System and methods for hybrid multi-lingual generative ai cybersecurity training platform and related methods
The hybrid multi-lingual generative AI cybersecurity training platform addresses the limitations of existing systems by providing a realistic and adaptive learning environment with AI-driven feedback and simulation, enhancing user preparedness for complex cyber threats.
Patent Information
- Application Number
- PCT/US2025/024609
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-12
- Filing Date
- 2025-04-14
- Publication Date
- 2025-10-16
AI Technical Summary
Current cybersecurity training systems lack the ability to provide realistic and dynamic training environments, fail to offer timely and actionable feedback, and do not integrate advanced analytics or adaptive learning techniques, leading to inadequate preparedness among trainees for sophisticated cyber threats.
A hybrid multi-lingual generative AI cybersecurity training platform that includes an AI Avatar Instructor, a Learning Management System, a Scoring System, Data Visualization, Simulation software technology, and encryption technology, simulating cybersecurity threats and providing a realistic learning environment tailored to individual user needs.
Enhances the effectiveness and adaptability of cybersecurity training by offering personalized, interactive, and adaptive learning experiences that simulate real-world scenarios, provide timely feedback, and integrate advanced analytics, thereby improving user preparedness for complex cyber threats.
Smart Images

Figure US2025024609_16102025_PF_FP_ABST
Abstract
Description
[0001] System and Methods for Hybrid Multi-lingual Generative Al Cybersecurity Training Platform and Related Methods
[0002] FIELD OF DISCLOSURE
[0003] The present disclosure generally relates to a field of data processing. More specifically, the present disclosure related to systems and methods of provisioning a cybersecurity training.
[0004] BACKGROUND
[0005] The field of cybersecurity training is paramount in today's digital age, where protecting critical infrastructure has become a cornerstone of national security and economic stability. As organizations increasingly rely on interconnected systems to manage operations, ensuring the readiness of cybersecurity professionals to safeguard these assets becomes a matter of utmost importance. Cybersecurity training serves as a vital tool in this endeavor, equipping individuals with the knowledge and skills necessary to identify, mitigate, and respond to cyber threats effectively.
[0006] The objective of enhancing the effectiveness and adaptability of cybersecurity training systems is highly desirable in this field. With the increasing sophistication of cyberattacks and the growing complexity of critical infrastructure, there is a pressing need for tools that can provide comprehensive, engaging, and personalized learning experiences. Current training systems may struggle to meet these demands, often falling short in terms of interactivity, scalability, and relevance.
[0007] One of the key challenges lies in the limited ability of existing systems to offer realistic and dynamic training environments. Traditional cybersecurity training may lack the depth and nuance required to mirror real-world scenarios, leading to inadequate preparedness among trainees. Additionally, many systems fail to provide timely and actionable feedback, limiting their effectiveness in helping users improve their skills. Furthermore, the inability of these systems to simulate advanced cyber threats and provide insights into potential vulnerabilities can leave professionals unprepared for sophisticated attacks.
[0008] Moreover, existing solutions often do not integrate advanced analytics or adaptive learning techniques, which could enhance training outcomes by providing data-driven insights and tailoring content to individual needs. The lack of real-time response simulation and historical analysis in threat scenarios further exacerbates these limitations, as trainees may not gain a complete understanding of how to respond effectively in high- stakes situations.
[0009] Therefore, there is a need for improved systems and methods of provisioning a cybersecurity training, that can overcome one or more of the preceding problems.
[0010] SUMMARY OF DISCLOSURE
[0011] This summary is provided to introduce a selection of concepts in a simplified form, that are further described below in the Detailed Description. This summary is not intended to identify key features or essential features of the claimed subject matter. Nor is this summary intended to be used to limit the claimed subject matter’s scope.
[0012] The present disclosure provides a method of provisioning a cybersecurity training. Further, the method may include receiving, using a communication device, a user data from a user device associated with a user. Further, the user data corresponds to a cybersecurity learning preference of the user. Further, the method may include determining, using a processing device, a threat data. Further, the threat data corresponds to a cybersecurity threat. Further, the method may include generating, using the processing device, a simulated training data based on each of the user data and the threat data. Further, the simulated training data corresponds to a simulated environment representing a simulation of one or more of the cybersecurity threat and a computer system. Further, the method may include transmitting, using the communication device, the simulated training data to the user device. Further, the user device may be configured to present the simulated training data on a user presentation device comprised in the user device. Further, the training data facilitates the cybersecurity training based on a user interaction with the simulated environment. Further, the method may include receiving, using the communication device, an interaction data from the user device. Further, the interaction data corresponds to the user interaction. Further, the method may include analyzing, using the processing device, the interaction data. Further, the method may include generating, using the processing device, a training result data based on the analyzing. Further, the training result data corresponds to a cybersecurity training result of the user.
[0013] The present disclosure provides a system of provisioning a cybersecurity training. Further, the system may include a communication device. Further, the communication device may be configured for receiving a user data from a user device associated with a user. Further, the user data corresponds to a cybersecurity learning preference of the user. Further, the communication device may be configured for transmitting a simulated training data to the user device. Further, the user device may be configured to present the simulated training data on a user presentation device comprised in the user device. Further, the training data facilitates the cybersecurity training based on a user interaction with the simulated environment. Further, the communication device may be configured for receiving an interaction data from the user device. Further, the interaction data corresponds to the user interaction. Further, the system may include a processing device. Further, the processing device may be configured for determining a threat data. Further, the threat data corresponds to a cybersecurity threat. Further, the processing device may be configured for generating the simulated training data based on each of the user data and the threat data. Further, the simulated training data corresponds to a simulated environment representing a simulation of one or more of the cybersecurity threat and a computer system. Further, the processing device may be configured for analyzing the interaction data. Further, the processing device may be configured for generating a training result data based on the analyzing. Further, the training result data corresponds to a cybersecurity training result of the user. Both the foregoing summary and the following detailed description provide examples and are explanatory only. Accordingly, the foregoing summary and the following detailed description should not be considered to be restrictive. Further, features or variations may be provided in addition to those set forth herein. For example, embodiments may be directed to various feature combinations and sub-combinations described in the detailed description.
[0014] BRIEF DESCRIPTIONS OF DRAWINGS
[0015] The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate various embodiments of the present disclosure. The drawings contain representations of various trademarks and copyrights owned by the Applicants. In addition, the drawings may contain other marks owned by third parties and are being used for illustrative purposes only. All rights to various trademarks and copyrights represented herein, except those belonging to their respective owners, are vested in and the property of the applicants. The applicants retain and reserve all rights in their trademarks and copyrights included herein, and grant permission to reproduce the material only in connection with reproduction of the granted patent and for no other purpose.
[0016] Furthermore, the drawings may contain text or captions that may explain certain embodiments of the present disclosure. This text is included for illustrative, non-limiting, explanatory purposes of certain embodiments detailed in the present disclosure.
[0017] Fig. 1 is an illustration of an online platform 100 consistent with various embodiments of the present disclosure.
[0018] Fig. 2 is a block diagram of a computing device 200 for implementing the methods disclosed herein, in accordance with some embodiments.
[0019] Fig. 3A illustrates a flowchart of a method 300 of provisioning a cybersecurity training, in accordance with some embodiments. Fig. 3B illustrates a continuation of the flowchart of the method 300 of provisioning a cybersecurity training, in accordance with some embodiments.
[0020] Fig. 4 illustrates a flowchart of a method 400 of provisioning a cybersecurity training including generating, using the processing device 804, a module data, in accordance with some embodiments.
[0021] Fig. 5 illustrates a flowchart of a method 500 of provisioning a cybersecurity training including generating, using the processing device 804, a response data, in accordance with some embodiments.
[0022] Fig. 6 illustrates a flowchart of a method 600 of provisioning a cybersecurity training including generating, using the processing device 804, an avatar data, in accordance with some embodiments.
[0023] Fig. 7 illustrates a flowchart of a method 700 of provisioning a cybersecurity training including generating, using the processing device 804, a user report data, in accordance with some embodiments.
[0024] Fig. 8 illustrates a block diagram of a system 800 of provisioning a cybersecurity training, in accordance with some embodiments.
[0025] Fig. 9 illustrates a flowchart of a method 900 of provisioning a cybersecurity training including encrypting, using the processing device 804, the training result data to obtain an encrypted training result data, in accordance with some embodiments.
[0026] Fig. 10 illustrates a flowchart of a method 1000 of provisioning a cybersecurity training including analyzing, using the processing device 804, the simulation data, in accordance with some embodiments.
[0027] Fig. 11 A illustrates a flowchart of a cybersecurity training, in accordance with some embodiments.
[0028] Fig. 1 IB illustrates a continuation of the flowchart of the cybersecurity training, in accordance with some embodiments. DETAILED DESCRIPTION OF DISCLOSURE
[0029] As a preliminary matter, it will readily be understood by one having ordinary skill in the relevant art that the present disclosure has broad utility and application. As should be understood, any embodiment may incorporate only one or a plurality of the abovedisclosed aspects of the disclosure and may further incorporate only one or a plurality of the above-disclosed features. Furthermore, any embodiment discussed and identified as being “preferred” is considered to be part of a best mode contemplated for carrying out the embodiments of the present disclosure. Other embodiments also may be discussed for additional illustrative purposes in providing a full and enabling disclosure. Moreover, many embodiments, such as adaptations, variations, modifications, and equivalent arrangements, will be implicitly disclosed by the embodiments described herein and fall within the scope of the present disclosure.
[0030] Accordingly, while embodiments are described herein in detail in relation to one or more embodiments, it is to be understood that this disclosure is illustrative and exemplary of the present disclosure, and are made merely for the purposes of providing a full and enabling disclosure. The detailed disclosure herein of one or more embodiments is not intended, nor is to be construed, to limit the scope of patent protection afforded in any claim of a patent issuing here from, which scope is to be defined by the claims and the equivalents thereof. It is not intended that the scope of patent protection be defined by reading into any claim limitation found herein and / or issuing here from that does not explicitly appear in the claim itself.
[0031] Thus, for example, any sequence(s) and / or temporal order of steps of various processes or methods that are described herein are illustrative and not restrictive. Accordingly, it should be understood that, although steps of various processes or methods may be shown and described as being in a sequence or temporal order, the steps of any such processes or methods are not limited to being carried out in any particular sequence or order, absent an indication otherwise. Indeed, the steps in such processes or methods generally may be carried out in various different sequences and orders while still falling within the scope of the present disclosure. Accordingly, it is intended that the scope of patent protection is to be defined by the issued claim(s) rather than the description set forth herein.
[0032] Additionally, it is important to note that each term used herein refers to that which an ordinary artisan would understand such term to mean based on the contextual use of such term herein. To the extent that the meaning of a term used herein — as understood by the ordinary artisan based on the contextual use of such term — differs in any way from any particular dictionary definition of such term, it is intended that the meaning of the term as understood by the ordinary artisan should prevail.
[0033] Furthermore, it is important to note that, as used herein, “a” and “an” each generally denotes “at least one,” but does not exclude a plurality unless the contextual use dictates otherwise. When used herein to join a list of items, “or” denotes “at least one of the items,” but does not exclude a plurality of items of the list. Finally, when used herein to join a list of items, “and” denotes “all of the items of the list.”
[0034] The following detailed description refers to the accompanying drawings. Wherever possible, the same reference numbers are used in the drawings and the following description to refer to the same or similar elements. While many embodiments of the disclosure may be described, modifications, adaptations, and other implementations are possible. For example, substitutions, additions, or modifications may be made to the elements illustrated in the drawings, and the methods described herein may be modified by substituting, reordering, or adding stages to the disclosed methods. Accordingly, the following detailed description does not limit the disclosure. Instead, the proper scope of the disclosure is defined by the claims found herein and / or issuing here from. The present disclosure contains headers. It should be understood that these headers are used as references and are not to be construed as limiting upon the subjected matter disclosed under the header.
[0035] The present disclosure includes many aspects and features. Moreover, while many aspects and features relate to, and are described in the context of the disclosed use cases, embodiments of the present disclosure are not limited to use only in this context. In general, the method disclosed herein may be performed by one or more computing devices. For example, in some embodiments, the method may be performed by a server computer in communication with one or more client devices over a communication network such as, for example, the Internet. In some other embodiments, the method may be performed by one or more of at least one server computer, at least one client device, at least one network device, at least one sensor and at least one actuator. Examples of the one or more client devices and / or the server computer may include, a desktop computer, a laptop computer, a tablet computer, a personal digital assistant, a portable electronic device, a wearable computer, a smart phone, an Internet of Things (loT) device, a smart electrical appliance, a video game console, a rack server, a super-computer, a mainframe computer, mini -computer, micro-computer, a storage server, an application server (e.g. a mail server, a web server, a real-time communication server, an FTP server, a virtual server, a proxy server, a DNS server etc.), a quantum computer, and so on. Further, one or more client devices and / or the server computer may be configured for executing a software application such as, for example, but not limited to, an operating system (e.g. Windows, Mac OS, Unix, Linux, Android, etc.) in order to provide a user interface (e.g. GUI, touch-screen based interface, voice based interface, gesture based interface etc.) for use by the one or more users and / or a network interface for communicating with other devices over a communication network. Accordingly, the server computer may include a processing device configured for performing data processing tasks such as, for example, but not limited to, analyzing, identifying, determining, generating, transforming, calculating, computing, compressing, decompressing, encrypting, decrypting, scrambling, splitting, merging, interpolating, extrapolating, redacting, anonymizing, encoding and decoding. Further, the server computer may include a communication device configured for communicating with one or more external devices. The one or more external devices may include, for example, but are not limited to, a client device, a third party database, public database, a private database and so on. Further, the communication device may be configured for communicating with the one or more external devices over one or more communication channels. Further, the one or more communication channels may include a wireless communication channel and / or a wired communication channel. Accordingly, the communication device may be configured for performing one or more of transmitting and receiving of information in electronic form. Further, the server computer may include a storage device configured for performing data storage and / or data retrieval operations. In general, the storage device may be configured for providing reliable storage of digital information. Accordingly, in some embodiments, the storage device may be based on technologies such as, but not limited to, data compression, data backup, data redundancy, deduplication, error correction, data finger-printing, role based access control, and so on.
