Context-Based Insight System for Cloud Security Alert Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems face inefficiencies, inaccuracies, and inflexibility in analyzing and reporting security incidents due to rigid methodologies that struggle to accommodate changing security alert combinations.

Innovation Solution

A context-based insight system utilizing a security alert generative language model to generate accurate, flexible, and efficient security incident reports by correlating security alerts and providing contextual insights and remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rigid methodologies are used to analyze security alerts, then system stability is maintained, but adaptability to changing security alert combinations deteriorates

Engineering Contradiction:
Improveadaptability to changing security alert combinationsVSAvoidmethodology complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the analysis approach by changing from rigid predefined rules to dynamic parameter-based analysis using LLMs. The system adjusts its analysis parameters based on the specific combination of security alerts, enabling adaptability without increasing operational complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical rule-based security analysis systems with an AI/LLM-based system. This substitution eliminates the need for rigid methodologies while maintaining systematic analysis through automated intelligent processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If existing security incident reports are generated, then basic security information is provided, but report quality and usefulness deteriorates

Engineering Contradiction:
Improveinformation quality and contextVSAvoidreport generation efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent introduces LLMs as intermediary systems between security alert data and final incident reports. These intermediaries process raw alert data, add contextual information, and generate high-quality reports, thereby improving information quality without sacrificing efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary contextual analysis and alert correlation before generating final reports. This preliminary action enriches the report content with relevant context and insights, improving quality while maintaining efficient automated processing.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive security analysis is performed, then analysis accuracy is improved, but processing time increases

Engineering Contradiction:
Improvesecurity incident analysis accuracyVSAvoidreport generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The LLM-based system performs self-service analysis by automatically correlating alerts, identifying patterns, and generating reports without requiring manual intervention. This self-service approach maintains high accuracy while reducing processing time through automated intelligent processing.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system maintains continuous analysis and reporting operations without interruption. The LLMs continuously process security alerts and generate updated reports in real-time, ensuring accurate analysis while minimizing time loss through uninterrupted automated processing.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250088517A1Correlating security alerts using large language models
Publication Date: 2025.03.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250088517A1 patent drawing
  • US20250088517A1 patent drawing
  • US20250088517A1 patent drawing

AI summary

The disclosure focuses on using a context-based insight system to determine security incident reports that include security incident insights and remediation actions based on various combinations of security alerts in cloud computing systems. The context-based insight system uses a security alert generative language model (GLM) to generate security incident reports based on correlated security alerts within a security incident and the attack-type contexts of those security alerts. By using the security alert GLM guided by attack-type contexts to generate security incident reports, the context-based insight system provides understandable text narratives that provide clear and accurate insights into security incidents including remediation actions to address the security incidents as a whole rather than just reporting individual security alerts of the security incident. Further, the context-based insight system dynamically updates the security incident report as additional related security alerts are detected and received.