Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

437 results about "Cybersafety" patented technology

Automated Mapping of Raw Data into a Data Fabric

The disclosed embodiments provide systems and methods for automated mapping of raw data into a data fabric. An innovative approach leveraging Artificial Intelligence (AI)-powered tools and a data fabric to automate the ingestion, transformation, and integration of raw data into a unified model is introduced. By automating the data mapping process, organizations can reduce reliance on manual methods and accelerate their ability to utilize robust insights for exposure management and attack surface reduction. The disclosed solution provides a scalable architecture for unifying cybersecurity signals across cloud and hybrid environments, enabling real-time decision-making and improved organizational resilience against cyber threats
Owner:AVALOR TECH LTD

Natural language query to domain-specific database query conversion with language models

A natural language to database query converter (converter) receives a natural language query from a user (i.e., a user utterance) and identifies a cybersecurity domain related to intent of the natural language query. The converter then generates a database query for a query language of the cybersecurity domain corresponding to the natural language query with a large language model (LLM). An initial prompt to the LLM generated by the converter specifies a grammar of the query language and instructs the LLM to generate an initial database query that functions like the natural language query and satisfies the grammar. If a lint program determines that the initial database query is not valid for the query language, the converter generates a follow-up prompt to the LLM that indicates valid database queries from which to generate a follow-up database query. A query parser retrieves data that satisfy the initial or follow-up database query and a visualization / summarization module generates graph visualizations and summaries of the retrieved data.
Owner:PALO ALTO NETWORKS INC

Systems and methods for modeling micro-protections using cybersecurity data and third-party parameters

Systems, methods, and computer-readable storage media for providing a composable cyber resilience object. A method can include identifying, by one or more processing circuits, a posture state of at least one entity, generating or selecting a first plurality of code blocks corresponding with a parameters of at least one third-party, and determining the entity qualifies for protection based on the posture state and the rules or conditions. The method can include generating or selecting a second plurality of code blocks including functions to provide the protection based on the rules or conditions and generating the composable cyber resilience object by integrating a portion of the first plurality of code blocks and the second plurality of code blocks into at least one data structure. The method can include linking the composable cyber resilience object and a computing or networking infrastructure of the entity using a communication interface or structure.
Owner:AS0001 INC

Cybersecurity event detection, analysis, and integration from multiple sources

The present disclosure presents methods and systems for determining cybersecurity risk exposure for entities. In one aspect, a method is provided that includes providing first text data to a trained LLM to identify data associated with a first candidate cybersecurity event for an entity, comparing the entity's identifier to domain information to verify the entity's identifier, determining if the first candidate cybersecurity event represents a new cybersecurity event based on com with previous data, and updating a cybersecurity risk score for the entity based on this determination. Further enhancements include training the LLM with cybersecurity event data, outputting documentation of the event source, and various methods for evaluating the novelty and severity of the cybersecurity event, including similarity measures and manual review triggers. The techniques leverage LLMs, machine learning models, and automated actions to provide a comprehensive approach to cybersecurity risk assessment and response. Other aspects are also provided.
Owner:SECURITYSCORECARD INC

Automated security testing systems using multi-tiered language models

PendingUS20250335601A1Platform integrity maintainanceLocal languageSecurity testing
Cost-effective cyber security risk countermeasure systems and methods enable LLM-based automated security testing for managed cybersecurity services, without leaking sensitive information about target systems. In embodiments, this is accomplished by utilizing flexible local language models that identify and filter target system specific information when communicating with a public large language model to obtain highly accurate security testing patterns.
Owner:HITACHI LTD

Cybersecurity alert response chatbot via large language models and natural langauge alert descriptors

As cybersecurity alerts are detected and logged as formatted descriptors across an organization, a text converter converts the formatted descriptors into natural language descriptors by extracting and inserting metadata fields into natural language templates corresponding to user personas for the organization. In response to an alert-based query from a user, a persona classifier predicts a persona of the user from historical chat logs and retrieves natural language descriptors for alerts related to the user and predicted persona. A prompt generator receives the retrieved natural language descriptors and generates a prompt that instructs a large language model (LLM) to respond to the user with data from the natural language descriptors. Once prompted, the LLM establishes a conversation with the user via an interface for alert resolution.
Owner:PALO ALTO NETWORKS INC

