Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

118 results about "Threat mitigation" patented technology

Threat Mitigation is the process used to lessen the extent of a problem or attack by isolating or containing a threat until the problem can be remedied. LEARN MORE ABOUT Threat Mitigation AND RELATED TECHNOLOGIES.

Security for generative models using attention analysis

Devices and techniques are generally described for security threat mitigation for generative machine learning models. In some examples, first prompt data including first data associated with a first natural language input and a first span may be determined. An LLM may determine first plan data using the first prompt data. The first plan data may include a call to the first API. A first classifier model may determine a first trust score for the first span. A first attention score may be determined for the first span and the first action plan. Second plan data may be generated based on at least one of the first trust score and the first attention score or the second trust score and the second attention score.
Owner:AMAZON TECH INC

Threat Mitigation System and Method

A computer-implemented method, computer program product and computing system for receiving a message concerning an event within a computer platform, wherein the message concerns a technology type and includes raw data; defining a cipher for the technology type, thus defining an associated cipher; processing the raw data included within the message using the associated cipher to define supplemental data for the technology type; and forming enriched data for the technology type based, at least in part, upon the raw data and the supplemental data.
Owner:RELIAQUEST HOLDINGS LLC

Knowledge-based taint policy inference

Security vulnerability analysis may be performed using policy inference. Application code may have operations that are labeled according to the respective functions that they perform. Some operations may be labeled according to a knowledge database of known operations while others may be inferred through similarity to known operations. The knowledge database may be associated with libraries of programmatic interfaces. Once components of the application code are labeled, a vulnerability database may be that identifies potential vulnerabilities based on data sources, data sinks and threat mitigation operations. Using the labeled operations, one or more potential vulnerabilities may be identified based on labeled data sources and data sinks. The application may then be evaluated for potential security threats based on the identified potential vulnerabilities.
Owner:AMAZON TECH INC

Systems and methods for automatically creating normalized security events in a cybersecurity threat detection and mitigation platform

A system, method, and computer-program product includes obtaining raw event data associated with a subscriber, automatically selecting an automated event ingestion instruction of a plurality of distinct automated event ingestion instructions for processing the raw event data, automatically generating a pre-normalized security event that includes the raw event data in a first structured data object in response to executing the automated event ingestion instruction, automatically transforming the pre-normalized security event to at least one normalized security event, automatically assessing a corpus of computer-executable detection instructions against the at least one normalized security event, generating a security alert based on the at least one normalized security event satisfying a set of alerting conditions of a subject computer-executable detection instruction of the corpus of computer-executable detection instructions, and executing a threat mitigation response that mitigates a security threat associated with the security alert.
Owner:EXPEL INC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for defining a formatting script for use with a Generative AI Model; receiving a plurality of notifications of a security event, wherein each of the plurality of notifications includes a computer-readable language portion that defines one or more specifics of the security event, thus defining a plurality of computer-readable language portions; processing at least a portion of each of the plurality of computer-readable language portions using the Generative AI Model and the formatting script to summarize each of the computer-readable language portions and generate a plurality of event summaries; and′ processing at least a portion of each of the plurality of event summaries using the Generative AI Model and the formatting script to summarize the plurality of event summaries and generate a summarized human-readable report.
Owner:RELIAQUEST HOLDINGS LLC

Security threat mitigation for large language models

Devices and techniques are generally described for security threat mitigation for generative machine learning models. In some examples, first request data including a first request may be received. First prompt data may be generated based at least in part on the first request data. First plan data may be generated, the first plan data including a first API call to a first API of a first computer-implemented service. The first API call may be executed and first result data may be received in response to the first API call. A determination may be made that the first result data includes a first impermissible instruction to inject data into a subsequent prompt. First output data may be generated indicating that the first request cannot be completed.
Owner:AMAZON TECH INC

Privacy-preserving real-time system for validating and mitigating threats to structured healthcare transactions

