (for example, spam detection logic can, in one embodiment, rely on language-agnostic analysis that requires text translation, summarization, and sentiment analysis functions).
[0049] In one embodiment of the present invention, at least one large language model is a generative model and / or a model for natural language processing (NLP) tasks such as text generation, language translation, sentiment analysis, text summarization, and / or question answering.
[0050] In one embodiment of the present invention, inputs for a threat detection system and / or inputs for elements of a threat detection system, such as decision-making logic, analysis of executable files, incident updates and decisions, evaluated reputations, and / or risk scores, are received as natural language in a structure, for example, as categories having meanings defined in natural language, and the threat detection controller converts the information received by at least one large language model into the format required by the threat detection element or the threat detection system.
[0051] The solution of the present invention, for example, decision-making logic (e.g., in-depth analysis of executable files, incident updates and decisions, evaluation of reputation and risk scores), can be described in natural language, and at least one large language model can translate natural language in the correct format to different elements according to what different elements require. Thus, in one embodiment of the present invention, at least one large language model can play the role of a script engine. In some embodiments, for example, decision-making logic can combine the strengths of existing expert mechanisms and facilities and utilize at least one large language model where it is required.
[0052] In one embodiment of the present invention, decision-making logic-related information such as in-depth analysis of executable files, incident updates and incident decisions, evaluated reputations, and / or risk scores is received as an input to the threat detection controller.
[0053] The solution of the present invention can be used, for example, in an endpoint protection (EPP) system. In one embodiment of the present invention, a host or computer can be protected by a threat detection system such as an endpoint protection (EPP) or EDR system. In the solution of the present invention, the system can be provided with endpoint-side security control that makes decisions in both local and distributed manners so that several functional elements, such as facilitating an attack detection process, are hosted remotely. The local decision-making process can rely on certain simple (and thus often prone to false negatives) security controls aimed at quickly and reliably preventing known attacks and their variants. Ambiguous objects such as untrusted executable files and the context of their appearance, which were not previously seen in uncertain situations, are analyzed by a remote service that can provide a wider and more complex detection and analysis tool than the tools on the local host or endpoint. The remote service can utilize, for example, a machine learning model that scrutinizes objects through deep static and dynamic inspections. In one embodiment of the present invention, a threat detection controller (for example, arranged on the server and backend side) can utilize at least one large language model when controlling this threat detection process, outputting data to these threat detection elements, and / or processing the information received from these threat detection elements in the analysis of ambiguous objects.
[0054] The solution of the present invention can be used, for example, in an EDR- or MDR-system. In an EDR / MDR system, an EDR / MDR agent consumes data from an EDR / MDR sensor element and performs an initial analysis to determine whether a given activity (e.g., a series of events) matches an initial definition of malicious (e.g., suspicious, beneficial) behavior. If there is a match, the information is transferred to the EDR / MDR backend. This information can be collected by the agent element to provide context information, thereby enabling a decision to be made regarding the action to be taken. The EDR / MDR backend can further analyze the information received from the agents deployed in the environment. The EDR / MDR sensor can operate passively by intercepting the data flowing through the system process, and since the sensor often needs to be located in-line with the process, it must operate quickly. The EDR / MDR backend uses various methods, such as heuristics or rule databases, to pass the data to its decision logic to check whether the activity is benign, meets its threshold for being logged, and is highlighted as suspicious, malicious, etc.
[0055] Creating and maintaining the logic of an EDR / MDR system affects a significant number of organizations and thus requires careful consideration. Usually, this issue is addressed by adjusting decision routines according to different environments, for example, to meet the needs of the organization. Another notable trade-off that needs to be considered is that agent-side logic can enable EDR / MDR to take immediate preventive measures, but usually, agent-side logic does not include the ability to analyze complex situations. Alternative back-end detection can support the analysis of complex situations but at the cost of introducing a time delay. In one embodiment of the present invention, when a threat detection controller (disposed on the server and back-end side) outputs data to these back-end threat detection elements, and / or when receiving and / or processing processing information connected to the back-end from these back-end threat detection elements, this EDR / MDR threat detection process can be controlled and at least one large language model can be utilized.
