Quantum computing and machine learning as security threats
Through the quantum state probability matrix and Bloch sphere generated by quantum computing, the security threat model is trained, which solves the shortcomings of traditional machine learning models in identifying new threats and artificial intelligence attacks, and achieves faster and more accurate threat recognition and prediction.
Patent Information
- Application Number
- CN202180032631.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-06
- Filing Date
- 2021-04-15
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2041-04-15
AI Technical Summary
Existing machine learning models are difficult to effectively deal with attacks by new behaviors or malicious actors with artificial intelligence when identifying security threats. Traditional methods rely on historical behavior patterns and cannot quickly identify new or unseen threats.
Using a machine learning model based on quantum computing, by generating a quantum state probability matrix and a Bloch ball, the security threat model is trained to identify potential threats, and the probability of multiple attack categories and methods is used to process threat classification in combination with SIEM and STIX-TAX11 frameworks.
It enables faster and more accurate identification of security threats than traditional methods, especially attacks by malicious AI actors, and can predict future attack patterns and methods.
Smart Images

Figure CN115486026B_ABST
Abstract
Description
Background Art
[0001] The present invention relates to security threats, and more particularly to quantum computing machine learning for security threats.
[0002] A machine learning model can be a computer-coded algorithm configured to learn how to perform a specific classification. A classification can be a determination made by the machine learning model to label a specific state. For example, in the field of computer security, classification can involve analyzing the state of a computer system, determining whether the system is under threat of attack, and labeling the computer state accordingly. Thus, an example machine learning model for security threats can perform classification of a computer system as either safe or threatened.
[0003] Conventional computing is useful for identifying potential security threats using models that can break the problem of identifying security threats into manageable levels of complexity. However, traditional methods can rely on assumptions about how malicious actors, such as hackers and malware, have behaved in the past. As a result, traditional methods may not be suitable for identifying security threats with new or unseen behaviors.
[0004] Furthermore, the increasing complexity of computing technology creates a competition between those who develop security threats and those who attempt to stop them. Thus, in the absence of new methods for identifying security threats, emerging technologies such as artificial intelligence and game theory may have the potential to increase the complexity of identifying security threats to a level beyond the solution capabilities of conventional computers. Summary of the Invention
[0005] An embodiment of a method for a security model is disclosed. The method includes generating a Bloch sphere based on System Information and Event Management (SIEM) and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11) for a security domain. The method also includes generating a quantum state probability matrix based on the Bloch sphere. Further, the method includes training a security threat model to perform security threat classification based on the quantum state probability matrix. In addition, the method includes performing machine learning classification of the security domain based on the quantum state probability matrix. Advantageously, such embodiments are useful for identifying security threats faster than current threat solutions. In an additional advantage, such embodiments are useful for identifying malicious actors of artificial intelligence.
[0006] Optionally, in some embodiments, the method further includes determining that a malicious actor is performing a specific attack category based on previous attack categories and the quantum state probability matrix. In another optional embodiment, the method further includes determining a specific attack method used by the malicious actor to perform the specific attack category based on the specific attack category and the quantum state probability matrix. Advantageously, such embodiments are useful for identifying specific attack methods and specific attack categories more quickly than current threat solutions.
[0007] An additional embodiment of a method for a security model is disclosed. The method includes generating a Bloch sphere based on a SIEM and STIX-TAX11 for a security domain. The method also includes generating a quantum state probability matrix based on the Bloch sphere. In addition, the method includes training a security threat model to perform security threat classification based on the quantum state probability matrix. Further, the security threat classification infers the next attack category against the security domain based on the previous attack category. Advantageously, such an embodiment is useful for identifying security threats faster than current threat solutions. Among other advantages, such an embodiment is useful for identifying malicious actors using artificial intelligence.
[0008] An additional embodiment of a method for a security model is disclosed. The method includes generating a Bloch sphere based on a SIEM and STIX-TAX11 for a security domain. The method also includes generating a quantum state probability matrix based on the Bloch sphere. The quantum state probability matrix includes multiple probabilities representing the likelihood of a malicious actor moving between all possible combinations of attack categories. Additionally, the multiple probabilities of the quantum state probability matrix represent the likelihood of a malicious actor using a specific attack method for all attack categories based on previous attack categories. Further, the method includes training a security threat model to perform security threat classification based on the quantum state probability matrix. The security threat classification infers the next attack category for the security domain based on the previous attack category. Advantageously, such an embodiment is useful for identifying security threats faster than current threat solutions. In an additional advantage, such an embodiment is useful for identifying malicious actors with artificial intelligence.
[0009] Other aspects of the present invention relate to systems and computer program products having functionality similar to that described above with respect to the computer-implemented method.This summary is not intended to describe every aspect, every implementation, and / or every embodiment of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The accompanying drawings included in this application are incorporated into and form a part of the specification. They illustrate embodiments of the present invention and, together with the specification, serve to explain the principles of the present invention. The accompanying drawings illustrate only certain embodiments and do not limit the present invention.
[0011] Figure 1is a block diagram of an example system for a quantum computing-based machine learning model according to some embodiments of the present invention.
[0012] Figure 2 is a diagram of an example Bloch sphere according to some embodiments of the present invention.
[0013] Figure 3 is a process flow diagram of a method for quantum computing machine learning models according to some embodiments of the present invention.
[0014] Figure 4 is a diagram of an example Bloch sphere according to some embodiments of the present invention.
[0015] Figure 5A is a diagram of an example Bloch sphere according to some embodiments of the present invention.
[0016] Figure 5B is a diagram of an example Bloch sphere according to some embodiments of the present invention.
[0017] Figure 6 is a diagram of an example Bloch sphere according to some embodiments of the present invention.
[0018] Figure 7 is a block diagram of an example security threat model manager according to some embodiments of the present invention.
[0019] Figure 8 is a cloud computing environment according to some embodiments of the present invention.
[0020] Figure 9 is a set of functional abstraction model layers provided by a cloud computing environment according to some embodiments of the present invention.
[0021] Although the present invention can be modified into various modifications and alternative forms, its details have been shown in the drawings by way of example and will be described in detail. However, it should be understood that the present invention is not limited to the described embodiments. On the contrary, the present invention is intended to cover all modifications, equivalents and alternatives that fall within the scope of the present invention. DETAILED DESCRIPTION
[0022] Machine learning is a useful way to identify potential security threats to computer systems and networks. Many machine learning models rely on specific frameworks to analyze potential security threats. Three example industry frameworks include the Diamond Model for Intrusion Analysis, the Structured Threat Information Expression-Trusted Automated Exchange of Indicator Information (STIX-TAXII) framework, and the Lockheed Martin Cyber Killer. These three frameworks are useful tools for determining how a malicious actor or adversary might attack. Interestingly, these frameworks are based on kinetic warfare models, such as those used on physical battlefields. Therefore, these traditional frameworks are referred to herein as linear (and kinetic) because, on a physical battlefield, a soldier or group of soldiers can move in a straight line from one geographic location to another or fire a weapon from one geographic location to another.
[0023] The Diamond framework states that everyone (individual, company, or group) is either a victim or an adversary. An adversary can become a victim, and a victim can become an adversary. A typical (dynamic / symmetric) attack will show an adversary using its ability to exploit certain infrastructure to reach a victim. The Diamond framework can use stochastic models to determine (within reason) the probability that an adversary will gain access to a victim via a specific attack path.
[0024] Lockheed Martin CyberKill A range of attack methods are defined. These attack methods include reconnaissance of a target, weaponization, delivery, exploitation, installation, command and control (C&C), and actions taken against the target. Reconnaissance refers to the surveillance of a potential attack target by a malicious actor. Weaponization can involve the use of tools of the target system to facilitate the attack. For example, a malicious actor or malware can obtain system credentials that provide login access to a computer system and weaponize the credentials by using them to break into the computer system for malicious purposes. Delivery and exploitation can involve initial access to the target system. Installation refers to copying the executable version of the malware onto the target system. The term "command and control" refers to a state in which the malicious actor and / or malware has complete control over the target system. The attack method "actions taken against the target" can involve actions taken once the bad actor has access (such as stealing or exfiltrating data). Within the security domain of the potential target system, such data can include state secrets, trade secrets, bank and credit card accounts, personal emails and pictures, etc.