Computer-implemented system for real-time validation and threat mitigation for structured health transactions, including: a client policy repository that contains client-specific validation rules, consent restrictions, and risk thresholds; a trusted policy execution enclave that only allows policies and models after remote attestation of code and configuration, and decrypts and processes protected fields exclusively within the enclave; a grammatically aware streaming validator that enforces format and semantic constraints and synthesizes an auto-repair suggestion in case of parser errors, transforming inputs into a policy-compliant form with minimal changes; a hybrid risk engine that calculates rule-based and learned risk scores and furthermore evaluates a subset of features using data protection-preserving calculations to determine risk contributions without decoding selected fields; a causal graph generator that correlates related transactions over time into an entity-resolved, time-aligned graph and identifies impossibility patterns with edge-wise responsibility values; a coordinator for federated learning who updates models from client-local aggregates under differential privacy budgets and suspends aggregation when a distribution drift above a policy threshold is detected; an audit subsystem that generates zero-knowledge evidence demonstrating that selected compliance predicates for a transaction have been met without disclosing protected health information; a risk-adaptive flow control system that directs high-risk substreams into micro-quarantine sections with enhanced testing while maintaining the basic service quality for low-risk substreams; and a register that stores a validity context mark which links each decision to the identity of the policies, models, scope of consent and runtime environment used.
Owner:BHATIA VISHI SINGH LOUISVILLE +3

Systems and processes for creating software bill of materials for large distributed builds

Systems are provided for generating, modifying and using SBOMs for facilitating risk assessment and threat mitigation for corresponding programs, and particularly for large programming builds. The creation and modification of the SBOMs includes processes for omitting declarations referenced in chunk SBOMs of program chunks incorporated into a final programming build associated with a build SBOM, but which are not actually utilized by the final programming build, as well as processes for adding new declarations for code segments that are not declared in the related chunk SBOMs, even though the code segments are utilized by the final programming build. Systems are also configured to use SBOMs in combination with configuration restriction records to assess and resolve threat events in a manner that can prevent unnecessary remedial actions for threat events that appear to be relevant to one or more files or dependencies incorporated into a program.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for generating one or more detection rules that are indicative of a security event, wherein the one or more detection rules are based upon historical suspect activity and / or historical security events; monitoring activity within a computing platform, thus defining monitored activity; comparing such monitored activity to the one or more detection rules to determine if such monitored activity includes suspect activity indicative of a security event; generating an initial notification of the security event, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; and iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.
Owner:RELIAQUEST HOLDINGS LLC

Systems and methods for automatically creating normalized security events in a cybersecurity threat detection and mitigation platform

A system, method, and computer-program product includes obtaining raw event data associated with a subscriber, automatically selecting an automated event ingestion instruction of a plurality of distinct automated event ingestion instructions for processing the raw event data, automatically generating a pre-normalized security event that includes the raw event data in a first structured data object in response to executing the automated event ingestion instruction, automatically transforming the pre-normalized security event to at least one normalized security event, automatically assessing a corpus of computer-executable detection instructions against the at least one normalized security event, generating a security alert based on the at least one normalized security event satisfying a set of alerting conditions of a subject computer-executable detection instruction of the corpus of computer-executable detection instructions, and executing a threat mitigation response that mitigates a security threat associated with the security alert.
Owner:EXPEL INC

Direct prompt injection threat mitigation using prompt processing units

In one implementation, a device identifies a first subject indicated by a prompt to a large language model. The device identifies a second subject indicated by the prompt to the large language model. The device determines whether the first subject and the second subject are mutually opposed subjects. The device prevents the large language model from processing the prompt when the first subject and the second subject are mutually opposed subjects.
Owner:CISCO TECHNOLOGY INC

Systems and methods for intelligently generating cybersecurity contextual intelligence and generating a cybersecurity intelligence interface

A system and method for adapting one or more cybersecurity microservices to accelerate cybersecurity threat mitigation includes constructing a subscriber-specific data corpus comprising a plurality of distinct pieces of computing environment-informative data of a target subscriber; adapting a subscriber-agnostic microservice of the cybersecurity service to a subscriber-specific microservice, wherein: the subscriber-agnostic microservice includes a plurality of subscriber-agnostic cybersecurity event handling instructions, and adapting the subscriber-agnostic microservice to the subscriber-specific microservice includes generating a plurality of context-informed cybersecurity event handling instructions; augmenting the subscriber-agnostic microservice to include the plurality of context-informed cybersecurity event handling instructions; computing for a target cybersecurity event a subscriber-specific threat severity level based on one or more of the plurality of context-informed cybersecurity event handling instructions; executing, by one or more computers, a threat mitigation action or threat disposal action based on the computing of the subscriber-specific threat severity level for the target cybersecurity event.
Owner:EXPEL INC

Systems and methods for real-time detection and mitigation of malicious electronic communications

