WO2025172801 - AUTOMATICALLY INVESTIGATING SECURITY INCIDENTS AND GENERATING SECURITY INCIDENT REPORTS USING A LARGE LANGUAGE MODEL (LLM)

National phase entry is expected:
Publication Number WO/2025/172801
Publication Date 21.08.2025
International Application No. PCT/IB2025/051278
International Filing Date 06.02.2025
Title **
[English] AUTOMATICALLY INVESTIGATING SECURITY INCIDENTS AND GENERATING SECURITY INCIDENT REPORTS USING A LARGE LANGUAGE MODEL (LLM)
[French] EXAMEN AUTOMATIQUE D'INCIDENTS DE SÉCURITÉ ET GÉNÉRATION DE RAPPORTS D'INCIDENTS DE SÉCURITÉ À L'AIDE D'UN GRAND MODÈLE DE LANGAGE (LLM)
Applicants **
VARONIS SYSTEMS, INC.
Inventors
BELGI, Amir
SNE, Ron
NEYSTADT, John Eugene
CHEN, Lior
Priority Data
18/440,980   14.02.2024   US
Application details
Total Number of Claims/PCT *
Number of Independent Claims *
Number of Priorities *
Number of Multi-Dependent Claims *
Number of Drawings *
Pages for Publication *
Number of Pages with Drawings *
Pages of Specification *
*
Number of Office Actions *
*
International Searching Authority
*
*
Recordal of a Change of the Applicant's Name/Address
*
Type of Assignment
*
Applicant's Legal Status
*
*
*
*
*
*
Entry into National Phase under
*
Patent Delivery
*
Translation

* The data is based on automatic recognition. Please verify and amend if necessary.

** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.

Quotation for National Phase entry

Country StagesTotal
China Filing, Examination, Granting2329
EPO Filing, Examination, Granting14378
Japan Filing, Examination, Granting2307
South Korea Filing, Examination, Granting2469
USA Filing, Examination, Granting4310
MasterCard Visa
Total: 25,793
Contact Us
Abstract[English] Automatically investigating security incidents and generating security incident reports using a Large Language Model (LLM). A computerized system receives an incoming Security Alert Message pertaining to a possible security-related incident. The system automatically feeds into the LLM at least: the content of the Security Alert Message; the metadata of the Security Alert Message; context information describing a security domain; and organization context information pertaining to users and machines of that organization. The system automatically prompts the LLM to automatically investigate the Security Alert Message and to automatically generate a detailed Incident Report pertaining to the Security Alert Message.[French] L'invention concerne l'examen automatique d'incidents de sécurité et la génération de rapports d'incident de sécurité à l'aide d'un grand modèle de langage (LLM). Un système informatisé reçoit un message d'alerte de sécurité entrant concernant un éventuel incident lié à la sécurité. Le système fournit automatiquement dans le LLM au moins : le contenu du message d'alerte de sécurité ; les métadonnées du message d'alerte de sécurité ; des informations de contexte décrivant un domaine de sécurité ; et des informations de contexte d'organisation concernant des utilisateurs et des machines de cette organisation. Le système invite automatiquement le LLM à examiner automatiquement le message d'alerte de sécurité et à générer automatiquement un rapport d'incident détaillé concernant le message d'alerte de sécurité.

Rejoining the server...