[0025] Lockheed Martin CyberKill The STIX-TAX11 framework includes a subset of attack methods. In addition, the STIX-TAX11 framework arranges attack methods in a different order (i.e., sequence). The STIX-TAX11 framework can be described as dynamic from the perspective of its attack strategy. The example STIX-TAX11 framework below includes a table of attack methods arranged by category. These categories and attack methods are only a subset of the STIX-TAX11 framework, which currently includes 433 attack methods, but continues to grow.
[0026]
[0027] Example STIX-TAXXI framework
[0028] The assumption in these frameworks of this type is that the malicious actor begins with initial access (A). Once access to the environment is gained, the actor can begin execution (B) of some malware (i.e., bot, virus, worm, trojan). From there, the actor can move to persistence (C) in order to move through the entire framework, and so on. Another assumption in this type of framework is that the adversary will start with some kind of exploit and progress along the attack chain in a linear or kinetic manner. Therefore, if the malicious actor is unsuccessful with the first initial access attack method (i.e., compromise drive), the actor can move down the initial access column and next attempt to exploit a public-facing application (app). However, if the compromise drive is successful, the malicious actor can move to the next column in the STIX-TAX11 framework by performing an attack method in the execution category.
[0029] The reason these frameworks are useful is that they can determine the probability that a malicious actor may take the next step in a kill chain or STIX-TAX11 framework. In this way, machine learning models that rely on these frameworks can classify malicious actors based on the view that they have linear thinking, and therefore, constantly move from step A to step B to C, and so on. However, malicious actors (such as, artificial intelligence malware) may violate this view. As such, these frameworks may not be useful for a cyber battlefield, where malicious actors may not move in a straight line of a particular framework. For example, artificial intelligence adversaries (e.g., generated adversary networks and quantum computing-based attackers) may randomly move through events in the example STIX-TAX11 framework layout.
[0030] Classical computing has provided benefits to organizations and individuals around the world. However, there are challenges that conventional systems cannot solve within a reasonable timeframe. More specifically, for problems of a certain size and complexity above, there is a lack of computational power to solve them using traditional binary computer processors (e.g., computational methods that use bits with a value of 0 or 1). One approach to attempting to solve some of these problems involves a relatively new class of computing: universal quantum computing. Universal quantum computers can exploit the quantum mechanical phenomena of superposition and entanglement to generate states that are exponentially proportional to the number of quantum bits (also referred to herein as quantum mechanical systems and qubits).
[0031] Thus, embodiments of the present invention provide a quantum computing-based machine learning model for identifying potential security threats. The model can be capable of determining multiple probabilities of a malicious actor moving from one attack category to any one of multiple attack categories. Furthermore, the model can be capable of determining the probability of a malicious actor moving from one attack method to any one of multiple attack methods.
[0032] For example, once access has been gained, a quantum computing-based machine learning model can determine the probability that a malicious actor will move from initial access to each of execution, persistence, privilege escalation, defense evasion, and credential access. Furthermore, a quantum computing-based machine learning model can determine the probability that a malicious actor will choose each potential attack method within each attack category.
[0033] Figure 1 1 is a block diagram of an example system 100 for quantum computing-based machine learning models according to some embodiments of the present invention. System 100 includes a network 102, a security domain 104, a security threat model 106, a quantum computing device 108, a trusted automated exchange of information (such as the Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11) framework 110), and a query engine 112.
[0034] The network 102 may include one or more computer communication networks. Example networks 102 may include the Internet, a local area network (LAN), a wide area network (WAN), a wireless network such as a wireless LAN (WLAN), and the like. The network 102 may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device implemented as part of the security domain 104, security threat model 106, quantum computing device 108, STIX-TAX11 framework 110, and query engine 112 may, for example, receive messages and / or instructions from and / or over the network 102, and forward the messages and / or instructions for storage or execution (etc.) to the corresponding memory or processor of the corresponding computing / processing device. Although for illustrative purposes, in Figure 1 While network 102 is described as a single entity in FIG, in other examples, network 102 may include multiple private and / or public networks over which components of system 100 may communicate.
[0035] The security domain 104 can be a computer hardware and software architecture for which the security threat model 106 can identify potential security threats. The computer hardware and software architecture can include personal computing devices, mobile computing devices, desktop and laptop computers, virtual appliances, containers, or any other cloud components. The security domain 104 can include a network system 114 and a security information and event management platform (SIEM platform 116). The networked system 114 can be one or more computer systems connected to one or more computer communication networks. For example, the networked system 114 can include a server cluster. Alternatively or additionally, the networked system 114 can include any number of computers and network nodes and associated hardware and software combinations. The SIEM platform 116 can refer to software tools and / or services that combine the management of security information with malicious attacks.
[0036] Security threat model 106 can be a machine learning model trained to identify potential attacks. The machine learning model can perform classification based on certain characteristics of a state. For example, the machine learning model can classify a digital image as containing a human or animal subject based on its characteristics. Characteristics of a digital image can include the color of each pixel and the composition of the pixels relative to each other. Using these characteristics, the machine learning model can calculate the probability that the digital photo contains a human or animal subject. The machine learning model can label the digital photo with the category with a higher probability.
[0037] In an embodiment of the present invention, the security threat model 106 may study the characteristics of the networked systems 114 of the security domain 104. Further, the security threat model 106 may determine the probabilities of multiple potential attack methods based on the characteristics of the security domain 104 and the networked systems 114. More specifically, the security threat model 106 may generate a quantum state probability (QSP) matrix 118 that represents the probability of a specific sequence of potential attack method types that a malicious attacker can execute. In some embodiments, the security threat model 106 may generate the QSP matrix 118 to include a probability for each potential attack method as arranged in the STIX-TAX11 framework 110. When generating the QSP matrix 118, the security threat model 106 may use the STIX-TAX11 framework 110 as a source of potential attack methods. The following example QSP matrix 1 is an example of a QSP matrix 118:
[0038] A B C D E A <1111111> <10101??> <1010101> <1010101> <1010101> B <1010101> <1111111> <1010101> <1010101> <1010101> C <1010101> <1010101> <1111111> <1010101> <1010101> D <1010101> <1010101> <1010101> <1111111> <1010101> E <1010101> <1010101> <1010101> <1010101> <1111111>
[0039] Example QSP Matrix 1
[0040] In this example, the row and column headings A through E represent specific states. A state can represent an attack category. Thus, A can represent initial access, B can represent reconnaissance, and so on. Further, the row headings of the example matrix 1 can represent the current state of the malicious actor, while the column headings can represent the inferred state of the malicious actor. The inferred state can represent the state that the security threat model 106 would potentially infer the malicious actor's next action given the initial state. Therefore, each cell of the example QSP matrix 1 can represent the calculated probability that the malicious actor will advance from a specific (current) attack category to another attack category. In some embodiments of the present invention, the probability can be represented as an array of binary values. The array of binary values can include a value for each potential attack method in the attack category. If a specific attack method is impossible, the QSP calculator 120 can set the binary value to 0, and if the specific attack method is possible, it can be set to 1. Thus, the binary value can be set to 1 to indicate that a specific attack method is more likely than not. Therefore, the QSP calculator 120 can use the individual probability determinations for each attack method in the category to determine the aggregate probability that the malicious actor will commit an attack category.
[0041] In the example QSP matrix 1, the binary array includes seven values to represent the seven different stages of the attack. A "?" can represent an unknown quantum position; whether the state after this unknown remains the same is also unknown. Furthermore, a "?" signifies that the probability of moving from A to B can be higher than the probability of moving from A to C by a predetermined threshold, as this is how it works in a linear model running on a classical computer.
[0042] However, the array can include more or fewer values. In some embodiments of the present invention, the number of values can be increased to 12 to cover the lateral regions of the MITRE ATT&CK framework and overlay those lateral regions onto the Bloch sphere (with vectors). In some embodiments using quantum states, the number of values can be two or four. By representing the likelihood of potential actions of malicious actors, patterns can be identified that enable security domain 104 to determine response capabilities, target security controls for specific areas, and improve cryptographic methods accordingly.
