LLM Alert Investigation With Converging Risk Score Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in efficiently and accurately evaluating numerous security alerts due to the high volume of incoming messages, lack of time and knowledge among administrators, and the dynamic nature of threat detection, leading to potential security breaches and inefficiencies in threat investigation.

Innovation Solution

An automated system using a Large Language Model (LLM) to generate an alert-specific playbook, iteratively calculate a risk score, and gather additional context information until convergence, enabling autonomous investigation and decision-making on security alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If administrators manually evaluate security alerts, then accuracy of threat detection can be maintained, but time consumption and workload increase significantly

Engineering Contradiction:
Improveaccuracy of threat detectionVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an LLM-based intermediary system that acts as a mediator between security alerts and administrators. The LLM automatically evaluates alerts, generates risk scores, and provides investigative conclusions, thereby reducing the time administrators spend on manual evaluation while maintaining detection accuracy through the LLM's automated analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the LLM to autonomously investigate security alerts without requiring administrator intervention for each alert. The LLM independently retrieves contextual information, evaluates threats, and generates conclusions, freeing administrators from repetitive manual evaluation tasks while preserving accurate threat detection.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If administrators manually investigate each alert with contextual information, then detection accuracy improves, but productivity decreases due to high volume of alerts

Engineering Contradiction:
Improvedetection accuracyVSAvoidthroughput of alert evaluation
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The LLM serves as an intermediary that automatically performs the investigative work normally requiring administrators. It retrieves contextual information from organizational sources, analyzes alerts comprehensively, and generates accurate detection results at high speed, thereby improving both detection accuracy and throughput simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the operational parameters of alert evaluation by transitioning from manual human analysis to automated LLM-based analysis. This parameter change enables the system to process alerts at much higher speeds while maintaining or improving detection accuracy through the LLM's ability to systematically evaluate contextual information.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated systems are used to evaluate alerts, then productivity increases, but accuracy and contextual understanding may deteriorate

Engineering Contradiction:
Improvethroughput of alert evaluationVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The LLM intermediary combines the advantages of both manual and automated approaches by providing automated high-speed processing while maintaining accurate contextual understanding. The LLM's natural language processing capabilities enable it to comprehend nuanced contextual information, ensuring detection accuracy is not compromised despite the automated nature of the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system incorporates feedback mechanisms where the LLM continuously refines its evaluations based on organizational context and alert patterns. This feedback loop enables the automated system to improve its detection accuracy over time while maintaining high productivity, bridging the gap between automated speed and human-level understanding.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If comprehensive contextual information is gathered for each alert, then detection accuracy improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The LLM performs multiple functions within a single unified system: it evaluates alerts, retrieves contextual information from various organizational sources, analyzes the combined data, and generates investigative conclusions. This multi-functionality reduces system complexity compared to having separate specialized systems for each task while maintaining comprehensive contextual analysis for accurate detection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12530469B2Automated multi-phase investigation of security incident alerts using a large language model (LLM) with converging dialogue
Publication Date: 2026.01.20 VARONIS SYSTEMS INC
  • US12530469B2 patent drawing
  • US12530469B2 patent drawing
  • US12530469B2 patent drawing

AI summary

Automated multi-phase investigation of security incident alerts using a Large Language Model (LLM) with converging dialogue. A computerized system receives a Security Alert Message pertaining to a possible security-related incident pertaining to an organization. The system automatically evaluates whether the Security Alert Message is either (I) a False Positive security alert message or (II) a True Positive security alert message, by performing an iterative multi-phase converging process in which the LLM evaluates at least: (i) the content of that Security Alert Message, and (ii) the meta-data of that Security Alert Message, and (iii) organizational context that is related to that Security Alert Message. An iterative process is performed by the LLM, which utilizes an Agent Module to fetch additional context information from organizational sources. The LLM re-updates the Risk Score and re-evaluates the Risk Score until convergence to a decision.