WO2026104964 - AUTOMATIC DETECTION AND HANDLING OF SECURITY-RELATED ANOMALIES BY UTILIZING MACHINE LEARNING AND A LARGE LANGUAGE MODEL

National phase entry is expected:
Publication Number WO/2026/104964
Publication Date 21.05.2026
International Application No. PCT/IB2025/061445
International Filing Date 10.11.2025
Title **
[English] AUTOMATIC DETECTION AND HANDLING OF SECURITY-RELATED ANOMALIES BY UTILIZING MACHINE LEARNING AND A LARGE LANGUAGE MODEL
[French] DÉTECTION ET GESTION AUTOMATIQUES D'ANOMALIES LIÉES À LA SÉCURITÉ, PAR APPRENTISSAGE AUTOMATIQUE ET GRAND MODÈLE DE LANGAGE
Applicants **
VARONIS SYSTEMS, INC.
Inventors
NEYSTADT, John Eugene
CHEN, Lior
RAVEH, Liron
BASS, David
Priority Data
18/945,613   13.11.2024   US
Application details
Total Number of Claims/PCT *
Number of Independent Claims *
Number of Priorities *
Number of Multi-Dependent Claims *
Number of Drawings *
Pages for Publication *
Number of Pages with Drawings *
Pages of Specification *
*
Number of Office Actions *
*
International Searching Authority
*
*
Recordal of a Change of the Applicant's Name/Address
*
Type of Assignment
*
Applicant's Legal Status
*
*
*
*
*
*
Entry into National Phase under
*
Patent Delivery
*
Translation

* The data is based on automatic recognition. Please verify and amend if necessary.

** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.

Quotation for National Phase entry

Country StagesTotal
China Filing, Examination, Granting2380
EPO Filing, Examination, Granting14641
Japan Filing, Examination, Granting2337
South Korea Filing, Examination, Granting2432
USA Filing, Examination, Granting4310
MasterCard Visa
Total: 26,100
Contact Us
Abstract[English] Automatic detection and handling of security-related anomalies by utilizing machine learning and a large language model (LLM). A computerized method for detecting and handling security threats in an organizational network of an organization includes: (a) collecting event data that pertain to organizational users, organizational devices, and organizational resources of the organizational network; (b) constructing user profiles, device profiles, and resource profiles; (c) constructing Organizational Context information that pertains to organizational users, organizational devices, and organizational resources; (d) constructing a time-series of events, enriched with the Organizational Context information; (e) analyzing the time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing the anomalous event.[French] La présente demande concerne la détection et la gestion automatiques d'anomalies liées à la sécurité, par apprentissage automatique et au moyen d'un grand modèle de langage (GML). Un procédé informatisé permettant de détecter et de gérer des menaces de sécurité dans le réseau organisationnel d'une organisation consiste : (a) à collecter des données d'événements relatives à des utilisateurs organisationnels, des dispositifs organisationnels et des ressources organisationnelles du réseau organisationnel ; (b) à construire des profils d'utilisateur, des profils de dispositif et des profils de ressource ; (c) à construire des informations de contexte organisationnel relatives aux utilisateurs organisationnels, aux dispositifs organisationnels et aux ressources organisationnelles ; (d) à construire une série chronologique d'événements, enrichie avec les informations de contexte organisationnel ; (e) à analyser la série chronologique d'événements par un processus d'apprentissage automatique qui détecte un événement anormal, et à générer automatiquement un message d'alerte concernant l'événement anormal et le décrivant.

Rejoining the server...