[0043] In the example QSP matrix 1, the cell representing the probability that a malicious actor will switch from attacking class A to attacking class B is represented as “ <1010101> ”, indicating that half of the potential attack methods within the same category are possible. Furthermore, QSP calculator 120 may consider these individual possibilities in aggregate to determine the likelihood of a particular attack category. Thus, where half of the individual attack methods are possible and considered in aggregate, the corresponding attack category is also possible. In this way, QSP matrix 118 may represent the likelihood that a malicious actor will move from one attack category to another. Additionally, if a malicious actor moves to a particular attack category, QSP matrix 118 may represent the likelihood that the malicious actor will use any attack method within that category.
[0044] It should be noted that the unit representing the probability that a malicious actor will use an attack method from the same class is “ <1111111> ”, indicating that all potential attack methods within the same category are possible. This may represent a scenario where the malicious actor simply remains in the same state. In addition, the QSP calculator 120 may consider these individual possibilities collectively to determine if all individual attack methods are possible and the corresponding attack category is also possible.
[0045] Generating the QSP matrix 118 may involve the use of a quantum computing device, such as the quantum computing device 108. The quantum computing device 108 may be generally described in comparison to conventional computing devices that rely on the ability to store and manipulate information in individual bits. A bit is a computer memory unit that stores information as binary 0 and 1 states. Compared to conventional computing devices, the quantum computing device 108 utilizes quantum mechanical properties to store and manipulate information. More specifically, the quantum computing device 108 uses the quantum mechanical properties of superposition, entanglement, and interference to manipulate the states of qubits. Superposition refers to the combination of states (which are described independently in conventional devices). The idea of superposition can be extended to the field of music, where playing two notes simultaneously creates a superposition of the two notes. Entanglement is a counterintuitive quantum phenomenon that describes behavior that is otherwise unseen in the physical universe. Entanglement refers to the phenomenon where independent particles behave together as a system.
[0046] Thus, the QSP calculator 120 can leverage the power of quantum computing to calculate multiple probabilities for multiple potential security threats as a linear complexity problem. The QSP calculator 120 can include vector equations, linear algebra tables, and other related mathematical methods to calculate each probability in the QSP matrix 118. This can include the probability that a malicious actor will perform each of a number of potential attack categories. This probability can be based on the most recent attack category. Additionally, the QSP calculator 120 can include mathematical methods to determine the probability that a malicious actor will perform each of a number of potential attack methods within a particular attack category. In this manner, the QSP calculator 120 can generate the QSP matrix 118.
[0047] In some embodiments of the present invention, QSP calculator 120 can generate an initial quantum state probability matrix 118 based on historical data from SIEM platform 116 and mobile network scopes to examine how malicious actors have executed their attacks in the past. Mobile network scope refers to a simulation of a security domain connected to a simulated internet environment. Mobile network scope can provide a secure, legal environment for security testing. By generating QSP matrix 118 in this manner, initial quantum state probability matrix 118 can include an initial table of probabilities based on past events that can be used to determine the probability that a malicious actor will carry out a specific attack category and corresponding attack method.
[0048] The STIX-TAX11 framework 110 may include a STIX database 122 and a TAX11 server 124. The term STIX refers to a standardized language for describing information about security threats. Therefore, STIX can describe incentives, capabilities, capabilities, and responses to security threats. STIX can be shared via TAX11 or other similar tools. Furthermore, the STIX database 122 may include multiple STIX files describing different security threats. In some embodiments, data from the STIX-TAX11 framework 110 can be preloaded into a SIEM engine or machine learning platform and used as the basis for threat intelligence data. Using artificial intelligence and machine learning, this data can be used as training data. However, without artificial intelligence and machine learning, this data can be used as a dataset for a rule engine to build. Thus, when an attack by a malicious actor occurs, the data from that actor or hacker is compared with the preloaded rule set. In terms of quantum state probability, data from the STIX-TAX11 framework 110 can be used to set initial vector positions within a Bloch sphere or as a dataset against which quantum models or quantum devices can be tested.
[0049] The TAX11 server 124 may be a tool for defining how information about security threats can be shared via online services and message exchanges. The TAX11 server 124 may provide access to the STIX database 122 by providing a RESTful API service (not shown) that is compatible with a common sharing model. For example, the TAX11 server 124 may define four services that can be selected, implemented, and combined into different sharing models.
[0050] The query engine 112 may represent a computer hardware and / or software architecture that can query the security threat model 106 to identify the likelihood of a potential attack. In this way, embodiments may make it possible to predict or infer future attacks. Querying the security threat model 106 may identify the likelihood that: 1) the attack is from a known malicious actor because it fits a pattern; 2) the attack fits a pattern based on similar attacks in the past; and / or 3) the attack will follow.
[0051] Figure 2 is a diagram of an example Bloch sphere 200 according to some embodiments of the present invention. In quantum mechanics, a Bloch sphere is a geometric representation of the space of pure states of a two-level qubit. In this example, Bloch sphere 200 can represent the full range of potential attack methods by a single malicious actor. Within Bloch sphere 200, each attack method is represented by a point in three-dimensional space. Example Bloch sphere 200 includes an origin 202 located at the center of Bloch sphere 200. Additionally, example Bloch sphere 200 includes axes 204 defining three spatial dimensions.
[0052] Axis 204 represents the three-dimensional space occupied by Bloch sphere 200. As a tool, axis 204 provides a multi-dimensional space in which the distance between two points on the surface of the sphere corresponds to the likelihood that a malicious actor will execute one class of attack methods and then proceed to execute another class of attack methods. Furthermore, the axis defines a multi-dimensional space in which the distance from origin 202 to a given point along a vector representing an attack class corresponds to the likelihood that a malicious actor selected from the given class will execute the attack method corresponding to the given point. While the example Bloch sphere 200 occupies a three-dimensional space, embodiments of the present invention may utilize Bloch spheres of three or more dimensions.
[0053] The number and definition of axes can vary, but for the purposes of this example, the axes represent three dimensions, including a time axis (Z) 204-1, a horizontal axis (X) 204-2, and a vertical axis (Y) 204-3. The time axis 204-1 can represent the time when the attack method occurred. The time when the attack method occurred can be determined from a source such as the SIEM platform 116. The time axis 204-1, the horizontal axis 204-2, and the vertical axis 204-3 can represent a conventional three-dimensional (x, y, z) space that the QSP calculator 120 can use in combination with a location point representing the attack method in the three-dimensional space as described above.
[0054] Advantageously, using a sphere rather than a linear model makes it easier to visualize the potential randomness of malicious attacks. For example, the Bloch sphere 200 includes a plurality of vectors 206 that originate at an origin 202 and terminate at points on the surface of the Bloch sphere 200. Each vector 206 represents a different attack method category, including, in this example, vectors 206 for categories such as initial access 206-1, privilege escalation 206-2, and exfiltration 206-3. The QSP calculator 120 can generate the vectors 206 in the Bloch sphere such that the relative position of each vector 206 to another vector represents the probability that a malicious actor will move from one attack category to another. Further, in an embodiment of the present invention, each attack method can represent a point along a vector. Thus, the distance from the origin 202 to each point can represent the probability that the malicious actor will use a particular attack method if the malicious actor chooses a particular attack category.
[0055] In this manner, QSP calculator 120 can use points on the surface of Bloch sphere 200 to determine the probability 208 that a malicious actor can move from one attack method category to another attack method category. Thus, the probability that a malicious actor can move from initial access to privilege escalation is represented by the distance from one point to another point on Bloch sphere 200, which is the distance between the surface points of vector 206 for initial access 206-1 and privilege escalation 206-2, as indicated by probability 208.
