Generative ML Model for Automated Security Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Human cybersecurity analysts face challenges in efficiently and accurately responding to security threats due to time pressure and inefficiencies in manual investigation processes, leading to potential security vulnerabilities.

Innovation Solution

Employing a bespoke generative machine learning model trained with domain-specific knowledge to automatically identify and mitigate security threats by analyzing security images and text data, generating appropriate cybersecurity mitigation actions through prompt engineering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If human analysts manually investigate security threats, then analysis accuracy can be maintained, but response time increases and productivity decreases

Engineering Contradiction:
Improvethreat response speedVSAvoidanalysis accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces manual human analysis with an automated machine learning system that processes security images and generates mitigation actions. The system uses a trained model to automatically identify threats, extract indicators of compromise, and determine appropriate responses, eliminating the need for manual investigation while maintaining high accuracy through sophisticated algorithms and continuous learning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the machine learning model independently analyzes security threats, generates findings, and proposes mitigation actions without requiring constant human intervention. The model continuously improves its performance through feedback loops and can autonomously update its knowledge base with new threat patterns and indicators.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual security analysis is performed, then detailed investigation can be conducted, but time pressure increases and efficiency decreases

Engineering Contradiction:
Improveanalysis efficiencyVSAvoidinvestigation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by automatically processing security images, extracting key information, and generating initial findings before human analysts need to intervene. The machine learning model pre-processes threat data, identifies patterns, and prepares mitigation recommendations in advance, reducing the time required for subsequent manual investigation and enabling faster overall response.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If human analysts respond to threats, then contextual understanding can be maintained, but error rates increase under time pressure

Engineering Contradiction:
Improvemitigation accuracyVSAvoidoperational difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces human decision-making with an automated machine learning system that objectively analyzes security images and generates mitigation actions based on trained patterns and indicators of compromise. This substitution eliminates human error while maintaining high contextual understanding through sophisticated image processing and pattern recognition capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250209156A1Security threat mitigation
Publication Date: 2025.06.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250209156A1 patent drawing
  • US20250209156A1 patent drawing
  • US20250209156A1 patent drawing

AI summary

The present disclosure provides methods, systems and computer readable media for training and implementing a generative machine learning model for identifying and mitigating security threats. Certain examples relate to generative model training, in which a training image is provided to a generative machine learning (ML) model in a training prompt, with an Indicator of Compromise (IoC) prediction instruction pertaining to the first security image. The model generates a predicted IoC and a parameter of the model is updated based on a loss function that quantifies error between a ground truth IoC and the predicted IoC. Other examples relate to the use of trained generative models for cybersecurity. A mitigation prompt comprising a second security image and an associated mitigation instruction is provided to a trained generative model. The model outputs an indication of a cybersecurity mitigation action based on the mitigation prompt, and the cybersecurity mitigation action is performed on the system. Certain example embodiments identify and automatically mitigate security issues using a multimodal generative model (MGM) though appropriate prompt engineering.