[0036] Further, one or more steps of the method disclosed herein may be initiated, maintained, controlled and / or terminated based on a control input received from one or more devices operated by one or more users such as, for example, but not limited to, an end user, an admin, a service provider, a service consumer, an agent, a broker and a representative thereof. Further, the user as defined herein may refer to a human, an animal or an artificially intelligent being in any state of existence, unless stated otherwise, elsewhere in the present disclosure. Further, in some embodiments, the one or more users may be required to successfully perform authentication in order for the control input to be effective. In general, a user of the one or more users may perform authentication based on the possession of a secret human readable secret data (e.g. username, password, passphrase, PIN, secret question, secret answer etc.) and / or possession of a machine readable secret data (e.g. encryption key, decryption key, bar codes, etc.) and / or or possession of one or more embodied characteristics unique to the user (e.g. biometric variables such as, but not limited to, fingerprint, palm-print, voice characteristics, behavioral characteristics, facial features, iris pattern, heart rate variability, evoked potentials, brain waves, and so on) and / or possession of a unique device (e.g. a device with a unique physical and / or chemical and / or biological characteristic, a hardware device with a unique serial number, a network device with a unique IP / MAC address, a telephone with a unique phone number, a smartcard with an authentication token stored thereupon, etc.). Accordingly, the one or more steps of the method may include communicating (e.g. transmitting and / or receiving) with one or more sensor devices and / or one or more actuators in order to perform authentication. For example, the one or more steps may include receiving, using the communication device, the secret human readable data from an input device such as, for example, a keyboard, a keypad, a touch-screen, a microphone, a camera and so on. Likewise, the one or more steps may include receiving, using the communication device, the one or more embodied characteristics from one or more biometric sensors.
[0037] Further, one or more steps of the method may be automatically initiated, maintained and / or terminated based on one or more predefined conditions. In an instance, the one or more predefined conditions may be based on one or more contextual variables. In general, the one or more contextual variables may represent a condition relevant to the performance of the one or more steps of the method. The one or more contextual variables may include, for example, but are not limited to, location, time, identity of a user associated with a device (e.g. the server computer, a client device etc.) corresponding to the performance of the one or more steps, environmental variables (e.g. temperature, humidity, pressure, wind speed, lighting, sound, etc.) associated with a device corresponding to the performance of the one or more steps, physical state and / or physiological state and / or psychological state of the user, physical state (e.g. motion, direction of motion, orientation, speed, velocity, acceleration, trajectory, etc.) of the device corresponding to the performance of the one or more steps and / or semantic content of data associated with the one or more users. Accordingly, the one or more steps may include communicating with one or more sensors and / or one or more actuators associated with the one or more contextual variables. For example, the one or more sensors may include, but are not limited to, a timing device (e.g. a real-time clock), a location sensor (e.g. a GPS receiver, a GLONASS receiver, an indoor location sensor etc.), a biometric sensor (e.g. a fingerprint sensor), an environmental variable sensor (e.g. temperature sensor, humidity sensor, pressure sensor, etc.) and a device state sensor (e.g. a power sensor, a voltage / current sensor, a switch-state sensor, a usage sensor, etc. associated with the device corresponding to performance of the or more steps).
[0038] Further, the one or more steps of the method may be performed one or more number of times. Additionally, the one or more steps may be performed in any order other than as exemplarily disclosed herein, unless explicitly stated otherwise, elsewhere in the present disclosure. Further, two or more steps of the one or more steps may, in some embodiments, be simultaneously performed, at least in part. Further, in some embodiments, there may be one or more time gaps between performance of any two steps of the one or more steps.
[0039] Further, in some embodiments, the one or more predefined conditions may be specified by the one or more users. Accordingly, the one or more steps may include receiving, using the communication device, the one or more predefined conditions from one or more and devices operated by the one or more users. Further, the one or more predefined conditions may be stored in the storage device. Alternatively, and / or additionally, in some embodiments, the one or more predefined conditions may be automatically determined, using the processing device, based on historical data corresponding to performance of the one or more steps. For example, the historical data may be collected, using the storage device, from a plurality of instances of performance of the method. Such historical data may include performance actions (e.g. initiating, maintaining, interrupting, terminating, etc.) of the one or more steps and / or the one or more contextual variables associated therewith. Further, machine learning may be performed on the historical data in order to determine the one or more predefined conditions. For instance, machine learning on the historical data may determine a correlation between one or more contextual variables and performance of the one or more steps of the method. Accordingly, the one or more predefined conditions may be generated, using the processing device, based on the correlation.
[0040] Further, one or more steps of the method may be performed at one or more spatial locations. For instance, the method may be performed by a plurality of devices interconnected through a communication network. Accordingly, in an example, one or more steps of the method may be performed by a server computer. Similarly, one or more steps of the method may be performed by a client computer. Likewise, one or more steps of the method may be performed by an intermediate entity such as, for example, a proxy server. For instance, one or more steps of the method may be performed in a distributed fashion across the plurality of devices in order to meet one or more objectives. For example, one objective may be to provide load balancing between two or more devices. Another objective may be to restrict a location of one or more of an input data, an output data and any intermediate data there between corresponding to one or more steps of the method. For example, in a client-server environment, sensitive data corresponding to a user may not be allowed to be transmitted to the server computer. Accordingly, one or more steps of the method operating on the sensitive data and / or a derivative thereof may be performed at the client device.
[0041] Overview:
[0042] The present disclosure describes system and methods for hybrid multi-lingual generative Al cybersecurity training platform and related methods
[0043] Further, the present disclosure describes a computer-implemented method and system for cybersecurity training. The method includes receiving input from a user interacting with an Al-based Cybersecurity Training Platform, providing interactive learning support to the user through an Al Avatar Instructor, and utilizing various Al capabilities to enhance the platform. The system includes a Cybersecurity Training Framework and solution, a Learning Management System, a Scoring System, a Data Visualization solution, a Simulation software technology, and a development application. The method and system also involve simulating cybersecurity threats, providing a realistic learning environment, securing the platform, storing data, collecting data from the internet, providing reference material, ensuring compliance, enabling the creation of learning content, providing a central access point, monitoring the platform, and managing the lab environment. The system pertains to the field of artificial intelligence and cybersecurity, specifically focusing on a training platform that integrates various technologies for critical infrastructure protection.
[0044] In accordance with embodiments, a computer-implemented method is provided for cybersecurity training. The method involves receiving input from a user interacting with an Al-based Cybersecurity Training Platform and providing interactive learning support to the user through an Al Avatar Instructor. The platform utilizes various Al capabilities to enhance its functionality. The user is monitored and assisted through a Cybersecurity Training Framework and solution. The learning process is managed through a Learning Management System (LMS) and the user's performance is evaluated through a Scoring System. Data is presented in a visual format through a Data Visualization solution and a simulated learning environment is provided through Simulation software technology. Cybersecurity threats are simulated through a penetration system and a realistic learning environment is provided through hardware simulation devices and system software application simulation. The platform is secured through encryption technology and data is stored in databases and Vector Databases. Cybersecurity threats are simulated through Scanning and Penetration solutions and data is collected from the internet through a WEB scraper and WebCrawler. Reference material is provided through research documents and compliance is ensured through international standards. Learning content is created through a course content creation-development platform and a central access point is provided through a Web Application platform. The platform is monitored through a monitoring server and the lab environment is managed through a lab environment management system. The user's performance is evaluated through an Al agent and score bot agents.
[0045] In the modem digital age, cybersecurity has become a paramount concern, especially in the context of critical infrastructure protection. Critical infrastructure refers to the physical and cyber systems and assets so vital to the United States that their incapacity or destruction would have a debilitating impact on national security, economic security, public health, or safety. These infrastructures are increasingly becoming targets of sophisticated cyber-attacks, which can lead to severe consequences.
[0046] The complexity and sophistication of these attacks necessitate advanced training for cybersecurity professionals. Traditional training methods often fall short in providing the necessary skills and knowledge to effectively counter these threats. They often lack the ability to simulate real-world scenarios and do not provide continuous, repetitive training that is necessary to build cybersecurity cognitive muscle memory.
[0047] Moreover, the rapid evolution of cyber threats requires cybersecurity professionals to stay current on emerging threats, defensive tactics, techniques, processes, and technologies. However, keeping up with the pace of change in the cybersecurity landscape is a significant challenge. Furthermore, the effectiveness of cybersecurity training is often difficult to measure. Traditional methods of assessment may not accurately reflect a trainee's ability to respond to real-world cyber threats. In addition, the increasing diversity of the workforce and the global nature of cyber threats necessitate a training platform that is inclusive and can cater to a multi-lingual, multi-racial, and multi-gender audience.
[0048] In accordance with other embodiments, a system is provided for cybersecurity training. The system comprises an Al-based Cybersecurity Training Platform, an Al Avatar Instructor, a plurality of Al capabilities, a Cybersecurity Training Framework and solution, a Learning Management System (LMS), a Scoring System, a Data Visualization solution, a Simulation software technology, a development application, a Penetration system, hardware simulation devices and system software application simulation, encryption technology, databases and Vector Databases, Scanning and Penetration solutions, a WEB scraper and WebCrawler, research documents, international standards, a course content creation-development platform, a Web Application platform, a monitoring server, a lab environment management system, and an Al agent and score bot agents.
[0049] Further, the method includes a first step of a user engaging with a cybersecurity training platform. This interaction is facilitated through input methods that could include keyboard, mouse, touch screen, or voice commands. The purpose of this engagement is to navigate the training modules, access learning materials, and participate in simulated cybersecurity scenarios. The actions within this step include the user providing input and the platform responding to facilitate the training experience. The user, who may be a student learner or a cybersecurity professional, and the cybersecurity training platform, which comprises both hardware and software components, are the primary participants in this step. The platform operates on a hybrid model, allowing access through both cloud services and on premise installations to ensure flexibility and scalability.
[0050] Further, the first step includes an integration of the platform with various technologies. These technologies include multimodal large language models, a Parametric efficient fine-tuning system application, Al agents, machine learning models, deep learning models, natural language processing, natural language understanding, and neural networks. The integration of these technologies is intended to enhance the platform's capabilities, providing an interactive learning experience that can simulate cybersecurity threats, offer guidance, and assess performance. The platform is designed to accommodate users with different linguistic backgrounds and learning preferences, utilizing a multi-racial and multi-gender human avatar instructor Chabot for interactive support.
[0051] In summary, a first step defines the user's engagement with the cybersecurity training platform and the platform's integration with a range of technologies to provide a dynamic cybersecurity training experience.
[0052] Further, the method includes a second step involves an Al Avatar Instructor providing interactive learning support to users. This Al Avatar Instructor is a Chabot with a human avatar that can interact with users, offering guidance and instruction tailored to their learning needs. The Al Avatar Instructor has the capability to analyze user responses, provide feedback, and guide learners through cybersecurity scenarios, with the aim of enhancing the learner's cognitive abilities related to cybersecurity knowledge retention, skill acquisition, and incident response tasks.
[0053] Further, the second step focuses on the Al Avatar Instructor's role in improving cognitive aspects of learning, such as knowledge, skills, and retention abilities. The Al Avatar Instructor uses its understanding of the learner's performance to offer personalized sessions for revision and practice, reinforcing knowledge and skills pertinent to cybersecurity incident response. This sub-step is designed to build the learner's proficiency in handling cybersecurity threats.
[0054] The Al Avatar Instructor in the second step assesses learner performance, provides personalized feedback, and adapts its instructional approach to meet the unique needs of each learner. These actions are driven by the objective to enhance the learner's ability to protect and secure infrastructure from cyber threats. The Al technologies that enable the instructor's capabilities include natural language processing and understanding, which allow the Al to comprehend and respond to user queries effectively.
[0055] Further, the method encompasses the integration of various technologies to enhance the capabilities of the cybersecurity training platform. These technologies include language models, system applications, Al agents, machine learning models, deep learning models, natural language processing, natural language understanding, and neural networks. Language models are algorithms capable of predicting the likelihood of a sequence of words, which is essential for generating human-like text for Chabot interactions and content creation within the training platform. System applications refer to software components that perform specific functions, such as optimizing the performance of Al models.