[0056] Assume that during an attack, the initial access 206-1 attack method involves a malicious actor cracking a password. The QSP calculator 120 can generate the quantum state probability matrix 118 based on the many possibilities in the attack chain, rather than attempting to identify future attack methods based on dynamic moves (lateral thinking). The Bloch sphere 200 thus provides a way to visualize a sequence of attack methods using a spherical shape. Therefore, the Bloch sphere 200 is useful for visualizing unforeseen sequences of attack methods, rather than being limited to a specific sequence of attack methods occurring in a straight, two-dimensional line, as in the STIX-TAX11 framework 110. For example, a malicious actor may successfully perform an initial access attack. However, instead of following the STIX-TAX11 framework and then performing the attack, the malicious actor may then attempt an exfiltration attack. Thus, the example Bloch sphere 200 provides potential paths from initial access 206-1 to exfiltration 206-3, where the distance represents the mathematical probability of that scenario. Therefore, the QSP calculator 120 can use a Bloch sphere such as the Bloch sphere 200 to populate the probabilities of the QSP matrix 118. Thus, by determining the distance between each vector 206 representing an attack category, the QSP calculator 120 can determine the probability of a malicious actor moving from one attack category to another. Further, once a malicious actor selects a new attack category, the QSP calculator 120 can determine the probability of the malicious actor attempting each attack method in that category by calculating the distance from the origin to the corresponding point along the associated vector 206.
[0057] In this example, Bloch sphere 200 includes three attack categories, representing a typical attack method sequence. This typical attack method sequence may include gaining access to a system by cracking a password, increasing the malicious actor's access rights to the attacked system, and exfiltrating data. This sequence may represent a scenario in which the malicious actor knows where to find the target information and therefore may not scan the system's files before exfiltrating.
[0058] For clarity, the example Bloch sphere 200 includes three attack categories. However, some embodiments of the present invention may include more than three attack categories. For example, the Bloch sphere 200 may include seven attack categories: reconnaissance, weaponization, delivery, privilege escalation, discovery, command and control, and exfiltration. Thus, for example, if a malicious actor does not follow a traditional linear attack sequence, the probability that the malicious actor performs a delivery attack method and then performs discovery or goes from privilege escalation back to weaponization can be determined. Additionally, historical data can make it possible to determine what attack sequence trends are for a particular malicious actor. For example, historical data can show whether the malicious actor starts with a binary filling or credential dumping attack method, and whether the malicious actor tends towards lateral movement or credential access attack methods.
[0059] Figure 3 3 is a process flow diagram of a method 300 for quantum computing a machine learning model according to some embodiments of the present invention. A QSP calculator and a security threat model (e.g., QSP calculator 120 and security threat model 106) can perform the method 300.
[0060] At operation 302, the QSP calculator 120 may generate a Bloch sphere based on the SIEM and STIX-TAX11 frameworks. For example, the Bloch sphere may be the Bloch sphere 200. In addition, the SIEM and STIX-TAX11 frameworks may be respectively relative to Figure 1 The SIEM platform 116 and the STIX-TAX11 framework 110 are described.
[0061] At operation 304, the QSP calculator 120 may generate a QSP matrix for the Bloch sphere 200 using the quantum state device. The QSP matrix may be, for example, the QSP matrix 118. Further, the quantum state device may be the quantum computing device 108. In some embodiments, the QSP calculator 120 may use the properties of the quantum computing device 108 described above to simultaneously populate all cells of the QSP matrix. Regarding the QSP matrix 118, as previously described, each cell of the QSP matrix 118 may include an array of values that, in combination, represent the probability that a second type of security event will occur after a first type of security event. Further, assuming that the second type of security event does occur, each value in the array may indicate whether a particular security event is likely to occur.
[0062] At operation 306, the security threat model 106 can train a classifier of the security threat model 106 to perform security threat classification based on the QSP matrix 118. Training the classifier can involve generating training data that describes features of potential security threats, with the training data having a label indicating whether the feature represents a security threat. The feature can include data that describes a specified state of the security domain 104, such as the Internet Protocol (IP) address of a potential attacker, an action performed by a potential attacker, etc. In some embodiments, the security threat model 106 can select training data features from the SIEM platform 116, and each training data transaction can be manually labeled. In this way, the classifier of the security threat model 106 can learn to identify potential security threats.
[0063] At operation 308, the security threat model 106 can use the trained classifier to infer security threat events for the security domain 104. Inference refers to the process of classification. Thus, the security threat model 106 makes inferences when its classifier determines possible attack categories and attack methods as described above. Therefore, the query engine 112 can ask the security threat model 106 to determine what potential attack category and attack method a malicious actor will attempt next. In response, the security threat model 106 can use the quantum state probability matrix 118 to determine which attack categories and methods are more likely than others.
[0064] Figure 4 is a diagram of an example Bloch sphere 400 according to some embodiments of the present invention. The example Bloch sphere 400 may be similar to the example Bloch sphere 400 of FIG. Figure 2 The example Bloch sphere 200 is depicted. Thus, the example Bloch sphere 400 includes an origin 402, an axis 404, attack method categories 406, and probabilities 408. Further, in the example Bloch sphere 400, the attack methods 406 include reconnaissance 406-1, weaponization 406-2, initial access 406-3, privilege escalation 406-4, discovery 406-5, command and control 406-6, and exfiltration 406-7.
[0065] In some embodiments of the present invention, the security threat model 106 can determine the probability of a malicious actor moving from one attack method 406 to another. For example, the security threat model 106 can determine the probability 408-1 that the malicious actor moves from reconnaissance 406-1 to weaponization 406-2. Similarly, the security threat model can determine the probability 408-2 that the malicious actor moves from privilege escalation 406-4 to discovery 406-5. However, such a sequence may reflect the assumption that a single actor is executing the threat and moving clockwise around the sphere in a systematic, rational manner. This would be similar to kinetic warfare. However, the malicious actor may move in random directions and / or experiment with different ways of attacking the target.
[0066] Therefore, it is useful to know two things: 1) If an attacker starts with a particular attack method category (e.g., the reconnaissance 406-1 attack method), what is the next possible attack method category, and 2) what is the next possible specific attack method? To determine the next possible category, the security threat model 106 can analyze the QSP matrix 118, which has the probability of a malicious actor moving from reconnaissance 406-1 to, for example, weaponization 406-2, initial access 406-3, privilege escalation 406-4, discovery 406-5, command and control 406-6, and exfiltration 406-7. To determine the next possible attack method, the security threat model 106 can analyze the probability of each potential attack method in the next possible category in the QSP matrix 118.
[0067] In some embodiments, the security threat model 106 may use a Markov chain to determine these probabilities.Example Probabilities Table 1 shows examples of the probabilities of a malicious actor moving between different attack methods.
[0068] reconnaissance Initial visit Weaponization reconnaissance 0.4 0.5 0.1 Initial visit 0.2 0.4 0.4 Weaponization 0.05 0.05 0.9
[0069] Example Probability Table 1
[0070] Example Probability Table 1 shows the probability that a malicious actor will switch from each attack method to another. For example, the probability that a malicious actor will switch from Reconnaissance to Initial Access is at least .50 (e.g., 50%); the probability that a malicious actor will switch from Reconnaissance to Weaponization is .10. This probability is relatively small because the malicious actor has not yet gained access to the environment. Further, the probability that a malicious actor will switch from Initial Access back to Reconnaissance is .05. Moreover, the probability that a malicious actor will switch from Initial Access to Weaponization is at least as high as the probability that the malicious actor will stay at Initial Access. Moreover, the probability that a malicious actor will stay at Weaponization is (very likely) .90, compared to the probability that a malicious actor will suddenly change their mind and switch back one step to Initial Access (.05) or two steps to Reconnaissance (.05).
[0071] Markov chains can be useful when applied to the past behavior of malicious actors (security threat model 106 can retrieve data from behavioral analysis tools). In addition, pattern recognition (we also have data from pattern recognition) as Markov events will have to have information about the previous event (event 1) to know what will happen next (event 2); and are useful for looking at historical data.
[0072] Figure 5A is a diagram of an example Bloch sphere 500A according to some embodiments of the present invention. The example Bloch sphere 500A may be similar to Figure 4Thus, the example Bloch sphere 500A includes an origin 502, an axis 504, an attack method category 506, and a probability 508, which can be similar to the probability of the attack method 508 with respect to the example Bloch sphere 400A. Figure 4 Described are origin 402, axis 404, attack method 406, and probability 408. Additionally, attack method 506 includes reconnaissance 506-1, weaponization 506-2, initial access 506-3, privilege escalation 506-4, discovery 506-5, command and control 506-6, and exfiltration 506-7.
