Security action based on agentic ai system-initiated framework-based threat mappings
Patent Information
- Application Number
- PCT/US2026/011025
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2026-01-13
- Publication Date
- 2026-10-01
Smart Images

Figure US2026011025_01102026_PF_FP_ABST
Abstract
Description
SECURITY ACTION BASED ON AGENTIC Al SYSTEM-INITIATED FRAMEWORKBASED THREAT MAPPINGSBACKGROUND
[0001] A security threat analysis technique is a technique in which information regarding a system and / or a user of the system is analyzed to identify, assess, and / or address (e.g., investigate, triage, mitigate, contain, and / or remediate) a security threat to the system and / or the user. A security threat is an occurrence (e.g., an action or an absence of action) that is capable of causing or facilitating harm to a system and / or a user of the system. Modem security threat analysis techniques typically process substantial volumes of raw logs from diverse data sources, which sometimes complicate efforts to identify correlated occurrences that form a meaningful “security storyline.”
[0002] Signature-based or correlation-rule techniques have been introduced to process large volumes of raw logs. However, such techniques traditionally rely on manual rule-writing, static threshold settings, and known indicator-of-compromise (IOC) lists. Manually writing rules for each individual event (e.g., file creation, user login, or privilege change) in the raw logs is timeconsuming and ty pically requires substantial expertise regarding the sources from which the raw logs are received.
[0003] The signature-based or correlation rule techniques therefore may be inefficient, lack scalability, and / or increase a likelihood of missing attack patterns. Accordingly, the signaturebased or correlation-rule techniques may leave systems and / or users vulnerable to stealthy or evolving threats, especially threats that span multiple log entries from various sources.SUMMARY
[0004] It may be desirable to use an agentic artificial intelligence (Al) system to generate queries for identifying potential security threat activities among targeted log events. The queries are generated by clustering identified log events into clusters corresponding to the potential security threat activities and mapping the potential security threat activities to an attack framework. The queries are capable of being used to identify the potential security threat activities among the targeted log events, for example, by executing the queries against the targeted log events. In an aspect, by using the queries that are generated using the clustering and the mapping, the potential security threat activities are identified more accurately, precisely, and / or reliably than conventional security threat analysis techniques.
[0005] An agentic Al system is an Al system that includes multiple Al sub-agents. An Al system is a system that uses artificial intelligence to perform a task. Artificial intelligence is intelligence of a machine (e.g.. a computing system) and / or code (e.g.. software and / orfirmware), as opposed to intelligence of a living creature (e.g., a human). Al sub-agents are computer programs (e.g., standalone computer programs) that use artificial intelligence to perform respective sub-tasks, which are included in a task performed by the agentic Al system.
[0006] A potential security threat activity is an activity that is potentially associated with a security threat. In an aspect, the potential security threat activity is identified as being potentially associated with the security threat based on one or more factors (e.g., attribute(s) of log events associated with the potential security' threat activity satisfying a criterion). In an example, the potential security threat activity is identified as being potentially associated with the security' threat based on types of event logs that correspond to the potential security threat activity being associated with one or more historic security threats. A potential security threat activity that is deemed to be associated with a security threat is referred to as a “security' threat activity.” A security' threat activity is capable of causing or facilitating harm to a system and / or a user of the system. In an example, the system is a computing system (e.g., a personal computer, a server, or an Internet of things (loT) device), a network, a router, a switch, or a firewall. In another example, the harm is an unauthorized or illegal access to the system.
[0007] Various approaches are described herein for, among other things, performing a security' action based on agentic Al system-initiated framework-based threat mappings. In an example approach, subsets of a first plurality of log events are caused to be aggregated into clusters by a first Al agent as a result of the subsets corresponding to potential security' threat activities. The potential security threat activities are caused to be mapped to attack framework techniques and / or attack framework tactics by a second Al agent to provide framework-based threat mappings. Queries that define the potential security threat activities are caused to be generated by a third Al agent using the framework-based threat mappings. A designated potential security threat activity is caused to be identified in a second plurality of log events by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security’ threat activity. The potential security threat activities include the designated potential security threat activity. The queries include the designated query. A security action is performed with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality' of log events corresponding to the designated potential security threat.
[0008] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identity' key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. Moreover, it is noted that the invention is not limited to the specific embodiments described in the Detailed Description and / or othersections of this document. Such embodiments are presented herein for illustrative purposes only. Additional embodiments will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein.BRIEF DESCRIPTION OF THE DRAWINGS / FIGURESE
[0009] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments of the present invention and, together with the description, further serve to explain the principles involved and to enable a person skilled in the relevant art(s) to make and use the disclosed technologies.
[0010] FIG. 1 is a block diagram of an example multi-agent framework-based threat mapping system in accordance with an embodiment.
[0011] FIGS. 2-3 depict flowcharts of example methods for performing a security action based on agentic Al system-initiated framework-based threat mappings in accordance with embodiments.
[0012] FIGS. 4 depicts a flowchart of an example method for causing subsets of a first plurality of logs to be aggregated into clusters in accordance with an embodiment.
[0013] FIG. 5 is a block diagram of an example computing system in accordance with an embodiment.
[0014] FIG. 6 depicts an example algorithm used by a clustering Al sub-agent shown in FIG. 5 to aggregate log events in accordance with an embodiment.
[0015] FIG. 7 depicts an example algorithm used by a clustering Al sub-agent shown in FIG. 5 to define potential security threat activities in accordance with an embodiment.
[0016] FIG. 8 depicts an example algorithm used by a validating Al sub-agent shown in FIG. 5 to validate potential security threat activities in accordance with an embodiment.
[0017] FIG. 9 depicts an example computer in which embodiments may be implemented.
[0018] The features and advantages of the disclosed technologies will become more apparent from the detailed description set forth below when taken in conjunction with the drawings, in which like reference characters identify corresponding elements throughout. In the drawings, like reference numbers generally indicate identical, functionally similar, and / or structurally similar elements. The drawing in which an element first appears is indicated by the leftmost digit(s) in the corresponding reference number.DETAILED DESCRIPTIONI. Example Embodiments
[0019] It may be desirable to use an agentic artificial intelligence (Al) system to generate queries for identifying potential security threat activities among targeted log events. The queries are generated by clustering identified log events into clusters corresponding to the potentialsecurity threat activities and mapping the potential security threat activities to an attack framework. The queries are capable of being used to identify the potential security threat activities among the targeted log events, for example, by executing the queries against the targeted log events. In an aspect, by using the queries that are generated using the clustering and the mapping, the potential security threat activities are identified more accurately, precisely, and / or reliably than conventional security threat analysis techniques.
[0020] An agentic Al system is an Al system that includes multiple Al sub-agents. An Al system is a system that uses artificial intelligence to perform a task. Artificial intelligence is intelligence of a machine (e.g.. a computing system) and / or code (e.g.. software and / or firmware), as opposed to intelligence of a living creature (e.g., a human). Al sub-agents are computer programs (e.g., standalone computer programs) that use artificial intelligence to perform respective sub-tasks, which are included in a task performed by the agentic Al system.
[0021] An Al sub-agent includes or invokes one or more Al models. An Al model is a model that utilizes artificial intelligence to perform a task of an Al system or a sub-task of an Al subagent therein in response to an Al input that is received by the Al model. In an aspect, the Al model is an artificial general intelligence model. An artificial general intelligence model is an Al model (e.g., an autonomous Al model) that is configured to be capable of performing any task that an intelligent being (e.g., a human) is capable of performing. In an example implementation, the artificial general intelligence model is capable of performing a task that surpasses the capabilities of an animal.
[0022] An Al input indicates (e.g., specifies) a task of an Al system or a sub-task of an Al subagent that is to be performed by an Al model. Examples of an Al input include but are not limited to an Al prompt and an application programming interface (API) input. An Al prompt is an Al input that causes an Al model to generate an answer that is responsive to the Al prompt. An answer to an Al prompt is referred to herein as an “Al response.” Examples of an Al prompt include but are not limited to a zero-shot prompt, a one-shot prompt, and a few-shot prompt. A zero-shot prompt is a prompt that indicates a task or a sub-task to be performed by an Al model that has not been trained on example(s) of the task or the sub-task. A one-shot prompt is a prompt that includes a target prompt along with a single example prompt and a single example answer that is responsive to the single example prompt. The example prompt and the example answer provide guidance as to how the Al model is expected to respond to the target prompt. A few-shot prompt is a prompt that includes a target prompt along with multiple example prompts and multiple example answers that are responsive to the respective example prompts. The example prompts and the example answers provide guidance as to how the Al model is expected to respond to the target prompt.
[0023] In an example, an Al prompt is a natural language prompt. A natural language prompt is a prompt that is written in a natural language. A natural language is a human language that has developed through use and repetition. In an example, the natural language has developed naturally without conscious planning or premeditation. Examples of a natural language include English, French. Spanish, and Mandarin. In an aspect, the natural language prompt is generated by a user (e.g., a human). In another aspect, the natural language prompt is generated by a computing system (e.g., an Al assistant that runs on the computing system).
[0024] In another example, an Al prompt is not written in a natural language. In an implementation of this example, the Al prompt includes (e.g., is) computer code. The Al prompt may be any suitable sequence of characters that is capable of being interpreted by an Al model.
[0025] An API input is an Al input that is provided via an API to request a service or a function. An API is an interface between a computing system and code (e.g., software or firmware).
[0026] Each of the Al sub-agents of the agentic Al system is capable of utilizing any one or more tools to perform a sub-task that the Al sub-agent is configured to perform. In an example, an Al sub-agent uses multiple tools to perform respective portions of its sub-task. In accordance with this example, the sub-task comprises multiple operations that define the respective portions. A tool is functionality (e.g., a sub-routine) that is configured to perform a particular type of operation. Example types of functionality include but are not limited to querying a database, executing code (e.g., an executable file), comparing particular types of data, and generating a particular type of output (e.g., a picture). A tool that includes functionality of an Al model is referred to herein as an "Al tool.’' Each Al tool may include its own Al model, though the example embodiments are not limited in this respect. Examples of a particular type of operation that is capable of being performed by functionality of an Al model include but are not limited to random forest learning, isolation forest anomaly detection, naive Bayes classification, K-nearest neighbors classification, K-nearest neighbors regression, gradient boosting, support vector machine (SVM) classification, linear regression, nonlinear regression, Poisson regression, quantile regression, nonparametric regression, stratified random sampling, cluster random sampling, systematic random sampling, frequency analysis, and P-value analysis.
[0027] Random forest learning is a supervised ensemble learning technique that uses multiple decision trees to determine likelihoods of outcomes (e.g., to make predictions). The random forest learning technique includes building the multiple decision trees (i.e., forest of decision trees), training each decision tree on a respective random subset of data, and aggregating outputs (e.g., predictions) of the respective decision trees to provide an output of the random forest learning technique.
[0028] Isolation forest anomaly detection is an unsupervised anomaly detection technique that isconfigured to identify outliers (i.e., anomalies) in a dataset. The isolation forest anomaly detection technique isolates observations by randomly selecting a feature and randomly selecting a split value in a range of the feature. A relatively shorter path indicates an anomaly.
[0029] Naive Bayes classification is a supervised classification technique that determines (e.g., predicts) a probability of an instance belonging to a class based on specified feature values. The naive Bayes classification technique assumes that features having the specified feature values are conditionally independent for the class.
[0030] K-nearest neighbors classification classifies an unlabeled data point to the class that is most common among its K nearest neighbors. K is a positive integer.
[0031] K-nearest neighbors regression estimates (e.g., predicts) an average value of a property based on values of its K nearest neighbors.
[0032] Gradient boosting is an ensemble learning technique that combines multiple weak learners (e.g., decision trees) to create a stronger model. The gradient boosting technique starts with an initial value (e.g., a mean of a target variable), and subsequent models are trained to minimize residual errors (i.e., differences between actual and estimated (e.g., predicted) values. Gradient boosting can be used for classification and regression.
[0033] SVM classification is a supervised classification technique that is configured to identify the largest gap between data points of different classes.
[0034] Linear regression estimates a linear relationship between a dependent variable and one or more independent variables. The linear regression technique is configured to identify the bestfitting line that represents a general trend of a dataset.
[0035] Nonlinear regression fits data to a mathematical function that does not follow a straight line.
[0036] Poisson regression analyzes count data by modeling a log-linear relationship between predictors (i.e., features) and expected counts. The Poisson regression technique assumes that a response variable Y has a Poisson distribution and that a logarithm of an expected value of Y can be modeled by a linear combination of unknown parameters.
[0037] Quantile regression estimates conditional quantiles (e.g., median, quartiles) of a response variable.
[0038] Nonparametric regression is a regression technique in which a predictor (i.e., feature) does not assume a predefined form. Rather, the nonparametric regression technique constructs a relationship between predictors and a dependent variable based on data information.
[0039] Stratified random sampling is a sampling technique in which a dataset is divided into homogeneous subsets based on respective attributes. Each data point of the dataset is included in a single homogeneous subset. A random sample is selected from each homogeneous subsetusing another sampling technique.
[0040] Cluster random sampling is a sampling technique in which a dataset is divided into clusters, and data points are randomly selected from the clusters to form a sample.
[0041] Systematic random sampling is a sampling technique in which data points are selected from a dataset at regular predefined intervals to form a sample.
[0042] Frequency analysis is a technique that determines a frequency with which a data point occurs in a dataset.
[0043] P-value analysis is a technique that determines a probability value (i.e., a p-value) indicating a likelihood that observed data could have occurred under the null hypothesis. The null hypothesis is that no relationship exists between variables of interest or no difference exists among groups. A relatively low p-value indicates that the observed data is inconsistent with the null hypothesis. In an aspect, the observed data being inconsistent with the null hypothesis indicates that another hypothesis likely is better supported by the observed data. A relatively high p-value indicates that the observed data is consistent with the null hypothesis.
[0044] In an aspect, a process of performing a security action based on agentic Al system-initiated framework-based threat mappings includes multiple steps, and each Al sub-agent is configured to perform a respective step of the process. In an example, the purpose of each Al sub-agent is to perform the respective step of the process. In another example, by focusing on a particular step, an Al sub-agent is capable of performing the particular step more accurately, precisely, and / or reliably than a more generic computer program that is configured to perform more (e.g., all) of the steps. In yet another example, the Al sub-agents achieving their respective purposes more accurately, precisely, and / or reliably than a more generic computer program would be capable of doing so increases security of a system and / or a user of the system.
[0045] In an aspect, an Al sub-agent is an autonomous Al sub-agent. An autonomous Al subagent is an Al sub-agent that is configured to select one or more Al tools of an Al model (e.g., in real-time) based on one or more factors to achieve a purpose for which the autonomous Al subagent is configured. In an example, the autonomous Al sub-agent selects first Al tool(s) of the Al model based on existence of first factor(s); the autonomous Al sub-agent selects second Al tool(s) of the Al model based on existence of second factor(s), and so on. In another example, the autonomous Al sub-agent uses multiple Al tools simultaneously to obtain respective results, and the autonomous Al sub-agent selects the most common result among those results to serve as an output of the autonomous Al sub-agent. By ‘'autonomous,” it is meant that each autonomous Al sub-agent is capable of operating in absence of the other autonomous subagents. Nevertheless, output of any one or more autonomous Al sub-agents may be used as input to any one or more other autonomous Al sub-agents.
[0046] A log indicates (e.g., identifies, specifies, or describes) events that occur with regard to one or more entities. An event that is indicated by a log is referred to herein as a "log event.” In an example, the log is generated based on (e.g., based at least on) an operation initiated by an application or a user. In accordance with this example, the application is a process that is incorporated into a system (i.e.. a built-in system process) or a custom application that is generated by a user of the system. Examples of an entity include but are not limited to a user, an application, a computing system, and an Internet Protocol (IP) address. In an aspect, the log pertains to a particular period of time.
[0047] Examples of a log include but are not limited to a system log, an application log, a security log, a network log, an audit log, an event log, a transaction log, a performance log, a firewall log, and an intrusion detection system (IDS) log. A system log is a log that indicates (e.g., identifies or memorializes) events related to an operating system (e.g., start up events, shutdown event, system errors, and / or hardware changes). An application log is a log that indicates events that are specific to one or more applications (e.g., software errors, user interactions, and / or application-specific messages). A security log is a log that indicates security-related events (e.g., login attempts, access control changes, and / or unauthorized access attempts). A network log is a log that indicates network activity (e.g., data transfer, connection attempts, and / or network errors). An audit log is a log that indicates system and user activity for purposes of accountability' and compliance with policies. An event log is a log that indicates events in categories that are deemed to be significant (e.g., system warnings, errors, and / or informational messages). A transaction log is a log that indicates transactions performed by application(s). A performance log is a log that indicates performance metrics (e.g., central processing unit (CPU) usage, memory usage, and / or response times). A firewall log indicates traffic that encounters or passes through a firewall, including allowed and blocked connections. An IDS log indicates potential security' incidents that are detected by an IDS.
