WO2026104964 - AUTOMATIC DETECTION AND HANDLING OF SECURITY-RELATED ANOMALIES BY UTILIZING MACHINE LEARNING AND A LARGE LANGUAGE MODEL
National phase entry is expected:
Publication Number
WO/2026/104964
Publication Date
21.05.2026
International Application No.
PCT/IB2025/061445
International Filing Date
10.11.2025
Title **
[English]
AUTOMATIC DETECTION AND HANDLING OF SECURITY-RELATED ANOMALIES BY UTILIZING MACHINE LEARNING AND A LARGE LANGUAGE MODEL
[French]
DÉTECTION ET GESTION AUTOMATIQUES D'ANOMALIES LIÉES À LA SÉCURITÉ, PAR APPRENTISSAGE AUTOMATIQUE ET GRAND MODÈLE DE LANGAGE
Applicants **
VARONIS SYSTEMS, INC.
Inventors
NEYSTADT, John Eugene
CHEN, Lior
RAVEH, Liron
BASS, David
Priority Data
18/945,613
13.11.2024
US
Application details
| Total Number of Claims/PCT | * |
| Number of Independent Claims | * |
| Number of Priorities | * |
| Number of Multi-Dependent Claims | * |
| Number of Drawings | * |
| Pages for Publication | * |
| Number of Pages with Drawings | * |
| Pages of Specification | * |
| * | |
| Number of Office Actions | * |
| * | |
International Searching Authority |
USPTO
* |
| * | |
| Recordal of a Change of the Applicant's Name/Address |
Change of Applicant's Name and Address
* |
| Type of Assignment |
The Standard Agent's Assignment
* |
| Applicant's Legal Status |
Legal Entity
* |
| * | |
| * | |
| * | |
| * | |
| * | |
| Entry into National Phase under |
Chapter I
* |
| Patent Delivery |
Send the Letters Patent by Courier
* |
| Translation |
|
* The data is based on automatic recognition. Please verify and amend if necessary.
** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.
Quotation for National Phase entry
| Country | Stages | Total | |
|---|---|---|---|
| China | Filing, Examination, Granting | 2380 | |
| EPO | Filing, Examination, Granting | 14641 | |
| Japan | Filing, Examination, Granting | 2337 | |
| South Korea | Filing, Examination, Granting | 2432 | |
| USA | Filing, Examination, Granting | 4310 |

Total:
26,100
Contact Us
Abstract[English]
Automatic detection and handling of security-related anomalies by utilizing machine learning and a large language model (LLM). A computerized method for detecting and handling security threats in an organizational network of an organization includes: (a) collecting event data that pertain to organizational users, organizational devices, and organizational resources of the organizational network; (b) constructing user profiles, device profiles, and resource profiles; (c) constructing Organizational Context information that pertains to organizational users, organizational devices, and organizational resources; (d) constructing a time-series of events, enriched with the Organizational Context information; (e) analyzing the time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing the anomalous event.[French]
La présente demande concerne la détection et la gestion automatiques d'anomalies liées à la sécurité, par apprentissage automatique et au moyen d'un grand modèle de langage (GML). Un procédé informatisé permettant de détecter et de gérer des menaces de sécurité dans le réseau organisationnel d'une organisation consiste : (a) à collecter des données d'événements relatives à des utilisateurs organisationnels, des dispositifs organisationnels et des ressources organisationnelles du réseau organisationnel ; (b) à construire des profils d'utilisateur, des profils de dispositif et des profils de ressource ; (c) à construire des informations de contexte organisationnel relatives aux utilisateurs organisationnels, aux dispositifs organisationnels et aux ressources organisationnelles ; (d) à construire une série chronologique d'événements, enrichie avec les informations de contexte organisationnel ; (e) à analyser la série chronologique d'événements par un processus d'apprentissage automatique qui détecte un événement anormal, et à générer automatiquement un message d'alerte concernant l'événement anormal et le décrivant.