[0056] The solution of the present invention can be used, for example, in exposure management where the exposure of resources is determined. In exposure management, the streaming of raw heterogeneous data collected from multiple sources is processed to form and maintain an asset inventory. For example, collecting variations of the asset inventory and general properties of the assets, forming their vulnerability scopes and postures, and further analyzing them to address the awareness aspect, for example, by scoring the reputations of public assets, supply chain providers, AI providers, etc. The overview of the awareness invention can prioritize aircraft and composite aircraft risk remediation activities for each asset through, for example, enriching the threat landscape to evaluate responsiveness via dynamic risk scoring. The number and output of the final output exposure management control are expected to be moderate. For example, it is a combination of the priority of risk remediation for each asset and the priority of asset risk remediation and the dynamic risk score. In one embodiment of the present invention, a threat detection controller (for example, arranged on the server and backend side) can utilize at least one large language model when controlling this exposure analysis process, when outputting data to these elements, and / or when processing information received from these elements. The at least one large language model can also be utilized when strengthening the overview of the awareness invention with threat landscape information.
[0057] In one embodiment of the present invention, at least one threat detection element performs actions regarding the prioritization of potential treatments for identified threats and / or for improving the security posture. In one embodiment of the present invention, the output of the threat detection element relates to at least one of the following: identified vulnerabilities, identified critical assets, the priority of identified vulnerabilities, the priority of critical assets, the risk value for the business of identified assets and / or vulnerabilities, attack path mapping, visualization, and reporting artifacts.
[0058] Figure 4 shows an exemplary method according to an embodiment of the present invention. In the exemplary method, a threat detection system utilizes at least two threat detection elements to detect cyber threats, and the threat detection elements are connected to a threat detection controller. The threat detection controller controls threat detection by assigning tasks and / or giving instructions to the threat detection elements and by following the output of the threat detection elements. The threat detection controller utilizes at least one large language model when outputting data to the threat detection elements and / or when processing information received from the threat detection elements.
[0059] Figure 5 presents an exemplary computing device such as a host, endpoint, and / or server according to an embodiment of the present invention. The computing device 510 can represent, for example, the local entity or host 1 of FIG. 1, or can represent the remote entity or server 2 of FIG. 1. The computing device 510 can execute procedures and / or be configured to perform functions as described in any one of FIGS. 1-4.
[0060] A computing device can include at least one processor 511, at least one memory 512 (and optionally at least one interface 513), which can be operably connected or coupled to each other, for example, by a bus 514. The processor 511 of the computing device 510 is configured to read and execute computer program code stored in the memory 512. The processor can be represented by a CPU (Central Processing Unit), an MPU (Micro Processor Unit), etc., or a combination thereof. The memory 512 of the computing device 510 is configured to store computer program code, such as respective programs, computer / processor executable instructions, macros or applets, etc., or parts thereof. When such computer program code is executed by the processor 511, it enables the computing device 510 to operate according to an exemplary embodiment of the present invention. The memory 512 can be represented by a RAM (Random Access Memory), a ROM (Read Only Memory), a hard disk, a secondary storage device, etc., or a combination of two or more of these. The interface 513 of the computing device 510 is configured to interface with another computing device and / or the user of the computing device 510. That is, the interface 513 can represent a communication interface (including, for example, a modem, an antenna, a transmitter, a receiver, a transceiver, etc.) and / or a user interface (a display, a touch screen, a keyboard, a mouse, a signal light, a loudspeaker, etc.).
[0061] According to an exemplary embodiment of the present invention, the electronic file to be analyzed for malware can be any electronic file, and in particular, includes any electronic file containing an executable / executable portion, such as any kind of application file. Exemplary embodiments of the present invention include, for example, Android (registered trademark) Application Package (APK), Portable Executable (PE), Microsoft Windows (registered trademark) Installer (MSI) files, or application software or middleware can be distributed and / or installed on a computer.
[0062] The data collected using the solution of the present invention can be stored in a database or a similar model for information storage for further use.
[0063] In one embodiment, when a malicious file, application, or activity is detected, further actions can be taken to secure the computer or computer network. Also, actions can be taken by changing the settings of the computer or other network nodes. Changing the settings can prevent, for example, one or more nodes (which can be computers or other devices) from being switched off to save information in the RAM, can switch on one or more nodes so that the firewall blocks the attacker immediately, can slow down or block the network connectivity of one or more of the network nodes, can place the suspicious file in removal or isolation, can collect logs from the network nodes, can execute a set of commands on the network nodes, can warn the users of one or more nodes that a threat or anomaly has been detected and their workstations are under investigation, and / or can send system updates or software patches from the security backend to the nodes. In one embodiment of the present invention, one or more of these operations can be automatically initiated.
[0064] In one embodiment, the threat detection system of the present invention can be a large language model (LLM) agent. A large language model agent is an artificial intelligence system that utilizes a large language model (LLM) as its core computing engine and demonstrates capabilities beyond text generation, such as conducting conversations, completing tasks, making inferences, and demonstrating autonomous behavior.