[0048] A potential security threat activity is an activity that is potentially associated with a security threat. In an aspect, the potential security threat activity is identified as being potentially associated with the security threat based on one or more factors (e.g., attribute(s) of log events associated with the potential security threat activity satisfying a criterion). In an example, the potential security threat activity is identified as being potentially associated with the security threat based on types of event logs that correspond to the potential security threat activity being associated with one or more historic security threats. A potential security threat activity that is deemed to be associated with a security threat is referred to as a “security' threat activity.” A security threat activity is capable of causing or facilitating harm to a system and / or a user of the system. In an example, the system is a computing system (e.g., a personal computer, a server, oran Internet of things (loT) device), a network, a router, a switch, or a firewall. In another example, the harm is an unauthorized or illegal access to the system.
[0049] In an aspect, a potential security' threat activity7represents a category that includes multiple log event types. A log event type includes one or more log events that share one or more common attributes. Examples of a log event type include but are not limited to file creation (i.e., creating a file), file modification (i.e., modifying a file), file opening (i.e., opening a file), file deletion (i.e., deleting a file), permission grant (i.e., granting permission(s)), permission denial (i.e., denying permission(s)), addition to group (i.e., adding a user to a group), removal from group (i.e.. removing a user from a group), group modification (i.e., modifying a group), log in (i.e., a user attempting to log into a system), log out (i.e., a user logging out of a system). Examples of a potential security7threat activity7include but are not limited to file manipulation, management activity, and authentication. In a first example, the “file manipulation"’ potential security7threat activity includes any one or more of the following log event types: file creation, file modification, file opening, and / or file deletion. In a second example, the “management activity ” potential security threat activity includes any7one or more of the following log event ty pes: permission grant, permission denial, addition to group, removal from group, and / or group modification. In a third example, the “authentication” potential security threat activity includes any one or more of the following log event types: log in and log out.
[0050] One example of a security7threat is a cyberattack. A cyberattack is an attempt to cause harm to a system and / or a user of the system. Examples of a cyberattack include but are not limited to a denial of service (DoS) attack, a distributed DoS (DDoS) attack, a man-in-the-middle (MITM) attack, a malware attack, a phishing attack, a ransomware attack, and a crosssite scripting (XSS) attack. A DoS attack is a cyberattack that renders a system unable to respond to a legitimate sen ice request by overwhelming resource(s) of the system. A DDoS attack is similar to a DoS attack but involves multiple (e.g., a vast array) malware-infected hosts that are controlled by the threat actor to cause resource exhaustion. An MITM attack is a cyberattack that enables the threat actor to eavesdrop on data exchanged between multiple entities (e.g., people, networks, or computers). A malware attack is a cyberattack in which malicious software is introduced (e.g., injected) to a system to damage the system and / or to steal information from the system. A phishing attack is a cyberattack in which a deceptive communication (e.g., an electronic mail (i.e., email) message) is provided to an entity to trick the entity7into revealing sensitive information or into downloading malware. A ransomware attack is a cyberattack that encry pts file(s) and / or system(s) and demands payment (i.e., a ransom) for decryption. An XSS attack is a cyberattack that exploits a vulnerability of a web application to introduce a malicious script into a web page that is viewed by other users.
[0051] An atack framework is a set of guideline(s) and / or standard(s) that are configured to, when implemented, increase security of a system and / or a user of the system. In an aspect, the attack framework provides a structured approach to identifying, protecting, detecting, responding to, and / or recovering from a security threat. In another aspect, the attack framework indicates (e.g.. identifies, defines, specifies, or describes) one or more tactics, one or more techniques, one or more procedures, and / or one or more sub-techniques. A tactic indicated by an attack framework is referred to herein as an “atack framework tactic.” An atack framework tactic indicates a technical goal of a threat actor associated with the security threat (e.g.. gaining initial access, executing malicious code, or exfiltrating data). A threat actor is an entity (e.g., a person, a group of people, or a system (e.g., an autonomous agent)) that intentionally causes (or tries to cause or is configured to cause) harm to a system and / or a user of the system. A technique indicated by an atack framework is referred to herein as an “atack framework technique.” An atack framework technique is a method to execute an atack framework tactic (e.g., a particular atack framework tactic). In an aspect, the atack framework technique includes multiple atack framework sub-techniques. An atack framework sub-technique is a method to execute a portion of an atack framework tactic. In accordance with this aspect, the multiple atack framework sub-techniques perform respective portions of an atack framework tactic. In an example, a first atack framework sub-technique performs a first portion of an atack framework tactic; a second atack framework sub-technique performs a second portion of an attack framework tactic, and so on. Any two or more of the atack framework sub-techniques may be mutually exclusive or overlap. A procedure indicated by an attack framework is referred to herein as an “atack framework procedure.” An attack framework procedure is an action plan that describes steps that are to be performed to execute an atack framework technique (e.g., a particular atack framework technique).
[0052] Examples of an atack framework include but are not limited to a MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK®) framework, developed and published by The MITRE Corporation; a Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE™) framework, developed and published by Microsoft Corporation; a National Institute of Standards and Technology (NIST®) Cybersecurity Framework, developed and published by NIST; an OWASP Top Ten® framework, developed and published by OWASP Foundation; a Center for Internet Security Controls (CIS Controls®) framework, developed and published by the Center for Internet Security, Inc.; and an International Organization for Standardization / Intemational Electrotechnical Commission 27001 (ISO / IEC 27001®) framework, developed and published by the International Organization for Standardization and the International ElectrotechnicalCommission.
[0053] Example embodiments described herein are capable of performing a security action based on agentic Al system-initiated framework-based threat mappings. Example techniques described herein have a variety of benefits as compared to conventional security threat analysis techniques. For instance, the example techniques are capable of identifying potential security threat activities more accurately, precisely, and / or reliably than conventional security threat analysis techniques. By increasing accuracy, precision, and / or reliability’ (e.g., statistical accuracy, statistical precision, and / or statistical reliability) with which the potential security threat activities are identified, the example techniques reduce a likelihood of missing (e.g., overlooking) a potential security threat activity indicated by log events. The example techniques are capable of identifying the potential security threat activities more quickly and / or efficiently than the conventional security threat analysis techniques. In an aspect, by using queries, which are generated by an agentic Al system using clustering of log events with regard to potential security threat activities and mapping of the potential security threat activities to an attack framework, to identify the potential security threat activities among log events, the statistical accuracy, precision, reliability’, speed, and / or efficiency with which the potential security' threat activities are identified is increased. The example techniques are capable of reducing noise and duplication in a dataset that is used to identify the potential security threat activities, reduce a volume of data stored in expensive real-time databases, and / or provide an end-to-end automated workflow for identifying the potential security threat activities.
[0054] The example techniques reduce (e.g., eliminate) a need for expertise regarding sources from which the event logs are received, for example, by using the clustering and the mapping for generation of the queries. The example techniques are capable of increasing security of a system and / or a user of the system to a greater extent than conventional security threat analysis techniques, for example, as a result of the increased accuracy, precision, reliability, speed, and / or efficiency with which the potential security threat activities are identified (e.g., in context of the system). For instance, the example techniques are capable of increasing threat detection coverage. The example techniques are capable of scaling to vast and evolving log volumes and security threats without sacrificing the accuracy, precision, reliability, speed, and / or efficiency with which the potential security threat activities are identified.
[0055] The example techniques are capable of reducing an amount of time and / or resources (e.g., processor cycles, memory’, network bandwidth) that is consumed (e.g., by a computing system) to identify' a potential security threat activity and / or to address (e.g., investigate, triage, mitigate, contain, and / or remediate) the potential security threat activity. In an example, by reducing the amount of time and / or resources that is consumed by a computing system toidentify the potential security threat activity and / or to address the potential security threat activity, efficiency of the computing system is increased. In another example, by reducing the amount of time and / or resources that is consumed by the computing system to identify the potential security threat activity and / or to address the potential security threat activity, a cost associated with identifying and / or addressing the potential security threat activity is reduced.
[0056] In a first aspect, by causing, by a first Al sub-agent, subsets of a first plurality of log events to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities; causing, by a second Al sub-agent, the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics to provide framework-based threat mappings; causing, by a third Al sub-agent, queries that define the potential security threat activities to be generated using the framework-based threat mappings; and / or causing a designated potential security threat activity to be identified in a second plurality of log events by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity, the example techniques reduce the amount of time and / or resources that otherwise would have been consumed to identify the designated potential security threat activity.
[0057] In a second aspect, by causing, by a first Al sub-agent, subsets of a first plurality of log events to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities; causing, by a second Al sub-agent, the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics to provide framework-based threat mappings; causing, by a third Al sub-agent, queries that define the potential security threat activities to be generated using the framework-based threat mappings; causing a designated potential security threat activity to be identified in a second plurality of log events by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity, the example techniques reduce the amount of time and / or resources that otherwise would have been consumed to identify the potential security threat activity; and / or performing a security action with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat, the designated potential security threat activity is addressed more quickly and / or efficiently, thereby reducing the amount of time and / or resources that is consumed to do so.
[0058] The example techniques are capable of automating at least some (e.g., all) aspects of performing a security' action based on agentic Al system-initiated framework-based threat mappings. In an example implementation, the example techniques automate any one or more (e.g., all) of the operations described above with regard to the first and second aspects. Byautomating one or more of the operations described above with regard to the first and second aspects, the example techniques reduce a number of the operations that are manually performed by an IT professional, which enables the IT professional to focus on other tasks. By automating one or more of the operations described above with regard to the first and second aspects, the example techniques reduce a cost of identifying and / or addressing the designated potential security threat activity mentioned therein. Accordingly, the example techniques are capable of reducing a cost of performing a security action based on agentic Al system-initiated frameworkbased threat mappings. In an aspect, by automating an operation described above with regard to the first or second aspect, the example embodiments eliminate a cost associated with time that otherwise would have been spent by an information technology (IT) professional to manually perform the operation.
[0059] In a first example, reducing the amount of time and / or resources that is consumed by a computing system to identify and / or address a potential security threat activity includes causing, by a first Al sub-agent, an Al model, which is utilized by the first Al sub-agent to aggregate subsets of a plurality of log events into clusters, to incrementally process respective portions of information regarding the plurality of log events. The Al model incrementally processes the respective portions of the information by limiting sizes of the respective portions to be less than or equal to a token limit of the Al model.
[0060] In a second example, reducing the amount of time and / or resources that is consumed by the computing system to identify and / or address a potential security threat activity includes causing the subsets of the plurality of log events to be sampled to provide sampled subsets of the plurality of log events, wherein the sampled subsets of the plurality of log events include fewer log events than the aforementioned subsets. In accordance with the second example, reducing the amount of time and / or resources that is consumed by the computing system further includes causing, by a second Al sub-agent, potential security threat activities that correspond to respective clusters of the plurality of log events to be mapped to attack framework techniques and / or attack framework tactics using the sampled subsets of the plurality of log events in lieu of the aforementioned subsets to provide framework -based threat mappings.
[0061] In an aspect, by causing (by the first Al sub-agent) the respective portions of the information regarding the plurality of log events to be incrementally processed, causing the subsets of the plurality of log events to be sampled, and / or causing (by the second Al sub-agent) the potential security threat activities to be mapped to the attack framework techniques and / or the attack framework tactics using the sampled subsets, as described in the first and second examples mentioned above, the example techniques reduce the amount of time and / or resources that is consumed by the computing system to identify and / or address the potential security threatactivity without compromising accuracy, precision, and / or reliability of the identification of the potential security threat activity.
[0062] By reducing the amount of time and / or resources that is consumed by a computing system to identify a potential security threat activity and / or to address the potential security threat activity with regard to a system, the example techniques are capable of increasing a user experience and / or efficiency of an IT professional who manages security of the system. The example techniques are capable of increasing a user experience and / or efficiency of an end user who uses the system, for example, by increasing security of the system. In an example, the user experience of the IT professional and / or the end user is increased in other ways, as well. In accordance with this example, the user experience and / or the efficiency is increased through a more accurate, precise, reliable, speedy, and / or efficient identification and / or address (e.g., investigation, triage, mitigation, containment, and / or remediation) of the potential security threat activity.
[0063] FIG. 1 is a block diagram of an example multi-agent framework-based threat mapping system 100 in accordance with an embodiment. Generally speaking, the multi-agent frameworkbased threat mapping system 100 operates to provide information to users in response to requests (e g., hypertext transfer protocol (HTTP) requests) that are received from the users. In an aspect, the information includes documents (Web pages, images, audio files, video files, etc.), output of executables, and / or any other suitable type of information. In accordance with example embodiments described herein, the multi-agent framework-based threat mapping system 100 performs a security action based on agentic Al system-initiated framework-based threat mappings. Detail regarding techniques for performing a security action based on agentic Al system-initiated framework-based threat mappings is provided in the following discussion.
[0064] As shown in FIG. 1, the multi-agent framework-based threat mapping system 100 includes a plurality of user devices 102A-102M, a network 104, and a plurality of servers 106A-106N. Communication among the user devices 102A-102M and the servers 106A-106N is carried out over the network 104 using well-known network communication protocols. In an aspect, the network 104 is a wide-area network (e.g., the Internet), a local area network (LAN), another type of network, or a combination thereof.
[0065] The user devices 102A-102M are computing systems that are capable of communicating with servers 106A-106N. A computing system is a system that includes at least a portion of a processor system such that the portion of the processor system includes at least one processor that is capable of manipulating data in accordance with a set of instructions. A processor system includes one or more processors. In an example, the one or more processors are on a same (e.g., single) device. In another example, the one or more processors are distributed among multiple(e.g., separate) devices. For instance, a computing system may be a computer, a personal digital assistant, etc. The user devices 102A-102M are configured to provide requests to the servers 106A-106N for requesting information stored on (or otherwise accessible via) the servers 106A-106N. In an example, a user initiates a request for executing a computer program (e g., an application) using a client (e.g.. a Web browser, Web crawler, or other type of client) deployed on a user device 102 that is owned by or otherwise accessible to the user. In accordance with some example embodiments, the user devices 102A-102M are capable of accessing domains (e.g., Web sites) hosted by the servers 104A-104N, so that the user devices 102A-102M are able to access information that is available via the domains. In an aspect, the domain include Web page(s). In an example the Web page(s) are provided as hypertext markup language (HTML) documents and objects (e.g., files) that are linked therein.
[0066] Each of the user devices 102A-102M may include any client-enabled system or device, including but not limited to a desktop computer, a laptop computer, a tablet computer, a wearable computer such as a smart watch or a head-mounted computer, a personal digital assistant, a cellular telephone, an Internet of things (loT) device, or the like. It will be recognized that any one or more of the user devices 102A-102M may communicate with any one or more of the servers 106A-106N.
[0067] The servers 106A-106N are computing systems that are capable of communicating with the user devices 102A-102M. The servers 106A-106N are configured to execute computer programs that provide information to users in response to receiving requests from the users. In an example, the information includes documents (Web pages, images, audio files, video files, etc.), output of executables, or any other suitable t pe of information. In accordance with some example embodiments, the servers 106A-106N are configured to host respective Web sites, so that the Web sites are accessible to users of the multi-agent framew ork-based threat mapping system 100.
[0068] One example type of computer program that may be executed by one or more of the servers 106A-106N is a computer security program. A computer security program is a computer program that provides security with regard to information and / or communications associated with a computing system. In an example, the information associated with the computing system includes information stored on the computing system and / or information accessed (e.g., read) by the computing system. In another example, the communications associated with the computing system includes communications received by the computing system and / or communications provided (e.g., transmitted) by the computing system. An example of a communication is an electronic message. Examples of a computer security program include Bitdefender® security' program, developed and distributed by Bitdefender IPR Management Ltd.; Norton® security’program, developed and distributed by Gen Digital Inc.; Avast® security program, developed and distributed by Avast Software S.R.O.; McAfee® security program, developed and distributed by McAfee, LLC; and Microsoft Defender® security program, developed and distributed by Microsoft Corporation. In an example implementation, one or more of the example techniques described herein are implemented using a computer security’ program. In an example, a software product (e.g., a subscription sendee, a non-subscription service, or a combination thereof) includes the computer security program, and the software product is configured to perform the example techniques.
[0069] In an aspect, the computer security program is a cloud native application protection platform (CNAPP). A CNAPP is an all-in-one platform that unifies security and compliance capabilities to prevent, detect, and respond to cloud security threats. A CNAPP integrates multiple cloud security solutions, which traditionally have been siloed, into a common (e.g., single) user interface. In an example, the cloud security solutions include cloud security posture management (CSPM), multipipehne development and operations (DevOps) security, a cloud workload protection platform (CWPP), cloud infrastructure entitlement management (CIEM), and / or cloud service network security’ (CSNS). CSPM provides a connected, prioritized view of potential vulnerabilities and misconfigurations across multi-cloud and hybrid environments. The CSPM continuously assesses overall security posture of a system and provides automated alerts and recommendations about critical issues that could expose the system to data breaches. In an example, the CSPM includes automated compliance management and remediation tools to identify and remedy compliance deficiencies. Multipipehne DevOps security’ provides a central console that enables management of DevOps security across multiple (e.g., all) pipelines. In an example, the multipipeline DevOps security is used to reduce cloud misconfigurations and to scan new code to keep vulnerabilities therein from reaching a production environment. In another example, the multipipeline DevOps security includes infrastructure-as-code scanning tools that analyze configuration files from the earliest stages of development to confirm that new configuration files are compliant with security policies. A CWPP provides real-time detection and response to threats based on up-to-date information regarding multi-cloud workloads (e.g., virtual machines, containers, Kubemetes, databases, storage accounts, network layers, and app senices). In an example, the CWPP enables a quick investigation into threats and reduce the attack surface of a system. CIEM centralizes permissions management across a cloud and hybrid footprint, which inhibits (e.g., prevents) accidental or malicious misuse of permissions. CSNS complements the CWPP by protecting cloud infrastructure in real time. In an example, the CSNS includes one or more security tools. Examples of a security tool include but are not limited to distributed denial-of-service protection, a web application firewall, transport layersecurity examination, and load balancing.