Cybersecurity Command Line Assessment

A cloud-based, machine-learned cybersecurity command line interpretation service simplifies complex command lines using plain language. Command lines are input to the cybersecurity command line interpretation service for an interpretation by a machine learning model. If, however, a command line is known and been previously interpreted, then the cybersecurity command line interpretation service may conserve hardware and software resources by retrieving a historical command line interpretation. If the command line is unknown or not historically logged, then the cybersecurity command line interpretation service may generate a current command line interpretation using the machine learning model. The cybersecurity command line interpretation service may then generate a cybersecurity prediction associated with the command line based on the historical or current command line interpretation. The cybersecurity command line interpretation service thus provides a much faster interpretation and cybersecurity prediction for assessing command lines as malicious or benign.
Owner:CROWDSTRIKE

Cybersecurity threat detection utilizing sensor-based aggregated runtime execution data

A system and method for cybersecurity threat detection using an activity baseline generated based on sensor-detected runtime execution data is presented. The method includes: receiving aggregated runtime data from a sensor deployed on a resource in a cloud computing environment; generating an event log based on the aggregated runtime data, each event in the event log generated by extracting data from the aggregated runtime data; generating an activity baseline for a process executed on the resource based on the event log; receiving a new event from the sensor; and determining that the new event is anomalous based on the generated activity baseline.
Owner:WIZ INC

Modular cybersecurity engine in a data intelligence system

Methods, systems, and computer storage media for providing a modular cybersecurity platform are described. The modular cybersecurity platform is implemented using a modular cybersecurity engine that operates based on an analytical framework for dynamic data analysis and data management in a data intelligence system. In particular, the analytical framework is based on complementary modular components that are designed to interoperate in the modular cybersecurity engine. The modular cybersecurity engine includes a modular distributed system, a credential detection system, and a credential semantic graph system. The modular cybersecurity engine supports cybersecurity and sensitive data management scenarios that can empower investigators in various investigations, and provide automated flows that are highly scalable and support different types of functionality (e.g., priority embedding pipeline, credential scanning, and credential semantic graph analysis). The utility of the modular cybersecurity engine is demonstrated by its wide-ranging application in addressing complex cybersecurity challenges and sensitive data management tasks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for training a generative adverserial model in a cybersecurity range

A system and method for utilizing a generative adversarial model for training in a cybersecurity range is presented. The method includes: generating a plurality of scenarios based on a plurality of predetermined actions in a cloud computing environment; initiating a cybersecurity range, the cybersecurity range including a secure cloud computing environment and a plurality of workloads deployed therein; generating a prompt for a large language model (LLM) based on a template, a scenario of the plurality of scenarios, and an identifier of a workload of the plurality of workloads; and initiating an action in the cybersecurity range based on an output generated by the LLM in response to the prompt.
Owner:CYMPIRE LTD

Systems and methods for improving cybersecurity using detection and response models and data valuation frameworks

A method can include determining, by one or more processing circuits, a cybersecurity resilience posture of an entity. The method can include identifying or generating, by the one or more processing circuits, at least one token comprising a proof or a posture state corresponding with the cybersecurity resilience posture of the entity. The method can include determining, by the one or more processing circuits using a cyber threat intelligence (CTI) model, at least one of a quantitative value or a qualitative value corresponding to the at least one token. The method can include updating, by the one or more processing circuits, a cybersecurity profile of the entity corresponding to at least one protection product.
Owner:AS0001 INC