[0056] Al agents are autonomous programs designed to perform tasks on behalf of users, guiding them through training modules or providing feedback. Machine learning models are algorithms that learn from data to make predictions or decisions, adapting the training content to the user's progress. Deep learning models, a subset of machine learning models, use networks with multiple layers to analyze complex patterns in data, which can be applied to image and voice recognition tasks within the platform.
[0057] Natural language processing enables the platform to understand and process user queries and responses, while natural language understanding, a branch of natural language processing, deals with machine reading comprehension, allowing the platform to grasp the context and intent behind user communication. Neural networks, computing systems inspired by biological neural networks, are utilized to recognize patterns and interpret sensory data. Together, these technologies provide a foundation for the platform to deliver an interactive and adaptive learning experience. They enable the platform to process user inputs, generate relevant content, and offer personalized guidance and support, simulating realistic cybersecurity scenarios and providing effective training.
[0058] Further, the method includes a framework that oversees and supports a user's progress throughout cybersecurity training. This framework includes guidelines, best practices, and monitoring tools that track interactions with the training platform. The framework and monitoring solutions evaluate the user's engagement with the training materials, provide feedback, and may adjust the training content or difficulty to better suit the learning needs. The purpose is to ensure effective learning and retention of necessary cybersecurity knowledge and skills. Further, the method includes a specific framework that targets the development of defensive knowledge and skills required to protect infrastructure. This framework, along with the solutions, monitors the user's progress, providing repetitive and continuous training opportunities to build and maintain proficiency in cybersecurity defense. This is necessary for staying updated with emerging threats and learning new defensive tactics, techniques, processes, and technologies. The goal is to build the user's ability to effectively respond to cybersecurity incidents.
[0059] These actions are manifested through the integrated technologies of the training platform, which likely includes tracking software, adaptive learning algorithms, and performance analytics. The framework may use metrics such as completion rates, accuracy, response times, and behavioral data to assess performance and adapt the training. The continuous nature of the training ensures that the user's skills remain sharp and updated, which is essential for the field of cybersecurity.
[0060] Further, the method includes a Learning Management System (LMS) that manages the learning process. The LMS is a software application or platform that performs several functions:
[0061] • Administering: It organizes and provides access to cybersecurity training courses and materials.
[0062] • Documenting: It records user progress and performance data.
[0063] • Tracking: It monitors user engagement, course completion rates, and other metrics.
[0064] • Reporting: It generates reports on user progress, scores, and analytics.
[0065] • Automating: It may automate tasks such as enrollment, reminders, and assessment grading.
[0066] • Delivering: It serves as a portal for users to access and engage with training content.
[0067] The LMS is used to provide a structured environment for learning and can handle data and interactions across multiple users. It manages the complexity of training programs, especially when dealing with cybersecurity training for infrastructure protection, which requires organization and tracking due to the sensitive nature of the content and the need for thorough documentation of user competencies. The LMS is likely integrated with other components of the cybersecurity training platform, such as Al capabilities, scoring systems, and simulation technologies, to provide a comprehensive learning experience. It may also interface with cybersecurity frameworks and solutions to ensure that the training aligns with current industry standards and practices. Further, the method involves the LMS functioning as the backbone of the learning process within the cybersecurity training platform, ensuring that educational content is delivered effectively, user progress is monitored, and the overall management of the training program is maintained efficiently.
[0068] Further, the method includes a Scoring System that evaluates user performance within the Al-based Cybersecurity Training Platform. This system operates by assessing various parameters and metrics that reflect the user's interactions with the platform. These parameters might include the accuracy of the user's responses, the time taken to complete tasks, and the effectiveness in identifying and mitigating threats. Further, the method involves specifies that the Scoring System comprises an Al agent and score bot agents. These components are programmed to monitor user interactions, log decisions, and calculate scores based on predefined criteria. The criteria for scoring are likely to encompass the user's proficiency in utilizing defensive cybersecurity solutions such as Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Intrusion Detection Systems (IDS), Data Loss Prevention (DLP), Next- Generation Antivirus (Next-Gen AV), Access Control systems, Firewalls, and Network Switches.
[0069] During virtual Blue Team Defensive Critical Infrastructure Cybersecurity labs and exercises, the Al agent and score bot agents analyze the user's actions, comparing them to established strategies for mitigating cyber threats. The scoring algorithm considers the severity of the simulated threats, the user's response time, the suitability of the defense mechanisms selected, and the impact of the user's actions on the security of the simulated infrastructure. In essence, a system within the cybersecurity training platform uses AL driven components to assess and score a user's performance in simulated environments, providing feedback on their preparedness to handle cybersecurity challenges. Further, the method includes a Data Visualization solution that presents data in a visual format. This step is part of a training platform that processes cybersecurity data and transforms it into graphical representations such as charts, graphs, heat maps, or other visual formats. The software responsible for this step takes input data, which could include information about cybersecurity incidents, network traffic, or other relevant metrics, and applies algorithms to generate visual output. The visual output is designed to highlight patterns, correlations, and trends within the data. The purpose of this step is to aid users in understanding complex datasets and to facilitate quicker decision-making. For example, visualizing the frequency and types of network attacks can help users identify areas of vulnerability within a network and prioritize their response efforts. Additionally, this step can serve an educational function by helping learners grasp cybersecurity principles through interactive content.
[0070] The effectiveness of the Data Visualization solution can be assessed by its accuracy in representing the data, the clarity of the visual output, and the processing speed at which it displays the information. The solution must be capable of managing large volumes of data and updating visualizations promptly to reflect the current state of the network or the progression of a simulated cyberattack within the training environment. In summary, this step involves converting cybersecurity data into visual formats that are easily interpretable, enhancing user understanding and ability to respond to cyber threats. This step provides a user-friendly interface for data analysis and contributes to the educational goals of the platform.
[0071] Further, the method includes the deployment of simulation software technology to create a simulated learning environment. This step is key for generating virtual scenarios that mirror cybersecurity threats and challenges, allowing users to engage in practice without the risks associated with live environments. The action in this step is the provision of a simulated learning environment, which is achieved through the use of 3D Digital Twin Simulation software technology. This technology constructs a digital replica of physical infrastructure systems, enabling users to interact with these systems as though they were actual systems. The simulation software is engineered to replicate the behavior of systems, including their responses to user actions and simulated cyberattacks. It accomplishes this by employing algorithms and models that represent the physical characteristics and operational logic of the systems being simulated. The computing hardware required to run these simulations must have sufficient processing power and memory to support the software's functions.
[0072] Users interact with the simulation via an interface that permits them to perform actions such as configuring system settings, deploying defensive measures, and responding to simulated cyberattacks. The objective of these interactions is to train users in the skills and knowledge necessary to protect and secure infrastructure systems from cyber threats. The simulation software technology provides a controlled environment for users to develop their cybersecurity skills. By practicing in a simulated environment, users can learn from errors, comprehend the outcomes of different actions, and enhance their decision-making abilities without causing harm to actual systems.
[0073] Further, the method focuses on a development application that facilitates the creation of learning content within a cybersecurity training platform. This development application is characterized by Low Code and No Code features, which streamline the process of generating educational materials. Users, who may range from content developers to subject matter experts, leverage this application to construct various forms of training content, such as interactive modules, assessments, and simulations.
[0074] The application provides an interface that simplifies the content creation process, allowing users to focus on the substance of the material rather than the complexities of software development. The integration of this application into the training platform ensures that newly created content can be readily accessed and utilized by learners. The application's design aims to accommodate rapid updates and modifications, which is essential for keeping the training content current with the latest cybersecurity practices and threats. The system supports a dynamic and responsive educational environment. This step enables users to contribute their expertise to the platform, enhancing the breadth and depth of the cybersecurity training offered. The application's Low Code and No Code capabilities ensure that the process of content creation is accessible, promoting a collaborative and inclusive approach to developing training resources. Further, the method involves a Penetration system that simulates cybersecurity threats within a cybersecurity training platform. This step is designed to provide users with practical experience in identifying and mitigating simulated cyberattacks. The Penetration system is a component of the training platform, offering a learning environment for users to develop their skills in defending against cyber threats. The actions include:
[0075] • Simulating Cybersecurity Threats: The Penetration system generates scenarios that replicate cyberattacks. These simulations aim to provide users with experience in dealing with a variety of potential vulnerabilities and attack vectors.
[0076] • Engaging Users in Threat Response: As the Penetration system presents threats, users are tasked with detecting, analyzing, and responding to these incidents. This involves applying knowledge and skills to counter simulated attacks and employing defensive tactics and processes to secure the simulated networks.
[0077] • Providing a Learning Environment: The Penetration system, along with hardware simulation devices and system software application simulation, creates an environment that mirrors the infrastructure found in actual systems.
[0078] • Enhancing Training: By simulating threats, the Penetration system improves the training by allowing users to practice incident response in a safe environment where they can learn from their actions without risk
[0079] In practice, the Penetration system would be a software tool capable of creating a range of cyber threats. It would be integrated with the platform's other components, such as the Al Avatar Instructor and the Cybersecurity Training Framework, to provide a comprehensive training experience. The system would include an interface for setting up and managing simulations, as well as tools for reviewing user performance. The Penetration system operates by executing programmed threat scenarios, while the users interact with the system to apply their cybersecurity knowledge and skills. The platform's infrastructure supports these interactions by providing computational resources and integrating with other technologies to ensure a seamless training experience. Further, the method involves the deployment of hardware simulation devices and system software application simulation to provide a learning environment that mirrors operational technology systems. This step is designed to create an experience that closely resembles the scenarios trainees may encounter in their professional roles, which is essential for effective cybersecurity training. The actions within this step include the use of hardware that simulates the physical components of Industrial Control Systems (ICS), such as Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), sensors, and actuators. These simulation devices are programmed to respond to inputs and commands as actual ICS components would. Additionally, the SCADA system software application simulation offers a virtual representation of SCADA interfaces and processes, allowing users to practice tasks associated with monitoring, controlling, and responding to events within a control system environment.
[0080] The hardware simulation devices, the emulation software, and the SCADA simulation software are the primary components. They interact with each other and with the user, who engages with the simulated environment as part of the training exercises. The objective is to provide a platform for users to develop their skills in identifying, responding to, and mitigating potential cybersecurity threats to ICS and SCADA systems.
[0081] By engaging in a simulated environment, users can gain experience with the types of systems they will work with, understand potential vulnerabilities, and learn best practices for securing such systems.
[0082] Further, the method involves the application of encryption technology within the AL based Cybersecurity Training Platform. Encryption technology is the process of encoding information to prevent unauthorized access. This step includes the use of algorithms that convert plain text into cipher text, which is not readily interpretable without the corresponding decryption key. The components involved in this step are the encryption algorithms, blockchain servers, and cryptographic keys. Algorithms are sets of mathematical instructions used to scramble data into cipher text. Blockchain servers may be utilized to create a secure, distributed ledger of transactions, enhancing data integrity and verifiability. Cryptographic keys, which include a public key for encryption and a private key for decryption, are essential for the encryption and decryption processes.
[0083] The purpose of using encryption technology is to safeguard the confidentiality and integrity of data within the platform. It ensures that data, if accessed without authorization, remains indecipherable without the correct decryption keys. This step is integral to the protection of data such as user interactions, performance metrics, and training content.
[0084] In practice, the method can be implemented by integrating encryption protocols into all data storage and communication channels within the platform. This could involve the use of secure sockets layer (SSL) protocols for web interactions, the encryption of databases where user data and training materials are stored, and the encryption of communication between different components of the platform. Parameters for this step might include the selection of encryption algorithms, key lengths, and key management protocols. This step ensures that data within the platform is stored and transmitted in a secure manner, maintaining the integrity of the platform and the confidentiality of user data.
[0085] Further, the method involves the storage of data within databases and Vector Databases as part of the Al-based Cybersecurity Training Platform. This step includes the creation, maintenance, and use of structured repositories that store, retrieve, and manage various types of data generated or used by the platform. These databases hold information necessary for the functioning of the platform, such as user data, training modules, cybersecurity incident data, and the results of user interactions with the platform.
[0086] The databases are likely to be relational, organizing data into tables with predefined relationships, allowing for efficient querying and data manipulation. Vector Databases are specialized for vector search and storage, essential for handling the complex data structures in machine learning, deep learning, and large language models. They store high-dimensional vectors representing various concepts in a format that enables fast retrieval and comparison, which is vital for the Al components of the platform. The processes within this step include data ingestion, where data is collected and entered into the system; indexing, which organizes the data for efficient access; querying, where the system retrieves specific data based on requests; and data maintenance, which includes tasks such as backup, recovery, and ensuring data integrity and security.
[0087] These processes are performed by database management systems and specialized vector database engines, which are software systems that use algorithms and data structures to handle volumes of data with performance and reliability. The individuals responsible for configuring and maintaining the databases, as well as the Al-based Cybersecurity Training Platform itself, interact with the databases to store and retrieve data as part of its operations.
[0088] The goal of the processes is to ensure that the platform has a scalable data storage solution that supports the data requirements of the Al and ML components, provides a foundation for the platform's learning management system, and enables the storage and analysis of cybersecurity-related data for training and simulation purposes.
[0089] Further, the method involves the simulation of cybersecurity threats through the use of Scanning and Penetration solutions. These solutions are designed to identify and analyze vulnerabilities within the simulated environment of the training platform. The process includes automated sweeps of the simulated network to detect potential security weaknesses, which are recognized by the scanning tools. These tools are programmed to recognize a range of vulnerabilities, such as software misconfigurations and missing patches.