[0073] Embodiments of the present invention are useful for identifying two or more attackers working together in an attack against a target. Working together can include conspiracy, collusion, and / or defection during an attack. Defection refers to when one (or both) malicious actors stop what they are doing and walk away from the attack. Defection only occurs when the malicious actors are human. Defection never occurs when the malicious actors are software, robots, algorithms, or artificial intelligence.
[0074] Cooperation through collusion, conspiracy, etc. is known as game theory. Even though multiple malicious actors can perform an attack together, the malicious actors may not be working on the same type of attack at the same time. For example, one actor may be performing reconnaissance 506-1 while another actor is performing privilege escalation 506-4 on the security domain 104 where the malicious actor found their credentials.
[0075] Thus, in some embodiments of the present invention, the QSP calculator 120 may generate multiple QSP matrices 118, where each QSP matrix 118 represents potential actions for each malicious actor. Further, the security threat model 106 may compare the QSP matrices 118 for overlap. The identified overlap may indicate that multiple malicious actors are working together. For example, probability 508-1 may represent the likelihood that a first malicious actor, having performed reconnaissance 506-1, will subsequently perform weaponization 506-2. Furthermore, probability 508-2 can represent the likelihood that a second malicious actor, having performed privilege escalation 506-4, will subsequently perform discovery 506-5. In embodiments of the present invention, the QSP matrices 118 representing possible attack methods for each malicious actor may overlap. The following example game theory Table 1 illustrates overlapping probabilities that may indicate a two-actor game theory attack where the goal of installing malware is successful:
[0076]
[0077]
[0078] Example Game Theory Table 1
[0079] In a game theory attack, the probability of two different malicious actors using the same attack method can be almost equal, until the method is weaponized. If one of the malicious actors is arrested, it is possible that the other malicious actor will continue to install the ransomware.
[0080] Figure 5B is a diagram of an example Bloch sphere 500B according to some embodiments of the present invention. The example Bloch sphere 500B may be similar to Figure 5A Described Bloch sphere 500A.
[0081] Example Bloch sphere 500B may represent a sphere in which a third malicious actor is associated with Figure 5A The scenario described above involves collusion between the first two malicious actors. Therefore, in some embodiments of the present invention, QSP calculator 120 may generate three QSP matrices 118, where each QSP matrix 118 represents the potential actions of each malicious actor. In this manner, security threat model 106 may determine whether there is overlap between the three malicious actors. Thus, in addition to probabilities 508-1 and 508-2, probability 508-3 may represent the likelihood that a third malicious actor, having performed weaponization 506-2, will subsequently perform initial access 506-3. Security threat model 106 may identify overlap between the third malicious actor and one or both of the other malicious actors.
[0082] An example of a three-way game theory attack is an insider threat. During an insider threat attack, a third malicious actor provides information useful for accessing the secure domain. Such information may include security credentials in the form of badges, key cards, or credential-like information from current or former employees of the company using secure domain 104. The Dark Web may also be a source of credential information such as server names, server locations, root administrator credentials, etc. Alternatively, the third malicious actor may be malware such as a script or pre-prepared code.
[0083] Example Game Theory Table 2 shows the overlap probability for a three-actor attack where the goal of installing malware is successful:
[0084]
[0085]
[0086] Example Game Theory Table 2
[0087] Example Game Theory Table 3 demonstrates the overlap probabilities of different three-actor attacks in which the target fails to install malware:
[0088]
[0089] Example Game Theory Table 3
[0090] In the example game theory table 3, the probabilities are not uniformly distributed, even during reconnaissance. Conversely, malicious actor A has a probability of 0.50 that they will monitor social media. However, the probability that malicious actors B and C will capture external and internal traffic, respectively, can depend on the success of malicious actor A. For initial access, the analysis can be the same. For weaponization, if malicious actor A provides nothing of value and is arrested, while malicious actor B, with valid credentials, decides that hacking is too risky and withdraws, malicious actor C will likely be unable to install ransomware.
[0091] Figure 6 is a diagram of an example Bloch sphere 600 according to some embodiments of the present invention. Thus, the example Bloch sphere 600 includes an origin 602, an axis 604, an attack method category 606, and a probability 608, which may be similar to the probability of Figure 4 Described are origin 402, axis 404, attack method 406, and probability 408. Additionally, attack method 606 includes exploitation 606-1, reconnaissance 606-2, weaponization 606-3, initial access 606-4, execution 606-5, privilege escalation 606-6, discovery 606-7, command and control 606-8, collusion 606-9, exfiltration 606-10, and persistence 606-11.
[0092] Example Bloch sphere 600 can represent an attack by an AI malicious actor. An AI malicious actor is different from a robot. A robot can be a computer program configured to execute a predetermined attack method. In contrast, an AI malicious actor can be trained to identify various different types of attack methods based on many potential scenarios. The amount of time it takes for an AI malicious actor to move through attack methods 606 may be less than 30 seconds, depending on the computing power behind the AI malicious actor. In some scenarios, the AI malicious actor can be trained through algorithms and machine learning to find the most relatively effective attack methods in a shorter amount of time. In this way, the AI malicious actor may not function like a human malicious actor. Therefore, the AI malicious actor can move around the sphere (i.e., execute the various categories of attack methods 606 represented in example Bloch sphere 600 relatively faster than human malicious behavior). The AI malicious actor may also select different attack methods 606 for entry than a human actor. Therefore, the entry point for the attack may not include exploit 606-1, but instead may be a vulnerability, software vulnerability, or malware.
[0093] Therefore, in some embodiments of the present invention, the quantum state probability calculator 120 can generate a quantum state probability matrix 118 for the probability of each transition between attack methods 606. For example, an artificial intelligence malicious actor can transition at a greater rate than a human malicious actor. Therefore, if an artificial intelligence malicious actor moves relatively quickly through exploitation 606-1, reconnaissance 606-2, weaponization 606-3, initial access 606-4, execution 606-5, privilege escalation 606-6, discovery 606-7, exfiltration 606-10, and persistence 606-11, the security threat model 106 can identify the malicious actor by comparing probabilities 608-1 to 608-7.
[0094] In some embodiments, the security threat model 106 can determine what kind of actor is attacking the system, i.e., is the malicious actor a human or an artificial intelligence system? Furthermore, the security threat model 106 can identify malicious actors with advanced skill sets and generate a probability that a particular malicious actor is a particular person in the suspect pool.
[0095] Further, a malicious actor can exploit a sequence of attack methods to lead to a scenario of potential exploitation on a completely different system. For example, an artificially intelligent malicious actor can use exploit 606-1 to enter a secure domain (such as secure domain 104). Once the artificially intelligent malicious actor obtains a useful set of credentials (e.g., a hard-coded username and password), the credentials can be used to move to another networked system. In some embodiments of the present invention, security threat model 106 can generate a Bloch sphere for each networked system 114 of security domain 104. In addition, quantum state probability calculator 120 can generate a quantum state probability matrix 118 that represents the probability that a malicious actor will move from a first networked system to a second networked system as part of an attack.
[0096] Figure 7 is a block diagram of an example security threat model manager 700 according to some embodiments of the present invention. In various embodiments, the security threat model manager 700 is similar to the event modeler 96 and may execute Figure 3 The methods described in and / or Figure 1 、 Figure 2 , Figure 5 and Figure 6 In some embodiments, security threat model manager 700 provides instructions for the methods and / or functions described above to a client machine, causing the client machine to perform a method or a portion of a method based on the instructions provided by security threat model manager 700. In some embodiments, security threat model manager 700 comprises software executed on hardware incorporated into a plurality of devices.
[0097] Security threat model manager 700 includes memory 725 , storage 730 , interconnect (eg, bus) 720 , one or more CPUs 705 (also referred to herein as processors 705 ), I / O device interface 710 , I / O device 712 , and network interface 715 .
