Threat Mitigation Reporting with Generative AI Across Security Subsystems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat mitigation systems face challenges in efficiently gathering and processing information from multiple security-relevant subsystems, requiring users to formulate unique queries for each subsystem.

Innovation Solution

A computer-implemented method that establishes connectivity with multiple security-relevant subsystems, processes initial notifications using a generative AI model and a formatting script, and generates a summarized human-readable report, thereby automating the query process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If users formulate unique queries for each security-relevant subsystem, then information can be gathered from multiple subsystems, but the complexity and time required for querying increases

Engineering Contradiction:
Improveinformation gathering completenessVSAvoidquery formulation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

A universal query language is introduced as an intermediary between the user and multiple security subsystems. This query language acts as a mediator that translates high-level security queries into subsystem-specific query formats, eliminating the need for users to learn and formulate unique queries for each subsystem while ensuring complete information gathering from all sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The universal query language is designed to be multi-functional, enabling a single query formulation to interact with multiple different security subsystems (firewall, intrusion detection, antivirus, etc.). This universal interface provides consistent query capabilities across all subsystems, reducing operational complexity while maintaining comprehensive information retrieval.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If multiple queries are formulated for different subsystems, then comprehensive security information can be obtained, but the time required for information gathering increases

Engineering Contradiction:
Improvesecurity information completenessVSAvoidquery processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

Multiple subsystem queries are merged into a single unified query operation. The universal query language consolidates what would traditionally require separate queries to each subsystem into one coordinated operation, enabling parallel information gathering from all security subsystems simultaneously and significantly reducing total query processing time while maintaining comprehensive coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary configuration of the universal query language and establishes connections to all security subsystems in advance. This preliminary setup enables rapid query execution without requiring time-consuming connection establishment and query formulation during actual security monitoring operations.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If subsystem-specific queries are used, then each subsystem can be queried precisely, but the ease of operation decreases

Engineering Contradiction:
Improvequery specificityVSAvoidquery formulation ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The universal query language serves as an intermediary layer that preserves query specificity while simplifying operation. It maintains the precision needed for targeted security investigations by providing structured query capabilities, while simultaneously offering user-friendly syntax and automatic subsystem routing that eliminates the complexity of learning multiple query dialects.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts query parameters based on the target subsystem. When a universal query is submitted, the query language automatically modifies and adapts the query parameters to match the specific requirements of each security subsystem, ensuring precise results while keeping the user interface consistent and simple.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12348554B2Threat mitigation system and method
Publication Date: 2025.07.01 RELIAQUEST HOLDINGS LLC
  • US12348554B2 patent drawing
  • US12348554B2 patent drawing
  • US12348554B2 patent drawing

AI summary

A computer-implemented method, computer program product and computing system for establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving an initial notification of a security event from one of the security-relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; and iteratively processing the initial notification using a generative AI model and a formatting script to produce a summarized human-readable report for the initial notification.