SOC Alert Investigation Using Neural-Symbolic AI Planning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Security Operations Centers (SOCs) face challenges in effectively analyzing complex logs across various compute domains, including endpoint, network, cloud, and security data lakes, to identify and remediate cyber threats due to the complexity and heterogeneity of these logs, requiring significant domain expertise.

Innovation Solution

A method for automatically investigating security alerts using a neural-symbolic AI model with Large Language Models (LLMs) for plan generation, assisted by security expert knowledge, and generative AI models for log comprehension, combined with ML models for log analysis, to execute security plans and generate reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis of security logs is performed by security experts, then detection precision is improved, but productivity deteriorates due to time-consuming manual review

Engineering Contradiction:
Improvedetection precisionVSAvoidproductivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables self-service by allowing the automated investigation system to independently analyze security logs, generate investigation plans, and execute remediation actions without requiring continuous human intervention. The neural-symbolic AI model autonomously processes log data from multiple compute domains, making the system self-sufficient in detecting and responding to security threats.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual analysis process with a neural-symbolic AI system that combines neural networks for pattern recognition with symbolic logic for reasoning and decision-making. This substitution eliminates the need for human security experts to manually review each log entry, thereby improving productivity while maintaining detection precision through intelligent automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated AI-based investigation is implemented, then productivity is improved, but device complexity increases due to multiple AI models and processing stages

Engineering Contradiction:
ImproveproductivityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The investigation system is segmented into distinct functional modules: log comprehension stage using generative AI models, plan generation stage using neural-symbolic AI models, plan execution stage for remediation actions, and reasoning stage for conclusions. This segmentation allows each module to be optimized independently and simplifies the overall system architecture by dividing complex tasks into manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system achieves universality by designing a multi-functional platform that can handle various compute domains (endpoint, network, cloud, email, SSO, security data lake) through a unified neural-symbolic AI architecture. The same core system performs multiple functions including log analysis, threat detection, investigation planning, and remediation execution, reducing the need for separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive log analysis across multiple compute domains is performed, then detection precision is improved, but device complexity increases due to heterogeneity of log formats and sources

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies parameter changes by transforming diverse log formats from different compute domains into a standardized internal representation. The neural-symbolic AI model adapts its processing parameters to handle various log types (endpoint, network, cloud, email, SSO, security data lake) while maintaining a consistent analysis framework, thereby reducing complexity despite the heterogeneity of input data.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary layer in the form of a standardized log comprehension interface that mediates between the heterogeneous log sources and the analysis engine. This intermediary translates and normalizes logs from different compute domains into a unified format, simplifying the system's interaction with diverse data sources while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260075070A1Automatically investigating security alerts for Security Operations Center (SOC)
Publication Date: 2026.03.12 CULMINATE INC
  • US20260075070A1 patent drawing
  • US20260075070A1 patent drawing
  • US20260075070A1 patent drawing

AI summary

Systems and methods for automatically investigating potential cyber security alerts threats are provided. A method includes receiving logs related to security alerts from multiple sources, the security alerts representing potential cyber security threats in a compute domain; and performing an automated investigation procedure configured to determine whether the logs represent actual cyber security threats, the automated investigation procedure including a plan generation stage in which high-level logical steps are planned for analyzing the logs and retrieving evidences for proving it either malicious or benign, a log comprehension stage in which details of the logs are analyzed to obtain observations of the logs, a plan execution stage in which the steps of the plan generation stage are executed with respect to the observations of the logs, a reasoning stage to conclude the case, and a re-planning stage to generate a new investigation plan for newly discovered entities or signal.