[0090] Penetration tools are used to actively exploit identified vulnerabilities, mimicking the actions of an attacker. This allows users to experience the impact of cyberattacks in a controlled environment and learn how to respond. The databases involved provide a repository of known vulnerabilities and associated exploits. These databases are updated to reflect the latest security findings and are used by the scanning and penetration tools to inform their operations. The purpose of the process is to create a dynamic training scenario that mirrors the challenges faced in securing networks. By engaging with these tools, users can develop skills in identifying and mitigating security threats, thereby enhancing their preparedness for actual incidents. In summary, the method involves the use of scanning and penetration tools, along with vulnerability databases, to simulate cybersecurity threats within the training platform. These tools and databases work together to provide an immersive learning experience that helps users build the knowledge and skills necessary to protect infrastructure from cyberattacks.
[0091] Further, the method involves the operation of a WEB scraper and a WebCrawler, which are software tools designed for automated navigation and data collection from the internet. The WEB scraper extracts data from web pages by parsing HTML content and stores it in a structured format. It is designed to automate the data collection process that would otherwise require significant manual effort.
[0092] The WebCrawler systematically browses the World Wide Web to index website content. It follows links across pages and sites, gathering data that includes page content, metadata, and other relevant information. The purpose of using both tools in the training platform is to provide access to up-to-date information about cybersecurity threats, which can be used to inform training scenarios. Further, the WEB scraper and WebCrawler target specific URLs or a range of URLs with defined parameters to identify and retrieve data pertinent to cybersecurity. This data might include details of vulnerabilities, reports of data breaches, or indicators of compromise. Once collected, this data is processed and integrated into the platform's databases for use in creating or updating training modules and exercises.
[0093] The performance of the WEB scraper and WebCrawler is evaluated based on their ability to retrieve accurate and relevant data in a timely manner, while adhering to the terms of service of the websites they access. They must filter through the vast amount of available data to focus on information that is applicable for cybersecurity training. The data collected by these tools is essential for simulating up-to-date cyberattack scenarios, thereby enhancing the learning experience by providing realistic and current cybersecurity challenges for users to address.
[0094] Further, the method focuses on the provision of reference material through research documents within the Al-based Cybersecurity Training Platform. This step involves making available a variety of research documents relevant to cybersecurity training. These documents can include white papers, academic articles, industry reports, best practice guides, regulatory compliance information, and other materials that support the learning objectives of the platform.
[0095] The components involved are the research documents and the subsystem within the platform that manages these documents. The documents serve as a knowledge base for users to reference and learn from, while the subsystem is responsible for organizing, updating, and presenting these documents in an accessible manner to the users. The purpose of providing these documents is to ensure that users have access to a comprehensive set of information that can enhance their understanding of cybersecurity concepts, emerging threats, and best practices.
[0096] The provision of reference material supports the educational aspect of the platform by supplementing interactive learning with in-depth written content. It provides a resource for users to consult when they need detailed information or when they encounter unfamiliar topics during their training. It also helps in ensuring that the training is aligned with current industry standards and practices, which is essential for the relevance and effectiveness of the training.
[0097] In the context of the Al-based Cybersecurity Training Platform, the research documents are likely to be integrated into the Learning Management System (LMS), allowing users to access them as part of their coursework or independently. The documents may be tagged and indexed to facilitate easy searching and retrieval. Additionally, the Al components of the platform, such as natural language processing (NLP) and natural language understanding (NLU), could be used to analyze the content of the documents to provide recommendations or to answer user queries related to the material.
[0098] The action of providing reference material is manifested in the platform through a user interface that allows users to browse, search, and read the documents. The platform may also track user interaction with the documents to provide insights into the frequently accessed materials, which can inform future updates or highlight areas where additional resources may be needed. The goal of this step is to enrich the learning experience and support the development of a well-rounded understanding of cybersecurity.
[0099] Further, the method involves the process of aligning the Al-based Cybersecurity Training Platform with international standards. This step is essential for maintaining the security and reliability of the platform and ensuring that the training provided aligns with recognized best practices and regulations.
[0100] Further, the method is manifested through the implementation of a compliance framework that aligns the platform's operations with international cybersecurity standards. These standards could include ISO / IEC 27001 for information security management, NIST frameworks for cybersecurity, and other relevant guidelines. The individuals responsible for this step include compliance officers, cybersecurity experts, and the development team.
[0101] Compliance officers and cybersecurity experts identify the relevant standards that the platform must adhere to. They conduct analyses to determine the current state of compliance and develop strategies to address any deficiencies. This process involves regular reviews and updates to the platform to incorporate changes in standards and regulations.
[0102] The development team is responsible for implementing the necessary controls, security measures, and features that enable the platform to meet these standards. This includes coding practices, data protection measures, and ensuring that the platform's infrastructure is secure against potential threats.
[0103] The goal of the actions is to provide a training environment that protects users' data and ensures that the training content and methods are effective and recognized internationally. Compliance with international standards also helps in building trust with users and stakeholders, demonstrating the platform's commitment to maintaining high- quality cybersecurity training and practices. Further, the method encompasses the process taken by the compliance officers, cybersecurity experts, and the development team to ensure that the Al-based Cybersecurity Training Platform adheres to international standards. This includes the identification of relevant standards, analysis, strategy development, and the implementation of necessary changes by the development team to achieve and maintain compliance.
[0104] Further, the method involves a platform that enables the creation and development of course content within a cybersecurity training system. This platform operates autonomously, utilizing IT, loT, OT, and Al-driven language models to generate educational materials. The platform's primary function is to facilitate the production of training modules, assessments, and simulations that reflect the current landscape of cybersecurity threats and defenses.
[0105] The platform performs several actions, including the generation, development, and updating of course content. It employs algorithms capable of analyzing trends, threats, and best practices in cybersecurity to produce accurate and effective educational materials. Additionally, the platform may use feedback and performance data to refine the content to meet the learning objectives and skill requirements of users.
[0106] In practice, this platform would appear as a software application or a set of tools that course developers can use to create educational content. It would provide interfaces for inputting expertise, selecting teaching methods, and customizing content to fit specific training scenarios. The platform is likely integrated with other components of the training system, such as learning management and scoring systems, to provide a cohesive learning experience.
[0107] The platform's objective is to streamline the process of creating and maintaining a dynamic curriculum that can adapt to changes in the cybersecurity environment and the diverse learning needs of users. This ensures that users are equipped to effectively respond to cybersecurity challenges and protect infrastructure.
[0108] Further, the method involves the operation of a Web Application platform that serves as the central access point for users to interact with the cybersecurity training system. This platform functions as a web-based interface where users can log in to access training materials, simulations, scoring systems, and other resources. The platform includes a user interface, backend systems such as servers and databases, and integrated technologies that support the training modules and interactive sessions.
[0109] The Web Application platform is designed to streamline user interactions by consolidating the functionalities of the training system into a single, unified interface. Users can navigate through the training modules, participate in sessions, and receive feedback on their performance through this platform. It is likely constructed using web development frameworks and may utilize Low Code or No Code development applications to facilitate its creation and maintenance.
[0110] The central access point provided by the Web Application platform allows users to manage their learning journey and track their progress within the training system. It may also offer customization options to users, enabling them to adjust their learning experience to meet their specific needs. In summary, the method involves operation of providing a central access point via the Web Application platform is manifested as a webbased user interface that centralizes access to the training system's resources, enhancing user experience and facilitating the learning process.
[0111] Further, the method describes the function of a monitoring server tasked with overseeing the operations of the Cybersecurity Training Platform. This server continuously collects and analyzes data related to the platform's performance, user activities, network traffic, and other operational metrics. The server utilizes software tools designed for logging events, tracking performance, and generating alerts to identify and respond to operational anomalies or security threats. The server is equipped with a dashboard or visualization interface that presents the collected data, allowing for efficient review and analysis. This interface is used to convey information about the platform's status to system administrators or automated systems that can take corrective action if necessary.
[0112] By monitoring the platform, the server supports the maintenance of the platform's functionality and security. It plays a role in detecting issues that could disrupt the training environment or compromise the integrity of the platform. The server also interacts with other components within the platform, such as Al agents, to provide feedback that can be used to improve the platform's capabilities and the support it provides to users. Further, the method uses the lab environment management system's role in overseeing the lab environment. This system is a software application tasked with the automation of virtual machine lab environments, which are used for cybersecurity training exercises.
[0113] The lab environment management system automates the provisioning of virtual machines, which includes creating, starting, and configuring these machines with necessary software and network settings to simulate various cybersecurity scenarios. It manages the lifecycle of these resources, ensuring they are available for training and decommissioned post-exercise. This automation supports scalability and efficiency, allowing multiple training sessions to be conducted without manual intervention.
[0114] The system's responsibilities include ensuring that the lab environment is consistent and reliable, reflecting scenarios that users are expected to encounter. It interfaces with other components of the platform to synchronize training activities and track user progress. The system adheres to security protocols to ensure that the simulated environments do not compromise the infrastructure on which they are hosted. In essence, method involves the automated management of the virtual lab environment, facilitating the creation, configuration, and management of virtual machines and resources for cybersecurity training exercises, while maintaining efficiency, scalability, and security.
[0115] Further, the method involves Al agent and score bot agents that contribute to the evaluation of user performance within a cybersecurity training platform. These software programs or algorithms operate within the platform to observe, record, and analyze the actions taken by the user during training exercises, which include responses to simulated cybersecurity threats and the implementation of defensive strategies. The Al agent oversees various aspects of user interaction with the platform, while score bot agents may focus on specific scoring metrics. These metrics assess the speed and accuracy of user responses, the effectiveness of strategies employed, and the ability to identify and mitigate simulated threats. The scoring system, inclusive of these agents, uses predefined criteria to evaluate performance. This could involve a point-based system where users earn points for correct actions and lose points for errors. The system may provide feedback to help users understand their performance and identify areas for improvement. The purpose is to provide a quantifiable measure of cybersecurity skills and knowledge, which is essential for understanding the effectiveness of the training and identifying areas where additional learning is required. The data collected can also be used to tailor future training sessions to the user's needs, enhancing the learning experience and ensuring the training is beneficial.
[0116] The AI-Based Cybersecurity Training System is designed to enhance cybersecurity training through the use of advanced Al technologies and interactive modules. This system provides a secure and interactive learning environment for users.
[0117] The Training Platform System serves as the foundational interface for user interaction with the platform. It is configured to receive inputs from users and respond accordingly within a cloud or on premise environment. The Al Instructor Module utilizes an Avatar Instructor Chabot to deliver personalized guidance and support to users. This module analyzes user performance to identify areas where additional assistance is needed and provides real-time feedback.
[0118] The Al Capabilities Module incorporates a range of Al technologies, including language models, machine learning, deep learning, natural language processing, and neural networks. These technologies process user inputs, support decision-making, and adapt the learning experience to the user's needs. They are integral to presenting cybersecurity threats, offering solutions, and evaluating user responses within the training platform.
[0119] As users engage with the system, their interactions are monitored and supported by the Al Instructor, while the Al technologies continuously adapt the training content. This ensures that the training experience is tailored to the user's learning progress, enhancing their skills in cybersecurity and preparing them for incident response tasks. The system's integrated approach allows for a feedback loop that informs the ongoing development of the user's cybersecurity knowledge and abilities.
[0120] The Training Platform System is a core element of the AI-Based Cybersecurity Training System, designed to facilitate interactive learning experiences. This system includes the Al Instructor Module, which utilizes an Al Avatar Instructor to provide support, and the Al Capabilities Module, which integrates Al technologies to enhance the platform's functionality. Within the Training Platform System, the Al Instructor Module deploys an Al Avatar Instructor, a Chabot designed to interact with users. This module provides learning support by analyzing user interactions to identify areas where the user may need additional assistance. It then offers guidance to improve the user's understanding and skills in cybersecurity. The Al Instructor Module operates by engaging with the user, responding to queries, and providing feedback based on the user's performance.
[0121] The Al Capabilities Module incorporates language models, system applications, machine learning, and deep learning models. This module processes natural language inputs and understands user queries to facilitate interaction with the Al Avatar Instructor. It is activated when data interpretation and real-time response generation are necessary, using neural networks and natural language processing to interpret user inputs and generate appropriate responses.
[0122] The combination of the Al Instructor Module and the Al Capabilities Module ensures that the Training Platform System provides a responsive learning environment. The Al Instructor Module engages with the user, while the Al Capabilities Module supports the interactive experience, adapting to the user's educational needs. This integration allows the Training Platform System to actively participate in the user's learning process, aiding in the development of cybersecurity skills.
[0123] The Training Framework System plays a key role in structuring the cybersecurity training process to ensure effective skill and knowledge development. It comprises the Learning Management Module and the Performance Evaluation Module. The Learning Management Module manages the delivery of educational content and tracks learner progress, while the Performance Evaluation Module uses scoring mechanisms and Al agents to assess user proficiency in cybersecurity practices.
[0124] Within the Training Framework System, the Learning Management Module functions as the educational orchestrator, delivering course materials, managing instructional content, and tracking progression through the curriculum. This module ensures that learners have structured access to resources and can navigate the training effectively.