[0070] In an aspect, a computer security program is incorporated into a cloud computing program (e.g., a cloud senice). A cloud computing program is a computer program that provides hosted service(s) via a network (e.g., network 104). In an example, the hosted service(s) are hosted by any one or more of the servers 106A-106N. In another example, the cloud computing program enables users (e g., at any of the user systems 102A-102M) to access shared resources that are stored on or are otherwise accessible to the server(s) via the network.
[0071] In an example of this aspect, the cloud computing program provides hosted service(s) according to a service model. Examples of a service model include but not limited to Backend as a Service (BaaS), Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Senice (laaS). BaaS enables applications (e.g., software programs) to use a BaaS provider’s backend services (e.g., push notifications, integration with social networks, and cloud storage) running on a cloud infrastructure. SaaS enables a user to use a SaaS provider's applications running on a cloud infrastructure. PaaS enables a user to develop and run applications using a PaaS provider’s application development environment (e.g., operating system, programminglanguage execution environment, database) on a cloud infrastructure. laaS enables a user to use an laaS provider’s computer infrastructure (e.g., to support an enterprise). In an example, laaS provides to the user virtualized computing resources that utilize the laaS provider’s physical computer resources.
[0072] Examples of a cloud computing program include but are not limited to a Google Cloud® program developed and distributed by Google Inc.; an Oracle Cloud® program developed and distributed by Oracle Corporation; an Amazon Web Services® program developed and distributed by Amazon.com, Inc.; a Salesforce® program developed and distributed by Salesforce.com, Inc.; an AppSource® program developed and distributed by Microsoft Corporation; an Azure® program developed and distributed by Microsoft Corporation; a GoDaddy® program developed and distributed by GoDaddy.com LLC; and a Rackspace® program developed and distributed by Rackspace US, Inc. In an aspect, one or more of the example techniques described herein are implemented using a cloud computing program. In an example, a software product (e.g., a subscription sendee, a non-subscription service, or a combination thereof) includes the cloud computing program, and the software product is configured to perform the example techniques.
[0073] The first server(s) 106A are shown to include multi-agent framework-based threat mapping logic 108 for illustrative purposes. The multi-agent framework-based threat mapping logic 108 is configured to perform a security7action based on agentic Al system-initiated framework-based threat mappings. In an example implementation, a first Al sub-agent in themulti-agent framework-based threat mapping logic 108 causes subsets of a first plurality of log events to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities. A second Al sub-agent in the multi-agent framework-based threat mapping logic 108 causes the potential security threat activities to be mapped to attack framework techniques and / or attack framework tactics to provide framework-based threat mappings. A third Al sub-agent in the multi-agent framework-based threat mapping logic 108 causes queries that define the potential security threat activities to be generated using the framework-based threat mappings. The multi-agent framework-based threat mapping logic 108 (e.g., a fourth Al subagent in the multi-agent framework-based threat mapping logic 108) causes a designated potential security threat activity to be identified in a second plurality of log events. The multiagent framework-based threat mapping logic 108 causes the designated potential security' threat activity to be identified by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity. The potential security threat activities include the designated potential security threat activity. The queries include the designated query. The multi-agent framework-based threat mapping logic 108 performs a security' action with regard to an identified subset of the second plurality' of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat.
[0074] The multi-agent framework-based threat mapping logic 108 may be implemented in various ways to perform a security- action based on agentic Al system-initiated framework-based threat mappings, including being implemented in hardware, software, firmware, or any combination thereof. In an aspect, the multi-agent framework-based threat mapping logic 108 is implemented as computer program code configured to be executed in one or more processors. In another aspect, at least a portion of the multi-agent framework-based threat mapping logic 108 is implemented as hardware logic / electrical circuitry. In an example of this aspect, at least a portion of the multi-agent framework-based threat mapping logic 108 is implemented in a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), an application-specific standard product (ASSP), a system-on-a-chip system (SoC), and / or a complex programmable logic device (CPLD). In an example, each SoC includes an integrated circuit chip that includes one or more of a processor (a microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or further circuits and / or embedded firmware to perform its functions.
[0075] In an aspect, the multi-agent framework-based threat mapping logic 108 is (or is included in) a computer security program and / or a cloud computing program.
[0076] The multi-agent framework-based threat mapping logic 108 is shown to be incorporatedin the first server(s) 106A for illustrative purposes and is not intended to be limiting. It will be recognized that the multi-agent framework-based threat mapping logic 108 (or any portion(s) thereof) may be incorporated in any one or more of the servers 106A-106N, any one or more of the user devices 102A-102M, or any combination thereof. In an example, client-side aspects of the multi-agent framework-based threat mapping logic 108 are incorporated in one or more of the user devices 102A-102M, and server-side aspects of multi-agent framework-based threat mapping logic 108 are incorporated in one or more of the servers 106A-106N.
[0077] FIGS. 2-3 depict flowcharts 200 and 300 of example methods for performing a security action based on agentic Al system-initiated framework-based threat mappings in accordance with embodiments. FIGS. 4 depicts a flowchart 400 of an example method for causing subsets of a first plurality of logs to be aggregated into clusters in accordance with an embodiment. In an aspect, flowcharts 200, 300, and 400 are performed by the first server(s) 106A shown in FIG. 1, for example. For illustrative purposes, flowcharts 200, 300, and 400 are described with respect to a computing system 500 shown in FIG. 5, which is an example implementation of the first server(s) 106 A. As shown in FIG. 5, the computing system 500 includes multi-agent frameworkbased threat mapping logic 508 and a store 510. The multi-agent framework-based threat mapping logic 508 includes a parsing Al sub-agent 512, a clustering Al sub-agent 514, a mapping Al sub-agent 516, a querying Al sub-agent 518. identification logic 520, security action logic 522, a validating Al sub-agent 524, a consolidating Al sub-agent 526, and a splitting Al sub-agent 528. The store 510 may be any suitable type of store. One type of store is a database. Examples of a database include but are not limited to a relational database, an entityrelationship database, an object database, an object relational database, and an extensible markup language (XML) database. The store 510 is shown to store attack framework information 550 and token limit information 552 for non-limiting, illustrative purposes. Further structural and operational embodiments will be apparent to persons skilled in the relevant art(s) based on the discussion regarding flowcharts 200, 300, and 400.
[0078] As shown in FIG. 2, the method of flowchart 200 begins at step 202. In step 202, subsets of a first plurality of log events are caused, by a first Al sub-agent, to be aggregated into clusters as a result of the subsets corresponding to potential security' threat activities. In an example implementation, the clustering Al sub-agent 514 causes subsets of first log events 532 to be aggregated into the clusters as a result of the subsets corresponding to the potential security¬ threat activities. In an aspect, the potential security threat activity’ information 542 cross-references the subsets of the first plurality' of log events and the potential security threat activities. In accordance with this aspect, the potential security' threat activity' information 542 further indicates the subsets of the first plurality of log events. In an example, the potentialsecurity threat activity information 542 cross-references a first subset of the first plurality of log events with a first potential security threat activity; the potential security7threat activity information 542 cross-references a second subset of the first plurality of log events with a second potential security threat activity that is different from the first potential security threat activity; the potential security threat activity information 542 cross-references a third subset of the first plurality of log events with a third potential security threat activity7that is different from the first potential security threat activity7and the second potential security threat activity7, and so on. In another aspect, the subsets of the first plurality of log events are mutually exclusive. In yet another aspect, any two or more of the subsets of the first plurality of log events may overlap. The clustering Al sub-agent 514 generates potential security threat activity information 542, which indicates (e.g., identifies, defines, specifies, or describes) the potential security threat activities.
[0079] In an example embodiment, an Al model is utilized by the first Al sub-agent to aggregate the subsets of the first plurality7of log events into the clusters. In accordance with this embodiment, causing the subsets of the first plurality of logs to be aggregated into the clusters at step 202 includes causing, by the first Al sub-agent, the Al model to incrementally process respective portions of information regarding the first plurality of log events by causing the Al model to limit sizes of the respective portions to be less than or equal to a token limit of the Al model. A token limit of an Al model represents a maximum amount of data that the Al model is capable of processing with regard to an Al input. In an example, the token limit is 4096 tokens, 8192 tokens, or 16,384 tokens. In an aspect, an Al input, which requests aggregation of the subsets of the first plurality of log events into the clusters, is provided by the first Al sub-agent to the Al model. In accordance with this aspect, the Al input indicates that the sizes of the respective portions of the information, which are to be incrementally processed, are to be less than or equal to the token limit of the Al model. In an example of this aspect, the Al input is provided together with contextual information, which includes the information, as inputs to the Al model. In another aspect, the information includes (e.g.. is) the first plurality of log events.
[0080] In an aspect of this embodiment, limiting the sizes of the respective portions of the information to be less than or equal to the token limit of the Al model reduces a likelihood of the Al model generating a hallucination or an incomplete reference. A hallucination is an Al response that is generated by an Al model in response to an Al request and that is incorrect, nonsensical, or irrelevant with regard to the Al request or references (e.g., utilizes) information that does not exist. In an example, the information includes (e.g., is) data or an entity7, such as a source of the data. An incomplete reference is an indication of a source of information (e.g., a citation) for which existence or credibility of the source unverifiable.
[0081] In an example implementation, the clustering Al sub-agent 514 causes (e.g., triggers) the Al model to incrementally process respective portions of information regarding the first log events 532 by causing the Al model to limit sizes of the respective portions to be less than or equal to the token limit of the Al model. In accordance with this implementation, the clustering Al sub-agent 514 causes the Al model to determine the token limit by providing the token limit information 552, which indicates the token limit, as an input to the Al model.
[0082] In another example embodiment, the clustering Al sub-agent 514 invokes or includes an Al model, which executes a clustering algorithm to aggregate the subsets of the first plurality of log events into the clusters. In an aspect of this embodiment, the clustering algorithm is density -based, distribution-based, centroid-based, or hierarchical-based. A density-based clustering algorithm clusters data points (e.g., log events), which are included in an area having a relatively high concentration of data points that is surrounded by area(s) having a relatively low concentration of data points, into a cluster. A distribution-based clustering algorithm clusters data points into clusters based on a distance of each data point to the center of each of multiple clusters, such that the data point is included in the cluster having a center that is closer to the data point than the center of each other cluster. A centroid-based clustering algorithm clusters data points into clusters based on a squared distance of each data point from each of multiple centroids in the data, such that the data point is included in the cluster corresponding to the centroid with the shortest squared distance to the data point. A hierarchical-based clustering algorithm clusters data points based on which of multiple hierarchical levels of a hierarchy includes the data points. For example, data points corresponding to a first hierarchical level are clustered into a first cluster: data points corresponding to a second hierarchical level are clustered into a second cluster, and so on.
[0083] In another aspect, the clustering algorithm performs a K-means clustering technique. The K-means clustering technique is an unsupervised learning centroid-based clustering technique. In an aspect, the K-means clustering technique attempts to minimize the variance of data points within each cluster.
[0084] In yet another aspect, the clustering technique is a density-based spatial clustering of applications with noise (DBSCAN) clustering technique. As indicated by its name, the DBSCAN clustering technique is a density -based clustering technique. The DBSCAN clustering technique defines arbitrarily shaped clusters based on density of data points in regions that are separated by areas of low-density.
[0085] Other examples of a clustering technique that may be performed by the clustering algorithm include but are not limited to a Gaussian mixture clustering technique, a balance iterative reducing and clustering using hierarchies (BIRCH) clustering technique, an affinity’propagation clustering technique, a mean-shifting clustering technique, an ordering points to identify the clustering structure (OPTICS) clustering technique, and an agglomerative hierarchy clustering technique.
[0086] At step 204, the potential security threat activities are caused, by a second Al sub-agent, to be mapped to attack framework techniques and / or attack framework tactics to provide framework-based threat mappings. In an example implementation, the mapping Al sub-agent 516 causes (e.g., triggers) the potential security threat activities to be mapped to the attack framework techniques and / or the attack framework tactics to provide framework-based threat mappings 544. In an aspect, the mapping Al sub-agent 516 causes the potential security threat activity information 542 to be analyzed to identify the potential security threat activities. In another aspect, the mapping Al sub-agent 516 causes the attack framework information 550 to be analyzed to identify the attack framework techniques and / or the attack framework tactics.
[0087] In an example embodiment, the potential security threat activities are caused to be mapped to the attack framework techniques and / or the attack framework tactics at step 204 by comparing attributes of the potential security threat activities and attributes of the attack framework techniques and / or the attack framework tactics. In an aspect, comparing the attributes of the potential security threat activities and the attributes of the attack framework techniques and / or the attack framework tactics includes determining relationships between the attributes of the potential security threat activities and the attributes of the attack framework techniques and / or the attack framework tactics.
[0088] At step 206, queries that define the potential security threat activities are caused, by a third Al sub-agent, to be generated using the framework-based threat mappings. In an aspect, the queries are written in a query language. A query language is a language that is configured to be used for querying a database and / or an information system. Examples of a uery language include but are not limited to a Kusto® Query Language (KQL), developed and distributed by Microsoft Corporation; a Structured Query’ Language (SQL®), developed and distributed by IBM Corporation; a SPARQL Protocol and RDF Query’ Language (SPARQL™), developed and distributed by World Wide Web Consortium (W3C); an Xquery™ language, developed and distributed by W3C; a GraphQL® language, developed and distributed by Meta Platforms, Inc.; and a Cypher® language, developed and distributed by Neo4j, Inc.
[0089] In an example implementation, the querying Al sub-agent 518 causes (e.g., triggers) queries 546 that define the potential security threat activities to be generated using the frameyvork-based threat mappings 544. In an aspect, the querying Al sub-agent 518 causes the queries 546 to be generated further using the potential security threat activity information 542. In another aspect, the querying Al sub-agent 518 causes a first query’ to be generated using afirst framework-based threat mapping; the querying Al sub-agent 518 causes a second query to be generated using a second framework-based threat mapping, and so on. In accordance with this aspect, the first query7defines a first potential security7threat activity corresponding to a first subset of the first plurality7of log events; the second query defines a second potential security7threat activity corresponding to a second subset of the first plurality of log events, and so on. In further accordance with this aspect, the first framework-based threat mapping maps the first potential security7threat activity7to first attack framework technique(s) and / or first attack framework tactic(s); the second framework-based threat mapping maps the second potential security threat activity to second attack framework technique(s) and / or second attack framework tactic(s), and so on.
[0090] At step 208, a designated potential security threat activity is caused to be identified in a second plurality of log events by causing a search of the second plurality7of log events to be performed using a designated query that defines the designated potential security threat activity. The potential security threat activities include the designated potential security7threat activity. The queries include the designated query7. In an aspect, the designated potential security7threat activity7is caused, by an Al sub-agent, to be identified in the second plurality7of log events. In accordance with this aspect, causing the designated potential security threat activity to be identified includes causing, by the Al sub-agent, the search of the second plurality of log events to be performed using the designated query.
[0091] In an example implementation, the identification logic 520 causes the designated potential security threat activity to be identified in second log events 534 by causing a search of the second log events 534 to be performed using the designated query7that defines the designated potential security7threat activity. In accordance with this implementation, the potential security threat activity information 542 indicates the designated potential security7threat activity. In further accordance with this implementation, the queries 546 include the designated query7. The identification logic 520 generates designated potential security7threat activity information 548, which indicates identification of the designated potential security threat activity in the second log events 534. In an aspect, the designated potential security threat activity information 548 indicates an identified subset of the second log events 534 that corresponds to the designated potential security7threat activity. In an example of this aspect, the designated potential security7threat activity information 548 identifies each log event in the second log events 534 that corresponds to the designated potential security threat activity7.
[0092] In an aspect, causing the designated potential security threat activity to be identified at step 208 includes identifying the designated potential security threat activity7by performing the search of the second plurality of log events. In an example implementation, the identificationlogic 520 identifies the designated potential security threat activity in the second log events 534 by performing the search of the second log events 534.
[0093] In another aspect, the designated potential security threat activity is caused to be identified at step 208 by an Al sub-agent. In an example implementation, the identification logic 520 is implemented as an Al sub-agent. In an aspect of this implementation, the identification logic 520 causes one or more Al models to identify the designated potential security threat activity in the second log events 534.