AI-Powered Policy Evaluation and Ethical Compliance System

An artificial intelligence (AI)-powered system for policy evaluation, bias mitigation, and regulatory compliance. The system retrieves AI policies from multiple sources, including APIs, document parsing, and structured web scraping, ensuring real-time updates. It applies machine learning and natural language processing (NLP) to generate unbiased policy summaries and detect cybersecurity, ethics, and compliance gaps. A policy optimization engine analyzes governance trends and refines recommendations based on adoption feasibility. The system includes a sandbox testing framework that simulates regulatory and societal impacts to assess policy effectiveness. This AI-driven approach enhances fairness, transparency, and cybersecurity resilience in AI governance, enabling policymakers to proactively align with global regulatory frameworks and mitigate policy risks.
Owner:CYBER INSTITUTE

System and method for policy management in cloud computing environments

A system and method for cybersecurity policy management in a computing environment is presented. The method includes receiving a selection of a first cybersecurity policy of a digital security platform of a computing environment; applying the first cybersecurity policy to generate a first measurement; generating a second cybersecurity policy based on the first cybersecurity policy and a result of the first measurement; applying the second cybersecurity policy to generate a second measurement; generating a third cybersecurity policy based on a result of the second measurement and the second cybersecurity policy; and applying the third cybersecurity policy on the computing environment.
Owner:CYERA LTD

System and Method for Cybersecurity Threat Detection and Prevention with Discrete Event Simulation

A system and method for comprehensive data loss prevention and compliance management designed to identify and prevent cybersecurity attacks on modern, highly-interconnected networks, to identify attacks before data loss occurs, using a combination of human level, device level, system level, and organizational level monitoring and protection.
Owner:QPX LLC

Devices, systems, and methods for categorizing, prioritizing, and mitigating cyber security risks

A method for managing cyber security risk for a client entity communicating with a plurality of target entities is disclosed. In one aspect, the method includes identifying a plurality of cyber asset footprints, wherein each cyber asset footprint comprises cyber assets associated with a different one of the target entities. In another aspect, the method includes monitoring a plurality of data sources comprising cyber security risk information to generate source data, wherein the source data is organized based on a plurality of risk factors, and wherein the risk factors are classified according to a cyber security risk taxonomy. In yet another aspect, the method includes identifying relevant observations in the source data, wherein each relevant observation comprises information related to one the risk factors, and wherein each relevant observation is identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints.
Owner:BLUEVOYANT LLC

Analysis and prioritization of vulnerabilities of connected vehicles

An automotive cybersecurity platform receives vulnerability alerts that may impact a connected vehicle. Software components of the connected vehicle are identified and listed. Software components that are affected by a vulnerability are identified using information from a vulnerability alert. An overall risk score of the vulnerability is determined based at least on whether the vulnerability can be triggered, how the vulnerability affects the connected vehicle when the vulnerability is triggered, and an intrinsic risk posed by the vulnerability. Remediation of the vulnerability is prioritized based at least on the overall risk score of the vulnerability.
Owner:VICONE CORP

System, method, and computer program for scoring and organizing evidence of cybersecurity threats from multiple data sources

The present disclosure relates to a system, method, and computer program for scoring and organizing evidence of cybersecurity threats from multiple data sources. The system receives potential evidence of cybersecurity threats from multiple different data sources, typically each with their own scoring scale. The system scores / rescores the incoming data items on a common scale based on a set of behavior indicators specific to each data stream. Threat paths are then identified and scored from the scored / rescored data from the different sources. In certain embodiments, the system alters the initial data item scores based on a set of prioritization weights that enables certain factors to be prioritized over other factors in assessing the cybersecurity risk associated with the data items. Likewise, in certain embodiments, the initial threat path scores are also altered based on another set of prioritization weights for threat paths. In certain embodiments, cases are automatically created for threat paths scores satisfying a case-creation threshold.
Owner:EXABEAM INC

Cybersecurity risk and feature freeze model

PendingUS20260023549A1Platform integrity maintainanceSoftware deploymentRisk levelChange management (ITSM)
A change management methodology for a bank's systems and applications which includes an evaluation of cybersecurity risk as a decision factor. The method includes calculating a cybersecurity risk level associated with non-security-driven changes to applications and systems in the bank's computing environment and, when the risk level of any change exceeds a threshold, freezing the change until the risk level can be reduced to a lower level. A cybersecurity risk calculation model computes a risk level for a proposed change to a system or application based on numerous factors. The risk level associated with the proposed change is combined with an existing risk level status of the system or application, and the business unit with which it is aligned. The aggregate risk level leads to a decision which is used as a go / no-go checkpoint in the change management methodology.
Owner:TRUIST BANK