[0098] Each CPU 705 retrieves and executes programming instructions stored in memory 725 or storage device 730. Interconnect 720 is used to move data, such as programming instructions, between CPU 705, I / O device interface 710, storage device 730, network interface 715, and memory 725. Interconnect 720 can be implemented using one or more buses. In different embodiments, CPU 705 can be a single CPU, multiple CPUs, or a single CPU with multiple processing cores. In some embodiments, CPU 705 can be a digital signal processor (DSP). In some embodiments, CPU 705 includes one or more 3D integrated circuits (3DICs) (e.g., 3D wafer-level packaging (3DWLP), 3D interposer-based integration, 3D stacked IC (3D-SIC), monolithic 3DIC, 3D heterogeneous integration, 3D system-in-package (3DSiP), and / or package-on-package (PoP) CPU configurations). Memory 725 is typically included to represent random access memory (e.g., static random access memory (SRAM), dynamic random access memory (DRAM), or flash memory). Storage 730 is typically included to represent non-volatile memory, such as a hard drive, a solid-state device (SSD), a removable memory card, optical storage, and / or a flash memory device. Additionally, storage 730 may include a storage area network (SAN) device, a cloud, or other device connected to security threat model manager 700 via I / O device interface 710 or to network 750 via network interface 715.
[0099] In some embodiments, memory 725 stores instructions 760. However, in various embodiments, instructions 760 are stored partially in memory 725 and partially in storage 730, or all in memory 725 or all in storage 730, or are accessed over network 750 via network interface 715.
[0100] Instruction 760 may be for executing Figure 3 The methods described in and / or Figure 1 、 Figure 2 , Figure 5 and Figure 6 Processor executable instructions for any or all of the functions discussed in .
[0101] In various embodiments, I / O device 712 includes an interface capable of presenting information and receiving input. For example, I / O device 712 can present information to a listener that interacts with security threat model manager 700 and receive input from the listener.
[0102] Security threat model manager 700 is connected to network 750 via network interface 715. Network 750 may include physical, wireless, cellular, or different networks.
[0103] In some embodiments, the security threat model manager 700 can be a multi-user mainframe computer system, a single-user system or a server computer, or a similar device having little or no direct user interface but receiving requests from other computer systems (clients). Further, in some embodiments, the security threat model manager 700 can be implemented as a desktop computer, a portable computer, a laptop or notebook computer, a tablet computer, a pocket computer, a phone, a smartphone, a network switch or router, or any other suitable type of electronic device.
[0104] It should be noted that Figure 7 The following is intended to depict representative major components of the exemplary security threat model manager 700. However, in some embodiments, individual components may have more Figure 7 The components represented in the example are of greater or lesser complexity and may have different Figure 7 components or in addition to those shown in Figure 7 Components other than those shown in the drawings may be included, and the number, type, and configuration of such components may vary.
[0105] Although the present disclosure includes detailed descriptions about cloud computing, the implementation of the teachings cited herein is not limited to a cloud computing environment. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment now known or later developed.
[0106] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be quickly provisioned and released with minimal management effort or interaction with the service provider. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0107] Features are as follows:
[0108] On-demand self-service: Cloud consumers can unilaterally and automatically provision computing capabilities, such as server time and network storage, as needed without requiring human interaction with the service provider.
[0109] Broad Network Access: Capabilities are available over the network and accessed through standard mechanisms that facilitate the use of heterogeneous thin-client or thick-client platforms (e.g., mobile phones, laptops, and PDAs).
[0110] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically allocated and reallocated based on demand. There is a sense of location independence, as consumers typically do not have control or knowledge of the exact location of the provided resources, but are able to specify the location at a higher level of abstraction (e.g., country, state, or data center).
[0111] Rapid elasticity: The ability to quickly and elastically provision capacity, in some cases automatically scaling down and releasing capacity to scale up quickly. To the consumer, the capacity available for provisioning typically appears unlimited and can be purchased in any quantity at any time.
[0112] Metered Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of the utilized services.
[0113] The service model is as follows:
[0114] Software as a Service (SaaS): The ability provided to consumers is to use the provider's applications running on a cloud infrastructure. Applications are accessible from various client devices through a thin client interface such as a web browser (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.
[0115] Platform as a Service (PaaS): The capability provided to consumers is to deploy applications created or acquired using programming languages and tools supported by the provider onto cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but do have control over the deployed applications and the configuration of the application hosting environment.
[0116] Infrastructure as a Service (IaaS): The capabilities provided to consumers are processing, storage, networking, and other basic computing resources on which consumers can deploy and run arbitrary software, including operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but rather have control over the operating system, storage, deployed applications, and potentially limited control over selected networking components (e.g., host firewalls).
[0117] The deployment model is as follows:
[0118] Private cloud: Cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can exist on-premises or off-premises.
[0119] Community cloud: Cloud infrastructure is shared by several organizations and supports a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organization or a third party and can exist on-premises or off-premises.
[0120] Public cloud: Cloud infrastructure is made available to the public or large industry groups and is owned by the organization that sells cloud services.
[0121] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).
[0122] Cloud computing environments are service-oriented and focus on statelessness, low coupling, modularity, and semantic interoperability. The core of cloud computing is the infrastructure that consists of a network of interconnected nodes.
[0123] Figure 8 8 is a cloud computing environment 810 according to some embodiments of the present invention. As shown in the figure, the cloud computing environment 810 includes one or more cloud computing nodes 800. The cloud computing nodes 800 can execute Figure 3 The methods described in and / or Figure 1 、 Figure 2 , Figure 5 and Figure 6 800N。 Figure 8 The types of computing devices 800A-800N shown in FIG are intended to be illustrative only, and computing node 800 and cloud computing environment 810 may communicate with any type of computerized device over any type of network and / or network-addressable connection (eg, using a web browser).
[0124] Figure 9 According to some embodiments of the present invention, the cloud computing environment 810 ( Figure 8 ) provides a set of functional abstract model layers. It should be understood in advance that Figure 9 The components, layers and functions shown are merely illustrative, and embodiments of the present invention are not limited thereto. As described below, the following layers and corresponding functions are provided.
[0125] The hardware and software layer 900 includes hardware and software components. Examples of hardware components include: host 902; server 904 based on RISC (Reduced Instruction Set Computer) architecture; server 906; blade server 908; storage device 910; and network and networking components 912. In some embodiments, software components include network application server software 914 and database software 916.
[0126] Virtualization layer 920 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 922 ; virtual storage 924 ; virtual networks 926 , including virtual private networks; virtual applications and operating systems 928 ; and virtual clients 930 .
[0127] In one example, the management layer 940 may provide the functionality described below. Resource provisioning 942 provides dynamic procurement of computing resources and other resources for performing tasks within the cloud computing environment. Metering and pricing 944 provides cost tracking as resources are utilized within the cloud computing environment and bills or invoices the consumption of these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. A user portal 946 provides access to the cloud computing environment for consumers and system administrators. Service level management 948 provides cloud computing resource allocation and management so that required service levels are met. Service level management 948 can allocate appropriate processing power and memory to process static sensor data. Service level agreement (SLA) planning and fulfillment 950 provides pre-scheduling and procurement of cloud computing resources in anticipation of future requirements for the cloud computing resources according to the SLA.
[0128] The workload layer 960 provides examples of functionality that can utilize a cloud computing environment. Examples of workloads and functionality that can be provided from this layer include: mapping and navigation 962; software development and lifecycle management 964; virtual classroom education delivery 966; data analytics processing 968; transaction processing 970; and security threat model manager 972.
[0129] The present invention may be a system, method and / or computer program product of any possible degree of technical detail integration. The computer program product may include a computer-readable storage medium (or multiple computer-readable storage media) having computer-readable program instructions thereon for causing a processor to perform various aspects of the present invention.
[0130] Computer readable storage medium can be a tangible device that can retain and store the instruction used by the instruction execution device.Computer readable storage medium can be, for example but not limited to, electronic storage device, magnetic storage device, optical storage device, electromagnetic storage device, semiconductor storage device or any suitable combination of the above.The non-exhaustive list of the more specific example of computer readable storage medium includes the following: portable computer disk, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical encoding device such as punch card or the convex structure in the groove with the instruction recorded thereon and any suitable combination of the above.Computer readable storage medium as used herein should not be interpreted as temporary signal itself, such as radio wave or other free propagation electromagnetic wave, electromagnetic wave (for example, light pulse through fiber optic cable) propagated by waveguide or other transmission medium or the electric signal emitted by wire.
