Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Security operations center" patented technology

A security operations center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. A SOC within a building or facility is a central location from where staff supervises the site, using data processing technology. Typically, a SOC is equipped for access monitoring, and controlling of lighting, alarms, and vehicle barriers.

System and method for dynamic network security risk identification based on multi-source information and ai driving

The application relates to the technical field of network security, and discloses a dynamic network security risk identification system and method based on multi-source intelligence and AI driving, which comprises a dynamic attack graph modeling module, an AI-driven attack simulation engine and a cooperation module.The modeling module fuses multi-source heterogeneous intelligence to construct a network attack graph and calculate node intelligence confidence; the AI engine takes the confidence into a state space, uses a dynamic entropy mechanism to real-time adjust the randomness of reinforcement learning exploration to accurately simulate an attack path; and the cooperation module links external attack surface management and a security operation center to execute closed-loop feedback verification of automatic defense response and path elimination.The application establishes a mapping relationship between intelligence confidence and exploration strategy, effectively solves the problems of uneven multi-source data quality and unknown path missing report, realizes an automatic closed loop from risk perception, simulation deduction to effect verification, and significantly improves risk identification accuracy and response timeliness.
Owner:CSG EHV POWER TRANSMISSION

Remote monitoring of a security operations center (SOC)

ActiveUS12652315B2Security arrangementSecuring communicationSecurity operations centerBusiness enterprise
Systems and methods for remote monitoring of a Security Operations Center (SOC) via a mobile application are provided. According to one embodiment, a management service retrieves information regarding multiple network elements that are associated with an enterprise network and extracts parameters of the monitored network elements from the retrieved information. The management service prioritizes the monitored network elements by determining a severity level associated with security-related issues of the network elements and generates various monitoring views that summarize in real time various categories of potential security-related issues detected by the SOC. Further, the management service assigns a priority to each monitoring view and displays a video on the display device that cycles through monitoring views in accordance with their respective assigned priorities.
Owner:FORTINET INC

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

Intelligent security operation method and device based on c4isr and electronic equipment

PendingCN122179228ASecuring communicationKnowledge based modelsLinguistic modelSecurity operations center
The application belongs to the technical field of information security, and relates to an intelligent security operation method and device based on C4ISR and electronic equipment, the method comprising: constructing a network security field large language model; embedding the network security field large language model as an intelligent core into an existing security operation center; establishing a multi-agent mapping model based on C4ISR; designing a multi-agent collaborative work architecture based on the multi-agent mapping model; formulating a multi-agent system closed-loop work process; and designing a hierarchical fusion security operation center platform architecture. The risk research and response efficiency is improved, global collaboration and active defense are realized, and asset management and situation awareness capabilities are enhanced.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Autonomous cybersecurity operations center utilizing micro-model architecture

ActiveUS20260142866A1Platform integrity maintainanceTransmissionTicketSecurity operations center
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
Owner:CONIFERS TECHNOLOGIES INC

System and method for using large language models to respond to information security incidents

An exemplary method for security monitoring and incident response using large language models comprises: receiving input data from elements of Security Operations Center (SOC), generating and sending a query based on the received input data to a Large Language Model (LLM), parsing a response received from the LLM, and performing analysis to determine whether a threat has been identified. In one aspect, the method further comprises: when a threat is identified, collecting artifacts of the threat, and analyzing the threat further with involvement of security professionals, when a threat is not identified, determining whether additional data is needed, and when additional data is needed, determining a type of the additional data, when the type of additional data that is determined, collecting additional information from elements of the SOC, and when additional data is not needed, terminating the incident response.
Owner:AO KASPERSKY LAB