Custom LLM Cloud Posture Remediation for Alert Fatigue

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security approaches and siloed on-premises security solutions are inadequate for securing cloud-native resources, generating excessive alerts, and failing to provide reliable protection for mission-critical applications and infrastructure.

Innovation Solution

A cloud-based system utilizing custom Large Language Models (LLMs) scans cloud environments for posture control data, generates alerts and remediation recommendations, and provides these recommendations to administrators via a Command Line Interface (CLI) command, with the ability to automatically perform actions and retrain on updated data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions are used to scan cloud environments, then security coverage is provided, but excessive alerts are generated causing alert fatigue

Engineering Contradiction:
Improvesecurity protectionVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

A large language model (LLM) is introduced as an intermediary between the alert generation system and administrators. The LLM processes raw security alerts, filters out false positives, and generates consolidated remediation recommendations, thereby reducing alert fatigue while maintaining security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system automatically generates remediation recommendations and can autonomously execute remediation actions without requiring constant administrator intervention. This self-service capability reduces the burden on security teams while maintaining reliable security protection.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If detailed remediation recommendations are provided for each alert, then actionable guidance is given, but system complexity increases

Engineering Contradiction:
Improveremediation guidanceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The LLM acts as an intelligent intermediary that automatically generates detailed remediation recommendations by analyzing alert patterns and drawing from security knowledge bases, providing actionable guidance without requiring complex manual configuration or analysis processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If custom LLMs are trained for each tenant to provide personalized recommendations, then recommendation accuracy improves, but training time and computational resources increase

Engineering Contradiction:
Improverecommendation accuracyVSAvoidtraining time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Tenant-specific customization data is collected and prepared in advance before LLM training begins. This preliminary action includes gathering cloud provider documentation, cloud security system documentation, and tenant-specific security requirements, enabling more efficient training processes and faster deployment of accurate recommendation models.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If continuous automated risk assessment is performed, then security posture is continuously monitored, but computational resources and processing time increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs risk assessments at periodic intervals rather than continuously, balancing security monitoring requirements with computational resource constraints. This periodic assessment approach maintains reliable security posture monitoring while reducing energy consumption and processing demands.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12487871B2Systems and methods for detailed cloud posture remediation recommendations utilizing custom large language models (LLMs)
Publication Date: 2025.12.02 ZSCALER INC
  • US12487871B2 patent drawing
  • US12487871B2 patent drawing
  • US12487871B2 patent drawing

AI summary

Systems and methods for detailed cloud posture remediation recommendations utilizing custom Large Language Models (LLMs). The present systems and methods are configured to perform the steps of scanning a cloud environment for posture control data; generating one or more alerts related to any of risky configurations and risky activities associated with the cloud environment; generating one or more remediation recommendations based on the one or more alerts; and providing the one or more alerts and the one or more remediation recommendations to administrators of the cloud environment.