[0131] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network), or downloaded to an external computer or external storage device. The network can include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in a computer-readable storage medium within the corresponding computing / processing device.
[0132] The computer-readable program instructions for performing the operation of the present invention can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, configuration data of integrated circuit or source code or object code written in any combination of one or more programming languages, these programming languages include object-oriented programming languages (such as Smalltalk, C++ etc.) and process programming languages (such as " C " programming languages or similar programming languages). The computer-readable program instructions can be performed completely on the user's computer, partly on the user's computer, performed as an independent software package, partly on the user's computer, partly on a remote computer or fully on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer by any type of network (including local area network (LAN) or wide area network (WAN)), or can be connected to an external computer (for example, using an internet service provider through the internet). In certain embodiments, the electronic circuit comprising for example programmable logic circuit, field programmable gate array (FPGA) or programmable logic array (PLA) can make the electronic circuit personalized to perform computer-readable program instructions by utilizing the state information of computer-readable program instructions, so as to perform various aspects of the present invention.
[0133] The present invention will be described below with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0134] These computer-readable program instructions can be provided to a processor of a computer or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device create a device for implementing the functions / actions specified in the flowchart and / or block diagram or multiple blocks. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to operate in a specific manner. Thus, the computer-readable storage medium having the instructions stored therein includes an article of manufacture containing instructions that implement aspects of the functions / actions specified in the flowchart and / or block diagram or multiple blocks.
[0135] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, so that a series of operational steps are performed on the computer, other programmable apparatus, or other device to produce computer-implemented processing, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / actions specified in or in multiple boxes in the flowchart and / or block diagram.
[0136] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functions and operations of possible implementations of systems, methods and computer program products according to different embodiments of the present invention. In this regard, each box in the flowchart or block diagram may represent a module, vector or instruction portion, which includes one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the box may not occur in the order marked in the figure. For example, two boxes shown in succession can actually be completed as a step, performed simultaneously, substantially simultaneously, in a partially or completely temporally overlapping manner, or the boxes can sometimes be performed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs a specified function or action or performs a combination of dedicated hardware and computer instructions.
[0137] The following is a non-limiting list of examples to demonstrate some aspects of the present invention. Example 1 is a computer-implemented method for a security model. The method includes: generating a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11); generating a quantum state probability matrix based on the Bloch sphere; training a security threat model to perform security threat classification based on the quantum state probability matrix; and performing machine learning classification of the security domain based on the quantum state probability matrix.
[0138] Example 2 includes the method of Example 1, including or excluding the optional features. In this example, the method includes determining that a malicious actor performs a specific attack category based on a previous attack category and a quantum state probability matrix. Optionally, the method includes determining that a malicious actor performs a specific attack method for the specific attack category based on the specific attack category and the quantum state probability matrix.
[0139] Example 3 includes the method of any one of Examples 1 to 2, including or excluding the optional features. In this example, the method includes determining that a plurality of malicious actors are performing a game theory attack. Optionally, determining that the malicious actors are performing a game theory attack includes: generating a plurality of quantum state probability matrices for moves between a plurality of attack category pairs; and determining that a plurality of probabilities overlap between two or more of the plurality of quantum state probability matrices.
[0140] Example 4 includes the method of any one of Examples 1 to 3, including or excluding the optional features. In this example, the quantum state probability matrix includes a plurality of probabilities representing: a likelihood that the malicious actor moves between all potential combinations of attack categories; and a likelihood that the malicious actor uses a specific attack method for all attack categories based on previous attack categories. Optionally, the likelihood that the malicious actor moves between combinations of attack categories includes a plurality of probabilities that the malicious actor performs a plurality of specific attack methods for a specific attack category.
[0141] Example 5 includes the method of any one of Examples 1 to 4, including or excluding the optional features. In this example, the Bloch sphere includes: an origin; and three axes representing a three-dimensional space, wherein one of the three axes represents a time when the attack method is executed.
[0142] Example 6 is a computer program product comprising program instructions stored on a computer-readable storage medium. The computer-readable medium comprises instructions that direct a processor to: generate a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11); generate a quantum state probability matrix based on the Bloch sphere; train a security threat model to perform security threat classification based on the quantum state probability matrix; and perform machine learning classification of the security domain based on the quantum state probability matrix.
[0143] Example 7 includes the computer-readable medium of Example 6, including or excluding optional features. In this example, the computer-readable medium includes determining that a malicious actor performs a specific attack category based on a previous attack category and a quantum state probability matrix. Optionally, the computer-readable medium includes determining a specific attack method for the malicious actor to perform the specific attack category based on the specific attack category and the quantum state probability matrix.
[0144] Example 8 includes the computer-readable medium of any one of Examples 6 to 7, including or excluding the optional feature. In this example, the computer-readable medium includes determining that a plurality of malicious actors are performing game theory attacks. Optionally, determining that the malicious actors are performing game theory attacks includes: generating a plurality of quantum state probability matrices for moves between a plurality of attack category pairs; and determining that a plurality of probabilities overlap between two or more of the plurality of quantum state probability matrices.
[0145] Example 9 includes the computer-readable medium of any one of Examples 6 to 8, including or excluding optional features. In this example, the quantum state probability matrix includes a plurality of probabilities representing: a likelihood that a malicious actor moves between all potential combinations of attack categories; and a likelihood that a malicious actor uses a specific attack method for all attack categories based on previous attack categories. Optionally, the likelihood that a malicious actor moves between combinations of attack categories includes a plurality of probabilities that the malicious actor performs a plurality of specific attack methods for a specific attack category.
[0146] Example 10 includes the computer-readable medium of any one of Examples 6 to 9, including or excluding the optional feature, wherein the Bloch sphere includes: an origin; and three axes representing a three-dimensional space, wherein one of the three axes represents a time when the attack method is executed.
[0147] Example 11 is a system. The system includes instructions for directing a processor to a computer processing circuit; and a computer-readable storage medium storing instructions, which, when executed by the computer processing circuit, are configured to cause the computer processing circuit to perform a method including: generating a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11); generating a quantum state probability matrix based on the Bloch sphere; training a security threat model to perform security threat classification based on the quantum state probability matrix; and performing machine learning classification of the security domain based on the quantum state probability matrix.
[0148] Example 12 includes the system of Example 11, including or excluding the optional features. In this example, the system includes: determining that a malicious actor performs a specific attack category based on previous attack categories and a quantum state probability matrix; and determining a specific attack method for the malicious actor to perform the specific attack category based on the specific attack category and the quantum state probability matrix.
[0149] Example 13 includes the system of any of Examples 11 to 12, including or excluding the optional features. In this example, the system includes determining that a plurality of malicious actors are performing a game theory attack, wherein determining that the malicious actors are performing a game theory attack includes: generating a plurality of quantum state probability matrices for moves between a plurality of attack category pairs; and determining that a plurality of probabilities overlap between two or more of the plurality of quantum state probability matrices.
[0150] Example 14 includes the system of any of Examples 11 to 13, including or excluding the optional features. In this example, the quantum state probability matrix includes a plurality of probabilities representing: a likelihood that the malicious actor moves between all possible combinations of attack categories; and a likelihood that the malicious actor uses a specific attack method for all attack categories based on previous attack categories. Optionally, the likelihood that the malicious actor moves between combinations of attack categories includes a plurality of probabilities that the malicious actor performs a plurality of specific attack methods for a specific attack category.
[0151] Example 15 includes the system of any one of Examples 11 to 14, including or excluding the optional features, wherein the Bloch sphere includes: an origin; and three axes representing a three-dimensional space, wherein one of the three axes represents a time when the attack method is executed.
[0152] Example 16 is a computer-implemented method for a security model. The method includes instructions that direct a processor to generate a Bloch sphere based on System Information and Event Management (SIEM) for a security domain and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11); generate a quantum state probability matrix based on the Bloch sphere; and train a security threat model to perform security threat classification based on the quantum state probability matrix, wherein the security threat classification infers a next attack category for the security domain based on a previous attack category.