[0094] At step 210, a security action is performed with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat. A security action is an action that is performed to increase security of a system and / or a user of the system. In an aspect, the security action is a remedial action. A remedial action is an action that mitigates (e.g., eliminates) a security vulnerability of a system or a security threat to the system. In another aspect, performance of the security action is triggered by identification of the designated potential security threat activity. In yet another aspect, the performance of the security action blocks or eliminates a security threat associated with the designated potential security threat activity. Examples of a security action include but are not limited to isolating a machine, containing (e.g,. quarantining) a user, containing an account, containing a file, containing a folder, stopping a virtual machine, blocking an Al model from generating an Al response in response to an Al prompt, replacing an Al response of the Al model with a replacement Al response, and rotating (e.g., changing) a secret (e.g., a password, an application programming interlace (API) key, an encryption key, or other credential). In an aspect, performing the security action at step 210 includes triggering (e.g., automatically triggering) execution of an instruction (e.g., a computer-readable instruction) that causes the security action to be performed. In another aspect, performing the security action at step 210 includes executing (e.g., automatically executing) an instruction that triggers performance of the security action.
[0095] In an example implementation, the security action logic 522 performs a security action 554 with regard to the identified subset of the second log events 534 as a result of the identified subset of the second log events 534 corresponding to the designated potential security threat. In an aspect, the security action logic 522 analyzes the designated potential security threat activity information 548 to determine that the identified subset of the second log events 534 corresponds to the designated potential security threat activity. In an example, of this aspect, the security action logic 522 analyzes the designated potential security threat activity information 548 to identity' each log event in the second log events 534. In another aspect, the designated potential security’ threat activity information 548 indicates that the identified subset of the second logevents 534 corresponds to a common (e.g., same) entity. In accordance with this aspect, the security action logic 522 performs the security action 554 with regard to the common entity (e.g., a particular user, a particular application, a particular computing system, or a particular IP address).
[0096] In an example embodiment, causing the potential security threat activities to be mapped at step 204 includes causing, by the second Al sub-agent, a specified potential security threat activity to be mapped to multiple attack framework techniques and / or multiple attack framework tactics to provide a specified framework-based threat mapping. In accordance with this embodiment, causing the queries to be generated at step 206 includes causing, by the third Al sub-agent, a specified query that defines the specified potential security threat activity to be generated using the specified framework-based threat mapping.
[0097] In an example implementation, one or more steps 202, 204, 206, 208, and / or 210 of flowchart 200 are not performed. In another example implementation, step(s) in addition to or in lieu of steps 202, 204, 206, 208, and / or 210 are performed. For instance, in an example parsing embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, attributes of the first plurality7of log events to be identified by causing the first plurality7of log events and schemas that define structures of respective subgroups of the first plurality of log events to be parsed. In an aspect, parsing information (e.g., log event(s) and / or schema(s)) includes identifying and extracting attributes of the information, structuring (e.g., formatting) representations of the attributes, normalizing the information, filtering the information, and / or categorizing the information. Examples of an attribute of information include but are not limited to a time stamp indicating a time at which the information was created, a type of the information, a source of the information, and a user identifier that indicates a user associated with the information. In an example, structuring representations of attributes includes formatting the representations into tables or structured logs. In another example, normalizing information includes unifying a format of the information and / or terminology included in the information. In yet another example, filtering and / or categorizing of information is based on a significance (e.g., an importance or a severity) or a type of the information.
[0098] A schema defines a structure of one or more log events. In an aspect, the schema defines one or more attributes of the structure. In an example of this aspect, the attribute(s) of the structure include a timestamp, an event type, a source, a severity, a description, a user identifier, an IP address, an event identifier, a category, and / or a host name. The timestamp indicates a date and / or a time at which an event associated with the event log occurred. The event ty pe indicates a classification of the event (e.g., error, warning, or security7alert). The source indicates an origin of the event. Examples of an origin include but are not limited to an application, a system,and a user. The severity indicates an importance or an impact of the event with regard to a system and / or a user of the system. The description describes the event. The user identifier identifies a user associated with the event. The IP address indicates a network address from which the event originated. The event identifier uniquely identifies the event. Accordingly, the event identifier distinguishes the event from other events. The category indicates a broader classification of the event (i.e., broader classification than the event type). The category includes multiple event ty pes. The host name indicates a name of a machine (e.g., a physical machine or a virtual machine) at which the event occurred. In an aspect, sources from which the first plurality' of log events is received have respective schemas. In an example of this aspect, a first subset of the first plurality of log events, which is received from a first source, has a first schema; a second subset of the first plurality7of log events, which is received from a second source, has a second schema that is different from the first schema; a third subset of the first plurality of log events, which is received from a third source, has a third schema that is different from the first schema and the second schema, and so on.
[0099] In an example implementation, the parsing Al sub-agent 512 causes attributes of the first log events 532 to be identified by causing the first log events 532 and schemas 530, which define structures of respective subgroups of the first log events 532, to be parsed. The parsing Al sub-agent 512 generates attribute information 540, which indicates the attributes of the first log events 532. In an aspect of this implementation, the attribute information 540 identifies each of the first log events 532. In accordance with this aspect, the attribute information 540 identifies each of the attributes. In further accordance with this aspect, the attribute information 540 cross-references each of the first log events 532 with a respective subset of the attributes that corresponds to the respective log event. In an example of this aspect, the attribute information 540 cross-references a first log event, which is included in the first log events 532, with a first subset of the attributes; the attribute information 540 cross-references a second log event, which is included in the first log events 532, with a second subset of the attributes, and so on.
[0100] In accordance with the parsing embodiment, the subsets of the first plurality of log events are caused to be aggregated into the clusters at step 202 as a result of the subsets of the first plurality' of log events having subsets of the attributes that correspond to the potential security' threat activities. In an example implementation, the clustering Al sub-agent 514 causes the subsets of the first log events 532 to be aggregated into the clusters as a result of the subsets of the first log events 532 having the subsets of the attributes that correspond to the potential security threat activities. In an aspect, the clustering Al sub-agent 514 causes the attribute information 540 to be analyzed to determine the attributes of the first log events 532.
[0101] In an example sampling embodiment, the method of flowchart 200 further includescausing the subsets of the first plurality of log events to be sampled to provide sampled subsets of the first plurality of log events. The sampled subsets of the first plurality of log events include fewer log events than the subsets of the first plurality of log events. In an example implementation, the clustering Al sub-agent 514 causes the subsets of the first log events 532 to be sampled to provide sampled subsets of the first log events 532. In accordance with this implementation, the sampled subsets of the first log events 532 include fewer log events than the subsets of the first log events 532. In accordance with the sampling embodiment, the potential security threat activities are caused to be mapped to attack framework techniques and / or attack framework tactics at step 204 using the sampled subsets of the first plurality of log events in lieu of the subsets of the first plurality of log events to provide the framework-based threat mappings. In an example implementation, the mapping Al sub-agent 516 causes the potential security threat activities, which are indicated by the potential security threat activity information 542, to be mapped to the attack framework techniques and / or the attack framework tactics using the sampled subsets of the first log events 532 in lieu of the subsets of the first log events 532 to provide the framework-based threat mappings 544.
[0102] In an aspect of the sampling embodiment, causing the subsets of the first plurality7of log events to be sampled includes causing a first subset of the first plurality of log events to be sampled to provide a first sampled subset of the first plurality of log events by causing one of multiple log events in the first subset that have a same attribute value to be included in the first sampled subset. In an example, the first subset of the first plurality7of log events includes a first log event and a second log event. In accordance with this example, the first log event and the second log event have the same attribute. In further accordance with this example, either the first log event or the second log event (but not both the first and second log events) is caused to be included in the first sampled subset.
[0103] In another aspect of the sampling embodiment, the subsets of the first plurality of log events are sampled using a stratified random sampling technique, a cluster random sampling technique, or a systematic random sampling technique.
[0104] In an example consolidating embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, a first subset of the first plurality of log events and a second subset of the first plurality of log events to be consolidated to provide a consolidated subset of the first plurality of log events. The first subset of the first plurality of log events corresponds to a first potential security threat activity. The second subset of the first plurality of log events corresponds to a second potential security threat activity. The consolidated subset of the first plurality7of log events corresponds to a consolidated potential security threat activity that includes the first potential security threat activity and the second potential security threatactivity. The first subset of the first plurality of log events and the second subset of the first plurality of log events are caused to be consolidated as a result of a difference between the first potential security threat activity and the second potential security' threat activity being less than or equal to a difference threshold.
[0105] In an example implementation, the consolidating Al sub-agent 526 causes a first subset of the first log events 532, which corresponds to the first potential security threat activity, and a second subset of the first log events 532, which corresponds to the second potential security threat activity', to be consolidated to provide a consolidated subset of the first log events 532. The consolidated subset of the first log events 532 corresponds to the consolidated potential security threat activity' that includes the first potential security threat activity and the second potential security threat activity'. The consolidating Al sub-agent 526 causes the first subset of the first log events 532 and the second subset of the first log events 532 to be consolidated as a result of the difference between the first potential security threat activity’ and the second potential security threat activity being less than or equal to the difference threshold. In an aspect, the consolidating Al sub-agent 526 causes the potential security threat activity information 542 to be analyzed to identify the first subset of the first log events 532, the first potential security' threat activity, the second subset of the first log events 532, and the second potential security threat activity. By causing the potential security threat activity information 542 to be analyzed, the consolidating Al sub-agent 526 causes a determination to be made that the first subset of the first log events 532 corresponds to the first potential security- threat activity and that the second subset of the first log events 532 corresponds to the second potential security threat activity. The consolidating Al sub-agent 526 generates consolidated subset information 536, which indicates the consolidated subset of the first log events 532 and the consolidated potential security threat activity'. In an aspect, the consolidated subset information 536 indicates that the consolidated subset of the first log events 532 corresponds to the consolidated potential security threat activity.
[0106] In accordance with the consolidating embodiment, causing the queries to be generated at step 206 includes causing, by the third Al sub-agent, a consolidated query that defines the consolidated potential security' threat activity to be generated in lieu of causing a first query that defines the first potential security' threat activity' and a second query that defines the second potential security threat activity to be generated. In an aspect, the consolidated potential security threat activity represents a combination of the first potential security threat activity and the second potential security threat activity'. In an example implementation, the querying Al subagent 518 causes the consolidated query, which defines the consolidated potential security threat activity, to be generated in lieu of causing the first query that defines the first potential securitythreat activity and the second query that defines the second potential security threat activity to be generated. In an aspect, the querying Al sub-agent 518 generates the queries 546 to include the consolidated query in lieu of the first query and the second query. In another aspect, the querying Al sub-agent 518 causes the consolidated subset information 536 to be analyzed to identity’ the consolidated potential security threat activity. In an example of this aspect, by causing the consolidated subset information 536 to be analyzed, the querying Al sub-agent 518 causes the consolidated subset of the first log events 532 to be identified. In accordance with this example, the consolidated subset information 536 indicates that the consolidated subset of the first log events 532 corresponds to the consolidated potential security threat activity. In another example of this aspect, the consolidated subset information 536 indicates that the consolidated potential security threat activity is to replace the first potential security- threat activity- and the second potential security threat activity-.
[0107] In an example splitting embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, an identified subset of the first plurality of log events to be split into a first subset of log events that are included in the identified subset and a second subset of the log events that are included in the identified subset. The identified subset of the first plurality of log events is caused to be split into the first subset and the second subset as a result of a number of the log events that are included in the identified subset being greater than or equal to a threshold number. The identified subset of the first plurality of log events corresponds to an identified potential security threat activity-. The first subset corresponds to a first potential security threat activity. The second subset corresponds to a second potential security threat activity.
[0108] In an example implementation, the splitting Al sub-agent 528 causes an identified subset of the first log events 532 to be split into a first subset of log events that are included in the identified subset and a second subset of the log events that are included in the identified subset. The splitting Al sub-agent 528 causes the identified subset of the first log events 532 to be split into the first subset and the second subset as a result of a number of the log events that are included in the identified subset being greater than or equal to the threshold number. The identified subset of the first log events 532 corresponds to the identified potential security- threat activity. The first and second subsets correspond to the first and second potential security threat activities, respectively. In an aspect, the splitting Al sub-agent 528 causes the potential security threat activity information 542 to be analyzed to identify the identified subset of the first log events 532 and / or the identified potential security- threat activity. The splitting Al sub-agent 528 generates split subset information 538, which indicates the first and second subsets of the log events that are included in the identified subset and the first and second potential security threatactivities. In an aspect, the split subset information 538 indicates that the first and second subsets of the log events correspond to the first and second potential security threat activities, respectively.
[0109] In accordance with the splitting embodiment, causing the queries to be generated at step 206 includes causing, by the third Al sub-agent, first and second queries that define the first and second potential security threat activities to be generated in lieu of causing an identified query that defines the identified potential security- threat activity to be generated. In an example implementation, the querying Al sub-agent 518 causes the first and second queries, which define the first and second potential security threat activities, to be generated in lieu of causing the identified query, which defines the identified potential security threat activity, to be generated. In an aspect, the querying Al sub-agent 518 generates the queries 546 to include the first and second queries in lieu of the identified query. In another aspect, the quer ing Al sub-agent 518 causes the split subset information 538 to be analyzed to identify the first and second potential security threat activities. In an example of this aspect, by causing the split subset information 538 to be analyzed, the querying Al sub-agent 518 causes the first and second subsets of the log events that are included in the identified subset to be identified. In accordance with this example, the split subset information 538 indicates that the first and second subsets of the log events that are included in the identified subset correspond to the first and second potential security threat activities, respectively. In another example of this aspect, the split subset information 538 indicates that the first and second potential security- threat activities are to replace the identified potential security threat activity.
[0110] In an example syntax embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, syntax of a specified query, which defines a specified potential security threat activity, to be corrected using a first subset of the first plurality of log events that corresponds to the specified potential security- threat activity. In an aspect, causing the syntax of the specified query to be corrected includes changing a spelling of a keyword (e.g., a SQL keyword, such as SELECT, FROM, or WHERE) in the query, changing a context in which the keyword is used, changing a spelling of a name of a row or a column of a table that is referenced in the query, correcting use of an operator (e.g., =, <, >, LIKE) in the query, changing a use of a clause (e.g., WHERE, GROUP BY, or ORDER BY) in the query, changing an order in which the clause is used among a plurality of clauses in the query, correcting a syntax of a JOIN operation in the query, correcting use or syntax of a function (e.g., COUNT, SUM, AVG), correcting use of a quotation mark or a parenthesis (e.g., to correct grouping or string handling), and / or correcting a definition or use of an alias of a table or a row or column therein.[OHl] In an example implementation, the validating Al sub-agent 524 causes the syntax of thespecified query to be corrected using a first subset of the first log events 532 that corresponds to the specified potential security threat activity. In an aspect, the validating Al sub-agent 524 causes the queries 546 to be analyzed to identify the specified query. In another aspect, the validating Al sub-agent 524 causes the potential security threat activity information 542 to be analyzed to identify the first subset of the first log events 532 and the specified potential security threat activity. In an example of this aspect, by causing the potential security threat activity information 542 to be analyzed, the validating Al sub-agent 524 causes a determination to be made that the first subset of the first log events 532 corresponds to the specified potential security threat activity.
[0112] In an example mapping accuracy embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, accuracy of a specified framework-based threat mapping, which maps a specified potential security threat activity' to a first attack framework technique and / or a first attack framework tactic, to be validated. In an example implementation, the validating Al sub-agent 524 causes the accuracy of the specified framework-based threat mapping to be validated. In an aspect, the validating Al sub-agent 524 causes the frameworkbased threat mappings 544 to be analyzed to identity' the specified framework-based threat mapping. In an example of this aspect, by causing the framework-based threat mappings 544 to be analyzed, the validating Al sub-agent 524 causes the specified potential security threat activity7, the first attack framework technique, and / or the first attack framework tactic to be identified. In another aspect, the validating Al sub-agent 524 causes first information to be compared with second information to determine the accuracy of the specified framework-based threat mapping. The first information includes the specified potential security threat activity, the first attack framework technique and / or the first attack framework tactic, and the specified framework-based threat mapping. The second information includes a reference potential security threat activity', a reference attack framework technique and / or a reference attack framework tactic, and a reference framework-based threat mapping. In an example of this aspect, the validating Al sub-agent 524 causes a first extent (e.g.. 80% or 93%) to which the specified potential security' threat activity and the first attack framework technique and / or the first attack framework tactic correspond to the specified framework-based threat mapping to be determined. In accordance with this example, the validating Al sub-agent 524 causes a second extent to which the reference potential security threat activity and the reference attack framework technique and / or the reference attack framework tactic correspond to the reference frameworkbased threat mapping to be determined. In further accordance with this example, the validating Al sub-agent 524 causes the accuracy of the specified framework-based threat mapping to be determined by causing the first extent and the second extent to be compared. In an exampleimplementation, validation of the accuracy results from a determination that the first extent is greater than or equal to the second extent. In another example implementation, validation of the accuracy results from a determination that a difference between the first extent and the second extent is less than or equal to a threshold (e.g., 5% or 10%). The validating Al sub-agent 524 generates a validation indicator 556 to indicate that the accuracy of the specified frameworkbased threat mapping is validated.