A system, method, and computer-program product includes detecting an electronic communication transmitted to a message storage repository monitored by a threat detection and response service, retrieving unstructured message data of the electronic communication in response to detecting the transmission of the electronic communication to the message storage repository, transforming the unstructured message data of the electronic communication into a structured message data object interpretable by the threat detection and response service, assessing the structured message data object that corresponds to the electronic communication against a set of subscriber-agnostic threat detection instructions provided by the threat detection and response service and a set of subscriber-composable enrichments that include subscriber-composed threat detection instructions, automatically detecting the electronic communication as malicious based on the assessment, and executing a threat mitigation action that mitigates a security threat associated with the electronic communication.
Owner:SUBLIME SECURITY INC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification, wherein the summarized human-readable report defines one or more recommended actions; and automatically executing some or all of the recommended actions to address the security event.
Owner:RELIAQUEST HOLDINGS LLC

Threat mitigation system and method

A threat mitigation platform includes: an agent subsystem configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform; an executor subsystem configured to iteratively process the mitigation plan using a generative AI model to generate an output; and an output formatter subsystem configured to format the output and generate a summarized human-readable report for the initial notification.
Owner:RELIAQUEST HOLDINGS LLC

Systems and methods for accelerated remediations of cybersecurity alerts and cybersecurity events in a cybersecurity event detection and response platform

A system and method for accelerating a threat mitigation of malicious cybersecurity activity includes: identifying, via one or more processors, a cybersecurity event associated with a third-party application or a third-party service of a subscriber; generating, via the one or more processors, a service-proposed remediation action for the cybersecurity event based on the identifying of the cybersecurity event; automatically assessing, via the one or more processors, the service-proposed remediation action against automated remediation criteria of the subscriber based on the generation of the service-proposed remediation action; automatically constructing, via the one or more processors, a remediation action application programming interface (API) request for the service-proposed remediation action based on the service-proposed remediation action satisfying the automated remediation criteria of the subscriber; and automatically executing, via the one or more processors, the remediation action API request to remediation or mitigate a suspected cybersecurity threat associated with the cybersecurity event.
Owner:EXPEL INC

Method to mitigate phone theft

A method of mitigating the theft of a portable electronic device communicatively connected to a second portable electronic device via a communications subsystem comprising a short range wireless network. Upon detecting that predetermined theft mitigation criteria have been met activating threat mitigation measures including at least locking the screen of the potentially stolen device and prompting the potentially stolen device to emit an alarm tone to alert bystanders.
Owner:MOTOROLA MOBILITY LLC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; processing the initial notification using a generative AI model and a formatting script to define one or more recommended actions; automatically generating a playbook to effectuate at least one of the recommended actions; and processing the playbook to address at least a portion of the security event.
Owner:RELIAQUEST HOLDINGS LLC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for accessing interface rules for a remote resource; generating a connector interface based, at least in part, upon the interface rules; and accessing the remote resource via the connector interface
Owner:RELIAQUEST HOLDINGS LLC

Threat Mitigation System and Method

A computer-implemented method, computer program product and computing system for receiving a result set; providing the result set to a first prompt / generative AI model pair to generate a first output; providing the result set to at least a second prompt / generative AI model pair to generate at least a second output; and providing the first output and the at least a second output to a large language model to define a superior output chosen from the first output and the at least a second output.
Owner:RELIAQUEST HOLDINGS LLC

Methods and systems for system vulnerability determination and utilization for threat mitigation

Disclosed embodiments include receiving network data associated with a first system of a network. The network data may comprise first data, second data, third data, fourth data, fifth data, and sixth data. The method may quantify, the first data, the second data, the third data, the fourth data, the fifth data, and the sixth data. The method may further determine, a risk parameter based on the quantifying. The method may generate, a vulnerability risk profile for a vulnerability based on the risk parameter. The vulnerability profile may indicate a security weakness of the first system or the second system. The method may determine, based on the security weakness of the first system or the second system, a remediation protocol for minimizing the security weakness of the first system of the network or the second system of the network.
Owner:QUALYS

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for defining a formatting script for use with a Generative AI Model; receiving a plurality of notifications of a security event, wherein each of the plurality of notifications includes a computer-readable language portion that defines one or more specifics of the security event, thus defining a plurality of computer-readable language portions; processing at least a portion of each of the plurality of computer-readable language portions using the Generative AI Model and the formatting script to summarize each of the computer-readable language portions and generate a plurality of event summaries; and’ processing at least a portion of each of the plurality of event summaries using the Generative AI Model and the formatting script to summarize the plurality of event summaries and generate a summarized human-readable report.
Owner:RELIAQUEST HOLDINGS LLC

