Protecting computer assets from malicious attacks

By identifying the type of the calculation asset and extracting a specific signature according to its asset context, only the corresponding signature is installed on the gateway that protects the calculation asset, the problem of inaccurate signature installation in the prior art is solved, and the gateway performance and protection efficiency are improved.

JP7674797B2Active Publication Date: 2025-05-12INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022568776
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-05-15
Filing Date
2021-05-11
Publication Date
2025-05-12
Estimated Expiration
2041-05-11

AI Technical Summary

Technical Problem

In the protection of computer assets, it is difficult to effectively associate known vulnerabilities to the specific computing assets with published supplier signatures, resulting in the need to install a large number of unrelated signatures or spend a lot of time manually applying protection measures.

Method used

By identifying different types of computed assets and extracting specific signatures based on their asset context, only the corresponding signature is installed on the gateway that protects the computed assets, and the installation location of the signature is determined using technologies such as deep neural networks.

Benefits of technology

It realizes accurate installation of signatures, reduces the loading of unnecessary signatures, improves the performance and efficiency of the gateway, and simplifies the process of protecting computer assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007674797000001
    Figure 0007674797000001
  • Figure 0007674797000002
    Figure 0007674797000002
  • Figure 0007674797000003
    Figure 0007674797000003
Patent Text Reader

Abstract

The method selectively installs a specific signature on a specific gateway based on the type of signature and the type of computer asset protected by the specific gateway. The system and / or analyst receives a plurality of signatures, with different signatures from the plurality of signatures being specific to different types of computer assets. The system and / or analyst identifies and extracts a specific signature from the plurality of signatures that protects the specific computer asset when implemented on an appropriate gateway. The system and / or analyst identifies an appropriate gateway that protects the specific computer asset and installs only the specific signature extracted from the plurality of signatures on the appropriate gateway.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to the field of protecting computer assets from malicious electronic attacks, and more particularly to the field of upgrading gateways that protect computer assets from malicious electronic attacks. [Background technology]

[0002] Computer assets such as databases, servers, programs, data, etc. are often protected by a gateway (e.g., a firewall), which prevents malicious attacks (i.e., intrusions) from attacking these computer assets. Behind such a gateway are numerous computer assets with different characteristics.

[0003] To protect computer assets, the Gateway may be updated with solutions against the latest known intrusions by security vendors. Such solutions are often referred to as "signatures" because the solution is specific to a particular intrusion having some code (i.e., binary). Thus, the term "signature" is used and defined herein as a solution / update / upgrade for the Gateway, where the signature addresses an intrusion / threat against the computer assets protected by the Gateway.

[0004] When end users (e.g., analysts and / or automated systems) receive the updated signatures, they often do not know which specific computer assets are behind the different gateways. Therefore, the updated signatures are often loaded onto all gateways used by the enterprise. This leads to poor gateway performance because the gateways are bogged down with irrelevant and unnecessary signatures.

[0005] Currently, there is no effective process for correlating known vulnerabilities for a given computer asset with published vendor signatures; that is, vendors have their own proprietary methods for managing protection policies and signatures. As a result, today it is necessary to mass enable signatures (install new / updated signatures on all gateways) without special oversight, and / or spend a great deal of time and effort manually reviewing and applying each required protection / signature to each specific gateway. Summary of the Invention

[0006] In one or more embodiments of the present invention, a method selectively installs a specific signature to a particular gateway based on a type of computer asset protected by the particular gateway. A system and / or analyst receives a plurality of signatures (e.g., intrusion prevention system (IPS) signatures) from a signature vendor. Different signatures from the plurality of signatures are specific to different types of computer assets. The system and / or analyst identifies a specific signature from the plurality of signatures that is specific to a particular type of computer asset. The specific signature is code that causes the gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset as described in the particular asset context. The system and / or analyst extracts a specific signature from the plurality of signatures based on the particular asset context and identifies a particular gateway that protects the particular computer asset. The system and / or analyst then installs the specific signature extracted from the plurality of signatures only to the particular gateway.

[0007] In one or more embodiments of the invention, the system and / or analyst affirmatively blocks any other signatures from the plurality of signatures, other than the particular signature extracted, from being installed on that particular gateway.

[0008] In one or more embodiments of the invention, the particular computer asset is a database system, and the particular asset context describes the vulnerability level of the database system, the identity of the database system, the hostname of the host computer on which the database system runs, and the operating system used by the database system.

[0009] In one or more embodiments of the invention, the particular computer asset is a database program, and the particular asset context describes the vulnerability level of the database program, the identity of the database program, the host name of the host computer on which the database program runs, the database system used by the database program, and the operating system used by the database system.

[0010] In one or more embodiments of the invention, the method further includes performing a Natural Language Processing (NLP) analysis on the set of vulnerabilities to extract risk-related information, where the set of vulnerabilities describes vulnerabilities that apply to a particular gateway, and where the risk-related information includes a list of vulnerable network resources that are vulnerable to intrusion and are protected by the particular gateway.

[0011] In one or more embodiments of the invention, the vulnerability of a particular computer asset to intrusion is from a set of identified vulnerabilities, whereby the set of identified vulnerabilities is identified in a Common Vulnerability Exposure (CVE) list generated by a third party that monitors vulnerabilities for multiple computer systems.

[0012] In one or more embodiments of the present invention, a Deep Neural Network (DNN) is trained to identify gateways that should receive a new signature based on a particular signature and the particular asset context referenced in that particular signature.

