LLM-Based Cloud Threat Hypothesis Generation with Attack Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional threat detection mechanisms in cloud environments lack specificity and adaptability due to reliance on predefined rules, which are not tailored to the unique characteristics of individual environments, and the generation of threat hypotheses is largely manual and difficult to reproduce.

Innovation Solution

A device generates a knowledge graph representing a hypothetical attack on a cloud computing environment, using telemetry data to train a large language model for threat detection, leveraging a domain-specific language and attack graph generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If predefined threat detection rules are used to cover broad range of threats, then threat coverage is improved, but specificity and adaptability to individual environments deteriorates

Engineering Contradiction:
Improvethreat coverageVSAvoidadaptability to individual environments
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by automatically generating environment-specific threat hypotheses and detection rules before actual threat detection occurs. The LLM generates customized threat scenarios based on the specific cloud environment configuration, assets, and vulnerabilities, creating tailored detection rules that are then applied proactively to monitor for those specific threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by dynamically adapting threat detection rules based on environment-specific parameters. The LLM analyzes environment configuration parameters (assets, vulnerabilities, architecture) and transforms them into customized threat hypotheses with modified detection parameters, making the detection system adaptable to each unique environment while maintaining broad coverage.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual human intervention is used to generate threat hypotheses, then domain knowledge and creativity are applied, but reproducibility and scalability deteriorates

Engineering Contradiction:
Improvedomain knowledge applicationVSAvoidreproducibility and scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system replaces the mechanical human process of manual threat hypothesis generation with an automated LLM-based system. The LLM incorporates domain knowledge through its training and prompt engineering, eliminating the need for manual human intervention while maintaining the quality of domain knowledge application. This substitution enables unlimited scalability and perfect reproducibility of threat hypothesis generation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by allowing the LLM to autonomously generate threat hypotheses without human intervention. The model takes environment configuration as input and automatically produces customized threat scenarios, detection rules, and validation mechanisms, making the threat intelligence generation process self-sufficient and highly scalable.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If conventional threat detection mechanisms are used, then broad threat coverage is achieved, but specificity to individual cloud environments deteriorates

Engineering Contradiction:
Improvethreat coverageVSAvoidspecificity to individual environments
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The system applies local quality by generating threat hypotheses that are specifically tailored to each cloud environment's unique characteristics. The LLM analyzes local environment parameters (specific assets, vulnerabilities, architecture) and creates customized threat scenarios with detection rules optimized for that particular environment, rather than applying generic detection rules uniformly across all environments.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250307712A1Large language model-based threat hypothesis generation
Publication Date: 2025.10.02 CISCO TECHNOLOGY INC
  • US20250307712A1 patent drawing
  • US20250307712A1 patent drawing
  • US20250307712A1 patent drawing

AI summary

In one implementation, a device generates a knowledge graph that represent a hypothetical attack on a cloud computing environment. The device obtains telemetry data observed from an emulation of the hypothetical attack on the cloud computing environment. The device performs, based on the telemetry data, a validation that the knowledge graph represents an actual attack. The device uses the telemetry data to train a large language model to identify a presence of an attack on the cloud computing environment, based on the validation.