Threat Mitigation System and Method

A computer-implemented method, computer program product and computing system for defining a target result set size; executing an initial search on a data set to generate an initial result set; comparing the size of the initial result set to the target result set size; if the size of the initial result set is compatible with the target result set size, providing the initial result set to a requesting entity; and if the size of the initial result set is not compatible with the target result set size, revising the initial search to generate a revised search that is executed on the data set to generate a revised result set.
Owner:RELIAQUEST HOLDINGS LLC

Security threat mitigation

The present disclosure provides methods, systems and computer readable media for training and implementing a generative machine learning model for identifying security threats. Examples relate to training, in which a training image is provided to a generative model in a training prompt, with an Indicator of Compromise (loC) instruction pertaining to the image. The model generates a predicted loC and a model parameter is updated based on a loss function. Other examples relate to the use of trained generative models for cybersecurity. A mitigation prompt comprising a security image and an associated instruction is provided to a trained generative model. The model outputs an indication of a cybersecurity mitigation action based on the mitigation prompt, and the cybersecurity mitigation action is performed on the system. Certain example embodiments identify and automatically mitigate security issues using a multimodal generative model (MGM) though appropriate prompt engineering.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Asset remediation trend map generation and utilization for threat mitigation

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.
Owner:QUALYS

Systems and methods for digital threat assessment and mitigation using t-digest score distribution representations and percentile-based threat scoring in a digital threat mitigation platform

A system and method for quantile-based assessment and handling of digital events in a digital threat mitigation platform includes receiving, via an application programming interface (API), a request from a subscriber to assess a threat of a digital event, computing, using one or more threat scoring machine learning models, a digital threat inference based on one or more corpora of feature vectors associated with the digital event, wherein the digital threat inference includes an uncalibrated digital threat score, retrieving, from a database, a T-Digest data structure of historical digital threat scores of the subscriber, computing, using the T-Digest data structure of historical digital threat scores, a percentile-based threat score based on the uncalibrated digital threat score computed for the digital event, and executing an automated disposal decision computed for the digital event based on at least the percentile-based threat score satisfying automated decisioning instructions of the digital threat mitigation platform.
Owner:SIFT SCIENCE INC

Systems and methods for accelerated remediations of cybersecurity alerts and cybersecurity events in a cybersecurity event detection and response platform

A system and method for accelerating a threat mitigation of malicious cybersecurity activity includes: identifying, via one or more processors, a cybersecurity event associated with a third-party application or a third-party service of a subscriber; generating, via the one or more processors, a service-proposed remediation action for the cybersecurity event based on the identifying of the cybersecurity event; automatically assessing, via the one or more processors, the service-proposed remediation action against automated remediation criteria of the subscriber based on the generation of the service-proposed remediation action; automatically constructing, via the one or more processors, a remediation action application programming interface (API) request for the service-proposed remediation action based on the service-proposed remediation action satisfying the automated remediation criteria of the subscriber; and automatically executing, via the one or more processors, the remediation action API request to remediation or mitigate a suspected cybersecurity threat associated with the cybersecurity event.
Owner:EXPEL INC

Threat mitigation system and method

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform; identifying two or more associated detection events included within the plurality of detection events; and grouping the two or more associated detection events to define a security incident.
Owner:RELIAQUEST HOLDINGS LLC

Security threat mitigation

The present disclosure provides methods, systems and computer readable media for training and implementing a generative machine learning model for identifying security threats. Examples relate to training, in which a training image is provided to a generative model in a training prompt, with an Indicator of Compromise (loC) instruction pertaining to the image. The model generates a predicted loC and a model parameter is updated based on a loss function. Other examples relate to the use of trained generative models for cybersecurity. A mitigation prompt comprising a security image and an associated instruction is provided to a trained generative model. The model outputs an indication of a cybersecurity mitigation action based on the mitigation prompt, and the cybersecurity mitigation action is performed on the system. Certain example embodiments identify and automatically mitigate security issues using a multimodal generative model (MGM) though appropriate prompt engineering.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods for mitigating denial of service attacks

ActiveUS12719924B2Data packInternet privacy
Examples of the present disclosure are directed to systems and methods for using router identifier information to mitigate denial of service attacks in an autonomous system (AS). Each router of the AS may be assigned a router identifier (ID) that is unique to the AS and may be periodically changed. The ingress router first receiving the packet within a particular AS may insert its router ID into the packet. A threat intelligence system may sample packets of traffic received by the AS and examine the inserted ingress router IDs in making a threat determination. If a distribution of detected ingress router IDs from sampled packets does not match an expected distribution of ingress router IDs, one or more threat mitigation actions may be invoked.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC