Artificial intelligence security engine in security management system

By introducing an artificial intelligence security engine into the security management system, generating an AI security graph and analyzing relevant data, the problem of inaccurate AI alarm identification in the existing system is solved, and efficient security situation management and threat response are achieved.

CN121586898APending Publication Date: 2026-02-27MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480047751.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-08-17
Filing Date
2024-07-22
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing security management systems fail to effectively generate and filter AI security alerts and lack integration with AI security engines, resulting in a large number of noisy alerts and inefficient security investigations in the computing environment, making it impossible to effectively identify and respond to potential threats from AI applications.

Method used

Employing an AI security engine, it generates AI security graphs, analyzes AI attack monitoring and operational data, identifies high-fidelity alerts, and provides security posture management. It is integrated into the security management system to improve the security management operations and interfaces of the computing environment.

Benefits of technology

It improves the accuracy of AI-based security alerts, reduces noise alerts, enhances the efficiency of security posture management, effectively detects and responds to potential threats in the computing environment, and provides real-time security posture information and remedial measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121586898A_ABST
    Figure CN121586898A_ABST
Patent Text Reader

Abstract

Methods, systems, and computer storage media for providing security situation management using an artificial intelligence security engine in a security management system. Security situation management supports security management of a computing environment based on contextual information associated with an application supported by artificial intelligence. A security management system provides an artificial intelligence security map associated with an application supported by artificial intelligence. An artificial intelligence engine uses an artificial intelligence security map to correlate artificial intelligence attack monitoring data with operational data of an application supported by artificial intelligence. In operation, artificial intelligence attack monitoring data is accessed. An artificial intelligence security map associated with a plurality of applications supported by artificial intelligence is accessed. Operational data of an application supported by artificial intelligence is accessed based on the artificial intelligence attack monitoring data and the artificial intelligence security map. The artificial intelligence attack monitoring data and the operational data are analyzed to identify artificial intelligence security alerts. An artificial intelligence security alert is transmitted.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] Users rely on computing environments with applications and services to accomplish computing tasks. Distributed computing systems host and support different types of applications and services in a managed computing environment. In particular, a computing environment can implement a security management system that provides security posture management functionality and supports threat protection in the computing environment. For example, data security posture management (DSPM), cloud security posture management (CSPM), and enterprise security posture management (collectively referred to as “security posture management”) can include identifying and remediating risks through automated visibility, performing continuous monitoring and threat detection, and providing remediation workflows to search for misconfigurations across different cloud computing environments and infrastructures. SUMMARY

[0002] Various aspects of the technology described herein generally relate to systems, methods, and computer storage media for providing security posture management, etc., using an artificial-intelligence security engine of a security management system. Security posture management supports security management of a computing environment based on contextual information associated with artificial-intelligence applications. In particular, a security management system provides an artificial-intelligence security graph that models artificial-intelligence-supported applications in the computing environment. An artificial-intelligence security engine uses the artificial-intelligence security graph to analyze artificial-intelligence attack monitoring data (e.g., anomalies or alerts) and correlate the artificial-intelligence attack monitoring data (e.g., anomalies or alerts) with operational data (e.g., behavioral data and communication data) of the artificial-intelligence-supported applications. The security management system can use the correlations identified between the artificial-intelligence attack monitoring data, artificial-intelligence security alerts, and operational data to filter or classify artificial-intelligence security alerts as high-fidelity alerts. Based on the artificial-intelligence security graph and artificial-intelligence security alerts, security posture management can be provided to support management of security aspects of data, resources, and workloads in the computing environment, including identifying and remediating risks.

[0003] An artificial-intelligence security engine is executed to provide security posture management based on generating an artificial-intelligence security graph using application data of artificial-intelligence-supported applications of a computing environment and generating, filtering, and classifying artificial-intelligence security alerts based on analyzing artificial-intelligence attack monitoring data and correlating the artificial-intelligence attack monitoring data with operational data of the artificial-intelligence-supported applications. An artificial-intelligence security engine operation is performed to generate an artificial-intelligence graph using application data associated with artificial-intelligence-supported applications. The artificial-intelligence security graph is deployed to support generation of security posture information of the computing environment. For example, a security administrator can request a security posture of the computing environment, and the security posture is provided based in part on the artificial-intelligence security graph.

[0004] Typically, security management systems are not configured with the comprehensive computing logic and infrastructure needed to effectively generate and filter AI security alerts within a computing environment. For example, they may lack the capability to run a security management system to identify malicious plugins that might be used on the interfaces of AI-powered applications, or to monitor malicious or anomalous attempts to access AI-powered applications. Such security management systems lack integration with AI security engine operations, which enhance the identification of high-fidelity AI security alerts for security posture management.

[0005] Technical solutions addressing the limitations of traditional security management systems may face the following challenges: generating and using AI security graphs to identify and filter AI security alerts; and providing security management operations and interfaces via an AI security engine within the security management system. This allows for improvements to the security management system based on AI security engine operations, which effectively determine and provide security posture information about the computing environment in a specific manner. The operation involves: accessing AI attack monitoring data; accessing AI security graphs associated with multiple AI-powered applications; accessing operational data of AI-powered applications based on AI attack monitoring data and AI security graphs; analyzing AI attack monitoring data and operational data to identify AI security alerts; and transmitting AI security alerts.

[0006] This summary is provided to present, in a simplified form, the selection of concepts further described below in the detailed embodiments. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to help determine the scope of the claimed subject matter. Attached Figure Description

[0007] The technology described herein is described in detail below with reference to the accompanying drawings, wherein: Figure 1A and Figure 1B This is a block diagram of an exemplary security management system, including an artificial intelligence security engine, based on various aspects of the technology described herein; Figure 1C This is a schematic diagram relating to an exemplary security management system, including an artificial intelligence security engine, based on various aspects of the technology described herein; Figure 2A This is a block diagram of an exemplary security management system, including an artificial intelligence security engine, based on various aspects of the technology described herein; Figure 2B This is a block diagram of an exemplary security management system, including an artificial intelligence security engine, based on various aspects of the technology described herein; Figure 3This paper provides a first exemplary method for providing security posture management using an artificial intelligence security engine based on various aspects of the techniques described herein. Figure 4 A second exemplary method for providing security posture management using an artificial intelligence security engine based on various aspects of the techniques described herein is provided. Figure 5 A third exemplary method for providing security posture management using an artificial intelligence security engine based on various aspects of the technology described herein is provided; Figure 6 Block diagrams are provided of exemplary distributed computing environments suitable for implementing various aspects of the techniques described herein; and Figure 7 This is a block diagram of an exemplary computing environment applicable to implementing various aspects of the techniques described herein. Detailed Implementation

[0008] SUMMARY Security management systems support the management of security aspects of data, resources, and workloads within computing environments. They help protect against threats, mitigate risks across different types of computing environments, and enhance the security posture of computing environments (i.e., the security status of computing resources, including networks and devices, and recommended remediation actions). For example, security management systems can provide real-time security alerts, centralized insights across different resources, and offer preventative protection, post-intrusion detection, and automated investigation and response. Furthermore, security management systems can support security posture management by leveraging security management operations that identify potential and actual threats (e.g., security investigation queries).

[0009] Traditionally, security management systems lack the comprehensive computing logic and infrastructure required to effectively generate and filter AI-driven security alert data within a computing environment. For example, they may be designed to identify malicious plugins that could be used on the interfaces of AI-powered applications, or to monitor malicious or anomalous attempts to access AI-powered applications. Such security management systems lack integration with AI security engine operations, which enhance the identification of high-fidelity AI-driven security alerts for security posture management.

[0010] Simply monitoring communications at interfaces associated with AI-powered applications—to identify attacks on AI applications—is insufficient. For example, if security systems only operate to identify classic traps—such as anomalous outbound network traffic, anomalies in privileged user account activity, or geographical irregularities—based on metadata, or listening to sessions at generative AI cues, applications powered by generative AI services may still be vulnerable. Furthermore, without adequate security solutions, resulting security alerts may consist of significant noise, and investigating security alerts in a computing environment can be lengthy and inefficient; and potential threats may become actual threats leading to unauthorized access to and malicious manipulation of data within the computing environment. Therefore, a more comprehensive security management system with an alternative foundation for performing security management operations can improve the computing operations and interfaces used for security management.

[0011] Embodiments of this technical solution relate to systems, methods, and computer storage media for providing security posture management, etc., using an AI security engine within a security management system. Security posture management supports the security management of a computing environment based on contextual information associated with AI applications. Specifically, the security management system provides an AI security graph that models AI-supported applications in the computing environment. The AI ​​security engine uses the AI ​​security graph to analyze AI attack monitoring data (e.g., anomalies or alerts) and correlate the AI ​​attack monitoring data (e.g., anomalies or alerts) with operational data (e.g., behavioral data and communication data) of AI-supported applications. The security management system can filter or classify AI security alerts into high-fidelity alerts using the correlations identified between AI attack monitoring data, AI security alerts, and operational data. Based on the AI ​​security graph and AI security alerts, security posture management can be provided to support the management of security aspects of data, resources, and workloads in the computing environment, including risk identification and remediation. Security posture management is provided using an AI security engine operatively integrated into the security management system. The security management system supports an AI security engine framework for computing components associated with the AI ​​security graph, which includes contextual information of AI-supported applications used to determine the security posture of the computing environment.

[0012] At a high level, the security management system is equipped with an AI security engine that implements an AI security graph. The security management system curates contextual information related to AI-powered applications and connects this contextual information to the AI ​​security graph (i.e., the contextual security graph). The AI ​​security graph can be used to provide a unified security posture and threat protection for the computing environment. For example, based on the AI ​​security graph and connections, the risk impact of AI-powered applications can be quantified, and mitigation actions can be prioritized. Furthermore, the contextual relevance of anomalies and AI security alerts can be determined to reveal high-fidelity AI security alerts. Additionally, risk assessment can include understanding relationships within the AI ​​security graph through contextual information and reducing the attack surface (i.e., potential points of attack such as network interfaces, web applications, APIs and integrations, and user accounts) that attackers can potentially target or compromise the computing environment through.

[0013] In this context, a computing environment can enable artificial intelligence (AI) systems for performing various types of computational tasks. AI systems can be used to generate new content, create models, or produce creative outputs. Specifically, AI systems can support generative AI technologies focused on generating data or content rather than analyzing existing data. Generative AI services can be associated with content creation, design and creativity, media production, simulation and virtual worlds, data augmentation, personalization, and scientific discovery. AI systems can implement AI models that are associated with AI applications that support other applications within the computing environment (i.e., AI-powered applications). AI applications can include interfaces (e.g., user interfaces or programming interfaces) that allow developers, users, or applications to interact with and utilize AI models (e.g., generative AI models) and capabilities. The interfaces of AI applications can be associated with input interaction, model interaction, output display, customization and parameters, integration, and feedback loops.

[0014] Compared to traditional computing systems, artificial intelligence (AI) systems and their interfaces can be vulnerable to various types of cyberattacks. Specifically, AI system interfaces can transcend traditional human-computer interaction, providing users and developers with AI-generated outputs, responses, and experiences. These interfaces can be dynamic, creative, and support personalized interactions; however, this can further expose AI systems and their corresponding computing environments (i.e., AI-powered applications) to cyberattacks. These attacks can specifically exploit the capabilities of generative AI models to cause harm and deception. In this way, while generative AI can be a powerful tool for creating content and enhancing user experiences, it also introduces new attack vectors and security challenges, such as deepfake attacks, AI-enhanced phishing, malicious content generation, security circumvention, AI-driven social engineering, AI-supported identity theft, and AI-driven DDoS attacks.

[0015] The AI ​​Security Engine supports the analysis and modeling of connections between AI-powered applications within a computing environment, as shown in the AI ​​Security Graph. The AI ​​Security Engine can collect application data (e.g., identity data, configuration data, code data) from AI-powered applications to generate the AI ​​Security Graph. The AI ​​Security Graph is a model of AI-powered applications, corresponding to computing components within the computing environment. Application data associated with applications and computing components in the computing environment can be used to generate the AI ​​Security Graph. The AI ​​Security Graph can be generated using an AI Security Graph Generation Model, which includes programmable instructions on how to generate the AI ​​Security Graph. The AI ​​Security Graph Generation Model can identify combinations of specified inputs and operations used to generate the AI ​​Security Graph.

[0016] AI-powered security graphs can be generated as multi-layered security graphs. The layers of a multi-layered security graph can be associated with different levels of automation and have varying levels of engineering and algorithmic complexity. For example, the first layer can be associated with graph edges added automatically (e.g., controls, identities, and labels), thus exhibiting low friction and low complexity; the second layer can be associated with manually added edges that are linked to AI-powered applications, thus exhibiting high friction but low complexity; and the third layer can be associated with code and behavioral analysis of AI-powered applications, which can be used to enhance connectivity, resulting in low friction and high complexity.

[0017] As an example, an AI security graph may include: users / identities with access to AI-powered applications or users / identities accessing AI-powered applications; users / identities whose work is emulated or represented by the AI ​​application; the processes of the AI-powered application; and the data storage of the AI-powered application, including its access, read, and write permissions. Furthermore, additional connections may be made based on analysis of the code of the AI-powered application and its code repository to identify connections associated with the AI-powered application.

[0018] AI security graphs are generated based on application data to include multiple connections between AI-powered applications. Based on these modeled connections, contextual information associated with AI-powered applications can be used to provide improved security posture management. AI security graphs can support understanding the impact of compromises on AI-powered applications—including what data a specific compromised AI-powered application has access to, the users exposed by the compromised application, and what security measures need to be taken to secure the application. Furthermore, by associating anomalies and suspicious behavior detected in applications using AI-powered applications with related applications, data storage, identity impersonation, and other indications, AI security graphs can support the creation of high-fidelity AI security alerts and incidents.

[0019] In this way, the AI ​​security engine operates using a contextual security framework that includes environmental awareness of the target computing environment. Traditional solutions result in noisy AI security alerts, which can be addressed by implementing a contextual security framework that supports improved security decisions and high-fidelity identification of AI security alerts. The contextual security framework facilitates answering questions such as: what applications need to be secured; how to reduce the attack surface of these applications; and how to detect and respond to attacks on these applications. It facilitates understanding application exposure; the potential impact of breaches; and provides indicators of compromised applications to aid in the detection of attacks against them.

[0020] The AI ​​security engine analyzes and correlates AI attack monitoring data, AI security alerts, and operational data to provide security posture management. AI attack monitoring data can refer to data monitored to identify cyberattacks associated with AI-powered applications. For example, AI attack monitoring data can be correlated with cyberattack constructs that include anomalous outbound network traffic, anomalies in privileged user account activity, or geographic irregularities. Specifically, AI attack monitoring data can include tracked inputs and outputs to AI models (e.g., generative AI models) to identify potential attacks, detect anomalies, and ensure the security and integrity of AI-generated content. AI attack monitoring data can be correlated with interfaces that connect AI models to applications in a computing environment, where the interface between the AI ​​model (e.g., a large language model) and the application supports the application's AI assistant features (e.g., Microsoft Co-PILOT). AI attack monitoring data can be based on model inputs, model outputs, model behavior, model training and updates, user behavior, contextual validation, and anomaly detection.

[0021] The AI ​​security engine can also generate preliminary AI security alerts, which can be further analyzed, filtered, or categorized using AI security graphs. For example, based on AI attack monitoring data, AI security alerts can be generated, and then analyzed using features and functionalities associated with the AI ​​security graph. AI security alerts can indicate potential security incidents or activities requiring attention, including the source and destination of the incident, the timestamp of the incident, the severity level, the alert type, the description, the reference identifier, the affected system or source, the user or identity account, recommendations, and additional data. AI security graphs and operational data can be used to analyze the security posture information from these AI alerts.

[0022] Operational data can refer to data collected for use in AI-powered applications and computing components to support correlations with AI attack monitoring data or initial AI security alerts. Operational data is associated with monitoring AI-powered applications to detect problems, anomalies, troubleshoot issues, and ensure security. Operational data can include server logs and performance metrics, network traffic and bandwidth usage, security logs and access control data, database usage and performance statistics, application uptime and response times, and backup and recovery status. Operational data can be stored as nodes or edges associated with AI-powered applications in the AI ​​security graph. Operational data can also include security posture information associated with AI-powered applications, at least partially stored in the AI ​​security graph. Specifically, operational data can include security log data, which includes recorded information capturing activities, events, and incidents related to the security of AI-powered applications.

[0023] Analyzing AI attack monitoring data, AI security alerts, and operational data is based on AI security operations that support operational data that correlates two or more of the following: patterns that change together among AI attack monitoring data, AI security alerts, and indication data. For example, an AI security engine can implement machine learning techniques and statistical methods for analyzing the correlations between variables or features of AI attack monitoring data, AI security alerts, and operational data. Machine learning techniques and statistical methods can include clustering algorithms, time series analysis, principal component analysis, and correlation matrices. Based on this analysis, inferences about AI security alerts can be made. For example, a high correlation score between features of AI attack monitoring data and operational data can indicate a high-fidelity signal for an AI security alert, and a low correlation score between features of AI attack monitoring data and operational data can indicate a low-fidelity signal for an AI security alert. High correlations can be detected when anomaly alerts at generative AI application prompts trigger communication from databases that should not be communicating with generative AI prompts; this type of correlation is facilitated by AI security graphs.

[0024] Advantageously, embodiments of this technical solution include several inventive features (e.g., operations, systems, engines, and components) associated with a security management system having an AI security engine. The AI ​​security engine supports AI security engine operations for generating AI security graphs and using these graphs to identify AI security alerts, and provides security management operations and interfaces via the AI ​​security engine within the security management system. The AI ​​security engine operations are a solution to specific problems in security management (e.g., limitations in the effective identification of AI security alerts). The AI ​​security engine provides an ordered combination of operations for generating and deploying AI security graphs, and uses these graphs in a manner that improves computational operations within the security management system. Furthermore, a large number of AI security alerts can be processed and filtered to provide security posture information to applications in a way that improves the user interface of the security management system.

[0025] Example systems and operations Examples and references are available. Figures 1A-1B To describe various aspects of the technical solution. Figure 1A A cloud computing system (environment) 100 is shown, which includes a security management system 100A; a network 100B; application data 100C; an artificial intelligence security engine 110, having an artificial intelligence security engine operation 112, an artificial intelligence security generation model 114, and an artificial intelligence security graph 116; a security posture management engine 120, having a security graph API 122 and a risk assessment operation 124; a security management client 130, having a security posture management engine client 132 and a security posture interface data 134; and an application client 140 supported by artificial intelligence.

[0026] Cloud computing environment 100 provides computing system resources for different types of managed computing environments. For example, cloud computing environment 100 supports the delivery of computing services, including servers, storage devices, databases, networking, and security intelligence. Multiple security management clients (e.g., security management client 130) include hardware or software for accessing resources in cloud computing environment 100.

[0027] Security management client 130 may include applications or services that support client-side functionality associated with cloud computing environment 100. Multiple security management clients may access computing components of cloud computing environment 100 via a network (e.g., network 100B) to perform computing operations. Artificial intelligence-enabled application client 140 may include applications or services that support client-side functionality associated with the cloud computing environment. Artificial intelligence-enabled application client 140 may provide an interface to an artificial intelligence application that operates in conjunction with other artificial intelligence-enabled applications in the cloud computing environment. Operations originating from the artificial intelligence-enabled application client may include cyberattack operations that can be identified in artificial intelligence security alerts.

[0028] Security Management System 100A is designed to provide security management using an Artificial Intelligence Security Engine 110. Security Management System 100A uses the Artificial Intelligence Security Engine 110, an Artificial Intelligence Security Graph generation model, and application data 100C to provide an integrated operating environment based on a security management framework associated with computing components that provide the Artificial Intelligence Security Graph 116. Security Management System 100A integrates the Artificial Intelligence Security Engine operation—which supports the generation of the Artificial Intelligence Security Graph and uses the Artificial Intelligence Security Graph 116 to identify Artificial Intelligence Security Alerts—into security management operations and interfaces to effectively provide the computing environment with security posture survey information, security posture information, and remediation information. For example, a security administrator can request security posture information for the computing environment, and this security posture information is provided in part based on the Artificial Intelligence Security Graph 116.

[0029] The AI ​​security engine 110 is responsible for generating an AI security graph 116 based on application data 100C, AI security engine operations 112, and an AI security graph generation model 114. The AI ​​security graph generation model 114 is a computational model that supports the generation of the AI ​​security graph 116. The computational model includes instructions for different data types and rules for integrating data types to generate the AI ​​security graph 116. The AI ​​security graph generation model 114 supports accessing application data 110C to generate the AI ​​security graph as a model of AI-supported applications and its connections within the computational environment. The computational model supports programmatically constructing and deriving connections based on application data from one or more layers of the AI ​​security graph.

[0030] The AI ​​security graph generation model 114 can specifically support the generation of an AI security graph 116 as a multi-layered security graph. The AI ​​security graph generation model 114 can include different layers associated with different levels of automation and different levels of engineering and algorithmic complexity. Therefore, each layer can be associated with friction identifiers and complexity identifiers (e.g., low, medium, and high), which are factors related to the efficiency, effectiveness, and user experience of supporting the generation of the AI ​​security graph 116. In this way, the AI ​​security graph generation model 114 can include instructions regarding: automatically added graph edges of the AI ​​security graph 116 (e.g., controls, identities, labels, etc.), manually added graph edges of the AI ​​security graph (e.g., the scope of the AI ​​application), and how to use code and code repositories to enhance the connections between the AI ​​application and other nodes in the computing environment (e.g., identities, data storage, and AI-supported applications).

[0031] The AI ​​security engine 110 accesses application data 100C from multiple data sources. Data sources may include cloud storage devices, databases, cloud applications, streaming data, service applications, and external data sources associated with security posture management. Application data 100C may specifically include AI models, AI-powered applications, identity data, configuration data, and code data. Application data 100C can be graphically represented in the AI ​​security graph 116. Application data 100C may be security log data that includes recorded information capturing security-related activities, events, and incidents in the computing environment. Security log data may also include data retrieved via the security graph API 122. Security log data can support providing detailed audit trails and evidence of security-related events for monitoring, analysis, and investigation purposes. Security log data can be associated with authentication events, authorization events, system events, intrusion detection / prevention systems (IDS / IPS), firewall logs, antivirus / anti-malware logs; SIEM logs, audit logs, and security event logs. Data sources support retrieving application data 100C associated with different data types defined in the AI ​​security graph 116. The data source is associated with multiple computing resources, such as virtual machines, storage devices, databases, tenants, content delivery networks, containers, monitoring and analytics, and development. The AI ​​security engine 110 may also include an application data 100C API (not shown) that supports retrieving different types of application data 100C to generate an AI security graph 116. The AI ​​security engine 110 deploys the AI ​​security graph 116 to support the generation of security posture information for the computing environment.

[0032] The security posture management engine 120 is responsible for communicating with the security management client 130, which has a security posture management engine client 132 and security event interface data 134. The security posture management engine client 132 supports client-side security management operations for providing security management within the security management system 100. The security posture management engine client 132 supports presenting security posture visualizations—including AI security alerts—associated with the AI ​​security graph 116, and transmitting instructions to perform remedial actions associated with the AI ​​security alerts. Therefore, the security event interface data 134 may include data associated with the AI ​​security engine 110 and data associated with the security posture management engine 120, which can be transmitted between the AI ​​security engine 110, the security posture management engine 120, and the security management client 130.

[0033] The security posture management engine 120 operates to provide visibility into the security status of resources in the computing environment. Security posture information can be associated with AI security graph 116, network, data, and identity resources of the computing environment. Security posture information may include AI security alerts and AI security alerts with updated priority identifiers, as described herein.

[0034] The security posture management engine 120 includes a security graph API 122, which provides access to a security graph (not shown) and security graph data. The security graph provides telemetry data associated with multiple resources in the computing environment. Specifically, the telemetry data may be security data associated with a security provider in the computing environment. The security graph and security graph API 122 can support the integration of security alerts from different security providers via an API connector that streams alerts to the security posture management engine 120. For example, the artificial intelligence security engine 110 can operate as a security provider for the security posture management engine 120.

[0035] The security posture management engine 120 can assess threats and generate risk scores—using a risk assessment operation 124 that includes attack path analysis—associated with threats and attack paths. Attack path analysis can refer to a graph-based algorithm that scans the cloud security graph to identify exploitable paths, including the attack surface an attacker might use to compromise the computing environment. Attack path analysis displays attack paths and suggests remedial actions to disrupt these paths and prevent successful compromise. In this way, attack path analysis helps address the security problem of exploiting immediate threats with the highest probability of exploitation in the computing environment. Embodiments of this disclosure envision other variations and combinations of risk assessment operations.

[0036] The risks associated with query results (e.g., AI-powered security alerts) can be used to generate security posture information. Specifically, a risk score can be a numerical value representing the level of risk associated with a specific security incident linked to an AI-powered security alert. It takes into account various factors, such as the likelihood of the incident occurring and its potential impact. Risk scores are used to prioritize actions and allocate resources accordingly. Furthermore, the likelihood or impact of a security threat quantified in the risk score can be based on multiple potential attack surfaces associated with that security threat.

[0037] The security posture management engine 120 can also support the generation of security posture visualizations based on security posture information, including AI security alerts and AI security alerts with updated priority identifiers associated with AI security graph 116. The security posture information may include query results, which can be provided in conjunction with attack path analysis, alerts, and other security management information. For example, the security posture visualization may include query results associated with AI security alerts and AI security graph 116. Security posture information can be generated based on AI security alerts, allowing the information to be prioritized and filtered. Priority identifiers (e.g., high, medium, low) can be provided for AI security alerts in the security posture visualization. Specifically, priority identifiers may include priority identifiers provided or updated using AI attack monitoring data and AI security graphs based on the analysis of AI security alerts. Alternatively, notifications associated with security management information, security priority information, or alerts can be delivered. The embodiments described herein envision other variations and combinations of communications associated with insecure credentials.

[0038] The security management client 130 can support accessing and displaying security posture visualization. The security management client 130 may include a security posture management engine client 132, which supports receiving security posture interface data 134 from the security management system 110A and displaying the security posture interface data 134. The security posture interface data 134 may specifically include security posture visualizations associated with AI security alerts. The security posture visualizations may also include remedial actions associated with different AI security alerts—including AI security alerts associated with query results.

[0039] The security management client 130 can also support the execution of remedial actions. Specifically, security posture visualization may include remedial actions for AI security alerts or AI security alerts with updated priority identifiers. The security management client 130 can receive instructions to execute remedial actions associated with query results. Based on receiving instructions to execute remedial actions, the security management client 130 can transmit instructions to execute remedial actions to induce their execution.

[0040] Therefore, AI security alerts and related security posture information are generated based on the AI ​​security engine 110 and are provided with remedial actions that can be selected and transmitted to enable remedial actions to be performed. Remedial actions can address actual or potential threats associated with the AI ​​security alert. For example, remedial actions may include logging onto a computing device, disabling a user, isolating files, closing external emails, or running an antivirus scan. Other variations and combinations of security posture visualization and AI security graph 114 are envisioned using the embodiments described herein.

[0041] refer to Figure 1B , Figure 1B The diagram shows: an artificial intelligence security engine 110, which includes an artificial intelligence security engine operation 112, an artificial intelligence security graph generation model 114, and an artificial intelligence security graph 116; and application data 110C, including an artificial intelligence model 150, an artificial intelligence-supported application 152, account data 154, configuration data 156, and code data 158.

[0042] The AI ​​security engine 110 provides an AI graph generation model 114 as a computational model to support the generation of an AI security graph 116. The AI ​​security graph generation model 114 can be associated with operations executed to generate the AI ​​security graph 116. The computational model is configured to provide instructions regarding application data 100C, which is processed to generate the AI ​​security graph 116 as a model of an AI-supported application for generating and filtering AI security alerts. The computational model supports programmatic access to and processing of the application data 100C. The computational model can also support different AI graph entity types and layers for representing AI-supported applications in a computing environment.

[0043] The AI ​​security engine 110 generates an AI security graph 116 based on an AI security graph generation model 114 and application data 100C. The AI ​​model 150 can refer to a machine learning model associated with an AI-powered application 152, where the AI ​​model 150 provides assistive functions (e.g., via AI applications and interfaces). Account data 154 can refer to a user or identity having access to or accessing an AI application associated with the AI ​​model 150. Application configuration data can include parameters, settings, and options that determine how the application behaves and interacts with the computing environment. Configuration data can be external to the application's code and can be used to customize the application's behavior to suit different needs, environments, and user preferences without requiring code changes. Configuration data can also allow the application to be flexible and adaptable without requiring recompilation or code modification. Code data can refer to source code or programming code, including human-readable instructions written by programmers to create the application. Code data can specifically identify data structures, control structures, functions, and methods with security implications, which can be used to generate the AI ​​security graph and to make relevance for generating and filtering AI security alerts.

[0044] The AI ​​security graph generation model specifies the inputs used to generate the AI ​​security graph 116. The AI ​​security graph can be generated as a multi-layered security graph. The layers of the multi-layered security graph can be associated with different levels of automation and have different levels of engineering and algorithmic complexity. For example, the first layer can be associated with graph edges added automatically (e.g., controls, identities, and labels), thus exhibiting low friction and low complexity; the second layer can be associated with manually added edges that are linked to AI-enabled applications, thus exhibiting high friction but low complexity; the third layer can be associated with code and behavioral analysis of AI-enabled applications, which can be used to enhance connections, resulting in low friction and high complexity.

[0045] refer to Figure 1C , Figure 1C A schematic diagram is shown that is associated with the artificial intelligence security engine 110 in the security management system 100A. Figure 1C It is a schematic representation of an AI security graph that models the connectivity of AI applications in a computing environment 102_C. Figure 1CThis includes AI application 110_C, user / identity 112_C, user / identity 114_C, data storage 116_C, and application / computing 118_C. AI application 110_C can be a generative AI application (e.g., MICROSOFT CO-PILOT) with interfaces supporting different types of functions and applications (e.g., AI-powered applications). AI application 110_C can mimic user / identity 112_C. User / identity 114_C can access AI application 110_C or may have access to user / identity 114_C. AI application 110_C may have permissions to data storage 116_C. AI application 110_C can be an AI assistant to application / computing 118_C. In this way, application data can be collected, and based on an AI security graph generation model, an AI security graph can be generated to support the provision of security posture management.

[0046] As an illustration, generative AI applications (e.g., AI-assisted applications or AI models) mimic and identify, assist processes and applications, have access to data, and have users who can access the generative AI application. The risk of an attack on a generative AI application may be the cumulative risk to all relevant entities and workloads. The risk is high if the data is important; the risk is also high if the user has privileges. An attack on a generative AI application is an attack on the user; therefore, an AI security graph can be used to conduct risk assessments and prioritize information based on AI security alerts—including connections between computational components and constructs identified in the AI ​​security graph. Furthermore, generative AI applications mimic users, may have access to data storage, or applications may be assisted by generative AI applications. Therefore, suspicious activity can be expected to manifest suspicious behavior on one or more relevant entities or workloads. Various indicators related to the attack increase the fidelity of suspicion (e.g., unusual dialogue and unusual behavior in access logs).

[0047] Examples and references are available. Figure 2A and Figure 2B To describe various aspects of the technical solution. Figure 2A Based on reference Figure 6 and Figure 7 A block diagram of an exemplary technical solution environment described for implementing embodiments of the illustrated technical solutions. Generally, the technical solution environment includes a technical solution system suitable for providing an example security management system 100 in which the methods of this disclosure can be employed. Specifically, Figure 2A A high-level architecture of a security management system 100A according to an embodiment of this disclosure is shown. Among other engines, managers, generators, selectors, or components (collectively referred to herein as "components") not shown, the technical solution environment of the security management system 100 corresponds to...Figure 1A and Figure 1B .

[0048] refer to Figure 2A , Figure 2A The diagram illustrates a security management system 100A, a security posture management engine 120, a security management client 130, and an application client 140 supported by artificial intelligence. The security management system 100A includes: a security management system 100A, an artificial intelligence security engine 110 including an artificial intelligence security engine operation 112, an artificial intelligence security graph generation model 114, an artificial intelligence security graph 116, and application data 100C.

[0049] The AI ​​security engine 110 is responsible for deploying the AI ​​graph 116 to support the generation and analysis of AI security alerts. The AI ​​security engine 110 accesses the AI ​​generation model 114, which provides instructions on how to generate the AI ​​security graph. The AI ​​security graph generation model 114 is a model of multiple AI-powered applications in the computing environment. The AI ​​security engine 110 accesses data associated with the multiple AI-powered applications (e.g., application data 100C). The AI ​​security engine 110 uses the application data 100C and the AI ​​security graph generation model 114 to generate the AI ​​security graph 116.

[0050] Generating an AI security graph can be based on instructions associated with an AI generation model 114. The AI ​​generation model 114 can specifically support the generation of multi-layered security graphs. For example, generating an AI security graph can also include one or more layers of the AI ​​security graph, including: generating a first layer of the AI ​​security graph based on a first set of application data from application data, wherein the first set of application data includes account-based connections between AI-enabled applications and AI applications; generating a second layer of the AI ​​security graph based on a second set of application data from application data, wherein the second set of application data includes configuration-based connections between AI-enabled applications and AI applications; and generating a third layer of the AI ​​security graph based on a third set of application data from application data, wherein the third set of application data includes code-based connections between AI-enabled applications and AI applications.

[0051] The AI ​​security engine 110 is responsible for transmitting AI security alerts. The AI ​​security engine 110 accesses AI attack monitoring data. AI attack monitoring data may include anomalous model input and output data from interfaces of AI applications. AI attack monitoring data can be specifically associated with cyberattacks that exploit AI applications and interfaces, such as adversarial attacks, data poisoning, evasion attacks, model inversion attacks, privacy violations, denial-of-service attacks, impersonation attacks, semantic attacks, and model extraction attacks. AI attack monitoring data can be continuously monitored for anomalies or alerts that trigger further investigation to identify actual or potential attacks associated with AI-powered applications.

[0052] Artificial intelligence (AI) attack monitoring data can be accessed from application data 100C from multiple sources supporting security posture management. AI attack monitoring data can be associated with AI-powered application clients 130, which access AI-powered applications. AI-powered application clients 130 can be associated with network attacks, causing AI attack monitoring data to be associated with anomalies or alerts, and application data associated with AI-powered applications (e.g., application data 110C) is also associated with anomalies or alerts.

[0053] The AI ​​security engine 100 accesses the AI ​​security graph 116. Based on AI attack monitoring data and the AI ​​security graph, the AI ​​security engine 110 accesses operational data from AI-powered applications. AI attack monitoring data can be correlated with anomalies or alerts, allowing the AI ​​security graph 116 to be accessed to identify additional information associated with the anomalies or alerts.

[0054] The AI ​​Security Engine 110 analyzes AI attack monitoring and operational data. It determines the correlation between these data to infer whether an AI security alert should be generated. For example, a correlation score can be calculated to quantify the likelihood of a set of data indicating an AI security alert, or to quantify the priority of such alerts. As an example, historical AI security alerts and their corresponding data can be analyzed. Based on this analysis, new data sets can be evaluated, and correlation scores associated with their potential security risks can be assigned to the computing environment.

[0055] Furthermore, risk scores can be calculated based on the probability or impact of security threats (e.g., actual or potential threats) associated with AI security alerts and corresponding additional factors associated with AI security graphs. In this way, a risk score is a calculated number (score) reflecting the severity of a risk due to a number of factors. Risk scores are calculated by multiplying probabilities (e.g., probability scores) and impacts (e.g., impact scores)—although other factors (such as weighting) can also be part of the calculation. For qualitative risk assessments, risk scores can be calculated using factors based on the range of probabilities and impacts. In quantitative risk assessments, risk probability and impact inputs can be discrete values ​​or statistical distributions. For example, if an AI-powered application provides access to a database without highly sensitive data, the risk score may be low; however, if an AI-powered application provides access to several databases with highly sensitive data, the risk score may be high. Other variations and combinations of relevance scoring systems and risk scoring systems are envisioned for the embodiments described herein.

[0056] The security posture management engine 120 is responsible for executing security queries and generating security posture visualizations. The security posture management engine 120 accesses security queries associated with the AI ​​security graph 116. The security posture management engine 120 uses the AI ​​security graph 116 to execute security queries and generates a first query result for the security queries. The first query result includes AI security alerts. Using the first query result, the security posture management engine 120 generates a security posture visualization. The security posture visualization also includes AI security alerts associated with updated priority identifiers and remediation actions. Updated priority identifiers can be generated using the AI ​​security graph, and remediation actions can be executed to address the security threats associated with the AI ​​security alerts.

[0057] The security management client 130 can transmit a request for a security posture assessment of the computing environment. Based on this request, the security management client 130 receives a security posture visualization associated with the computing environment, wherein the security posture visualization includes AI security alerts associated with AI security graph 116. The security management client 130 enables the display of the security posture visualization including the AI ​​security alerts. refer to Figure 2B , Figure 2BA security management system 100A is illustrated, comprising an AI security engine 110, a security management client 130, and a security posture management engine 120. At box 10, the AI ​​security engine 110 accesses an AI security graph generation model; at box 12, it accesses application data associated with multiple AI-enabled applications; at box 14, it generates an AI security graph using the application data and the AI ​​security graph generation model; and at box 16, it deploys and analyzes the AI ​​security graph associated with AI security alerts.

[0058] At box 18, the security management client 130 transmits a request for the security posture of the computing environment. At box 20, the security posture management engine accesses the request for the security posture of the computing environment; at box 22, it accesses AI attack monitoring data associated with AI security alerts for AI-enabled applications; at box 24, it accesses operational data of AI-enabled applications based on AI attack monitoring data, AI security alerts, and AI security graphs; at box 26, it analyzes the AI ​​attack monitoring data and operational data; at box 28, it updates the priority identifier associated with the AI ​​security alerts; and at box 30, it transmits a security posture visualization including the AI ​​security alerts and the updated priority identifiers. At box 32, the security management client 130 receives the security posture visualization associated with the computing environment based on the request; and at box 28, it causes the display of the security posture visualization including the AI ​​security alerts associated with the updated priority identifiers.

[0059] Example Method refer to Figure 3 , Figure 4 and Figure 5 A flowchart illustrating a method for providing security posture management using an artificial intelligence security engine in a security management system is provided. This method can be performed using the security management system described herein. In embodiments, one or more computer storage media having computer-executable or computer-usable instructions embodied thereon can, when executed by one or more processors, cause one or more processors to perform a method (e.g., a computer-implemented method) in the security management system (e.g., a computerized system or computing system).

[0060] Turn Figure 3A flowchart illustrating method 300 for providing security posture management using an AI security engine in a security management system is provided. In box 302, AI attack monitoring data is accessed. In box 304, an AI security graph associated with multiple AI-powered applications is accessed. In box 306, operational data of the AI-powered applications is accessed based on the AI ​​attack monitoring data and the AI ​​security graph. In box 308, the AI ​​attack monitoring data and operational data are analyzed. In box 310, AI security alerts are identified. In box 312, AI security alerts are delivered.

[0061] Go to Figure 4 A flowchart illustrating a method 400 for providing security posture management using an AI security engine in a security management system is provided. At box 402, AI attack monitoring data associated with AI security alerts for AI-powered applications is accessed. At box 404, AI security graphs associated with multiple AI-powered applications are accessed. At box 406, operational data of the AI-powered applications is accessed based on the AI ​​attack monitoring data, AI security alerts, and AI security graphs. At box 408, the AI ​​attack monitoring data, AI security alerts, and operational data are analyzed. At box 408, the priority identifier associated with the AI ​​security alerts is updated based on the analysis of the AI ​​attack monitoring data, AI security alerts, and operational data.

[0062] Turn Figure 5 The document provides a flowchart illustrating a method 500 for providing security posture management using an AI security engine within a security management system. In box 502, the AI ​​security graph generation model is accessed. Also in box 502, application data associated with multiple AI-powered applications is accessed. In box 506, an AI security graph is generated using the application data and the AI ​​security graph generation model. In box 508, the AI ​​security graph associated with the analysis of AI security alerts is deployed.

[0063] TECHNICAL IMPROVEMENT Embodiments of this technical solution have been described with reference to several inventive features (e.g., operations, systems, engines, and components) associated with security management systems. The described inventive features include: the arrangement of operations, interfaces, data structures, and computing resources associated with providing the functionality described herein with respect to an AI security engine. The functionality of embodiments of this technical solution has been further described through implementation methods and case examples to illustrate operations for providing an AI security engine (e.g., generating an AI security graph and using the AI ​​security graph to identify AI security alerts based on AI security engine operations). The AI ​​security engine serves as a solution to specific problems in security management technology (e.g., limitations in the effective identification of AI security alerts). The AI ​​security engine improves computational operations associated with security investigations and provides security posture information within the security management system. In general, these improvements result in less CPU computation, smaller memory requirements, and increased flexibility within the security management system compared to previous conventional security management system operations performed for similar functionality.

[0064] Additional support for specific implementation methods Example distributed computing system environment Now for reference Figure 6 , Figure 6 An example distributed computing environment 600 in which embodiments of the present disclosure may be employed is shown. In particular, Figure 6 A high-level architecture of an example cloud computing platform 610 that can host a technology solution environment or a portion thereof (e.g., a data trustee environment) is shown. It should be understood that this and other arrangements described herein are illustrative only. For example, as mentioned above, many of the elements described herein can be implemented as discrete or distributed components or combined with other components, and implemented in any suitable combination and location. Other arrangements and elements (e.g., machines, interfaces, functions, sequences, and functional groupings) may be used in addition to or instead of those shown.

[0065] The data center can support a distributed computing environment 600, which includes a cloud computing platform 610, racks 620, and nodes 630 (e.g., computing devices, processing units, or blades) within the racks 620. A technology solution environment can be implemented using the cloud computing platform 610, which runs cloud services across different data centers and geographic regions. The cloud computing platform 610 can implement a fabric controller 640 component for provisioning and managing the allocation, deployment, upgrades, and management of cloud services. Typically, the cloud computing platform 610 is used to store data or run service applications in a distributed manner. The cloud computing infrastructure 610 in the data center can be configured to host and support the operation of endpoints for specific service applications. The cloud computing infrastructure 610 can be a public cloud, a private cloud, or a dedicated cloud.

[0066] Node 630 may be supplied with a host 650 (e.g., an operating system or runtime environment) on which a defined software stack runs. Node 630 may also be configured to perform specialized functions (e.g., compute nodes or storage nodes) within the cloud computing platform 610. Node 630 is allocated to run one or more portions of a tenant's service application. A tenant may refer to a customer utilizing the resources of the cloud computing platform 610. The service application components of the cloud computing platform 610 supporting a particular tenant may be referred to as multi-tenant infrastructure or leases. The terms service application, application, or service are used interchangeably herein and broadly refer to any software or portion of software that runs on or accesses storage and computing devices within a data center.

[0067] When node 630 supports more than one individual service application, node 630 can be partitioned into virtual machines (e.g., virtual machine 652 and virtual machine 654). Physical machines can also run individual service applications simultaneously. Virtual machines or physical machines can be configured as personalized computing environments supported by resources 660 (e.g., hardware and software resources) in the cloud computing platform 610. It is conceivable that resources can be configured for specific service applications. Furthermore, each service application can be partitioned into functional parts, allowing each functional part to run on a separate virtual machine. In the cloud computing platform 610, multiple servers can be used to run service applications and perform data storage operations in a cluster. In particular, servers can perform data operations independently, but are exposed as a single device referred to as a cluster. Each server in the cluster can be implemented as a node.

[0068] Client device 680 can connect to service applications in cloud computing platform 610. Client device 680 can be any type of computing device, which can correspond to the reference... Figure 6The described computing device 600, for example, client device 680, can be configured to issue commands to cloud computing platform 610. In embodiments, client device 680 can communicate with service applications via Virtual Internet Protocol (IP) and load balancers or other components that route communication requests to designated endpoints within cloud computing platform 610. Components of cloud computing platform 610 can communicate with each other via a network (not shown), which may include, but is not limited to, one or more local area networks (LANs) and / or wide area networks (WANs).

[0069] Example computing environment Having briefly described an overview of embodiments of this technical solution, the following describes an example operating environment in which embodiments of this technical solution may be implemented, in order to provide a general context for various aspects of this technical solution. First, refer to... Figure 6 The illustration shows an example operating environment for implementing an embodiment of the present technical solution, and is generally designated as computing device 600. Computing device 600 is merely an example of a suitable computing environment and is not intended to impose any limitation on the scope or functionality of the technical solution. Computing device 600 should also not be construed as having any dependency or requirement in relation to any one or combination of the illustrated components.

[0070] Technical solutions can be described in the general context of computer code or machine-usable instructions, including computer-executable instructions such as program modules that are executed by a computer or other machine (such as a personal data assistant or other handheld device). Typically, program modules, which include routines, programs, objects, components, data structures, etc., refer to code that performs a specific task or implements a specific abstract data type. Technical solutions can be implemented in a variety of system configurations, including handheld devices, consumer electronics, general-purpose computers, and more specialized computing devices. Technical solutions can also be implemented in distributed computing environments, where tasks are performed by remote processing devices linked through a communication network.

[0071] refer to Figure 7 The computing device 700 includes a bus 710 that directly or indirectly couples to the following devices: a memory 712, one or more processors 714, one or more presentation components 716, an input / output port 718, an input / output component 720, and an illustrative power supply 722. The bus 710 can represent one or more buses (such as an address bus, a data bus, or a combination thereof). For clarity of concept, Figure 7 The various boxes are shown with lines, and other arrangements of the described components and / or component functions are also envisioned. For example, a presentation component such as a display device can be considered an I / O component. Furthermore, the processor has memory. We recognize this as essential to the art and reiterate... Figure 7The figures are merely illustrations of example computing devices that can be used in conjunction with one or more embodiments of this technical solution. No distinction is made between categories such as "workstation," "server," "laptop," and "handheld device," as all of these are envisioned in... Figure 7 Within the scope and refer to "Computing Devices".

[0072] Computing device 700 typically includes a variety of computer-readable media. Computer-readable media can be any available media that can be accessed by computing device 700, and includes volatile and non-volatile media, removable and non-removable media. By way of example and not limitation, computer-readable media can include computer storage media and communication media.

[0073] Computer storage media includes volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage devices, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other media that can be used to store desired information and is accessible by the computing device 700. Computer storage media does not include the signal itself.

[0074] Communication media typically embody computer-readable instructions, data structures, program modules, or other data in the form of modulated data signals, such as carrier waves or other transmission mechanisms, and include any information transmission medium. The term "modulated data signal" refers to a signal whose one or more characteristics are set or altered in a manner that encodes information in the signal. By way of example and not limitation, communication media include wired media such as wired networks or direct wired connections, and wireless media such as acoustic, RF, infrared, and other wireless media. Any combination of the foregoing should also be included within the scope of computer-readable media.

[0075] Memory 712 includes computer storage media in the form of volatile and / or non-volatile memory. Memory can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, etc. Computing device 700 includes one or more processors that read data from various entities such as memory 712 or I / O components 720. Presentation component 716 presents data indications to a user or other device. Exemplary presentation components include display devices, speakers, printing components, vibration components, etc.

[0076] I / O port 718 allows computing device 700 to be logically coupled to other devices including I / O components 720, some of which may be built-in. Illustrative components include microphones, joysticks, game controllers, satellite antennas, scanners, printers, wireless devices, etc.

[0077] Additional structural and functional features of embodiments of the technical solution Various components used herein have been identified, and it should be understood that any number of components and arrangements can be employed to achieve the desired functionality within the scope of this disclosure. For example, components in the embodiments depicted in the figures are shown with lines for clarity of concept. Other arrangements of these and other components can also be implemented. For example, although some components are depicted as single components, many elements described herein can be implemented as discrete or distributed components or in combination with other components, and in any suitable combination and location. Some elements may be omitted entirely. Furthermore, the various functions described herein as being performed by one or more entities can be performed by hardware, firmware, and / or software, as described below. For example, various functions can be performed by a processor executing instructions stored in memory. Therefore, other arrangements and elements (e.g., machines, interfaces, functions, sequences, and functional groups) may be used in addition to or in lieu of those shown.

[0078] The embodiments described in the following paragraphs may be combined with one or more of the specifically described alternatives. In particular, the claimed embodiments may include references to more than one other embodiment in the alternatives. The claimed embodiments may specify further limitations on the claimed subject matter.