Domain knowledge-driven threat intelligence characteristic index generation method

The invention discloses a domain knowledge-driven threat intelligence characteristic index generation method, and belongs to the field of network security. Aiming at the problems of domain knowledge deficiency, insufficient interpretability, poor dynamic adaptability and the like existing in a traditional data driving method, the invention provides a framework fusing expert knowledge and data driving through domain knowledge graph construction, multi-modal feature fusion and dynamic weight optimization; comprising the steps of domain knowledge modeling, multi-modal feature fusion and index generation and verification. According to the method, the interpretable indexes conforming to the ST IX format are generated, practice verifies that the defects of a traditional method are effectively overcome, and the accuracy, interpretability and dynamic adaptability of threat intelligence analysis are improved.
Owner:GUANGXI POWER GRID CORP

Detection engine having risk-based severity alerts

A system and method for executing mitigation actions in a cloud computing environment based on a severity of a detected cybersecurity risk is presented. The method includes detecting a cybersecurity risk based on an enriched event record from a cloud log, the enriched event record including runtime data from a resource deployed in a cloud computing environment and a state of an entity detected in the runtime data; determining a severity score for the detected cybersecurity risk of the enriched event record; prioritizing a plurality of mitigation actions based on the severity score; and executing at least a mitigation action in the cloud computing environment based on the prioritization.
Owner:WIZ INC

System and Method for Automated Penetration Testing and Security Assessment

PendingUS20250343818A1Securing communicationAttackSocial engineering (security)
A system for automated penetration testing using artificial intelligence (AI) is described, which aims to enhance cybersecurity by simulating attacks on software and computer systems in order to measure and identify vulnerability. The platform employs AI agents to perform tasks including script execution for vulnerability testing, social engineering simulations, comprehensive security assessments, and more, thereby reducing costs, time, potential risks associated with traditional penetration testing methods, and providing a more complete and available solution than humans can produce alone.
Owner:IMMESOETE CAMERON

System and method for delayed log ingestion utilizing agentless collection

A system and method for ingesting delayed logs for cybersecurity detection is presented. The method includes detecting a resource deployed in a computing environment, the resource configured to generate a local log on a disk of the resource; periodically fetching the local log from the disk, the local log including a plurality of event records written by at least a software application executed on the resource; applying a control on the fetched local log; and detecting a cybersecurity issue on the resource based on a result of applying the control.
Owner:WIZ INC

System and Method for Adaptive, Closed-Loop Prioritization of Cybersecurity Controls

PendingUS20250378178A1Metadata text retrievalPlatform integrity maintainanceMultiple-criteria decision analysisEngineering
A computer-implemented system and method for dynamic, explainable, and adaptive prioritization of cybersecurity controls is disclosed. The system ingests unstructured threat reports and employs a natural language processing (NLP) module to automatically extract adversary tactics, techniques, and procedures (TTPs). A scoring module applies a mathematical time-decay function to the extracted intelligence. A novel hybrid prioritization engine provides explainability-by-design by computationally integrating these objective, data-driven scores with organization-specific context within a transparent multi-criteria decision analysis (MCDA) model. Critically, the system establishes a self-optimizing closed feedback loop; it receives real-world control effectiveness metrics from the operational environment and uses this data as new ground-truth labels to continuously and automatically retrain internal machine learning models. This adaptive mechanism improves the computer's own predictive accuracy and resource allocation efficiency over time, representing a tangible technical improvement.
Owner:PETTINGILL JEFFREY

