AI Security Correlation Bot for Natural-Language Breach Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data platforms face challenges in efficiently identifying and responding to security breaches due to the complexity of multiple security microservices, leading to uncertainties from false positives and negatives, and the inefficiency of manual investigation through complex user interfaces.

Innovation Solution

Implementing an AI bot that correlates data across security features using machine learning models, trained on general and specific security knowledge bases, to interact with users and provide natural language responses for security breach analysis and response actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple different security microservices are executed to support security breach identification and analysis, then security coverage is improved, but device complexity increases and ease of operation deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security microservices into a unified AI bot that performs security breach identification and analysis. The bot integrates functions from various microservices (ransomware detection, data classification, intrusion detection) into a single interface that correlates data across all these services, reducing system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AI bot acts as an intermediary between the complex security microservices infrastructure and the end user. It correlates data from multiple microservices and presents unified security findings to users, shielding them from the underlying complexity while maintaining access to comprehensive security analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple different security microservices are executed to support security breach identification and analysis, then security coverage is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The AI bot provides a universal interface that handles multiple security functions through a single interaction point. Users can query security status, investigate breaches, and receive recommendations without needing to navigate multiple microservice-specific interfaces, significantly improving ease of operation while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The bot serves as an intermediary that translates complex microservice data into user-friendly responses. It correlates information from multiple security services and presents unified findings, allowing users to interact with the complex security infrastructure through simple natural language queries.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If keyword searches are performed with respect to each of the multiple different security microservices, then security breach investigation is attempted, but productivity deteriorates and loss of time increases

Engineering Contradiction:
Improvesecurity breach detectionVSAvoidresponse efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The AI bot merges the data correlation capabilities across all security microservices into a single unified process. Instead of requiring separate keyword searches for each microservice, the bot simultaneously correlates data from all services, dramatically improving productivity while maintaining comprehensive security breach detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The bot performs preliminary data correlation and analysis across all security microservices before presenting findings to users. It proactively aggregates and correlates security data in the background, so when users query about security breaches, the correlated information is already prepared and immediately available, eliminating the need for time-consuming manual searches.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If AI bot correlates data from various security features, then measurement precision of security breach identification is improved, but use of energy increases

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The AI bot implements selective data correlation, focusing computational resources on correlating only the most relevant security data from various microservices based on the specific breach scenario. This partial action approach maintains high measurement precision by concentrating analysis on critical data points while reducing overall energy consumption compared to exhaustive correlation of all available security data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4645136A1Actionable artificial intelligence bot for data security correlations
Publication Date: 2025.11.05 COHESITY INC
  • EP4645136A1 patent drawingFigure 1A
  • EP4645136A1 patent drawingFigure 1B
  • EP4645136A1 patent drawingFigure 2

AI summary

Techniques are described for techniques for an actionable artificial intelligence bot based on data security correlations. An example method comprises determining, by a data platform implemented by a computing system, a plurality of tags for a snapshot executed by the data platform, detecting, by the data platform, an indication of a security breach relating to the snapshot, processing, by the data platform and using a machine learning model, a plurality of attributes of the security breach and the plurality of tags to identify a potential compromise of the snapshot, processing, by the data platform and using a large language model, at least the plurality of attributes to generate an actionable prompt including a natural language description of at least one security response, and outputting, by the data platform, the actionable prompt.