[0113] In an example activity attributes embodiment, the method of flowchart 200 includes one or more of the steps shown in flowchart 300 of FIG. 3. As shown in FIG. 3, the method of flowchart 300 begins at step 302. In step 302, titles that identify the potential security threat activities are causes to be generated by the first Al sub-agent. In an example implementation, the clustering Al sub-agent 514 causes the titles, which identify the potential security threat activities, to be generated. In an aspect, the clustering Al sub-agent 514 causes the attribute information 540 to be analyzed to generate the titles. In another aspect, the clustering Al subagent 514 configures the potential security threat activity information 542 to indicate the titles. In an example of this aspect, the potential security threat activity7information 542 cross-references the potential security threat activities and the titles.
[0114] At step 304, descriptions that explain reasoning for the subsets of the first plurality of log events being aggregated into the clusters are caused to be generated by the first Al sub-agent. In an example implementation, the clustering Al sub-agent 514 causes the descriptions, which explain the reasoning for the subsets of the first plurality of log events being aggregated into the clusters, to be generated. In an aspect, the clustering Al sub-agent 514 causes the attribute information 540 to be analyzed to generate the descriptions. In another aspect, the clustering Al sub-agent 514 configures the potential security threat activity information 542 to indicate the descriptions. In an example of this aspect, the potential security threat activity information 542 cross-references the subsets of the first plurality of log events (and / or the potential security threat activities) and the descriptions.
[0115] At step 306, the queries that define the potential security threat activities are caused to be generated using the titles and the descriptions. In an example implementation, the querying Al sub-agent 518 causes the queries 546, which define the potential security threat activities, to be generated using the titles and the descriptions. In an aspect, the querying Al sub-agent 518 causes the potential security threat activity information 542 to be analyzed to determine the titles and the descriptions.
[0116] In a first example implementation of the activity attributes embodiment, the potential security threat activities include a “file manipulation"’ potential security' threat activity. The title of the “file manipulation"’ potential security threat activity is “file manipulation.” Thedescription associated with the “file manipulation” potential security threat activity is “Detects file manipulation events (creation, modification, and deletion) within a 1-hour window, potentially indicating suspicious user activity.” The “file manipulation” potential security threat activity is mapped to attack framework tactic “TA0009,” attack framework technique “T1565,” and attack framework sub-technique “T1565.001.” A query that defines the “file manipulation” potential security threat activity is as follows:let fileManipulationActions = dynamic(['FileCreated', 'FileModified', 'FileDeleted']); CloudAppEventswhere TimeGenerated >= ago(lh)where ActionType in (fileManipulationActions)summarize countQ by bin(TimeGenerated, Im), ActionType, AccountDisplayName, IPAddress, FileName = tos tri ng(RawEvent Data. Object Id)where count_> 1.
[0117] In a second example implementation of the activity attributes embodiment, the potential security threat activities include a “DLP rule match” potential security threat activity. The title of the “DLP rule match” potential security' threat activity7is “DLP Rule Match.” The description associated with the “DLP rule match” potential security7threat activity is “Indicates potential data exfiltration or policy violation events where sensitive information was accessed or shared.” The “DLP rule match” potential security threat activity is mapped to attack framework tactic “Exfiltration,” attack framework technique “T1020,” and attack frameyvork sub-technique “T1020.001.” A query that defines the “DLP rule match” potential security threat activity7is as follows:CloudAppEventswhere TimeGenerated >= ago(lh)where ActionType == 'DlpRuleMatch'extend Sensitiveinfo = tostring(parseJson(RawEventData).SensitiveInfoTypeData) mv-expand Sensitiveinfoextend SensitivelnfoTypeName = tostring(Sensitivelnfo.SensitivelnfoTypeName), Confidence = tostring(SensitiveInfo. Confidence),Count = tostring(SensitiveInfo. Count)summarize countQ by bin(TimeGenerated, Im). AccountDisplayName.SensitivelnfoTypeName, Confidence, Count.
[0118] In an aspect of the activity' attributes embodiment, steps 302 and 304 are included in step 202 shown in FIG. 2. In accordance yvith this aspect, step 306 is included in step 206 shown in FIG. 2.
[0119] In another aspect of the activity attributes embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, accuracy of a specified title, which identifies a specified potential security threat activity7, to be validated. The titles include the specified title. The potential security threat activities include the specified potential security threat activity. In an example implementation, the validating Al sub-agent 524 causes the accuracy of the specified title to be validated. In an aspect, the validating Al sub-agent 524 causes the potential security threat activity information 542 to be analyzed to identity7the specified title. In an example of this aspect, by causing the potential security7threat activity information 542 to be analyzed, the validating Al sub-agent 524 causes the specified potential security threat activity to be identified. In another aspect, the validating Al sub-agent 524 causes the specified title and the specified potential security7threat activity7to be compared with a reference title and a reference potential security7threat activity to determine the accuracy of the title. In an example of this aspect, the validating Al sub-agent 524 causes a first extent (e.g.. 85% or 97%) to which the specified title corresponds to the specified potential security threat activity to be determined. In accordance with this example, the validating Al sub-agent 524 causes a second extent to which the reference title corresponds to the reference potential security threat activity to be determined. In further accordance with this example, the validating Al sub-agent 524 causes the accuracy of the specified title to be determined by causing the first extent and the second extent to be compared. In an example implementation, validation of the accuracy results from a determination that the first extent is greater than or equal to the second extent. In another example implementation, validation of the accuracy results from a determination that a difference between the first extent and the second extent is less than or equal to a threshold (e.g., 8% or 13%). The validating Al sub-agent 524 generates a validation indicator 556 to indicate that the accuracy of the specified title is validated.
[0120] In yet another aspect of the activity7attributes embodiment, the method of flowchart 200 further includes causing, by a fourth Al sub-agent, accuracy of a specified description, which explains reasoning for a specified subset of the first plurality of log events being aggregated into a specified cluster, to be validated. The descriptions include the specified description. The subsets of the first plurality7of log events include the specified subset of the first plurality7of log events. The clusters include the specified cluster. In an example implementation, the validating Al sub-agent 524 causes the accuracy of the specified description, which explains reasoning for a specified subset of the first log events 532 being aggregated into the specified cluster, to be validated. In an aspect, the validating Al sub-agent 524 causes the potential security threat activity information 542 to be analyzed to identity7the specified description. In an example of this aspect, by causing the potential security threat activity information 542 to be analyzed, thevalidating Al sub-agent 524 causes the specified potential security threat activity and / or the specified subset of the first log events 532 to be identified. In another aspect, the validating Al sub-agent 524 causes first information and second information to be compared. The first information includes the specified description, the specified potential security threat activity, and / or the specified subset of the first log events 532. The second information includes a reference description, a reference potential security threat activity, and / or a reference subset of log events. In an example of this aspect, the validating Al sub-agent 524 causes a first extent (e.g., 85% or 97%) to which the specified description corresponds to the specified potential security threat activity and / or the specified subset of the first log events 532 to be determined. In accordance with this example, the validating Al sub-agent 524 causes a second extent to which the reference description corresponds to the reference potential security threat activity and / or the reference subset of log events to be determined. In further accordance with this example, the validating Al sub-agent 524 causes the accuracy of the specified description to be determined by causing the first extent and the second extent to be compared. In an example implementation, validation of the accuracy results from a determination that the first extent is greater than or equal to the second extent. In another example implementation, validation of the accuracy results from a determination that a difference between the first extent and the second extent is less than or equal to a threshold (e.g.. 4% or 9%). The validating Al sub-agent 524 generates a validation indicator 556 to indicate that the accuracy of the specified description is validated.
[0121] In an example iteration embodiment, the method of flow chart 200 includes one or more of the steps show n in flowchart 400 of FIG. 4. As shown in FIG. 4, the method of flow chart 400 begins at step 402. In step 402, a first potential security threat activity is caused to be defined by the first Al sub-agent using (e.g., by taking into consideration) first attributes of a first subset of the first plurality' of log events. In an example implementation, the clustering Al sub-agent 514 causes the first potential security threat activity to be defined using first attributes of a first subset of the first log events 532.
[0122] At step 404, a second potential security threat activity is caused to be defined by the first Al sub-agent using second attributes of a second subset of the first plurality' of log events and the first potential security threat activity. In an aspect, using the first potential security threat activity to define the second potential security' threat activity reduces a likelihood that the second potential security threat activity will be substantially same as the first potential security threat activity. In another aspect, using the first potential security threat activity’ to define the second potential security' threat activity reduces a likelihood that the first and second potential security threat activities will overlap. In an example implementation, the clustering Al sub-agent 514 causes the second potential security threat activity to be defined using second attributes of asecond subset of the first log events 532 and the first potential security threat activity.
[0123] At step 406, a third potential security threat activity is caused to be defined by the first Al sub-agent using third attributes of a third subset of the first plurality of log events, the first potential security threat activity, and the second potential security threat activity. In an aspect, using the first and second potential security threat activities to define the third potential security threat activity reduces a likelihood that the third potential security threat activity will be substantially same as the first potential security threat activity or the second potential security threat activity. In another aspect, using the first and second potential security threat activities to define the third potential security’ threat activity reduces a likelihood that the third potential security threat activity will overlap the first potential security’ threat activity' or the second potential security threat activity. In an example implementation, the clustering Al sub-agent 514 causes the third potential security threat activity to be defined using third attributes of a third subset of the first log events 532, the first potential security threat activity, and the second potential security threat activity.
[0124] It will be recognized that the method of flowchart 400 is capable of being extrapolated or expanded to define any suitable number of potential security threat activities. In an aspect, the method of flowchart 400 includes further steps to define a fourth potential security threat activity, a fifth potential security threat activity, and so on.
[0125] In an example implementation, the computing system 500 does not include one or more of the multi-agent framework-based threat mapping logic 508, the store 510, the parsing Al subagent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the query ing Al subagent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528. In another example implementation, the computing system 500 includes component(s) in addition to or in lieu of the multi-agent framework-based threat mapping logic 508, the store 510, the parsing Al sub-agent 512, the clustering Al sub-agent 514. the mapping Al sub-agent 516, the querying Al sub-agent 518. the identification logic 520. the security’ action logic 522, the validating Al subagent 524, the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528.
[0126] In an example parsing embodiment, the parsing Al sub-agent 512 causes (e.g., triggers) a first Al model to analyze (e g., develop and / or refine an understanding of) a first Al input, first contextual information (including the schemas 530 and the first log events 532), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the parsing Al sub-agent 512 causes the first Al model to compare features of the first Al input and the first contextual information (including the schemas 530 and the first log events 532) using artificial intelligence to identify the attributes of the first log events 532. In an example, the firstcontextual information further includes sample Al input(s) and sample contextual information (e.g., sample schemas and sample log events).
[0127] In an example clustering embodiment, the clustering Al sub-agent 514 causes (e.g., triggers) a second Al model to analyze (e.g., develop and / or refine an understanding of) a second Al input, second contextual information (including the first log events 532), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the clustering Al sub-agent 514 causes the second Al model to compare attributes of the second Al input and the second contextual information (including the first log events 532) using artificial intelligence to aggregate the first log events 532 into the clusters, to provide the sampled subsets of the first log events 532, to cause the titles of the potential security threat activities to be generated, and / or to cause the descriptions associated with the potential security threat activities to be generated. In an example, the second contextual information further includes sample Al input(s) and sample contextual information (e.g., sample log events).
[0128] In an example mapping embodiment, the mapping Al sub-agent 516 causes (e.g., triggers) a third Al model to analyze (e.g., develop and / or refine an understanding of) a third Al input, third contextual information (including the potential security threat activity information 542 and the attack framework information 550), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the mapping Al sub-agent 516 causes the third Al model to compare attributes of the third Al input and the third contextual information (including the potential security threat activity7information 542 and the attack framework information 550) using artificial intelligence to provide the framework-based threat mappings 544. In an example, the third contextual information further includes sample Al input(s) and sample contextual information (e.g., sample potential security threat activity information and sample attack framework information).
[0129] In an example querying embodiment, the querying Al sub-agent 518 causes (e.g., triggers) a fourth Al model to analyze (e.g., develop and / or refine an understanding of) a fourth Al input, fourth contextual information (including the potential security threat activity information 542 and / or framework-based threat mappings 544), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the query ing Al sub-agent 518 causes the fourth Al model to compare attributes of the fourth Al input and the fourth contextual information (including the potential security threat activity information 542 and / or frameworkbased threat mappings 544) using artificial intelligence to generate the queries 546. In an example, the fourth contextual information further includes sample Al input(s) and sample contextual information (e.g., sample potential security7threat activity information and / or sample framework-based threat mappings).
[0130] In an example activity identification embodiment, the identification logic 520 causes (e.g., triggers) a fifth Al model to analyze (e.g., develop and / or refine an understanding ol) a fifth Al input, fifth contextual information (including the second log events 534, the potential security threat activity information 542 and / or the queries 546 (or the designated query’ therein)), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the identification logic 520 causes the fifth Al model to compare attributes of the fifth Al input and the fifth contextual information (including the potential security’ threat activity’ information 542 and the attack framework information 550) using artificial intelligence to identify the designated potential security’ threat activity in second log events 534. In an example, the fifth contextual information further includes sample Al input(s) and sample contextual information (e.g., sample log events, sample potential security threat activity' information, and / or sample queries).
[0131] In an example consolidation embodiment, the consolidating Al sub-agent 526 causes (e.g., triggers) a sixth Al model to analyze (e.g., develop and / or refine an understanding ol) a sixth Al input, sixth contextual information (including the first log events 532 and the potential security’ threat activity’ information 542), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the consolidating Al sub-agent 526 causes the sixth Al model to compare attributes of the sixth Al input and the sixth contextual information (including the first log events 532 and the potential security threat activity information 542) using artificial intelligence to consolidate the first subset of the first log events 532 and the second subset of the first log events 532 to provide the consolidated subset of the first log events 532. In an example, the sixth contextual information further includes sample Al input(s) and sample contextual information (e.g., sample log events and sample potential security threat activity7information).
[0132] In an example splitting embodiment, the splitting Al sub-agent 528 causes (e.g., triggers) a seventh Al model to analyze (e.g., develop and / or refine an understanding of) a seventh Al input, seventh contextual information (including the first log events 532 and the potential security threat activity information 542), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the splitting Al sub-agent 528 causes the seventh Al model to compare attributes of the seventh Al input and the seventh contextual information (including the first log events 532 and the potential security threat activity¬ information 542) using artificial intelligence to split the identified subset of the first log events 532 into the first subset of log events, which are included in the identified subset, and the second subset of the log events, which are included in the identified subset. In an example, the seventh contextual information further includes sample Al input(s) and sample contextual information(e.g., sample log events and sample potential security threat activity information).
[0133] In an example validation embodiment, the validating Al sub-agent 524 causes (e.g., triggers) a eighth Al model to analyze (e.g., develop and / or refine an understanding of) a eighth Al input, eighth contextual information (including the first log events 532. the potential security threat activity information 542. the framework-based threat mappings 544, and / or the queries 546), relationships between any of the foregoing, and confidences in those relationships. In an aspect, the validating Al sub-agent 524 causes the eighth Al model to compare attributes of the eighth Al input and the eighth contextual information (including the first log events 532, the potential security threat activity information 542, the framework-based threat mappings 544, and / or the queries 546) using artificial intelligence to correct the syntax of the specified query, to validate the accuracy of the specified framework-based threat mapping, to validate the accuracy of the specified title of the specified potential security threat activity7, and / or to validate the accuracy of the specified description associated with the specified potential security threat activity. In an example, the eighth contextual information further includes sample Al input(s) and sample contextual information (e.g., sample log events, sample potential security threat activity7information, sample framework-based threat mappings, and / or sample queries).
[0134] In some example embodiments, an Al model includes a neural network that uses the artificial intelligence to determine (e.g., predict) relationships between any of the Al inputs described herein and any of the corresponding contextual information and confidences in the relationships. The neural network uses those relationships to generate the corresponding Al responses. In an example, attributes of the Al input, the contextual information, and potentially example Al input(s) and example Al response(s) to the Al input(s) are compared to determine similarities and differences between those attributes. In accordance with this example, the neural network uses those similarities and differences to generate the corresponding Al responses.
[0135] Examples of a neural network include but are not limited to a feed forward neural network and a transformer-based neural network. A feed forward neural network is an artificial neural network for which connections between units in the neural network do not form a cycle. The feed forward neural network allows data to flow forward (e.g., from the input nodes toward to the output nodes), but the feed forward neural network does not allow data to flow backward (e.g., from the output nodes toward to the input nodes). In an example embodiment, the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528 employs a feed forward neural network to train an Al model, which is used to determine AI-based confidences. In an example, such Al-based confidences are used to determine likelihoodsthat events will occur.
[0136] A transformer-based neural network is a neural network that incorporates a transformer. A transformer is a deep learning model that utilizes attention to differentially weight the significance of each portion of sequential input data, such as natural language. Attention is a technique that mimics cognitive attention. Cognitive attention is a behavioral and cognitive process of selectively concentrating on a discrete aspect of information while ignoring other perceivable aspects of the information. Accordingly, the transformer uses the attention to enhance some portions of the input data while diminishing other portions. The transformer determines which portions of the input data to enhance and which portions of the input data to diminish based on the context of each portion. In an example, the transformer is trained to identify the context of each portion using any suitable technique, such as gradient descent.
[0137] In an example embodiment, the transformer-based neural network generates a parsing model (e.g., to identify attributes of log events): a clustering model (e.g.. to aggregate log events into the clusters, to provide sampled subsets of log events, to cause titles of potential security threat activities to be generated, and / or to cause descriptions associated with potential security threat activities to be generated); a mapping model (e.g., to provide framework-based threat mappings); a query ing model (e g., to generate queries); an activity identification model (e.g., to identify a potential security threat activity in log events); a consolidation model (e.g., to consolidate subsets of log events to provide a consolidated subset of the log events); a splitting model (e.g., to split a subset of log events into multiple subsets of the log events); and / or a validation model (e.g., to correct syntax of a query, to validate accuracy of a framework-based threat mapping, to validate accuracy of a title of a potential security threat activity, and / or to validate accuracy of a description associated with a potential security threat activity) by utilizing information, such as Al inputs, contextual information, relationships between any of the foregoing, and Al-based confidences that are derived therefrom.
[0138] In example embodiments, the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528 includes training logic, and Al model(s) include inference logic. The training logic is configured to train Al algorithm(s) of the Al model(s) that the inference logic uses to determine (e.g., infer) the Al-based confidences. In an example, the training logic provides sample Al inputs and sample contextual information as inputs to the Al algorithm(s) to train the Al algorithm(s). In another example, the sample data is labeled. In yet another example, the Al algorithm(s) are configured to derive relationships between the features (e.g., the Al input and the contextual information) and the resulting Al-based confidences. Theinference logic is configured to utilize the Al algorithm(s), which are trained by the training logic, to determine the Al-based confidence when the features are provided as inputs to the algorithm.
[0139] In an example embodiment, an Al model is a generative language model. A generative language model is an Al model that is capable of generating original text output based on sample data. Examples of a generative language model include but are not limited to a generative pre-trained transformer 3 (GPT-3®) model and a generative pre-trained transformer 4 (GPT-4®) model, developed and distributed by OpenAI, Inc.; a Phi™ model and a Turing-NLG™ model, developed and distributed by Microsoft Corporation; a large language model Meta Al (LLaMA®) model, developed and distributed by Meta Platforms Inc.; a language model for dialogue applications (LaMDA®) model and a Gemini® model, developed and distributed by Google LLC; and a BigScience large open-science open-access multilingual language model (BLOOM) model, developed and distributed by the BigScience collaborative initiative. A generative language model may use any suitable relevancy determination and / or ranking technique. In an example, the generative language model uses a BM25 (Okapi BM25) ranking function to perform its analysis (e.g., based on keywords).
[0140] In another example embodiment, an Al model is a large language model (LLM). A large language model is an artificial neural network that is capable of performing natural language processing (NLP) tasks. In an example, the large language model uses a transformer model to perform the NLP tasks. In an aspect, the large language model is trained (e.g., pre-trained) using self-supervised learning and semi-supervised learning. Examples of a large language model include but are not limited to the GPT-3® and GPT-4® models, developed and distributed by OpenAI, Inc.; the LLaMA® model, developed and distributed by Meta Platforms Inc.; and a pathways language model (PaLM®) model and the Gemini® model, developed and distributed by Google LLC.
[0141] In yet another example embodiment, an Al model is an embedding model. An embedding model is an Al model that uses deep learning to convert data into vectors, which represent attributes of the data, and that compares at least a subset of the vectors to determine an extent to which the vectors that are included in the subset are similar. In an aspect, each vector represents a semantic meaning of one or more Al inputs, one or more instances of contextual information, and / or one or more Al responses. In another aspect, an embedding is a numerical representation of data (e.g., a log, one or more log events, a schema, a potential security threat activity, an attack framework technique, an attack framework tactic, a framework-based threat mapping, or a query ). In an example of this aspect, the embedding is generated by converting the data (e.g., text) into a vector (e.g., an array of numbers). In another example of this aspect, theembedding represents the meaning and the context of the data. In another example of this aspect, embeddings serve as generic representations of a corpus of data (e.g., a plurality of logs, a plurality7of log events, a plurality of schemas, a plurality of security threat activities, a plurality7of attack framework techniques and / or attack framework tactics, a plurality of framework-based threat mappings, or a plurality of queries) without requiring explicit feature engineering. In an aspect of this embodiment, the Al model generates an Al response to an Al input described herein using an embedding model. In an example of this aspect, the embedding model is an encoder-only model. One example of an encoder-only model is the bidirectional encoder representations from transformers (BERT™) model, which is developed and distributed by¬ Google LLC. In another example of this aspect, the embedding model is a decoder-only model. In yet another example of this aspect, the embedding model is an encoder-decoder model. One example of an encoder-decoder model is the FLAN-T5™ model, which is developed and distributed by Google LLC.
[0142] In still another example embodiment, any one or more of the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security7action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528 invokes or includes multiple types of Al models. In an example, weights are applied to the responses generated by the respective ty pes of Al models. In an aspect, the multiple ty pes of Al models include a generative Al model and an embedding model. In an example of this aspect, a first weight is applied to a first response generated by the generative Al model to provide a first weighted response, and a second weight that is different from the first weight is applied to a second response of the embedding model to provide a second weighted response. In accordance with this example, the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the query ing Al sub-agent 518, the identification logic 520, the security7action logic 522, the validating Al sub-agent 524. the consolidating Al sub-agent 526, and / or the splitting Al sub-agent 528 combines (e.g.. sums) the first weighted response and the second weighted response to generate a combined response.
[0143] FIG. 6 depicts an example algorithm 600 used by the clustering Al sub-agent 514 shown in FIG. 5 to aggregate log events in accordance with an embodiment.
[0144] FIG. 7 depicts an example algorithm 700 used by the clustering Al sub-agent 514 shown in FIG. 5 to define potential security threat activities in accordance with an embodiment. Potential security' threat activities are referred to as “behaviors’’ in the algorithm 700 for brevity and readability .
[0145] FIG. 8 depicts an example algorithm 800 used by the validating Al sub-agent 524 shownin FIG. 5 to validate potential security threat activities in accordance with an embodiment. Potential security threat activities are referred to as “behaviors” in the algorithm 800 for brevity and readability .
[0146] Although the operations of some of the disclosed methods are described in a particular, sequential order for convenient presentation, it should be understood that this manner of description encompasses rearrangement, unless a particular ordering is required by specific language set forth herein. In an example, operations described sequentially are in some cases rearranged or performed concurrently. Moreover, for the sake of simplicity, the attached figures may not show the various ways in which the disclosed methods may be used in conjunction with other methods.
[0147] Any one or more of the multi-agent framework-based threat mapping logic 108, the multi-agent framework-based threat mapping logic 508, the parsing Al sub-agent 512, the clustering Al sub-agent 514. the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, the splitting Al sub-agent 528, flowchart 200, flowchart 300, and / or flowchart 400 may be implemented in hardware, software, firmware, or any combination thereof.
[0148] In an example, any one or more of the multi-agent framework-based threat mapping logic 108, the multi-agent framework-based threat mapping logic 508, the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, the splitting Al sub-agent 528, flowchart 200, flowchart 300, and / or flowchart 400 are implemented, at least in part, as computer program code configured to be executed in one or more processors.
[0149] In another example, any one or more of the multi-agent framework-based threat mapping logic 108, the multi-agent framework-based threat mapping logic 508. the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, the splitting Al sub-agent 528, flowchart 200, flowchart 300, and / or flowchart 400 are implemented, at least in part, as hardware logic / electrical circuitry. In an example implementation, such hardware logic / electrical circuitry includes one or more hardware logic components. Examples of a hardware logic component include but are not limited to a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), an application-specific standard product (ASSP), a system-on-a-chip system (SoC), a complex programmable logic device (CPLD), etc. In an example, a SoC includes an integratedcircuit chip that includes one or more of a processor (e.g., a microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or further circuits and / or embedded firmware to perform its functions.II. Further Discussion of Some Example Embodiments
[0150] (Al) An example system (Figure 1. 102A-102M, 106A-106N; Figure 5, 500: Figure 6, 600) comprises a processor system (Figure 6, 602) and a memory (Figure 6, 604, 608, 610) that stores computer-executable instructions. The computer-executable instructions are executable by the processor system to at least execute a first artificial intelligence (Al) sub-agent (Figure 5, 514) that causes (Figure 2, 202) subsets of a first plurality of log events (Figure 5, 532) to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities. The computer-executable instructions are executable by the processor system further to at least execute a second Al sub-agent (Figure 5, 516) that causes (Figure 2, 204) the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics to provide framework-based threat mappings (Figure 5, 544). The computerexecutable instructions are executable by the processor system further to at least execute a third Al sub-agent (Figure 5, 518) that causes (Figure 2, 206) queries (Figure 5, 546), which define the potential security threat activities, to be generated using the framework-based threat mappings. The computer-executable instructions are executable by the processor system further to at least cause (Figure 2, 208) a designated potential security threat activity to be identified in a second plurality of log events (Figure 5, 534) by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity. The potential security threat activities include the designated potential security threat activity. The queries include the designated query. The computer-executable instructions are executable by the processor system further to at least perform (Figure 2, 210) a security action (Figure 5, 554) with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat.
[0151] (A2) In the example system of Al, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent that causes attributes of the first plurality of log events to be identified by causing the first plurality of log events and schemas that define structures of respective subgroups of the first plurality of log events to be parsed; and execute the first Al sub-agent, which causes the subsets of the first plurality of log events to be aggregated into the clusters as a result of the subsets of the first plurality of log events having subsets of the attributes that correspond to the potential security threat activities.
[0152] (A3) In the example system of any of A1-A2, wherein the computer-executable instructions are executable by the processor system to at least: execute the first Al sub-agent, which causes titles and descriptions to be generated, the titles identifying the potential security threat activities, the descriptions explaining reasoning for the subsets of the first plurality of log events being aggregated into the clusters; and execute the third Al sub-agent, which causes the queries that define the potential security threat activities to be generated using the titles and the descriptions.
[0153] (A4) In the example system of any of A1-A3, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent that causes accuracy of a specified title, which identifies a specified potential security threat activity, to be validated; wherein the titles include the specified title; and wherein the potential security threat activities include the specified potential security threat activity.
[0154] (A5) In the example system of any of A1-A4, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent that causes accuracy of a specified description, which explains reasoning for a specified subset of the first plurality of log events being aggregated into a specified cluster, to be validated; wherein the descriptions include the specified description; wherein the subsets of the first plurality of log events include the specified subset of the first plurality of log events; and wherein the clusters include the specified cluster.
[0155] (A6) In the example system of any of A1-A5, wherein the computer-executable instructions are executable by the processor system to at least: cause the subsets of the first plurality of log events to be sampled to provide sampled subsets of the first plurality of log events, the sampled subsets of the first plurality of log events including fewer log events than the subsets of the first plurality of log events; and execute the second Al sub-agent, which causes the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics using the sampled subsets of the first plurality of log events in lieu of the subsets of the first plurality of log events to provide the framework-based threat mappings.
[0156] (A7) In the example system of any of A1-A6, wherein the computer-executable instructions are executable by the processor system to at least: cause a first subset of the first plurality of log events to be sampled to provide a first sampled subset of the first plurality of log events by causing one of multiple log events in the first subset that have a same attribute value to be included in the first sampled subset.
[0157] (A8) In the example system of any of A1-A7, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent thatcauses a first subset of the first plurality of log events, which corresponds to a first potential security threat activity, and a second subset of the first plurality of log events, which corresponds to a second potential security7threat activity7, to be consolidated to provide a consolidated subset of the first plurality of log events as a result of a difference between the first potential security7threat activity and the second potential security threat activity being less than or equal to a difference threshold, wherein the consolidated subset of the first plurality of log events corresponds to a consolidated potential security' threat activity7, which includes the first potential security threat activity and the second potential security threat activity; and execute the third Al sub-agent, which causes a consolidated query that defines the consolidated potential security threat activity' to be generated in lieu of causing a first query that defines the first potential security threat activity7and a second query7that defines the second potential security threat activity7to be generated.
[0158] (A9) In the example system of any of A1-A8, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent that causes an identified subset of the first plurality of log events, which corresponds to an identified potential security7threat activity7, to be split into a first subset of log events that are included in the identified subset and a second subset of the log events that are included in the identified subset as a result of a number of the log events that are included in the identified subset being greater than or equal to a threshold number, the first subset corresponding to a first potential security threat activity, the second subset corresponding to a second potential security' threat activity; and execute the third Al sub-agent, which causes first and second queries that define the first and second potential security threat activities to be generated in lieu of causing an identified query that defines the identified potential security' threat activity to be generated.
[0159] (A10) In the example system of any of A1-A9, wherein the computer-executable instructions are executable by the processor system to at least: execute the first Al sub-agent, which causes a first potential security threat activity to be defined using first attributes of a first subset of the first plurality of log events, which further causes a second potential security threat activity to be defined using second attributes of a second subset of the first plurality of log events and the first potential security7threat activity', and which further causes a third potential security7threat activity to be defined using third attributes of a third subset of the first plurality of log events, the first potential security threat activity7, and the second potential security threat activity'.
[0160] (All) In the example system of any of A1-A10, wherein the computer-executable instructions are executable by the processor system to at least: execute the first Al sub-agent, which causes an Al model that is utilized by the first Al sub-agent to aggregate the subsets ofthe first plurality of log events into the clusters to incrementally process respective portions of information regarding the first plurality of log events by causing the Al model to limit sizes of the respective portions to be less than or equal to a token limit of the Al model.
[0161] (A12) In the example system of any of Al -Al l, wherein the computer-executable instructions are executable by the processor system to at least: execute the second Al sub-agent, which causes a specified potential security threat activity to be mapped to at least one of multiple attack framework techniques or multiple attack framework tactics to provide a specified framework-based threat mapping; and execute the third Al sub-agent, which causes a specified query that defines the specified potential security threat activity to be generated using the specified framework-based threat mapping.
[0162] (A13) In the example system of any of A1-A12, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent that causes syntax of a specified query, which defines a specified potential security threat activity, to be corrected using a first subset of the first plurality of log events that corresponds to the specified potential security7threat activity.
[0163] (A14) In the example system of any of A1-A13, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent that causes accuracy of a specified framework-based threat mapping, which maps a specified potential security’ threat activity to at least one of a first attack framework technique or a first attack framework tactic, to be validated.
[0164] (Bl) An example method is implemented by a computing system (Figure 1, 102A-102M, 106A-106N; Figure 5, 500; Figure 6, 600). The method comprises causing (Figure 2, 202), by a first artificial intelligence (Al) sub-agent (Figure 5, 514), subsets of a first plurality of log events (Figure 5, 532) to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities. The method further comprises causing (Figure 2, 204), by a second Al sub-agent (Figure 5, 516), the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics to provide framework-based threat mappings (Figure 5, 544). The method further comprises causing (Figure 2, 206), by a third Al sub-agent (Figure 5, 518), queries (Figure 5, 546) that define the potential security threat activities to be generated using the framework-based threat mappings. The method further comprises causing (Figure 2, 208) a designated potential security threat activity to be identified in a second plurality of log events (Figure 5, 534) by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity. The potential security threat activities include the designated potential security threat activity. The queries include the designated query. The method further comprisesperforming (Figure 2, 210) a security action (Figure 5, 554) with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat.
[0165] (B2) In the example method of Bl, further comprising: causing, by a fourth Al subagent, attributes of the first plurality of log events to be identified by causing the first plurality of log events and schemas that define structures of respective subgroups of the first plurality of log events to be parsed; wherein causing the subsets of the first plurality of log events to be aggregated into the clusters comprises: causing, by the first Al sub-agent, the subsets of the first plurality of log events to be aggregated into the clusters as a result of the subsets of the first plurality of log events having subsets of the attributes that correspond to the potential security threat activities.
[0166] (B3) In the example method of any of B1-B2, wherein causing the subsets of the first plurality of log events to be aggregated into the clusters comprises: causing, by the first Al subagent, titles that identify the potential security threat activities to be generated; and causing, by the first Al sub-agent, descriptions that explain reasoning for the subsets of the first plurality of log events being aggregated into the clusters to be generated; and wherein causing the queries to be generated comprises: causing, by the third Al sub-agent, the queries that define the potential security threat activities to be generated using the titles and the descriptions.
