Entity-Guided Query Creation for Cloud Security AI Assistants

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient and comprehensive method for monitoring and securing cloud environments, particularly in detecting insider threats and anomalies within complex network systems, which are crucial for data security and compliance.

Innovation Solution

A generative artificial intelligence (AI)-enabled assistant is employed to analyze data from cloud environments, utilizing agents to collect and process data, creating polygraphs to identify patterns and anomalies, and providing real-time insights for anomaly detection and security monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive monitoring and detection of insider threats is implemented, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a polygraph as an intermediary data structure that mediates between raw cloud environment data and security analysis. The polygraph transforms complex monitoring data into a standardized graph format with nodes representing entities (users, processes, files) and edges representing relationships, enabling comprehensive security monitoring without directly processing the raw complexity of cloud data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the monitoring function into multiple agents deployed across different cloud environments, each responsible for collecting data from their local environment. These agents independently build local polygraphs and communicate only necessary information to central analysis services, dividing the complex monitoring task into manageable segments.

Inventive Principle:
Principle #1Segmentation

2Speed

If real-time anomaly detection is implemented, then response speed is improved, but data processing complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoiddata processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-defining the polygraph schema and data collection templates before actual monitoring occurs. Agents are pre-configured with the expected polygraph structure, allowing them to immediately transform incoming data into the required format without complex real-time processing, enabling fast anomaly detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by transforming diverse cloud data into a standardized polygraph representation with consistent node and edge types. This parameter transformation from varied raw data formats to a unified graph schema enables efficient real-time processing while maintaining processing simplicity through standardization.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If comprehensive data collection from cloud environments is implemented, then detection capability is improved, but information overload increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidinformation overload
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent extracts only the essential information needed for security monitoring from the vast cloud environment data. By defining specific polygraph schemas that capture only relevant entity relationships (users, processes, files, networks) and their connections, the system extracts meaningful security-relevant data while filtering out unnecessary information overload.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The polygraph structure provides universality by serving multiple functions simultaneously: data collection, data transformation, relationship mapping, and anomaly detection. This multi-functional data structure consolidates what would otherwise be separate processing stages into a single unified representation, reducing information overload through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12418555B1Guiding query creation for a generative artificial intelligence (AI)-enabled assistant
Publication Date: 2025.09.16 FORTINET INC
  • US12418555B1 patent drawing
  • US12418555B1 patent drawing
  • US12418555B1 patent drawing

AI summary

Guiding query creation for a generative artificial intelligence (AI)-enabled assistant, including: receiving, via a natural language interface for a security framework monitoring a cloud deployment, a natural language input comprising one or more entity identifiers; gathering information based on the one or more entity identifiers; providing, to a generative artificial intelligence (AI) model, a prompt based on the natural language input and comprising the gathered information; and receiving, from the generative AI model, a response to the prompt.