[0065] As described above, the present invention has been explained with reference to preferred embodiments, but it should be understood that these embodiments are merely illustrative and the claims are not limited to these embodiments. Those skilled in the art will be able to make modifications and alternatives in consideration of the disclosure that is considered to be within the scope of the appended claims. Each feature disclosed or exemplified in this specification can be incorporated into the present invention either alone or in any suitable combination with any other feature disclosed or exemplified in this specification. The lists and groups of examples provided in the above description are not exhaustive unless otherwise specifically stated.
Claims
1. A method for threat detection in a threat detection system comprising at least one endpoint (101, 205a - 205h) and / or at least one server (102, 202), the method comprising: The method comprises: utilizing, by the threat detection system, at least two threat detection elements for detecting cyber threats; including; the threat detection elements are connected to a threat detection controller that controls threat detection by assigning tasks and / or giving instructions to the threat detection elements and by following the output of the threat detection elements; the threat detection controller utilizes at least one large language model when outputting data to the threat detection elements and / or when processing information received from the threat detection elements; Method.
2. The method according to claim 1, wherein the threat detection controller is arranged in a server (102, 202), or a service such as a backend service (202) and / or a cloud service, and / or an endpoint (101, 205a - 205h).
3. Inputs to the threat detection system such as decision-making logic, analysis of executable files, incident updates and decisions, evaluated reputations and / or risk scores, and / or inputs to elements of the threat detection system are received as natural language, structure, numbers, categories or combinations thereof, the threat detection controller converts the received information into a format required by the threat detection elements or the threat detection system by means of the at least one large language model; The method according to claim 1 or claim 2.
4. The at least two threat detection elements comprise: at least one of service elements such as a parser, an antivirus engine, for example, an EDR and / or MDR rule-based engine, an EDR and / or MDR AI-based engine, etc.; external data sources such as a domain search database, a virus database, or an information source; internal data sources such as a threat intelligence information database, an incident information database, an asset information database, etc.; The method according to any one of claims 1 to 3.
5. The threat detection element and / or the task given to the threat detection element relate to machine translation, sentiment analysis, grammar checking, and / or identifying synonyms and semantically similar statements, and the method according to any one of claims 1 to 4.
6. Deep analysis of executable files, incident updates and incident determination, decision-making logic-related information such as evaluated reputation and / or risk score, etc. are received as inputs to the threat detection controller, and the method according to any one of claims 1 to 5.
7. The method further includes summarizing, by the at least one large language model, the output from the threat detection system and / or the threat detection controller, such as decisions and / or reasons for decisions, and the method according to any one of claims 1 to 6.
8. The at least one large language model is a generative model and / or a model for natural language processing (NLP) tasks such as text generation, language translation, sentiment analysis, text summarization, and / or question answering, and the method according to any one of claims 1 to 7.
9. The at least one endpoint (101, 205a - 205h) collects threat detection-related data from the endpoint by a security agent module installed on the endpoint (101, 205a - 205h), transmits the collected threat detection-related data to the threat detection system, for example, the server (102, 202) of the threat detection system, for further analysis, the threat detection controller controls the analysis of the collected threat detection-related data, and the method according to any one of claims 1 to 8.
10. At least one of the threat detection elements performs processing related to prioritizing identified threats and / or potential actions for improving the security posture, and / or the output of the threat detection element is related to at least one of identified vulnerabilities, identified critical assets, the priority of identified vulnerabilities, the priority of critical assets, the risk value for the business of identified assets and / or vulnerabilities, attack path mapping, visualization, and reporting artifacts, and the method according to any one of claims 1 to 9.
11. A server of a threat detection system, comprising at least one endpoint (101, 205a - 205h) and at least one server (102, 202), wherein the server (102, 202) comprises at least one or more processors, and the processor is configured to utilize at least two threat detection elements for detecting cyber threats, and is configured such that, the server (102, 202) comprises a threat detection controller, and the threat detection elements are connected to the threat detection controller configured to control threat detection by assigning tasks and / or giving instructions to the threat detection elements and by following the outputs of the threat detection elements, wherein the threat detection controller utilizes at least one large language model when outputting data to the threat detection elements and / or when processing inputs from the threat detection elements, a server.
12. A threat detection system comprising at least one endpoint (101, 205a - 205h) and / or at least one server, wherein the server is the server (102, 202) according to Claim 11.
13. A threat detection system configured to execute the method according to any one of Claims 2 to 10.
14. A computer program comprising instructions which, when executed by a computer, cause the computer to execute the method according to any one of Claims 1 to 10.
15. A computer-readable medium comprising the computer program according to Claim 14.