Cloud-Based File Integrity Monitoring

ActiveUS20250371154A1Platform integrity maintainanceTransmissionFile integrity monitoringOperational system
A cloud-based file integrity monitoring service identifies content changes to a computer file. An endpoint cybersecurity agent monitors its host client device for read / write and other operating system events associated with the computer file. When the endpoint cybersecurity agent detects each operating system event, the endpoint cybersecurity agent captures and reports, in real time or near real time, a snapshot of the file content representing the computer file. So, as the host client device changes the computer file with each operating system event, the endpoint cybersecurity agent uploads timestamped snapshots of the file content to a cloud-based file integrity monitoring service. The cloud-based file integrity monitoring service stores each snapshot of the file content, thus logging a change history for the computer file. The cloud-based file integrity monitoring service may thus retrieve and analyze different snapshots at different points in time, thus quickly identifying the content changes to the computer file.
Owner:CROWDSTRIKE

AutoWrap robotics: humanoid AI for autonomous vehicle service centers

The AutoWrap Robotics Humanoid Service Center System is an innovative AI platform that autonomously manages vehicle service centers using a fleet of humanoid robots. It coordinates customer interaction, advanced diagnostics (including for EVs / SDVs) with Explainable AI, and autonomous vehicle repairs, alongside facility and outdoor maintenance. Integrating cutting-edge humanoid robots with sophisticated AI, machine learning, and multi-modal sensing, the platform provides semantic understanding of complex environments. It boosts service quality, reduces labor demands, and dramatically increases operational efficiency, transforming underperforming properties into highly productive autonomous centers. Key features include augmented reality interfaces, robust cybersecurity for in-vehicle networks and robot operations, predictive maintenance, and real-time, socially adaptive humanoid-mediated customer communication. Delivered as a scalable Software-as-a-Service (SaaS) solution, the system provides essential AI intelligence for fully autonomous, comprehensive, and sustainable vehicle servicing.
Owner:AUTOWRAP ROBOTICS LLC

Generative AI report on security risk using LLMs

Systems and methods for sing Large Language Models (LLMs) to generate an Artificial Intelligence (AI) report on security risk using the cybersecurity data include obtaining cybersecurity monitoring data for an organization where the cybersecurity monitoring data is from a plurality of sources including from cybersecurity monitoring of a plurality of users associated with the organization; inputting the cybersecurity monitoring data to a first Large Language Model (LLM) to generate an initial output for a security report; inputting the initial output to a second LLM for critiquing the initial output against a set of rules to check for predefined flaws and to check for what was done correctly to generate a critique; resolving the initial output and the critique to generate a final output; and providing the final output for the security report.
Owner:ZSCALER INC

Dynamically providing cybersecurity training based on user-specific threat information

Aspects of the disclosure relate to dynamically providing cybersecurity training based on user-specific threat information. A computing platform may receive, from a targeted attack protection (TAP) server, user-specific threat information indicating at least one threat that has been encountered by at least one user. The computing platform may identify one or more users to receive cybersecurity training in a first cybersecurity training topic based on the user-specific threat information indicating the at least one threat that has been encountered by the at least one user. Subsequently, the computing platform may load one or more cybersecurity training modules based on identifying the one or more users to receive the cybersecurity training in the first cybersecurity training topic. Then, the computing platform may provide the one or more cybersecurity training modules to one or more user computing devices.
Owner:PROOFPOINT INC

Prediction of False Positive Cybersecurity Detections

PendingUS20260089177A1Securing communicationComputer usageData science
Prediction of false positive cybersecurity detections greatly improves computer functioning. When a client device reports a cybersecurity detection, the cybersecurity detection is compared to a false positive cybersecurity detection profile. The false positive cybersecurity detection profile represents false positive characteristics associated with false positive cybersecurity detections. If the cybersecurity detection conforms to the false positive cybersecurity detection profile, then the cybersecurity detection may be categorized as false positive and normal operation. If, however, the cybersecurity detection fails to conform to the false positive cybersecurity detection profile, then the cybersecurity detection may be categorized as true positive and abnormal operation. The identification of false positive cybersecurity detections produces a more accurate detection of legitimate computer usage / activity.
Owner:CROWDSTRIKE