[0125] The Performance Evaluation Module assesses the learner's understanding and application of cybersecurity concepts through a scoring system linked to Al agents. These agents evaluate user actions during simulated cybersecurity scenarios, such as virtual Blue Team Defensive exercises. They analyze the user's management of cybersecurity solutions, including Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM) systems, and firewalls.
[0126] The integration of these modules within the Training Framework System (204) ensures that the training process is informative and adaptive, providing feedback and guidance that is tailored to the learner's performance. This approach helps learners improve their skills and maintain current knowledge of emerging cybersecurity threats and defense mechanisms.
[0127] The Data Visualization System plays a role in presenting cybersecurity data visually, aiding in the analysis within training scenarios. This system includes the Simulation Technology Module, which provides simulated environments for cybersecurity training, and the Content Development Module, which facilitates the creation of educational content.
[0128] The Simulation Technology Module generates virtual representations of cybersecurity infrastructures, creating an interactive learning environment. Users engage with these simulations to understand cybersecurity threats and defenses. The module uses 3D Digital Twin Simulation software technology to replicate scenarios, allowing users to navigate cybersecurity landscapes. This module is used during training sessions to enhance the learning experience through visual interaction.
[0129] The Content Development Module offers tools for the creation of training materials and scenarios. It utilizes Low Code and No Code development applications, enabling users with different technical backgrounds to create content. This module is used when updating the training curriculum or customizing the learning experience to meet specific needs. These modules work together to ensure that the Data Visualization System effectively displays data and supports the development of training content, aligning with the evolving nature of cybersecurity threats and defenses.
[0130] The Threat Simulation System serves as a component of the cybersecurity training platform, designed to simulate cyber threat scenarios for educational purposes. It comprises the Hardware Simulation Module and the Platform Security Module. The Hardware Simulation Module includes devices and software that emulate industrial control systems (ICS) and supervisory control and data acquisition (SCAD A) systems, providing a practical experience in a controlled environment. The Platform Security Module integrates encryption technologies to protect the training platform, ensuring the integrity and confidentiality of the simulation exercises.
[0131] The Hardware Simulation Module replicates the functionality of ICS and SCADA systems, which are targets in cyberattacks. This replication is achieved through hardware devices and system software applications that mimic the behavior of industrial systems. The purpose of this module is to provide a training ground where users can practice their response to cyber incidents without the risk of affecting operational technology.
[0132] The Platform Security Module secures the Threat Simulation System. It uses encryption technology to protect the integrity of the simulations and the privacy of the users' interactions. This module is essential when the system is used for training in environments where the confidentiality of the scenarios and the responses is necessary. Both modules operate together to deliver a training experience. The Hardware Simulation Module offers the scenarios for training, while the Platform Security Module provides the secure framework within which these scenarios can be explored. They create a platform for cybersecurity professionals to develop their skills, ensuring they are prepared to handle threats. This system is designed to function in various settings, including cloudbased or on premise, and can adapt to the training needs of the organization using it.
[0133] The Data Storage System is a component of the Al-based Cybersecurity Training System that serves as the repository for data. This includes Databases and Vector Databases which are essential for the platform's function. The Threat Simulation Solutions Module contains Scanning and Penetration solutions that are used for simulating cybersecurity threats. The Data Collection Module is equipped with a WEB scraper and WebCrawler, which are used for gathering data on cybersecurity incidents from the internet.
[0134] Within the Data Storage System, the Databases and Vector Databases are structured to store a variety of datasets. These datasets include user performance metrics, cybersecurity incident records, and training materials. The databases are designed to support efficient data retrieval and management, providing the system's Al components with access to necessary information for processing and analysis.
[0135] The Threat Simulation Solutions Module uses Scanning and Penetration solutions to generate a dynamic cybersecurity threat landscape. This module updates threat signatures used to test and improve users' defensive capabilities in the training environment. By simulating attacks, the system offers practical experience in identifying and mitigating security breaches.
[0136] The Data Collection Module uses a WEB scraper and WebCrawler to collect cybersecurity threat intelligence from online sources. This process ensures that the training scenarios are up-to-date with the latest threat vectors. The data collected also supports the continuous improvement of the Al models, allowing them to adapt to changes in the threat landscape. These sub-components work together to ensure that the Data Storage System is a dynamic component that contributes to the training platform's effectiveness.
[0137] The Research Material System is a component of the cybersecurity training platform that provides reference materials to support the learning process. This system includes the Compliance Standards Module, which ensures adherence to international standards, and the Content Creation Platform Module, which facilitates the development of course content.
[0138] The Compliance Standards Module functions as a regulatory reference point within the training platform, aligning the training content with international cybersecurity standards. This module operates by cross-referencing training activities and content against a database of standards, ensuring that the curriculum is up-to-date with current regulations. It adjusts the training material to comply with local and international laws, providing a compliant learning environment.
[0139] The Content Creation Platform Module enables the generation of new learning materials, drawing from the latest cybersecurity research and incident data. It assists educators in creating content that is relevant to the current cybersecurity landscape. This module works in conjunction with the Compliance Standards Module to ensure that all content produced is not only educational but also meets the necessary compliance standards.
[0140] The Web Application System serves as the central interface for user interaction within the cybersecurity training platform. It provides access to training modules, learning materials, and progress management. The system is designed for ease of use, allowing users to effectively engage with the platform's features.
[0141] The Platform Monitoring Module within the system is responsible for monitoring the platform's performance and security. It detects issues such as server downtime or security breaches and addresses them to maintain platform integrity. This module ensures the platform is operational and secure for user access.
[0142] The Lab Management Module oversees the virtual lab environments essential for hands-on cybersecurity training. It handles the setup and configuration of lab scenarios, enabling users to practice in a simulated environment. The module automates the management of these labs, ensuring they are available and configured for the training exercises.
[0143] These sub-components work in conjunction to provide a streamlined interface for the cybersecurity training platform, facilitating user engagement and maintaining the system's functionality and security.
[0144] The following are the key aspects:
[0145] 1. A computer-implemented method for cybersecurity training, comprising: • receiving input from a user interacting with an Al-based Cybersecurity Training Platform;
[0146] • providing interactive learning support to the user through an Al Avatar Instructor;
[0147] • utilizing language models, system applications, Al agents, ML models, DL models, NLP, NLU, and neural networks to enhance the Al capabilities of the platform;
[0148] • monitoring and assisting the user through a Cybersecurity Training Framework and solution;
[0149] • managing the learning process through a Learning Management System (LMS);
[0150] • evaluating the user's performance through a Scoring System;
[0151] • presenting data in a visual format through a Data Visualization solution;
[0152] • providing a simulated learning environment through a Simulation software technology;
[0153] • enabling the creation of learning content through a development application;
[0154] • simulating cybersecurity threats through a Penetration system; providing a realistic learning environment through hardware simulation
[0155] • devices and system software application simulation;
[0156] • securing the platform through encryption technology;
[0157] • storing data in databases and Vector Databases;
[0158] • simulating cybersecurity threats through Scanning and Penetration solutions;
[0159] • collecting data from the internet through a WEB scraper and WebCrawler;
[0160] • providing reference material through research documents;
[0161] • ensuring compliance through international standards;
[0162] • enabling the creation of learning content through a course content creation-development platform;
[0163] • providing a central access point through a Web Application platform; • monitoring the platform through a monitoring server;
[0164] • managing the lab environment through a lab environment management system;
[0165] • providing interactive learning support to the user through an Al Avatar Instructor;
[0166] • monitoring and assisting the user through a Cybersecurity Training Framework and solutions;
[0167] • evaluating the user's performance through a Scoring System;
[0168] • contributing to the evaluation of the user's performance through an Al agent and score bot agents. Further, the Al-based Cybersecurity Training Platform integrates with various technologies including a multi-racial and multi-gender human Avatar Instructor Chabot, several multimodal large language models (LLMs), a Parametric efficient fine-tuning (PEFT) system application, server / PC / mobile devices Al agents, machine learning (ML) models, deep learning (DL) models, natural language processing (NLP), natural language understanding (NLU), neural networks, a Cybersecurity Defensive Cognitive Knowledge and Skill Development Framework and monitoring solution, a learning management system (LMS), a Score Engine System and Score bot, GIS Imaging Data Visualization solution, 3D Digital Twin Simulation software technology, Low Code and No Code development application, a breach and attack Penetration system, physical ICS hardware simulation and emulation devices and SCADA system software application simulation, blockchain servers and cryptography encryption technology, databases, Al, ML, DL, and LLM Vector Databases, Vulnerability Scanning and Penetration solutions and databases, global internet Cybersecurity incidents data breaches and attacks WEB scraper and WebCrawler, research documents, and international standards, autonomous IT / IoT / OT / Cybersecurity course content creation-development AI-LLM platform, an advance central Web Application Convergence Center platform, Cybersecurity Data Breach monitoring server, and a virtual machine lab environment automation management system. Further, the Al Avatar Instructor has deep visibility and understanding to help the student learners improve their cognitive knowledge, skills, and retention abilities for performing key Cybersecurity Incident Response tasks to mitigate cyberattacks against US and Global Critical Infrastructure facilities in a more human-like way. Further, the Cybersecurity Defensive Cognitive Knowledge and Skill Development Framework and solutions are used to monitor and help the student learner or Cybersecurity professional as they partake in continuous, repetitive, Cybersecurity Defensive Knowledge and Skills building training courses, labs, and cyber exercises, to remain current / proficient on emerging threats, defensive tactics, techniques, processes, and technologies to protect and secure ICS system networks systems. Further, the scoring engine system and Al agent and score bot agents are used for tracking and scoring the user's activities and proficiency in using defensive IT, loT, OT, and Cybersecurity solutions (EDR, SIEM, OT-IDS, DLP, Next-Gen AV, Access Control, Firewalls, and Switches) during virtual Blue Team Defensive Critical Infrastructure Cybersecurity labs and exercises. A system for cybersecurity training, comprising:
[0169] • an Al-based Cybersecurity Training Platform configured to receive input from a user;
[0170] • an Al Avatar Instructor configured to provide interactive learning support to the user;
[0171] • a plurality of Al capabilities including language models, system applications, Al agents, ML models, DL models, NLP, NLU, and neural networks;
[0172] • a Cybersecurity Training Framework and solution configured to monitor and assist the user;
[0173] • a Learning Management System (LMS) configured to manage the learning process;
[0174] • a Scoring System configured to evaluate the user's performance;
[0175] • a Data Visualization solution configured to present data in a visual format; • a Simulation software technology configured to provide a simulated learning environment;
[0176] • a development application configured to enable the creation of learning content;
[0177] • a Penetration system configured to simulate cybersecurity threats;
[0178] • hardware simulation devices and system software application simulation configured to provide a realistic learning environment;
[0179] • encryption technology configured to secure the platform;
[0180] • databases and Vector Databases configured to store data;
[0181] • Scanning and Penetration solutions configured to simulate cybersecurity threats;
[0182] • a WEB scraper and WebCrawler configured to collect data from the internet;
[0183] • research documents configured to provide reference material; international standards configured to ensure compliance;
[0184] • a course content creation-development platform configured to enable the creation of learning content;
[0185] • a Web Application platform configured to provide a central access point; a monitoring server configured to monitor the platform;
[0186] • a lab environment management system configured to manage the lab environment;
[0187] • an Al Avatar Instructor configured to provide interactive learning support to the user;
[0188] • a Cybersecurity Training Framework and solutions configured to monitor and assist the user;
[0189] • a Scoring System, an Al agent, and score bot agents configured to evaluate the user's performance. Further, the Al-based Cybersecurity Training Platform integrates with various technologies including a multi-racial and multi-gender human Avatar Instructor Chabot, several multimodal large language models (LLMs), a Parametric efficient fine-tuning (PEFT) system application, server / PC / mobile devices Al agents, machine learning (ML) models, deep learning (DL) models, natural language processing (NLP), natural language understanding (NLU), neural networks, a Cybersecurity Defensive Cognitive Knowledge and Skill Development Framework and monitoring solution, a learning management system (LMS), a Score Engine System and Score bot, GIS Imaging Data Visualization solution, 3D Digital Twin Simulation software technology, Low Code and No Code development application, a breach and attack Penetration system, physical ICS hardware simulation and emulation devices and SCADA system software application simulation, blockchain servers and cryptography encryption technology, databases, Al, ML, DL, and LLM Vector Databases, Vulnerability Scanning and Penetration solutions and databases, global internet Cybersecurity incidents data breaches and attacks WEB scraper and WebCrawler, research documents, and international standards, autonomous IT / IoT / OT / Cybersecurity course content creation-development ALLLM platform, an advance central Web Application Convergence Center platform, Cybersecurity Data Breach monitoring server, and a virtual machine lab environment automation management system. Further, wherein the Al Avatar Instructor has deep visibility and understanding to help the student learners improve their cognitive knowledge, skills, and retention abilities for performing key Cybersecurity Incident Response tasks to mitigate cyberattacks against US and Global Critical Infrastructure facilities in a more human-like way. Further, the Cybersecurity Defensive Cognitive Knowledge and Skill Development Framework and solutions are used to monitor and help the student learner or Cybersecurity professional as they partake in continuous, repetitive, Cybersecurity Defensive Knowledge and Skills building training courses, labs, and cyber exercises, to remain current / proficient on emerging threats, defensive tactics, techniques, processes, and technologies to protect and secure ICS system networks systems. Further, the scoring engine system and Al agent and score bot agents are used for tracking and scoring the user's activities and proficiency in using defensive IT, IoT, OT, and Cybersecurity solutions (EDR, SIEM, OT-IDS, DLP, Next-Gen AV, Access Control, Firewalls, and Switches) during virtual Blue Team Defensive Critical Infrastructure Cybersecurity labs and exercises.