[0153] Example 17 includes the method of Example 16, including or excluding the optional features. In this example, the method includes performing machine learning classification of the security domain based on the quantum state probability matrix.
[0154] Example 18 is a computer-implemented method for a security model. The method includes instructions that direct a processor to generate a Bloch sphere based on a system information and event management (SIEM) and structured threat information expression-trusted automated exchange of indicator information (STIX-TAX11) for a security domain; generate a quantum state probability matrix based on the Bloch sphere, wherein the quantum state probability matrix includes multiple probabilities, the multiple probabilities representing: the likelihood of a malicious actor moving between all possible combinations of attack categories; and the likelihood of the malicious actor using specific attack methods for all attack categories based on previous attack categories; and train a security threat model to perform security threat classification based on the quantum state probability matrix, wherein the security threat classification infers a next attack category for the security domain based on the previous attack category.
[0155] In a preferred embodiment of the present invention described above, a computer-implemented method for a security model is provided, comprising: generating a Bloch sphere based on System Information and Event Management (SIEM) for a security domain and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11); generating a quantum state probability matrix based on the Bloch sphere; and training a security threat model to perform security threat classification based on the quantum state probability matrix, wherein the security threat classification infers the next attack category against the security domain based on the previous attack category. Preferably, the method further comprises performing security threat classification for the security domain based on the quantum state probability matrix. In a preferred embodiment of the present invention described above, a computer-implemented method for a security model is provided, comprising: generating a Bloch sphere based on System Information and Event Management (SIEM) and Structured Threat Information Expression-Trusted Automated Exchange of Indicator Information (STIX-TAX11) for a security domain; generating a quantum state probability matrix based on the Bloch sphere, wherein the quantum state probability matrix includes multiple probabilities representing: the likelihood of a malicious actor moving between all possible combinations of attack categories; and the likelihood of a malicious actor using specific attack methods for all attack categories based on previous attack categories; and training a security threat model to perform security threat classification based on the quantum state probability matrix, wherein the security threat classification infers the next attack category for the security domain based on the previous attack category.
Claims
1. A computer-implemented method for a security model, comprising: Generate a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11), where the distance between two points on the Bloch sphere surface corresponds to the probability that a malicious actor will continue to execute an attack method of another attack category after executing an attack method of one attack category; generating a quantum state probability matrix based on the Bloch sphere by determining a probability that the malicious actor will perform each attack category in the potential attack categories and, for a particular attack category, determining a probability that the malicious actor will perform each attack method in the plurality of potential attack methods in the attack category, the quantum state probability matrix including a plurality of probabilities representing the likelihood that the malicious actor will move between all potential combinations of the attack categories and the likelihood that the malicious actor will use a particular attack method in all attack categories based on previous attack categories; training a security threat model to perform security threat classification based on the quantum state probability matrix; as well as A machine learning classification of the security domain is performed based on the quantum state probability matrix.
2. The method of claim 1 further comprising determining that a malicious actor is performing a particular attack class based on previous attack classes and the quantum state probability matrix. 3 . The method according to claim 2 , further comprising determining a specific attack method for a malicious actor to perform the specific attack category based on the specific attack category and the quantum state probability matrix.
4. The method of claim 1 , further comprising determining that a plurality of malicious actors are performing a game theory attack.
5. The method according to claim 4, wherein Determining that a malicious actor is performing the described game theory attack involves: generating a plurality of quantum state probability matrices for movement between a plurality of attack category pairs; and A plurality of probabilities is determined to overlap between two or more of the plurality of quantum state probability matrices.
6. The method according to claim 5, wherein: The possibility for a malicious actor to move between combinations of attack categories includes multiple possibilities for a malicious actor to perform multiple specific attack methods of a specific attack category.
7. The method according to claim 1, wherein The Bloch sphere includes: Origin; and Representing three axes of a three-dimensional space, wherein one of the three axes represents the time when the attack method is executed.
8. A computer program product comprising program instructions stored on a computer-readable storage medium, the program instructions being executable by a processor to cause the processor to perform a method comprising: Generate a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11), where the distance between two points on the Bloch sphere surface corresponds to the probability that a malicious actor will continue to execute an attack method of another attack category after executing an attack method of one attack category; generating a quantum state probability matrix based on the Bloch sphere by determining a probability that the malicious actor will perform each attack category in potential attack categories and, for a particular attack category, determining a probability that the malicious actor will perform each attack method in a plurality of potential attack methods in the attack category, the quantum state probability matrix including a plurality of probabilities representing: a likelihood that the malicious actor will move between all possible combinations of the attack categories, and a likelihood that the malicious actor will use a particular attack method in all attack categories based on previous attack categories; training a security threat model to perform security threat classification based on the quantum state probability matrix; as well as A machine learning classification of the security domain is performed based on the quantum state probability matrix.
9. The computer program product of claim 8, further comprising: A malicious actor is determined to perform a specific attack class based on previous attack classes and the quantum state probability matrix.
10. The computer program product of claim 9, further comprising: A specific attack method for a malicious actor to execute the specific attack category is determined based on the specific attack category and the quantum state probability matrix.
11. The computer program product of claim 8, further comprising determining that a plurality of malicious actors are performing game theory attacks.
12. The computer program product of claim 11, wherein: Determining that a malicious actor is performing a game theory attack involves: generating a plurality of quantum state probability matrices for movement between a plurality of attack category pairs; and A plurality of probabilities is determined to overlap between two or more of the plurality of quantum state probability matrices.
13. The computer program product of claim 8, wherein: The possibility for a malicious actor to move between combinations of attack categories includes multiple possibilities for a malicious actor to perform multiple specific attack methods of a specific attack category.
14. The computer program product of claim 8, wherein: The Bloch sphere includes: Origin; and Representing three axes of a three-dimensional space, wherein one of the three axes represents the time when the attack method is executed.
15. A system for a security model, comprising: Computer processing circuits; as well as A computer-readable storage medium storing instructions that, when executed by the computer processing circuit, are configured to cause the computer processing circuit to perform a method comprising: Generate a Bloch sphere based on System Information and Event Management (SIEM) for security domains and Structured Threat Information Expression - Trusted Automated Exchange of Indicator Information (STIX-TAX11), where the distance between two points on the Bloch sphere surface corresponds to the probability that a malicious actor will continue to execute an attack method of another attack category after executing an attack method of one attack category; generating a quantum state probability matrix based on the Bloch sphere by determining a probability that the malicious actor will perform each attack category in potential attack categories and, for a particular attack category, determining a probability that the malicious actor will perform each attack method in a plurality of potential attack methods in the attack category, the quantum state probability matrix including a plurality of probabilities representing: a likelihood that the malicious actor will move between all possible combinations of the attack categories, and a likelihood that the malicious actor will use a particular attack method in all attack categories based on previous attack categories; training a security threat model to perform security threat classification based on the quantum state probability matrix; as well as A machine learning classification of the security domain is performed based on the quantum state probability matrix.
16. The system of claim 15, further comprising: determining that a malicious actor performs a particular attack class based on previous attack classes and the quantum state probability matrix; as well as A specific attack method for a malicious actor to execute the specific attack category is determined based on the specific attack category and the quantum state probability matrix.
17. The system of claim 15, further comprising determining that a plurality of malicious actors are performing game theory attacks, wherein Determining that a malicious actor is performing the described game theory attack involves: generating a plurality of quantum state probability matrices for movement between a plurality of attack category pairs; and A plurality of probabilities is determined to overlap between two or more of the plurality of quantum state probability matrices.
18. The system according to claim 15, wherein: The possibility for a malicious actor to move between combinations of attack categories includes multiple possibilities for a malicious actor to perform multiple specific attack methods of a particular attack category.
19. The system of claim 15, wherein: The Bloch sphere includes: Origin; and Representing three axes of a three-dimensional space, wherein one of the three axes represents the time when the attack method is executed.
Citation Information
Patent Citations
Threat disposition analysis and modeling using supervised machine learning
US20180367561A1
Quantum feature kernel estimation
US20190378025A1