Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Security analyst" patented technology

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Protection for electronic communications

A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

Protection for electronic communications

PCT designated stageWO2026147764A1Electronic communicationEngineering
A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

Network security text-to-kql query generation method and system based on pattern screening and semantic verification, and storage medium

The application provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium, and the method comprises the following steps: S1, data input and task definition; receiving a user natural language query Q and a whole database pattern S, wherein Q is a user natural language retrieval / analysis intention, and S represents a set of all tables and fields in the system; S2, pattern optimization based on a hybrid attention model; S3, candidate KQL generation based on few-shot adaptation; and S4, KQL verification and selection based on execution signature and reasoning. The application has the beneficial effects that the application solves the problem of how to accurately and efficiently convert a natural language into a KQL query statement, reduces the technical threshold of a security analyst in a data query process, improves the efficiency of data query and analysis, and enhances the ability and response speed of network security protection.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)