[0190] Further, the system features machine learning models trained on extensive datasets to predict and identify potential threats more accurately, enhancing security.
[0191] Further, the system incorporates quantum -resistant algorithms, ensuring secure data transmission even as computational capabilities evolve.
[0192] Further, the system ensures secure, immutable records of training activities and insights without compromising data privacy.
[0193] Further, the system combines behavioral analysis with biological metrics to enhance user authentication security in some embodiments.
[0194] Further, the system uses advanced techniques to ensure that data analytics respect user privacy, protecting sensitive information while providing actionable insights.
[0195] Further, the system integrates autonomous mechanisms to detect and mitigate threats without waiting for human input, reducing downtime in some cases.
[0196] FIG. 1 is an illustration of an online platform 100 consistent with various embodiments of the present disclosure. By way of non-limiting example, the online platform 100 may be hosted on a centralized server 102, such as, for example, a cloud computing service. The centralized server 102 may communicate with other network entities, such as, for example, a mobile device 106 (such as a smartphone, a laptop, a tablet computer etc ), other electronic devices 110 (such as desktop computers, server computers etc.), databases 114, and sensors 116 over a communication network 104, such as, but not limited to, the Internet. Further, users of the online platform 100 may include relevant parties such as, but not limited to, end-users, administrators, service providers, service consumers and so on. Accordingly, in some instances, electronic devices operated by the one or more relevant parties may be in communication with the platform.
[0197] A user 112, such as the one or more relevant parties, may access online platform 100 through a web based software application or browser. The web based software application may be embodied as, for example, but not be limited to, a website, a web application, a desktop application, and a mobile application compatible with a computing device 200.
[0198] With reference to FIG. 2, a system consistent with an embodiment of the disclosure may include a computing device or cloud service, such as computing device 200. In a basic configuration, computing device 200 may include at least one processing unit 202 and a system memory 204. Depending on the configuration and type of computing device, system memory 204 may comprise, but is not limited to, volatile (e.g. randomaccess memory (RAM)), non-volatile (e.g. read-only memory (ROM)), flash memory, or any combination. System memory 204 may include operating system 205, one or more programming modules 206, and may include a program data 207. Operating system 205, for example, may be suitable for controlling computing device 200’ s operation. In one embodiment, programming modules 206 may include image-processing module, machine learning module. Furthermore, embodiments of the disclosure may be practiced in conjunction with a graphics library, other operating systems, or any other application program and is not limited to any particular application or system. This basic configuration is illustrated in FIG. 2 by those components within a dashed line 208.
[0199] Computing device 200 may have additional features or functionality. For example, computing device 200 may also include additional data storage devices (removable and / or non-removable) such as, for example, magnetic disks, optical disks, or tape. Such additional storage is illustrated in FIG. 2 by a removable storage 209 and a nonremovable storage 210. Computer storage media may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, program modules, or other data. System memory 204, removable storage 209, and non-removable storage 210 are all computer storage media examples (i.e., memory storage.) Computer storage media may include, but is not limited to, RAM, ROM, electrically erasable readonly memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store information and which can be accessed by computing device 200. Any such computer storage media may be part of device 200. Computing device 200 may also have input device(s) 212 such as a keyboard, a mouse, a pen, a sound input device, a touch input device, a location sensor, a camera, a biometric sensor, etc. Output device(s) 214 such as a display, speakers, a printer, etc. may also be included. The aforementioned devices are examples and others may be used.
[0200] Computing device 200 may also contain a communication connection 216 that may allow device 200 to communicate with other computing devices 218, such as over a network in a distributed computing environment, for example, an intranet or the Internet. Communication connection 216 is one example of communication media. Communication media may typically be embodied by computer readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. The term “modulated data signal” may describe a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media. The term computer readable media as used herein may include both storage media and communication media.
[0201] As stated above, a number of program modules and data files may be stored in system memory 204, including operating system 205. While executing on processing unit 202, programming modules 206 (e.g., application 220 such as a media player) may perform processes including, for example, one or more stages of methods, algorithms, systems, applications, servers, databases as described above. The aforementioned process is an example, and processing unit 202 may perform other processes. Other programming modules that may be used in accordance with embodiments of the present disclosure may include machine learning applications.
[0202] Generally, consistent with embodiments of the disclosure, program modules may include routines, programs, components, data structures, and other types of structures that may perform particular tasks or that may implement particular abstract data types. Moreover, embodiments of the disclosure may be practiced with other computer system configurations, including hand-held devices, general purpose graphics processor-based systems, multiprocessor systems, microprocessor-based or programmable consumer electronics, application specific integrated circuit-based electronics, minicomputers, mainframe computers, and the like. Embodiments of the disclosure may also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules may be located in both local and remote memory storage devices.
[0203] Furthermore, embodiments of the disclosure may be practiced in an electrical circuit comprising discrete electronic elements, packaged or integrated electronic chips containing logic gates, a circuit utilizing a microprocessor, or on a single chip containing electronic elements or microprocessors. Embodiments of the disclosure may also be practiced using other technologies capable of performing logical operations such as, for example, AND, OR, and NOT, including but not limited to mechanical, optical, fluidic, and quantum technologies. In addition, embodiments of the disclosure may be practiced within a general-purpose computer or in any other circuits or systems.
[0204] Embodiments of the disclosure, for example, may be implemented as a computer process (method), a computing system, or as an article of manufacture, such as a computer program product or computer readable media. The computer program product may be a computer storage media readable by a computer system and encoding a computer program of instructions for executing a computer process. The computer program product may also be a propagated signal on a carrier readable by a computing system and encoding a computer program of instructions for executing a computer process. Accordingly, the present disclosure may be embodied in hardware and / or in software (including firmware, resident software, micro-code, etc.). In other words, embodiments of the present disclosure may take the form of a computer program product on a computer-usable or computer-readable storage medium having computer-usable or computer-readable program code embodied in the medium for use by or in connection with an instruction execution system. A computer-usable or computer-readable medium may be any medium that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device.
[0205] The computer-usable or computer-readable medium may be, for example but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or propagation medium. More specific computer-readable medium examples (a non-exhaustive list), the computer-readable medium may include the following: an electrical connection having one or more wires, a portable computer diskette, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disc read-only memory (CD-ROM). Note that the computer-usable or computer-readable medium could even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, via, for instance, optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and then stored in a computer memory.
[0206] Embodiments of the present disclosure, for example, are described above with reference to block diagrams and / or operational illustrations of methods, systems, and computer program products according to embodiments of the disclosure. The functions / acts noted in the blocks may occur out of the order as shown in any flowchart. For example, two blocks shown in succession may in fact be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality / acts involved.
[0207] While certain embodiments of the disclosure have been described, other embodiments may exist. Furthermore, although embodiments of the present disclosure have been described as being associated with data stored in memory and other storage mediums, data can also be stored on or read from other types of computer-readable media, such as secondary storage devices, like hard disks, solid state storage (e.g., USB drive), or a CD- ROM, a carrier wave from the Internet, or other forms of RAM or ROM. Further, the disclosed methods’ stages may be modified in any manner, including by reordering stages and / or inserting or deleting stages, without departing from the disclosure. Fig. 3 A and Fig. 3B illustrate a flowchart of a method 300 of provisioning a cybersecurity training, in accordance with some embodiments.
[0208] Accordingly, the method 300 may include a step 302 of receiving, using a communication device 802, a user data from a user device associated with a user. Further, the user data corresponds to a cybersecurity learning preference of the user. Further, the method 300 may include a step 304 of determining, using a processing device 804, a threat data. Further, the threat data corresponds to a cybersecurity threat. Further, the method 300 may include a step 306 of generating, using the processing device 804, a simulated training data based on each of the user data and the threat data. Further, the simulated training data corresponds to a simulated environment representing a simulation of one or more of the cybersecurity threat and a computer system. Further, the method 300 may include a step 308 of transmitting, using the communication device 802, the simulated training data to the user device. Further, the user device may be configured to present the simulated training data on a user presentation device comprised in the user device. Further, the training data facilitates the cybersecurity training based on a user interaction with the simulated environment. Further, the method 300 may include a step 310 of receiving, using the communication device 802, an interaction data from the user device. Further, the interaction data corresponds to the user interaction. Further, the method 300 may include a step 312 of analyzing, using the processing device 804, the interaction data. Further, the method 300 may include a step 314 of generating, using the processing device 804, a training result data based on the analyzing. Further, the training result data corresponds to a cybersecurity training result of the user.
[0209] Fig. 4 illustrates a flowchart of a method 400 of provisioning a cybersecurity training including generating, using the processing device 804, a module data, in accordance with some embodiments.
[0210] Further, in some embodiments, the method 400 further may include a step 402 of generating, using the processing device 804, a module data based on the user data. Further, the module data corresponds to a training module of the cybersecurity training. Further, in some embodiments, the method 400 further may include a step 404 of transmitting, using the communication device 802, the module data to the user device. Further, the user device may be configured to present the module data on the user presentation device. Further, the cybersecurity training may be based on a user engagement with the training module.
[0211] In some embodiments, the simulated environment corresponds to a digital representation of a physical infrastructure associated with the computed system, may. Further, the simulated environment may be configured to emulate a characteristic of the computer system, may. Further, the characteristic corresponds to one or more of a cyberattack response and a user action response. Further, the cyberattack response and the user action response corresponds to a response of the computer system in relation to the cybersecurity threat and the user interaction respectively.
[0212] In some embodiments, the computer system includes one or more of a hardware device and a software application. Further, the simulated environment associated with one or more of a simulated hardware device and a simulated software application. Further, the simulated hardware device and the simulated software application corresponds to the simulation of one or more of the hardware device and the software application respectively.
[0213] Fig. 5 illustrates a flowchart of a method 500 of provisioning a cybersecurity training including generating, using the processing device 804, a response data, in accordance with some embodiments.
[0214] Further, in some embodiments, the method 500 further may include a step 502 of receiving, using the communication device 802, a user query data from the user device. Further, the user query data corresponds to a user query corresponding to a cybersecurity learning. Further, in some embodiments, the method 500 further may include a step 504 of analyzing, using the processing device 804, the user query data. Further, in some embodiments, the method 500 further may include a step 506 of generating, using the processing device 804, a response data based on the analyzing of the user query data. Further, the response data corresponds to a response to the user query. Further, the generating of the response data may be further based on an Al model. Further, in some embodiments, the method 500 further may include a step 508 of transmitting, using the communication device 802, the response data to user device. Further, the user device may be configured to present the response data on the user presentation device.
[0215] Fig. 6 illustrates a flowchart of a method 600 of provisioning a cybersecurity training including generating, using the processing device 804, an avatar data, in accordance with some embodiments.
[0216] Further, in some embodiments, the method 600 further may include a step 602 of generating, using the processing device 804, an avatar data. Further, the avatar data corresponds to a digital representation of a human emulating a human characteristic. Further, the human characteristic may be associated with the response. Further, in some embodiments, the method 600 further may include a step 604 of transmitting, using the communication device 802, the avatar data to the user device. Further, the user device may be configured to present the digital representation of the human on the user presentation device.
[0217] In some embodiments, the method 300 may further include storing, using the processing device 804, the training result data in a database. Further, the generating of a second simulated training data at a second time instance may be based on the training result data. Further, the training result data corresponds to the simulated training data generated at a first time instance. Further, the second time instance occurs after the first time instance.
[0218] Fig. 7 illustrates a flowchart of a method 700 of provisioning a cybersecurity training including generating, using the processing device 804, a user report data, in accordance with some embodiments.
[0219] Further, in some embodiments, the method 700 further may include a step 702 of receiving, using the communication device 802, a user engagement data from the user device. Further, the user engagement data corresponds to an indication of the user engagement with the training module. Further, in some embodiments, the method 700 further may include a step 704 of generating, using the processing device 804, a user report data based on the user engagement data. Further, the user report data corresponds a user report of the cybersecurity training. Further, in some embodiments, the method 700 further may include a step 706 of transmitting, using the processing device 804, the user report data to the user device.
[0220] In some embodiments, the method 400 may further include determining, using the processing device 804, a cybersecurity data based on an external database. Further, the cybersecurity data corresponds to a cybersecurity detail. Further, the generating of the module data may be further based on the cybersecurity data. Further, the training module corresponds to a visual representation of the cybersecurity data.
[0221] In some embodiments, the generating of the training result data may be further based on a predefined criterion corresponding to a defensive cybersecurity solution associated with the user interaction. Further, the user utilizes the defensive cybersecurity solution to mitigate the cybersecurity threat. Further, the defensive cybersecurity solution corresponds to one or more of an endpoint detection and response, a security information and event management, an intrusion detection system, a data loss prevention, a nextgeneration antivirus, an access control system, a firewall, an operational technology, an internet of things, and a network switch.