[0167] (B4) In the example method of any of B1-B3, further comprising: causing, by a fourth Al sub-agent, accuracy of a specified title, which identifies a specified potential security threat activity, to be validated, wherein the titles include the specified title, and wherein the potential security threat activities include the specified potential security threat activity.
[0168] (B5) In the example method of any of B1-B4, further comprising: causing, by a fourth Al sub-agent, accuracy of a specified description, which explains reasoning for a specified subset of the first plurality of log events being aggregated into a specified cluster, to be validated, wherein the descriptions include the specified description, wherein the subsets of the first plurality of log events include the specified subset of the first plurality of log events, and wherein the clusters include the specified cluster.
[0169] (B6) In the example method of any of B1-B5, further comprising: causing the subsets of the first plurality of log events to be sampled to provide sampled subsets of the first plurality of log events, the sampled subsets of the first plurality of log events including fewer log events than the subsets of the first plurality’ of log events; wherein causing the potential security threat activities to be mapped comprises: causing, by the second Al sub-agent, the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics using the sampled subsets of the first plurality of log events in lieu of the subsets of thefirst plurality of log events to provide the framework-based threat mappings.
[0170] (B7) In the example method of any of B1-B6, wherein causing the subsets of the first plurality7of log events to be sampled comprises: causing a first subset of the first plurality of log events to be sampled to provide a first sampled subset of the first plurality of log events by causing one of multiple log events in the first subset that have a same attribute value to be included in the first sampled subset.
[0171] (B8) In the example method of any of B1-B7, further comprising: causing, by a fourth Al sub-agent, a first subset of the first plurality of log events, which corresponds to a first potential security threat activity, and a second subset of the first plurality of log events, which corresponds to a second potential security threat activity, to be consolidated to provide a consolidated subset of the first plurality of log events, which corresponds to a consolidated potential security threat activity that includes the first potential security threat activity and the second potential security threat activity7, as a result of a difference between the first potential security threat activity and the second potential security threat activity being less than or equal to a difference threshold; wherein causing the queries to be generated comprises: causing, by the third Al sub-agent, a consolidated query that defines the consolidated potential security threat activity to be generated in lieu of causing a first query that defines the first potential security threat activity and a second query that defines the second potential security threat activity to be generated.
[0172] (B9) In the example method of any of B1-B8, further comprising: causing, by a fourth Al sub-agent, an identified subset of the first plurality of log events, which corresponds to an identified potential security threat activity, to be split into a first subset of log events that are included in the identified subset and a second subset of the log events that are included in the identified subset as a result of a number of the log events that are included in the identified subset being greater than or equal to a threshold number, the first subset corresponding to a first potential security threat activity, the second subset corresponding to a second potential security threat activity; wherein causing the queries to be generated comprises: causing, by the third Al sub-agent, first and second queries that define the first and second potential security threat activities to be generated in lieu of causing an identified query that defines the identified potential security threat activity to be generated.
[0173] (B10) In the example method of any of B1-B9, wherein causing the subsets of the first plurality of logs to be aggregated into the clusters comprises: causing, by the first Al sub-agent, a first potential security threat activity7to be defined using first attributes of a first subset of the first plurality of log events; causing, by the first Al sub-agent, a second potential security threat activity to be defined using second attributes of a second subset of the first plurality of logevents and the first potential security threat activity; and causing, by the first Al sub-agent, a third potential security threat activity to be defined using third attributes of a third subset of the first plurality of log events, the first potential security threat activity7, and the second potential security7threat activity.
[0174] (B l 1) In the example method of any of B1-B10, wherein causing the subsets of the first plurality of logs to be aggregated into the clusters comprises: causing, by the first Al sub-agent, an Al model, which is utilized by the first Al sub-agent to aggregate the subsets of the first plurality of log events into the clusters, to incrementally process respective portions of information regarding the first plurality of log events by causing the Al model to limit sizes of the respective portions to be less than or equal to a token limit of the Al model.
[0175] (B12) In the example method of any of Bl-Bll, wherein causing the potential security threat activities to be mapped comprises: causing, by the second Al sub-agent, a specified potential security threat activity7to be mapped to at least one of multiple attack framework techniques or multiple attack framework tactics to provide a specified framework-based threat mapping; and wherein causing the queries to be generated comprises: causing, by the third Al sub-agent, a specified query7that defines the specified potential security7threat activity7to be generated using the specified framework-based threat mapping.
[0176] (B13) In the example method of any of B1-B12, further comprising: causing, by a fourth Al sub-agent, syntax of a specified query, which defines a specified potential security threat activity7, to be corrected using a first subset of the first plurality7of log events that corresponds to the specified potential security threat activity7.
[0177] (B14) In the example method of any of B1-B13, further comprising: causing, by a fourth Al sub-agent, accuracy of a specified framework-based threat mapping, which maps a specified potential security' threat activity7to at least one of a first attack framework technique or a first attack framework tactic, to be validated.
[0178] (Cl) An example computer program product (Figure 6, 618, 622) comprises a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system (Figure 1, 102A-102M, 106A-106N; Figure 5, 500; Figure 6, 600) to perform operations. The operations comprise executing a first artificial intelligence (Al) sub-agent (Figure 5, 514) that causes (Figure 2, 202) subsets of a first plurality of log events (Figure 5, 532) to be aggregated into respective clusters as a result of the subsets corresponding to respective potential security threat activities. The operations further comprise executing a second Al sub-agent (Figure 5, 516) that causes (Figure 2, 204) the respective potential security7threat activities to be mapped to at least one of respective attack framework techniques or respective attack framework tactics to provide respective framework-based threat mappings (Figure 5, 544). The operationsfurther comprise executing a third Al sub-agent (Figure 5, 518) that causes (Figure 2, 206) queries (Figure 5, 546), which define the respective potential security threat activities, to be generated using the respective framework-based threat mappings. The operations further comprise causing (Figure 2, 208) a designated potential security threat activity to be identified in a second plurality of log events (Figure 5. 534) by causing a search of the second plurality of log events to be performed using a designated query that defines the designated potential security threat activity. The respective potential security' threat activities include the designated potential security threat activity. The queries include the designated query. The operations further comprise performing (Figure 2, 210) a security action (Figure 5, 554) with regard to an identified subset of the second plurality’ of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat.
[0179] (DI) A second example system (Figure 1, 102A-102M, 106A-106N; Figure 5, 500; Figure 6, 600) comprises a processor system (Figure 6. 602) and a memory (Figure 6. 604, 608, 610) that stores computer-executable instructions. The computer-executable instructions are executable by the processor system to at least execute a first artificial intelligence (Al) sub-agent (Figure 5, 514), which triggers (Figure 2, 202) a first Al model to aggregate subsets of a first plurality of log events (Figure 5, 532) into clusters using relationships between attributes of the first plurality of log events as a result of the subsets corresponding to potential security threat activities by providing a first Al input together with first contextual information as first inputs to the first Al model. The first Al input requests aggregation of the first plurality of log events into the clusters. The first contextual information includes the first plurality of log events. The first contextual information includes context regarding the first Al input. A first Al response that is received from the first Al model in response to the first Al input indicates the clusters. The computer-executable instructions are executable by the processor system further to at least execute a second Al sub-agent (Figure 5, 516), which triggers (Figure 2, 204) a second Al model to map the potential security threat activities to at least one of attack framework techniques or attack framework tactics using relationships between attributes of the potential security threat activities and attributes of the at least one of the attack framework techniques or the attack framework tactics to provide framework-based threat mappings (Figure 5, 544) by providing a second Al input together with second contextual information as second inputs to the second Al model. The second Al input requests mapping of the potential security’ threat activities to the at least one of the attack framework techniques or the attack framework tactics. The second contextual information includes the potential security' threat activities and the at least one of the attack framework techniques or the attack framework tactics. The second contextual information includes context regarding the second Al input. A second Al response that is received from thesecond Al model in response to the second Al input indicates the framework-based threat mappings. The computer-executable instructions are executable by the processor system further to at least execute a third Al sub-agent (Figure 5, 518), which triggers (Figure 2, 206) a third Al model to generate queries (Figure 5. 546) that define the potential security threat activities using relationships between attributes of the framework-based threat mappings by providing a third Al input together with third contextual information as third inputs to the third Al model. The third Al input requests generation of the queries. The third contextual information includes the framework-based threat mappings. The third contextual information includes context regarding the third Al input. A third Al response that is received from the third Al model in response to the third Al input indicates the queries. The computer-executable instructions are executable by the processor system further to at least identify (Figure 2, 208) a designated potential security threat activity' in a second plurality7of log events (Figure 5, 534) by performing a search of the second plurality of log events using a designated query7that defines the designated potential security threat activity. The potential security threat activities include the designated potential security threat activity. The queries include the designated query. The computer-executable instructions are executable by the processor system further to at least perform (Figure 2, 210) a security7action (Figure 5, 554) with regard to an identified subset of the second plurality of log events as a result of the identified subset of the second plurality of log events corresponding to the designated potential security threat.
[0180] (D2) In the second example system of DI, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent, which triggers a fourth Al model to parse the first plurality of log events and schemas that define structures of respective subgroups of the first plurality of log events to identify the attributes of the first plurality of log events using relationships between the first plurality of log events and the schemas by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests identification of the attributes of the first plurality of log events, wherein the fourth contextual information includes the first plurality of log events and the schemas, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the attributes of the first plurality of log events; and execute the first Al sub-agent, which triggers the first Al model to aggregate the subsets of the first plurality of log events into the clusters as a result of the subsets of the first plurality of log events having subsets of the attributes that correspond to the potential security7threat activities.
[0181] (D3) In the second example system of any of D1-D2, wherein the computer-executableinstructions are executable by the processor system to at least: cause the subsets of the first plurality of log events to be sampled to provide sampled subsets of the first plurality of log events, the sampled subsets of the first plurality of log events including fewer log events than the subsets of the first plurality of log events; and execute the second Al sub-agent, which triggers the second Al model to map the potential security threat activities to the at least one of the attack framework techniques or the attack framework tactics using the sampled subsets of the first plurality of log events in lieu of the subsets of the first plurality of log events to provide the framework-based threat mappings.
[0182] (D4) In the second example system of any of D1-D3, wherein the computer-executable instructions are executable by the processor system to at least: cause a first subset of the first plurality of log events to be sampled to provide a first sampled subset of the first plurality of log events by causing one of multiple log events in the first subset that have a same attribute value to be included in the first sampled subset.
[0183] (D5) In the second example system of any of D1-D4, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent, which triggers a fourth Al model to consolidate a first subset of the first plurality7of log events, which corresponds to a first potential security threat activity, and a second subset of the first plurality of log events, which corresponds to a second potential security threat activity, using relationships between attributes of the first potential security threat activity and attributes of the second potential security threat activity to provide a consolidated subset of the first plurality of log events as a result of a difference between the first potential security threat activity and the second potential security threat activity being less than or equal to a difference threshold by¬ providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests consolidation of identified subsets of the first plurality of log events corresponding to identified potential security threat activities having a difference that is less than or equal to the difference threshold, wherein the fourth contextual information includes the subsets of the first plurality of log events and the potential security threat activities, wherein the fourth contextual information includes context regarding the fourth Al input, wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the consolidated subset of the first plurality of log events, and wherein the consolidated subset of the first plurality of log events corresponds to a consolidated potential security threat activity, which includes the first potential security threat activity and the second potential security threat activity; and execute the third Al sub-agent, which triggers the third Al model to generate a consolidated query that defines the consolidated potential security threat activity in lieu of generating a first query that defines the first potential security threatactivity and a second query that defines the second potential security threat activity.
[0184] (D6) In the second example system of any of D1-D5, wherein the computer-executable instructions are executable by the processor system to at least: execute a fourth Al sub-agent, which triggers a fourth Al model to split an identified subset of the first plurality of log events, which corresponds to an identified potential security threat activity, into a first subset of log events that are included in the identified subset and a second subset of the log events that are included in the identified subset as a result of a number of the log events that are included in the identified subset being greater than or equal to a threshold number by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests splitting of a subset of the first plurality of log events into multiple subsets as a result of a number of log events in the subset being greater than or equal to the threshold number, wherein the fourth contextual information includes the subsets of the first plurality of log events, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the first subset of log events that are included in the identified subset and the second subset of the log events that are included in the identified subset, the first subset corresponding to a first potential security threat activity, the second subset corresponding to a second potential security threat activity; and execute the third Al subagent, which triggers the third Al model to generate first and second queries that define the first and second potential security threat activities in lieu of generating an identified query that defines the identified potential security' threat activity.
[0185] (D7) In the second example system of any of D1-D6, wherein the computer-executable instructions are executable by the processor system to at least: execute the first Al sub-agent, which triggers the first Al model to define a first potential security threat activity using first attributes of a first subset of the first plurality of log events, to define a second potential security threat activity using second attributes of a second subset of the first plurality of log events and the first potential security threat activity, and to define a third potential security threat activity using third attributes of a third subset of the first plurality of log events, the first potential security threat activity', and the second potential security threat activity.
[0186] (D8) In the second example system of any of D1-D7, wherein the computer-executable instructions are executable by the processor system to at least: execute the first Al sub-agent, which triggers the first Al model to incrementally process respective portions of information regarding the first plurality of log events by limiting sizes of the respective portions to be less than or equal to a token limit of the Al model, wherein the first Al input indicates that the sizes of the respective portions are to be less than or equal to the token limit.
[0187] (D9) In the second example system of any of D1-D8, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent, which triggers a fourth Al model to correct syntax of a specified query, which defines a specified potential security threat activity, using a first subset of the first plurality of log events that corresponds to the specified potential security threat activity by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests checking correctness of the syntax of the specified query, wherein the fourth contextual information includes the first subset of the first plurality of log events, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates corrected syntax of the specified query that corrects the syntax.
[0188] (D10) In the second example system of any of D1-D9, wherein the computer-executable instructions are executable by the processor system further to at least: execute a fourth Al subagent, which triggers a fourth Al model to validate accuracy of a specified framework-based threat mapping, which maps a specified potential security threat activity to at least one of a first attack framework technique or a first attack framework tactic, by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests validation of the accuracy of the specified framework-based threat mapping, wherein the fourth contextual information includes the specified framework-based threat mapping, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates that the accuracy is validated.III. Example Computer System
[0189] FIG. 9 depicts an example computer 900 in which embodiments may be implemented. Any one or more of the user devices 102A-102M and / or any one or more of the servers 106A-106N shown in FIG. 1 and / or the computing system 500 shown in FIG. 5 may be implemented using computer 900. including one or more features of computer 900 and / or alternative features. In an example, computer 900 is a general-purpose computing device in the form of a conventional personal computer, a mobile computer, or a workstation, for example. In another example, computer 900 is a special purpose computing device. The description of computer 900 provided herein is provided for purposes of illustration, and is not intended to be limiting. Embodiments may be implemented in further types of computer systems, as would be known to persons skilled in the relevant art(s).
[0190] As shown in FIG. 9, computer 900 includes a processor system 902, a system memory 904, and a bus 906 that couples various system components including system memory 904 toprocessor system 902. Bus 906 represents one or more of any of several t pes of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety7of bus architectures. System memory 904 includes read only memory7(ROM) 908 and random access memory (RAM) 910. A basic input / output system 912 (BIOS) is stored in ROM 908.
[0191] Computer 900 also has one or more of the following drives: a hard disk drive 914 for reading from and writing to a hard disk, a magnetic disk drive 916 for reading from or writing to a removable magnetic disk 918, and an optical disk drive 920 for reading from or writing to a removable optical disk 922 such as a CD ROM, DVD ROM, or other optical media. Hard disk drive 914, magnetic disk drive 916, and optical disk drive 920 are connected to bus 906 by a hard disk drive interface 924, a magnetic disk drive interface 926, and an optical drive interface 928, respectively. The drives and their associated computer-readable storage media provide nonvolatile storage of computer-readable instructions, data structures, program modules and other data for the computer. Although a hard disk, a removable magnetic disk and a removable optical disk are described, other types of computer-readable storage media can be used to store data, such as flash memory7cards, digital video disks, random access memories (RAMs), read only memories (ROM), and the like.
[0192] A number of program modules may be stored on the hard disk, magnetic disk, optical disk, ROM, or RAM. These programs include an operating system 930, one or more application programs 932, other program modules 934, and program data 936. In an example, application programs 932 and / or program modules 934 include computer program logic for implementing any one or more of (e.g., at least a portion of) the multi-agent framework-based threat mapping logic 108, the multi-agent framework-based threat mapping logic 508, the parsing Al sub-agent 512, the clustering Al sub-agent 514, the mapping Al sub-agent 516, the querying Al sub-agent 518, the identification logic 520, the security action logic 522, the validating Al sub-agent 524, the consolidating Al sub-agent 526, the splitting Al sub-agent 528, flowchart 200 (including any step of flowchart 200), flowchart 300 (including any step of flowchart 300), and / or flowchart 400 (including any step of flowchart 400), as described herein.