[0079] This document specifically describes embodiments of technical solutions to meet legal requirements. However, the description itself is not intended to limit the scope of this patent. Rather, the inventors have envisioned that the claimed subject matter may also be embodied in other ways in combination with other current or future technologies to include different steps or combinations of steps similar to those described in this document. Furthermore, although the terms “step” and / or “box” may be used herein to refer to different elements of the method employed, these terms should not be construed as implying any particular order among or between the various steps disclosed herein, unless and only when the order of the individual steps is explicitly described.

[0080] For the purposes of this disclosure, the word “comprising” has the same broad meaning as the word “including”, and the word “access” includes “receiving,” “referencing,” or “retrieval.” Furthermore, the word “communication” has the same broad meaning as the words “receiving” or “transmitting” facilitated by a software- or hardware-based bus, receiver, or transmitter using the communication medium described herein. Additionally, unless otherwise indicated, words such as “a” and “an” include both plural and singular forms. Thus, for example, the constraint “feature” is satisfied where one or more features are present. Furthermore, the term “or” includes conjunctions, adversative conjunctions, and both (a or b therefore includes both a and b).

[0081] For the purposes of the detailed discussion above, embodiments of the present technical solution are described with reference to a distributed computing environment; however, the distributed computing environment depicted herein is merely exemplary. Components can be configured to perform novel aspects of the embodiments, wherein the term "configured for" can refer to code being "programmed" to perform a specific task or implement a specific abstract data type. Furthermore, while embodiments of the present technical solution generally refer to the technical solution environment and schematic diagrams described herein, it should be understood that the described technology can be extended to other implementation contexts.

[0082] Embodiments of the present invention have been described with respect to specific embodiments which are intended to be illustrative rather than limiting in all respects. Alternative embodiments will become apparent to those skilled in the art without departing from the scope of the present invention.

[0083] As can be seen from the foregoing, this technical solution is well-suited to achieving all the goals and objectives described above, as well as other obvious and inherent structural advantages.

[0084] It should be understood that certain features and sub-combinations are practical and can be used without reference to other features or sub-combinations. This is contemplated by the claims and is within the scope of the claims.

Claims

1. A computerized system, comprising: One or more computer processors; as well as A computer memory stores computer-usable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations including: Access (302) AI attack monitoring data; Access (304) to an AI security graph associated with multiple AI-powered applications in the computing environment; Based on the AI ​​attack monitoring data and the AI ​​security graph, access (306) the operational data of the AI-supported application; Analyze the AI ​​attack monitoring data and the operation data described in (308); Based on the analysis of the AI ​​attack monitoring data and the operation data described in (310), an AI security alert is identified; and Transmit the artificial intelligence security alert (312).

2. The system of claim 1, wherein the artificial intelligence attack monitoring data includes abnormal model input data or abnormal model output data from the interface of an artificial intelligence application, wherein the artificial intelligence application is associated with one or more artificial intelligence-supported applications in the computing environment.

3. The system of claim 1, wherein the operation data includes security log data associated with the AI-supported application, wherein the operation data is identified based on nodes or edges of the AI-supported application in the AI ​​security graph.

4. The system of claim 1, wherein analyzing the AI ​​attack monitoring data and the operational data includes relating the AI ​​attack monitoring data to the operational data, wherein relating the AI ​​attack monitoring data to the operational data AI security alerts supports identifying the AI ​​security alerts.

5. The system of claim 1, further comprising generating a risk score that quantifies the likelihood or impact of a security threat associated with the AI ​​security alert, wherein the likelihood or impact of the security threat is associated with the number of potential attack surfaces associated with the security threat.

6. The system of claim 1, further comprising transmitting a security posture visualization including the AI ​​security alert, wherein the AI ​​security alert is associated with a priority identifier and a risk score.

7. The system according to claim 1, wherein the operation further comprises: Receive instructions to perform remedial actions associated with the AI ​​security alert, wherein the remedial actions are associated with security posture visualization; as well as Perform the remedial action.

8. The system according to claim 1, wherein the operation further comprises: Access the AI ​​attack monitoring data associated with the AI ​​security alerts for the AI-powered application; Access the AI ​​security graph; Based on the AI ​​attack monitoring data, the AI ​​security alerts, and the AI ​​security graph, access the operational data of the AI-supported application; Analyze the AI ​​attack monitoring data, the AI ​​security alerts, and the operational data; as well as Based on the analysis of the AI ​​attack monitoring data, the AI ​​security alerts, and the operational data, the priority identifier associated with the AI ​​security alerts is updated.

9. The system according to claim 1, wherein the operation further comprises: Receive a request for the security posture of the computing environment; Generate a security posture visualization associated with the computing environment, wherein the security posture visualization includes the artificial intelligence security alert; as well as The security posture visualization, including the aforementioned AI security alert, is transmitted.

10. The system according to claim 1, wherein the operation further comprises: Based on the request, receive the security posture visualization associated with the computing environment, wherein the security posture visualization includes the artificial intelligence security alert; as well as This makes the security posture, including the AI ​​security alert, visible.

11. One or more computer storage media having computer-executable instructions contained thereon, which, when executed by a computing system having a processor and a memory, cause the processor to perform operations, the operations including: Access (402) AI attack monitoring data associated with AI security alerts for AI-powered applications; Access (404) to an AI security graph associated with multiple AI-powered applications in the computing environment; Based on the AI ​​attack monitoring data, the AI ​​security alert and the AI ​​security graph, access (406) the operational data of the AI-supported application; Analysis (408) of the AI ​​attack monitoring data, the AI ​​security alerts, and the operational data; and Based on the analysis of the AI ​​attack monitoring data, the AI ​​security alert, and the operational data, update (410) the priority identifier associated with the AI ​​security alert.

12. The medium of claim 11, wherein analyzing the AI ​​attack monitoring data, the AI ​​security alert, and the operational data comprises: The AI ​​attack monitoring data, the AI ​​security alerts, and the operational data are correlated, wherein correlating the AI ​​attack monitoring data, the AI ​​security alerts, and the operational data supports updating the priority identifier.

13. The medium according to claim 11, further comprising: Receive a request for the security posture of the computing environment; Generate a security posture visualization associated with the computing environment, wherein the security posture visualization includes the AI ​​security alert and the updated priority identifier; as well as The security posture visualization is transmitted, including the AI ​​security alert and the updated priority identifier.

14. A computer-implemented method, the method comprising: Access (502) the AI ​​security graph generation model, which includes instructions on how to generate an AI security graph; Access (504) application data associated with multiple AI-powered applications in the computing environment; Using the application data and the AI ​​security graph generation model, generate (506) the AI ​​security graph of the plurality of AI-supported applications; as well as Deploy (508) the AI ​​security graph associated with the analysis of AI security alerts.

15. The method of claim 14, wherein generating the AI ​​security graph comprises: The first layer of the AI ​​security graph is generated based on a first set of application data from the application data, wherein the first set of application data includes account-based connections between AI-supported applications and AI applications. The second layer of the AI ​​security graph is generated based on a second set of application data from the application data, wherein the second set of application data includes configuration-based connections between the AI-supported application and the AI ​​application. as well as A third layer of the AI ​​security graph is generated based on a third set of application data from the application data, wherein the third set of application data includes code-based connections between the AI-supported application and the AI ​​application.