[0222] Fig. 8 illustrates a block diagram of a system 800 of provisioning a cybersecurity training, in accordance with some embodiments.
[0223] Accordingly, the system 800 may include a communication device 802. Further, the communication device 802 may be configured for receiving a user data from a user device associated with a user. Further, the user data corresponds to a cybersecurity learning preference of the user. Further, the communication device 802 may be configured for transmitting a simulated training data to the user device. Further, the user device may be configured to present the simulated training data on a user presentation device comprised in the user device. Further, the training data facilitates the cybersecurity training based on a user interaction with the simulated environment. Further, the communication device 802 may be configured for receiving an interaction data from the user device. Further, the interaction data corresponds to the user interaction. Further, the system 800 may include a processing device 804. Further, the processing device 804 may be configured for determining a threat data. Further, the threat data corresponds to a cybersecurity threat. Further, the processing device 804 may be configured for generating the simulated training data based on each of the user data and the threat data. Further, the simulated training data corresponds to a simulated environment representing a simulation of one or more of the cybersecurity threat and a computer system. Further, the processing device 804 may be configured for analyzing the interaction data. Further, the processing device 804 may be configured for generating a training result data based on the analyzing. Further, the training result data corresponds to a cybersecurity training result of the user.
[0224] In some embodiments, the processing device 804 may be further configured for generating a module data based on the user data. Further, the module data corresponds to a training module of the cybersecurity training. Further, the communication device 802 may be further configured for transmitting the module data to the user device. Further, the user device may be configured to present the module data on the user presentation device. Further, the cybersecurity training may be based on a user engagement with the training module.
[0225] In some embodiments, the simulated environment corresponds to a digital representation of a physical infrastructure associated with the computed system, may. Further, the simulated environment may be configured to emulate a characteristic of the computer system, may. Further, the characteristic corresponds to one or more of a cyberattack response and a user action response. Further, the cyberattack response and the user action response corresponds to a response of the computer system in relation to the cybersecurity threat and the user interaction respectively.
[0226] In some embodiments, the computer system includes one or more of a hardware device and a software application. Further, the simulated environment associated with one or more of a simulated hardware device and a simulated software application. Further, the simulated hardware device and the simulated software application corresponds to the simulation of one or more of the hardware device and the software application respectively. Further, in some embodiments, the communication device 802 may be further configured for receiving a user query data from the user device. Further, the user query data corresponds to a user query corresponding to a cybersecurity learning. Further, the communication device 802 may be further configured for transmitting a response data to user device. Further, the user device may be configured to present the response data on the user presentation device. Further, the processing device 804 may be further configured for analyzing the user query data. Further, the processing device 804 may be further configured for generating the response data based on the analyzing of the user query data. Further, the response data corresponds to a response to the user query. Further, the generating of the response data may be further based on an Al model.
[0227] In some embodiments, the processing device 804 may be further configured for generating an avatar data. Further, the avatar data corresponds to a digital representation of a human emulating a human characteristic. Further, the human characteristic may be associated with the response. Further, the communication device 802 may be further configured for transmitting the avatar data to the user device. Further, the user device may be configured to present the digital representation of the human on the user presentation device.
[0228] In some embodiments, the processing device 804 may be further configured for storing the training result data in a database. Further, the generating of a second simulated training data at a second time instance may be based on the training result data. Further, the training result data corresponds to the simulated training data generated at a first time instance. Further, the second time instance occurs after the first time instance.
[0229] Further, in some embodiments, the communication device 802 may be further configured for receiving a user engagement data from the user device. Further, the user engagement data corresponds to an indication of the user engagement with the training module. Further, the communication device 802 may be further configured for transmitting a user report data to the user device. Further, the processing device 804 may be further configured for generating the user report data based on the user engagement data. Further, the user report data corresponds a user report of the cybersecurity training. In some embodiments, the processing device 804 may be further configured for determining a cybersecurity data based on an external database. Further, the cybersecurity data corresponds to a cybersecurity detail. Further, the generating of the module data may be further based on the cybersecurity data. Further, the training module corresponds to a visual representation of the cybersecurity data.
[0230] In some embodiments, the generating of the training result data may be further based on a predefined criterion corresponding to a defensive cybersecurity solution associated with the user interaction. Further, the user utilizes the defensive cybersecurity solution to mitigate the cybersecurity threat. Further, the defensive cybersecurity solution corresponds to one or more of an endpoint detection and response, a security information and event management, an intrusion detection system, a data loss prevention, a nextgeneration antivirus, an access control system, a firewall, an operational technology, an internet of things, and a network switch.
[0231] In some embodiments, the user device may be associated with a user input device. Further, the user interaction with the simulated environment happens through the user input device.
[0232] In some embodiments, the user input device includes one or more of a keyboard and a mouse.
[0233] In some embodiments, the user presentation device includes a display screen comprising a touch screen.
[0234] In some embodiments, the user interaction corresponds to a voice command from the user.
[0235] In some embodiments, the cybersecurity learning preference may include an industry preference.
[0236] In some embodiments, the determining of the threat data may be based on the cybersecurity learning preference. Further, the cybersecurity learning preference includes the industry preference. In some embodiments, the cybersecurity learning preference may include a language preference.
[0237] In some embodiments, the user includes a student.
[0238] In some embodiments, the user includes a cybersecurity professional.
[0239] In some embodiments, the method 300 may further include analyzing, using the processing device 804, the user data. Further, the analyzing may be based on an Al model. Further, one or more of the determining and the generating may be further based on the analyzing of the Al model.
[0240] In some embodiments, the Al model includes one or more of a multimodal large language model, a machine learning model, and a deep learning model.
[0241] In some embodiments, the Al model may be based a neural network.
[0242] In some embodiments, the Al model may be configured to perform one or more of a natural language understanding and a natural language processing.
[0243] In some embodiments, the avatar data corresponds an Al avatar.
[0244] In some embodiments, the artificial intelligence avatar includes an Al avatar instructor.
[0245] In some embodiments, the response data corresponds to a cybersecurity guideline for a cybersecurity scenario.
[0246] In some embodiments, the response data corresponds to a cybersecurity training guidance.
[0247] In some embodiments, the response data corresponds to a cybersecurity learning instruction.
[0248] In some embodiments, the generating of the response data may be further based on the training result data. Further, the user query data may be associated with the cybersecurity training. Further, the response data corresponds to a performance feedback. In some embodiments, the generating of the avatar data may be further based on the response data.
[0249] In some embodiments, the training data may be configured to improve a cognitive ability of the user. Further, the cognitive ability corresponds to one or more of a cybersecurity knowledge retention, a cybersecurity skill acquisition, and a cyber-threat response skill.
[0250] In some embodiments, the generating of the response data may be further based on the user data. Further, the response may be tailored based on the cybersecurity learning preference.
[0251] In some embodiments, the user data further represents a user knowledge level. Further, the training data may be tailored based on the user knowledge data.
[0252] In some embodiments, the method 300 may further include transmitting, using the communication device 802, the training result data to the user device.
[0253] In some embodiments, the analyzing of the interaction data includes evaluating a user cybersecurity skill.
[0254] In some embodiments, the generating of the response data may be further based on the training result data. Further, the response data corresponds to a personalized cybersecurity guidance.
[0255] In some embodiments, the generating of the simulated training data at a second time instance may be based on the training result data facilitates adapting the simulated training data to a user progress.
[0256] In some embodiments, the simulated training data based on the user data facilitates a personalized training.
[0257] In some embodiments, the training data facilities the user to practice on a real-world cyberattack scenario. Further, the simulated environment mimics the real-world cyberattack scenario. In some embodiments, the generating of the response data may be based on an Al agent.
[0258] In some embodiments, the cybersecurity training includes the cybersecurity defense training.
[0259] In some embodiments, the cybersecurity training includes repetitive cybersecurity training based on two or more simulated training data.
[0260] In some embodiments, the module data corresponds to one or more of a training course and a training material.
[0261] In some embodiments, the method 700 may further include tracking, using the processing device 804, two or more user engagement data. Further, the generating of the user report data may be further based on the tracking.
[0262] In some embodiments, the training module corresponds to a cybersecurity course. Further, the two or more user engagement data represents a course completion rate of the user.
[0263] In some embodiments, the training result data includes a score representing a performance of the user in relation to the cybersecurity threat.
[0264] In some embodiments, the generating of the user report data may be further based on the training result data.
[0265] In some embodiments, the generating of the simulated training data may be further based on one or more of a cybersecurity standard 1100 and a cybersecurity practices.
[0266] In some embodiments, the analyzing of the interaction data includes analyzing a parameter associated with the user interaction.
[0267] In some embodiments, the parameter corresponds to a time interval associated with the user interaction.
[0268] In some embodiments, the parameter corresponds to an accuracy of the user interaction. In some embodiments, the parameter corresponds to one or more of identifying the cybersecurity threat and mitigating the cybersecurity threat.
[0269] In some embodiments, the cybersecurity training result may be based on the time interval.
[0270] In some embodiments, the cybersecurity training result may be based on a time taken to identify the cybersecurity threat in the simulated environment.
[0271] In some embodiments, the analyzing of the interaction data may be further based on a predefined mitigation strategy, may. Further, the cybersecurity threat may be configured to be mitigated based on the predefined mitigation strategy.
[0272] In some embodiments, the generating of the training result data based on an Al agent.
[0273] In some embodiments, the Al agent includes a score bot agent.
[0274] In some embodiments, the simulated environment corresponds to an infrastructure of cybersecurity lab.
[0275] In some embodiments, the parameter corresponds to a severity of the cybersecurity threat and an impact of the user interaction on a security of the computer system.
[0276] In some embodiments, the visual representation includes a graphical representation.
[0277] In some embodiments, the cybersecurity detail corresponds to one or more of a cybersecurity incident and a network traffic.
[0278] In some embodiments, the training module highlights one or more of a pattern of the cybersecurity data, a correlation of the cybersecurity data, and a trend of the cybersecurity data.
[0279] In some embodiments, the training module may include a visualization one or more of a frequency of the network attack and a type of the network attack
[0280] In some embodiments, the training module facilitates the user to make decision in short period of time. In some embodiments, the method 400 may further include determining, using the processing device 804, an updated cybersecurity data from an external database. Further, the updated cybersecurity data corresponds to an updated cybersecurity detail; generating, using the processing device 804, an updated module data based on the updated cybersecurity data. Further, the updated module data corresponds to an updated training module of the cybersecurity training; and transmitting, using the communication device 802, the updated module data to the user device. Further, the user device may be configured to present the updated module data on the user presentation device.
[0281] In some embodiments, the updated module data includes an updated visual representation of the cybersecurity detail.
[0282] In some embodiments, the generating of the simulated training data may be based on an algorithm representing one or more of a physical characteristic and an operational logic of the computer system.
[0283] In some embodiments, the user interaction corresponds to one or more of configuring system setting, deploying defensive measure, and responding to the cybersecurity threat.
[0284] In some embodiments, the generating, of the simulated training data may be based on a three dimensional digital twin simulation software technology.
[0285] In some embodiments, the training module corresponds to a cybersecurity education material.
[0286] In some embodiments, the method 400 may further include receiving, using the communication device 802, a user request data from the user device. Further, the user request data corresponds to a user request corresponding to the training module. Further, the generating of the module data may be further based on the user request data.
[0287] In some embodiments, the method 400 may further include receiving, using the communication device 802, a user resource data from the user device. Further, the user resource data corresponds to a user-preferred cybersecurity learning resource. Further, the generating of the module data may be further based on the user resource data. In some embodiments, the simulated training data may be tailored for two or more user tasks. Further, the two or more user tasks corresponds to one or more of detecting the cybersecurity threat, analyzing the cybersecurity threat, and responding to the cybersecurity threat.
[0288] In some embodiments, the responding to the cybersecurity threat corresponds to employing a defensive tactic.
[0289] In some embodiments, the simulated environment corresponds to a scenario associated with a cybersecurity professional role.
[0290] In some embodiments, the simulated hardware device corresponds to one or more of an industrial control system, a programmable logic controller, a remote terminal unit, a sensor and an actuator.
[0291] In some embodiments, the simulated hardware device may be configured to responds to the user interaction.
[0292] In some embodiments, the simulated software application corresponds to a supervisory control and data acquisition application.
[0293] In some embodiments, the simulated software application facilitates the user to practice task associated with one or more of monitoring, controlling and responding to the cybersecurity threat.
[0294] Fig. 9 illustrates a flowchart of a method 900 of provisioning a cybersecurity training including encrypting, using the processing device 804, the training result data to obtain an encrypted training result data, in accordance with some embodiments.
[0295] Further, in some embodiments, the method 900 further may include a step 902 of encrypting, using the processing device 804, the training result data to obtain an encrypted training result data. Further, the encrypted training result data corresponds to an encrypted cybersecurity training result data. Further, in some embodiments, the method 900 further may include a step 904 of storing, using the processing device 804, the encrypted training result data in a database. In some embodiments, the encrypting of the training result data may be based on an encrypting algorithm.
[0296] In some embodiments, the database includes a decentralized database corresponds to a blockchain.
