Threat Detection Controller Using Large Language Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat detection systems face challenges in maintaining and updating decision logic, requiring significant effort to configure different systems and rely on third-party services, which can lead to technology dependency and privacy concerns.

Innovation Solution

A threat detection system utilizing at least two threat detection components connected to a threat detection controller, which employs a large language model to control and orchestrate different components, handle inputs and outputs, and convert decision-making logic from natural language to the required format for various components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional threat detection systems use multiple specialized mechanisms and third-party services for comprehensive threat detection, then detection accuracy and capability are improved, but system complexity and maintenance effort increase significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a large language model as an intermediary layer between the user interface and multiple threat detection components. This LLM intermediary handles natural language inputs, translates them into appropriate component-specific queries, and aggregates results, thereby shielding users from system complexity while maintaining comprehensive detection capabilities across multiple specialized mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The large language model serves as a universal interface that can handle diverse threat detection tasks through a single system. Instead of requiring separate configuration for each detection mechanism (virus scanning, malware analysis, network traffic monitoring, etc.), the LLM provides a unified natural language interface that routes requests to appropriate specialized components, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional systems rely on third-party services for specialized detection actions, then detection capability is enhanced, but technology dependency and privacy concerns increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidtechnology independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the threat detection system into independent modular components (virus scanner, malware analyzer, network monitor, etc.) that can be configured and controlled locally. The large language model orchestrates these segmented components without requiring external third-party services, enabling organizations to maintain detection capability while preserving technology independence and data privacy

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive threat detection uses multiple detection components and iterative analysis steps, then detection thoroughness is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The large language model dynamically determines which threat detection components to activate based on the specific input and context. Rather than running all detection mechanisms iteratively on every input, the LLM adaptively selects and coordinates only the necessary components, maintaining thorough detection where needed while improving processing efficiency for routine threats

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4571549A1A method for threat detection in a threat detection system and a threat detection system
Publication Date: 2025.06.18 F SECURE CORP
  • EP4571549A1 patent drawingFigure 1
  • EP4571549A1 patent drawingFigure 2
  • EP4571549A1 patent drawingFigure 3

AI summary

A threat detection system, a server of a threat detection system and a method for threat detection in a threat detection system, which threat detection system comprises at least one endpoint (101, 205a-205h) and/or at least one server (102, 202). The method comprises utilizing by the threat detection system at least two threat detection components for detecting cyber threats, wherein the threat detection components are connected to a threat detection controller which controls the threat detection by assigning tasks and/or giving instructions to the threat detection components and by following outputs of the threat detection components, wherein the threat detection controller utilizes at least one large language model when outputting data to a threat detection component and/or when processing information received from a threat detection component.