[0193] A user may enter commands and information into the computer 900 through input devices, such as keyboard 938 and pointing device 940. Other examples of an input device (not shown) include but are not limited to a microphone, a joystick, a game pad, a satellite dish, a scanner, a touch screen, a camera, an accelerometer, and a gyroscope. These and other input devices often are connected to the processor system 902 through a serial port interface 942 that is coupled to bus 906, but may be connected by other interfaces, such as a parallel port, game port, or a universal serial bus (USB).
[0194] A display device 944 (e.g., a monitor) is also connected to bus 906 via an interface, such as a video adapter 946. In an example, computer 900 includes other peripheral output devices (e.g., speakers or a printer), in addition to display device 944.
[0195] Computer 900 is connected to a network 948 (e g., the Internet) through a network interface 950 (e.g.. a network adapter), a modem 952, or other means for establishing communications over the network. Modem 952 is connected to bus 906 via serial port interface 942. In an example, modem 952 is incorporated into the computer. In another example, modem 952 is external to computer 900.
[0196] As used herein, the terms "‘computer program medium’" and “computer-readable storage medium” are used to generally refer to media (e.g., non-transitory media) such as the hard disk associated with hard disk drive 914, removable magnetic disk 918, removable optical disk 922, as well as other media such as flash memory' cards, digital video disks, random access memories (RAMs), read only memories (ROM), and the like. A computer-readable storage medium is not a signal, such as a carrier signal or a propagating signal. In an example, a computer-readable storage medium does not include a signal. Accordingly, a computer-readable storage medium does not constitute a signal per se. Such computer-readable storage media are distinguished from and non-overlapping with communication media (do not include communication media). Communication media embodies computer-readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media includes wireless media such as acoustic, RF. infrared and other wireless media, as well as wired media. Example embodiments are also directed to such communication media.
[0197] In an example, computer programs and modules (including application programs 932 and other program modules 934) are stored on the hard disk, magnetic disk, optical disk, ROM, or RAM. In another example, such computer programs are received via network interface 950 or serial port interface 942. Such computer programs, when executed or loaded by an application, enable computer 900 to implement features of embodiments discussed herein. Accordingly, such computer programs represent controllers of the computer 900.
[0198] Example embodiments are also directed to computer program products comprising software (e.g., computer-readable instructions) stored on any computer-useable medium. Such software, when executed in one or more data processing devices, causes data processing device(s) to operate as described herein. Embodiments may employ any computer-useable or computer-readable medium, known now or in the future. Examples of computer-readablemediums include, but are not limited to storage devices such as RAM, hard drives, floppy disks, CD ROMs, DVD ROMs, zip disks, tapes, magnetic storage devices, optical storage devices, MEMS-based storage devices, nanotechnology-based storage devices, and the like.
[0199] It will be recognized that the disclosed technologies are not limited to any particular computer or type of hardware. Certain details of suitable computers and hardware are well known and need not be set forth in detail in this disclosure.IV. Conclusion
[0200] The foregoing detailed description refers to the accompanying drawings that illustrate exemplary embodiments of the present invention. However, the scope of the present invention is not limited to these embodiments, but is instead defined by the appended claims. Thus, embodiments beyond those shown in the accompanying drawings, such as modified versions of the illustrated embodiments, may nevertheless be encompassed by the present invention.
[0201] References in the specification to “one embodiment." “an embodiment,” “an example embodiment,” or the like, indicate that the embodiment described may include a particular feature, structure, or characteristic, though each embodiment need not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the relevant art(s) to implement such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0202] Descriptors such as “first”, “second”, “third”, etc. are used to reference some elements discussed herein. Such descriptors are used to facilitate the discussion of the example embodiments and do not indicate a required order of the referenced elements, unless an affirmative statement is made herein that such an order is required.
[0203] Although the subject matter has been described in language specific to structural features and / or acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as examples of implementing the claims, and other equivalent features and acts are intended to be within the scope of the claims.
Claims
CLAIMS1. A system (102A-102M, 106A-106N, 500, 600) comprising:a processor system (602); anda memory (604, 608, 610) that stores computer-executable instructions that are executable by the processor system (602) to at least:execute a first artificial intelligence (Al) sub-agent ( 14), which triggers (202) a first Al model to aggregate subsets of a first plurality of log events (532) into clusters using relationships between attributes of the first plurality of log events (532) as a result of the subsets corresponding to potential security threat activities by providing a first Al input together with first contextual information as first inputs to the first Al model, wherein the first Al input requests aggregation of the first plurality of log events (532) into the clusters, wherein the first contextual information includes the first plurality of log events (532), wherein the first contextual information includes context regarding the first Al input, and wherein a first Al response that is received from the first Al model in response to the first Al input indicates the clusters;execute a second Al sub-agent (516), which triggers (204) a second Al model to map the potential security threat activities to at least one of attack framework techniques or attack framework tactics using relationships between attributes of the potential security’ threat activities and attributes of the at least one of the attack framework techniques or the attack framework tactics to provide framework-based threat mappings (544) by providing a second Al input together with second contextual information as second inputs to the second Al model, wherein the second Al input requests mapping of the potential security threat activities to the at least one of the attack framework techniques or the attack framework tactics, wherein the second contextual information includes the potential security threat activities and the at least one of the attack framework techniques or the attack framework tactics, wherein the second contextual information includes context regarding the second Al input, and wherein a second Al response that is received from the second Al model in response to the second Al input indicates the framework-based threat mappings (544);execute a third Al sub-agent (518), which triggers (206) a third Al model to generate queries (546) that define the potential security threat activities using relationships between attributes of the framework-based threat mappings (544) by providing a third Al input together with third contextual information as third inputs to the third Al model, wherein the third Al input requests generation of the queries (546), wherein the third contextual information includes the framework-based threat mappings(544), wherein the third contextual information includes context regarding the third Al input, and wherein a third Al response that is received from the third Al model in response to the third Al input indicates the queries (546);identify (208) a designated potential security threat activity in a second plurality of log events (534) by performing a search of the second plurality of log events (534) using a designated query that defines the designated potential security threat activity, wherein the potential security threat activities include the designated potential security threat activity, and wherein the queries (546) include the designated query; and perform (210) a security action (554) with regard to an identified subset of the second plurality of log events (534) as a result of the identified subset of the second plurality of log events (534) corresponding to the designated potential security threat.
2. The system according to claim 1, wherein the computer-executable instructions are executable by the processor system to at least:execute a fourth Al sub-agent, which triggers a fourth Al model to parse the first plurality of log events and schemas that define structures of respective subgroups of the first plurality of log events to identify the attributes of the first plurality of log events using relationships between the first plurality of log events and the schemas by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests identification of the attributes of the first plurality of log events, wherein the fourth contextual information includes the first plurality of log events and the schemas, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the attributes of the first plurality of log events; andexecute the first Al sub-agent, which triggers the first Al model to aggregate the subsets of the first plurality of log events into the clusters as a result of the subsets of the first plurality of log events having subsets of the attributes that correspond to the potential security threat activities.
3. The system according to any one of claims 1 to 2, wherein the computer-executable instructions are executable by the processor system to at least:cause the subsets of the first plurality of log events to be sampled to provide sampled subsets of the first plurality of log events, the sampled subsets of the first plurality of log events including fewer log events than the subsets of the first plurality of log events; andexecute the second Al sub-agent, which triggers the second Al model to map the potential security threat activities to the at least one of the attack framework techniques or the attack framework tactics using the sampled subsets of the first plurality of log events in lieu ofthe subsets of the first plurality of log events to provide the framework-based threat mappings.
4. The system according to any one of claims 1 to 3, wherein the computer-executable instructions are executable by the processor system to at least:cause a first subset of the first plurality of log events to be sampled to provide a first sampled subset of the first plurality of log events by causing one of multiple log events in the first subset that have a same attribute value to be included in the first sampled subset.
5. The system according to any one of claims 1 to 4, wherein the computer-executable instructions are executable by the processor system to at least:execute a fourth Al sub-agent, which triggers a fourth Al model to consolidate a first subset of the first plurality of log events, which corresponds to a first potential security threat activity, and a second subset of the first plurality of log events, which corresponds to a second potential security threat activity, using relationships between attributes of the first potential security threat activity and attributes of the second potential security threat activity to provide a consolidated subset of the first plurality of log events as a result of a difference between the first potential security threat activity and the second potential security threat activity being less than or equal to a difference threshold by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests consolidation of identified subsets of the first plurality of log events corresponding to identified potential security threat activities having a difference that is less than or equal to the difference threshold, wherein the fourth contextual information includes the subsets of the first plurality of log events and the potential security threat activities, wherein the fourth contextual information includes context regarding the fourth Al input, wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the consolidated subset of the first plurality' of log events, and wherein the consolidated subset of the first plurality of log events corresponds to a consolidated potential security threat activity, which includes the first potential security threat activity and the second potential security threat activity; and execute the third Al sub-agent, which triggers the third Al model to generate a consolidated query that defines the consolidated potential security threat activity in lieu of generating a first query that defines the first potential security threat activity and a second query that defines the second potential security threat activity.
6. The system according to any one of claims 1 to 5, wherein the computer-executable instructions are executable by the processor system to at least:execute a fourth Al sub-agent, which triggers a fourth Al model to split an identified subset of the first plurality' of log events, which corresponds to an identified potential security threat activity, into a first subset of log events that are included in the identified subset and asecond subset of the log events that are included in the identified subset as a result of a number of the log events that are included in the identified subset being greater than or equal to a threshold number by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests splitting of a subset of the first plurality of log events into multiple subsets as a result of a number of log events in the subset being greater than or equal to the threshold number, wherein the fourth contextual information includes the subsets of the first plurality of log events, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates the first subset of log events that are included in the identified subset and the second subset of the log events that are included in the identified subset, the first subset corresponding to a first potential security threat activity, the second subset corresponding to a second potential security threat activity; andexecute the third Al sub-agent, which triggers the third Al model to generate first and second queries that define the first and second potential security threat activities in lieu of generating an identified query that defines the identified potential security threat activity.
7. The system according to any one of claims 1 to 6, wherein the computer-executable instructions are executable by the processor system to at least:execute the first Al sub-agent, which triggers the first Al model to define a first potential security threat activity using first attributes of a first subset of the first plurality of log events, to define a second potential security threat activity using second attributes of a second subset of the first plurality of log events and the first potential security threat activity, and to define a third potential security threat activity using third attributes of a third subset of the first plurality of log events, the first potential security threat activity, and the second potential security threat activity.
8. The system according to any one of claims 1 to 7, wherein the computer-executable instructions are executable by the processor system to at least:execute the first Al sub-agent, which triggers the first Al model to incrementally process respective portions of information regarding the first plurality of log events by limiting sizes of the respective portions to be less than or equal to a token limit of the Al model, wherein the first Al input indicates that the sizes of the respective portions are to be less than or equal to the token limit.
9. The system according to any one of claims 1 to 8, wherein the computer-executable instructions are executable by the processor system further to at least:execute a fourth Al sub-agent, which triggers a fourth Al model to correct syntax of a specified query, which defines a specified potential security threat activity, using a first subset ofthe first plurality of log events that corresponds to the specified potential security threat activity by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests checking correctness of the syntax of the specified query, wherein the fourth contextual information includes the first subset of the first plurality of log events, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates corrected syntax of the specified query that corrects the syntax.
10. The system according to any one of claims 1 to 9, wherein the computer-executable instructions are executable by the processor system further to at least:execute a fourth Al sub-agent, which triggers a fourth Al model to validate accuracy of a specified framework-based threat mapping, which maps a specified potential security threat activity to at least one of a first attack framework technique or a first attack framework tactic, by providing a fourth Al input together with fourth contextual information as fourth inputs to the fourth Al model, wherein the fourth Al input requests validation of the accuracy of the specified framework-based threat mapping, wherein the fourth contextual information includes the specified framework-based threat mapping, wherein the fourth contextual information includes context regarding the fourth Al input, and wherein a fourth Al response that is received from the fourth Al model in response to the fourth Al input indicates that the accuracy is validated.
11. A method implemented by a computing system (102A-102M, 106A-106N, 500, 600), the method comprising:causing (202), by a first artificial intelligence (Al) sub-agent (514), subsets of a first plurality of log events (532) to be aggregated into clusters as a result of the subsets corresponding to potential security threat activities;causing (204), by a second Al sub-agent (516), the potential security threat activities to be mapped to at least one of attack framework techniques or attack framework tactics to provide framework-based threat mappings (544);causing (206), by a third Al sub-agent (518), queries (546) that define the potential security threat activities to be generated using the framework-based threat mappings (544); causing (208) a designated potential security threat activity to be identified in a second plurality of log events (534) by causing a search of the second plurality of log events (534) to be performed using a designated query that defines the designated potential security threat activity, wherein the potential security' threat activities include the designated potential security threat activity, and wherein the queries (546) include the designated query: andperforming (210) a security action (554) with regard to an identified subset of the secondplurality of log events (534) as a result of the identified subset of the second plurality of log events (534) corresponding to the designated potential security threat.
12. The method according to claim 11, further comprising:causing, by a fourth Al sub-agent, attributes of the first plurality of log events to be identified by causing the first plurality of log events and schemas that define structures of respective subgroups of the first plurality of log events to be parsed;wherein causing the subsets of the first plurality of log events to be aggregated into the clusters comprises:causing, by the first Al sub-agent, the subsets of the first plurality of log events to be aggregated into the clusters as a result of the subsets of the first plurality of log events having subsets of the attributes that correspond to the potential security threat activities.
13. The method according to any one of claims 11 to 12, wherein causing the subsets of the first plurality of log events to be aggregated into the clusters comprises:causing, by the first Al sub-agent, titles that identify the potential security threat activities to be generated; andcausing, by the first Al sub-agent, descriptions that explain reasoning for the subsets of the first plurality of log events being aggregated into the clusters to be generated; and wherein causing the queries to be generated comprises:causing, by the third Al sub-agent, the queries that define the potential security threat activities to be generated using the titles and the descriptions.
14. The method according to any one of claims 11 to 13, further comprising:causing, by a fourth Al sub-agent, accuracy of a specified title, which identifies a specified potential security threat activity, to be validated, wherein the titles include the specified title, and wherein the potential security threat activities include the specified potential security' threat activity.
15. The method according to any one of claims 11 to 14, further comprising:causing, by a fourth Al sub-agent, accuracy of a specified description, which explains reasoning for a specified subset of the first plurality' of log events being aggregated into a specified cluster, to be validated, wherein the descriptions include the specified description, wherein the subsets of the first plurality of log events include the specified subset of the first plurality of log events, and wherein the clusters include the specified cluster.
16. The method according to any one of claims 11 to 15, wherein causing the subsets of the first plurality7of logs to be aggregated into the clusters comprises:causing, by the first Al sub-agent, a first potential security' threat activity to be defined using first attributes of a first subset of the first plurality of log events;causing, by the first Al sub-agent, a second potential security threat activity to be defined using second attributes of a second subset of the first plurality' of log events and the first potential security threat activity; andcausing, by the first Al sub-agent, a third potential security threat activity to be defined using third attributes of a third subset of the first plurality of log events, the first potential security threat activity, and the second potential security threat activity.
17. The method according to any one of claims 11 to 16, wherein causing the potential security threat activities to be mapped comprises:causing, by the second Al sub-agent, a specified potential security threat activity to be mapped to at least one of multiple attack framework techniques or multiple attack framework tactics to provide a specified framework-based threat mapping; andwherein causing the queries to be generated comprises:causing, by the third Al sub-agent, a specified query that defines the specified potential security threat activity to be generated using the specified framework-based threat mapping.
18. The method according to any one of claims 11 to 17, further comprising:causing, by a fourth Al sub-agent, syntax of a specified query', which defines a specified potential security’ threat activity, to be corrected using a first subset of the first plurality of log events that corresponds to the specified potential security threat activity.
19. The method according to any one of claims 11 to 18, further comprising:causing, by a fourth Al sub-agent, accuracy of a specified framework-based threat mapping, which maps a specified potential security threat activity to at least one of a first attack framework technique or a first attack framework tactic, to be validated.
20. A computer program product (618, 622) comprising a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system (102A-102M, 106A-106N, 500. 600) to perform operations, the operations comprising:executing a first artificial intelligence (Al) sub-agent (514) that causes (202) subsets of a first plurality' of log events (532) to be aggregated into respective clusters as a result of the subsets corresponding to respective potential security threat activities (544);executing a second Al sub-agent (516) that causes (204) the respective potential security threat activities (544) to be mapped to at least one of respective attack framework techniques or respective attack framework tactics to provide respective framework-based threat mappings; executing a third Al sub-agent (518) that causes (206) queries (546), yvhich define the respective potential security threat activities (544), to be generated using the respective framework-based threat mappings;causing (208) a designated potential security threat activity to be identified in a second plurality of log events (534) by causing a search of the second plurality of log events (534) to be performed using a designated query that defines the designated potential security threat activity, wherein the respective potential security threat activities (544) include the designated potential security threat activity, and wherein the queries (546) include the designated query; and performing (210) a security action (554) with regard to an identified subset of the second plurality of log events (534) as a result of the identified subset of the second plurality of log events (534) corresponding to the designated potential security threat.