[0297] In some embodiments, the encrypted training result data may be accessed based on a cryptographic key.
[0298] In some embodiments, the database includes a vector database.
[0299] In some embodiments, the database includes one or more of the user data, the simulated training data, and the training result data.
[0300] In some embodiments, the database includes one or more of the user data, the simulated training data, and the training result data in a structured format.
[0301] In some embodiments, the structured format includes a table format.
[0302] In some embodiments, the determining of the threat data includes retrieving the threat data from a database. Further, the database includes two or more cybersecurity attacks.
[0303] In some embodiments, the determining of the threat data includes determining the threat data from an external content associated with an external webpage.
[0304] In some embodiments, the simulated training data facilitates an immersive learning experience.
[0305] Fig. 10 illustrates a flowchart of a method 1000 of provisioning a cybersecurity training including analyzing, using the processing device 804, the simulation data, in accordance with some embodiments.
[0306] Further, in some embodiments, the method 1000 further may include a step 1002 of determining, using the processing device 804, a simulation data based on an external simulation database. Further, the simulation data corresponds to a pre-established simulated environment of the computed system. Further, in some embodiments, the method 1000 further may include a step 1004 of analyzing, using the processing device 804, the simulation data. Further, the generating of the simulated training data includes an ingesting of the cybersecurity threat in the pre-established simulated environment.
[0307] In some embodiments, the analyzing of the simulation data includes identifying a security vulnerability of the pre-established simulated environment of the computed system.
[0308] In some embodiments, the ingesting of the cybersecurity threat may be further based on the security vulnerability.
[0309] In some embodiments, the determining of the threat data may be based on a web data extraction tool comprising one or more of a web scraper and a WebCrawler.
[0310] In some embodiments, the training module includes a research document comprising one or more of a white paper, an academic article, an industry report, a best practice guide, and a regulatory compliance detail.
[0311] In some embodiments, the cybersecurity standard includes one or more of an ISO / IEC 27001 and an NIST framework.
[0312] In some embodiments, the simulated training data corresponds to a cybersecurity assessment.
[0313] In some embodiments, the method 400 may further include receiving, using the communication device 802, a user feedback from the user device. Further, the user feedback data corresponds to a feedback of the cybersecurity training. Further, the generating of one or more of the simulated training data and the training module data may be further based on the user feedback data.
[0314] In some embodiments, the simulated environment includes a virtual lab environment.
[0315] In some embodiments, the method 400 may further include generating, using the processing device 804, an issue data based on the generating of one or more of the simulated training data and the module data. Further, the issue data corresponds to an issue associated with the cybersecurity training. Fig. 11 A illustrates a flowchart of a cybersecurity training, in accordance with some embodiments.
[0316] Fig. 1 IB illustrates a continuation of the flowchart of the cybersecurity training, in accordance with some embodiments.
[0317] Accordingly, the cybersecurity training includes a step 1102 of User interacting with an Al-based Cybersecurity Training Platform. Further, the cybersecurity training includes a step 1104 and a step 1106 of Al Avatar instructor providing interactive learning support to the user and Language models, system application, Al agents, ML models, DL models, NLP, NLU, and neural networks enhancing the Al capabilities of the platform respectively. Further, the cybersecurity training includes a step 1108 of Cybersecurity Training Framework and solution monitoring end assisting the user. Further, the cybersecurity training includes a step 1110 of Learning Management System (LMS) managing the learning process. Further, the cybersecurity training includes a step 112 of scoring system evaluating the user’s performance. Further, the cybersecurity training includes a step 1114 of data visualization solution presenting data in a visual format. Further, the cybersecurity training includes a step 1116 of simulation software technology providing a simulated learning environment. Further, the cybersecurity training includes a step 1118 of development application enabling the creation of learning content. Further, the cybersecurity training includes a step 1120 of penetration system simulating cybersecurity threats. Further, the cybersecurity training includes a step 1122 of hardware simulation devices and system software application simulation providing a realistic learning environment. Further, the cybersecurity training includes a step 1124 of encryption technology securing the platform, further, the cybersecurity training includes a step 1126 of database and vector databases storing data. Further, the cybersecurity training includes a step 1128 of scanning and penetration solutions simulating cybersecurity threats. Further, the cybersecurity training includes a step 1130 of web scraper and WebCrawler collecting data from the internet. Further, the cybersecurity training includes a step 1132 of research documents providing references material. Further, the cybersecurity training includes a step 1134 of international standards ensuring compliance. Further, the cybersecurity training includes a step 1136 of course content creation-development platform enabling the creation of learning content. Further, the cybersecurity training includes a step 1138 of web application platform proving a central access point. Further, the cybersecurity training includes a step 1140 of monitoring server monitoring the platform. Further, the cybersecurity training includes a step 1142 of lab environment management system managing the lab environment.
[0318] Further, the cybersecurity training includes a step 1144 of Al agent score bot agents contributing to the evaluation of the user’s performance.
[0319] Although the invention has been explained in relation to its preferred embodiment, it is to be understood that many other possible modifications and variations can be made without departing from the spirit and scope of the invention as hereinafter claimed.
Claims
CLAIMS1. A method of provisioning a cybersecurity training, wherein the method comprising: receiving, using a communication device, a user data from a user device associated with a user, wherein the user data corresponds to a cybersecurity learning preference of the user; determining, using a processing device, a threat data, wherein the threat data corresponds to a cybersecurity threat; generating, using the processing device, a simulated training data based on each of the user data and the threat data, wherein the simulated training data corresponds to a simulated environment representing a simulation of at least one of the cybersecurity threat and a computer system; transmitting, using the communication device, the simulated training data to the user device, wherein the user device is configured to present the simulated training data on a user presentation device comprised in the user device, wherein the training data facilitates the cybersecurity training based on a user interaction with the simulated environment; receiving, using the communication device, an interaction data from the user device, wherein the interaction data corresponds to the user interaction; analyzing, using the processing device, the interaction data; and generating, using the processing device, a training result data based on the analyzing, wherein the training result data corresponds to a cybersecurity training result of the user.
2. The method of claim 1 further comprises: generating, using the processing device, a module data based on the user data, wherein the module data corresponds to a training module of the cybersecurity training; andtransmitting, using the communication device, the module data to the user device, wherein the user device is configured to present the module data on the user presentation device, wherein the cybersecurity training is based on a user engagement with the training module.
3. The method of claim 1, wherein the simulated environment corresponds to a digital representation of a physical infrastructure associated with the computed system, wherein the simulated environment is configured to emulate a characteristic of the computer system, wherein the characteristic corresponds to at least one of a cyberattack response and a user action response, wherein the cyberattack response and the user action response corresponds to a response of the computer system in relation to the cybersecurity threat and the user interaction respectively.
4. The method of claim 3, wherein the computer system comprises at least one of a hardware device and a software application, wherein the simulated environment associated with at least one of a simulated hardware device and a simulated software application, wherein the simulated hardware device and the simulated software application corresponds to the simulation of at least one of the hardware device and the software application respectively.
5. The method of claim 1 further comprises: receiving, using the communication device, a user query data from the user device, wherein the user query data corresponds to a user query corresponding to a cybersecurity learning; analyzing, using the processing device, the user query data; generating, using the processing device, a response data based on the analyzing of the user query data, wherein the response data corresponds to a response to the user query, wherein the generating of the response data is further based on an Al model; and transmitting, using the communication device, the response data to user device, wherein the user device is configured to present the response data on the user presentation device.
6. The method of claim 5 further comprises: generating, using the processing device, an avatar data, wherein the avatar data corresponds to a digital representation of a human emulating a human characteristic, wherein the human characteristic is associated with the response; and transmitting, using the communication device, the avatar data to the user device, wherein the user device is configured to present the digital representation of the human on the user presentation device.
7. The method of claim 1 further comprises storing, using the processing device, the training result data in a database, wherein the generating of a second simulated training data at a second time instance is based on the training result data, wherein the training result data corresponds to the simulated training data generated at a first time instance, wherein the second time instance occurs after the first time instance.
8. The method of claim 2 further comprises: receiving, using the communication device, a user engagement data from the user device, wherein the user engagement data corresponds to an indication of the user engagement with the training module; generating, using the processing device, a user report data based on the user engagement data, wherein the user report data corresponds a user report of the cybersecurity training; and transmitting, using the processing device, the user report data to the user device.
9. The method of claim 2 further comprises determining, using the processing device, a cybersecurity data based on an external database, wherein the cybersecurity data corresponds to a cybersecurity detail, wherein the generating of the module data is further based on the cybersecurity data, wherein the training module corresponds to a visual representation of the cybersecurity data.
10. The method of claim 1, wherein the generating of the training result data is further based on a predefined criterion corresponding to a defensive cybersecurity solutionassociated with the user interaction, wherein the user utilizes the defensive cybersecurity solution to mitigate the cybersecurity threat, wherein the defensive cybersecurity solution corresponds to at least one of an endpoint detection and response, a security information and event management, an intrusion detection system, a data loss prevention, a nextgeneration antivirus, an access control system, a firewall, an operational technology, an internet of things, and a network switch.
11. A system of provisioning a cybersecurity training, wherein the system comprising: a communication device configured for: receiving a user data from a user device associated with a user, wherein the user data corresponds to a cybersecurity learning preference of the user; transmitting a simulated training data to the user device, wherein the user device is configured to present the simulated training data on a user presentation device comprised in the user device, wherein the training data facilitates the cybersecurity training based on a user interaction with the simulated environment; receiving an interaction data from the user device, wherein the interaction data corresponds to the user interaction; a processing device configured for: determining a threat data, wherein the threat data corresponds to a cybersecurity threat; generating the simulated training data based on each of the user data and the threat data, wherein the simulated training data corresponds to a simulated environment representing a simulation of at least one of the cybersecurity threat and a computer system; analyzing the interaction data; and generating a training result data based on the analyzing, wherein the training result data corresponds to a cybersecurity training result of the user.
12. The system of claim 11, wherein the processing device is further configured for generating a module data based on the user data, wherein the module data corresponds to a training module of the cybersecurity training, wherein the communication device is further configured for transmitting the module data to the user device, wherein the user device is configured to present the module data on the user presentation device, wherein the cybersecurity training is based on a user engagement with the training module.
13. The system of claim 11, wherein the simulated environment corresponds to a digital representation of a physical infrastructure associated with the computed system, wherein the simulated environment is configured to emulate a characteristic of the computer system, wherein the characteristic corresponds to at least one of a cyberattack response and a user action response, wherein the cyberattack response and the user action response corresponds to a response of the computer system in relation to the cybersecurity threat and the user interaction respectively.
14. The system of claim 13, wherein the computer system comprises at least one of a hardware device and a software application, wherein the simulated environment associated with at least one of a simulated hardware device and a simulated software application, wherein the simulated hardware device and the simulated software application corresponds to the simulation of at least one of the hardware device and the software application respectively.
15. The system of claim 11, wherein the communication device is further configured for: receiving a user query data from the user device, wherein the user query data corresponds to a user query corresponding to a cybersecurity learning; transmitting a response data to user device, wherein the user device is configured to present the response data on the user presentation device, wherein the processing device is further configured for: analyzing the user query data; andgenerating the response data based on the analyzing of the user query data, wherein the response data corresponds to a response to the user query, wherein the generating of the response data is further based on an Al model.
16. The system of claim 15, wherein the processing device is further configured for generating an avatar data, wherein the avatar data corresponds to a digital representation of a human emulating a human characteristic, wherein the human characteristic is associated with the response, wherein the communication device is further configured for transmitting the avatar data to the user device, wherein the user device is configured to present the digital representation of the human on the user presentation device.
17. The system of claim 11, wherein the processing device is further configured for storing the training result data in a database, wherein the generating of a second simulated training data at a second time instance is based on the training result data, wherein the training result data corresponds to the simulated training data generated at a first time instance, wherein the second time instance occurs after the first time instance.
18. The system of claim 12, wherein the communication device is further configured for: receiving a user engagement data from the user device, wherein the user engagement data corresponds to an indication of the user engagement with the training module; and transmitting a user report data to the user device, wherein the processing device is further configured for generating the user report data based on the user engagement data, wherein the user report data corresponds a user report of the cybersecurity training.
19. The system of claim 12, wherein the processing device is further configured for determining a cybersecurity data based on an external database, wherein the cybersecurity data corresponds to a cybersecurity detail, wherein the generating of the module data is further based on the cybersecurity data, wherein the training module corresponds to a visual representation of the cybersecurity data.
20. The system of claim 11, wherein the generating of the training result data is further based on a predefined criterion corresponding to a defensive cybersecurity solutionassociated with the user interaction, wherein the user utilizes the defensive cybersecurity solution to mitigate the cybersecurity threat, wherein the defensive cybersecurity solution corresponds to at least one of an endpoint detection and response, a security information and event management, an intrusion detection system, a data loss prevention, a nextgeneration antivirus, an access control system, a firewall, an operational technology, an internet of things, and a network switch.
Citation Information
Patent Citations
Mission-based, game-implemented cyber training system and method
US20220084431A1
System and Method for Social Engineering Cyber Security Training
US20220094702A1
System and methods to incentivize engagement in security awareness training
US20220377101A1
Cited By
Dynamic cybersecurity policy management based on contextual adaptive learning
US20260058995A1