[0013] In one or more embodiments of the invention, a computer program product includes a computer readable storage medium having program code embodied therein, the computer readable storage medium being not a transitory signal per se. The program code is readable and executable by a processor to perform a method including, but not limited to, receiving a plurality of Intrusion Prevention System (IPS) signatures, where different IPS signatures from the plurality of IPS signatures are specific to different types of IPS gateways protecting different types of computer assets; identifying a specific IPS signature from the plurality of IPS signatures, where the specific IPS signature is specific to a specific type of computer asset, the specific IPS signature causing a specific IPS gateway to block intrusions from reaching a specific computer asset of the specific type of computer assets, the specific computer asset having a specific asset context specific to the specific computer asset; extracting the specific IPS signature from the plurality of IPS signatures based on the specific asset context; identifying a specific IPS gateway protecting the specific computer asset; and installing only the specific IPS signature extracted from the plurality of IPS signatures to the specific IPS gateway.

[0014] In one or more embodiments of the present invention, a computer system includes one or more processors, one or more computer readable memories, and one or more computer readable non-transitory storage media, and program instructions are stored in at least one of the one or more computer readable non-transitory storage media for execution by at least one of the one or more processors via at least one of the one or more computer readable memories, the stored program instructions including receiving a plurality of Intrusion Prevention System (IPS) signatures, different IPS signatures from the plurality of IPS signatures being specific to different types of IPS gateways protecting different types of computer assets, and identifying a particular IPS signature from the plurality of IPS signatures. and code for causing a particular IPS gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset, the particular IPS signature being specific to a particular type of computer asset, the particular IPS signature being code executed to perform a method including, but not limited to, identifying a particular computer asset having a particular asset context specific to the particular computer asset, extracting a particular IPS signature from the plurality of IPS signatures based on the particular asset context, identifying a particular IPS gateway protecting the particular computer asset, and installing only the particular IPS signature extracted from the plurality of IPS signatures to the particular IPS gateway. [Brief description of the drawings]

[0015] [Figure 1] FIG. 1 illustrates an exemplary system and network in which the present invention may be implemented in one or more embodiments of the present invention. [Diagram 2] FIG. 1 illustrates a high-level overview of components of one or more embodiments of the present invention. [Diagram 3]FIG. 2 illustrates a data grabber process for receiving new signatures in accordance with one or more embodiments of the present invention. [Figure 4] FIG. 2 illustrates a signature ticket issuance flow in accordance with one or more embodiments of the present invention. [Diagram 5] FIG. 2 illustrates a recommendation engine flow according to one or more embodiments of the present invention. [Figure 6] FIG. 1 illustrates an example deep neural network (DNN) that is trained to determine which gateways should receive a particular signature. [Figure 7] 1 is a high-level flowchart of one or more steps performed in accordance with one or more embodiments of the present invention. [Figure 8] FIG. 1 illustrates a cloud computing environment according to an embodiment of the present invention. [Figure 9] A diagram illustrating abstract model layers of a cloud computing environment according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0016] As described herein, in one or more embodiments, the invention utilizes a recommendation engine that collects Common Vulnerabilities and Exposures (CVE) information and other types of vulnerability information and scan data. From this information / data, the invention evaluates a CVE-based score (e.g., impact to the entire system based on the severity of the intrusion / attack, criticality of the resource being attacked, etc.), attack vector (e.g., the path through which the intrusion is attempted to occur), impact score (based on the impact the intrusion has on a particular set of computing assets), exploit score (e.g., the level to which the intrusion can exploit / extract computing assets such as data, programs, etc.), signature accuracy (e.g., the accuracy of recognizing the intrusion that the signature is designed to counter), signature implementation impact (e.g., the amount of time and resource usage required to install and implement the signature), and vendor recommendations (e.g., gateways that are recommended by the signature vendor / supplier to install new signatures).

[0017] In one or more embodiments of the invention, the system uses this data to filter only for network exploits, such as which computer assets are affected by an intrusion. The system recommendation for gateways on which to install signatures is based on weighted metrics that are compared against a matrix of responses from the system.

[0018] In one or more embodiments of the invention, recommendations are provided to a user / system / analyst who may choose to block or not block the installation of the signature on a protection device (e.g., gateway, firewall, etc.).

[0019] In one or more embodiments of the present invention, an implementation engine compiles the correct syntax to enable the signature on the protection device as well as any other relevant and necessary mechanisms.

[0020] In one or more embodiments of the invention, inventory scan data describing (among other things) the computer assets used / managed / owned by a particular customer is incorporated into recommendations to filter out irrelevant threats: if a signature vendor sends a customer a new signature that protects a certain type of computer asset, but the customer's inventory scan data indicates that this type of computer asset is not used by that customer, the customer will not install the new signature on any of its gateways.

[0021] No existing tool found in the prior art uses the combination of vulnerability data, live device configurations, and scan data in a manner that allows a system and / or analyst to automatically assess and implement protections across multiple different vendor platforms with just one request. However, one or more embodiments of the present invention provide these features.

[0022] Thus, one or more embodiments of the present invention collect vendor-specific vulnerability definitions and key them with CVE-specific fields in a common vulnerability database.

[0023] Using security operations center (SOC)-based assessment techniques, one or more embodiments of the present invention programmatically recommend protective techniques in real time.

[0024] Thus, as described herein, one or more embodiments of the present invention simplify the process of protecting against known vulnerabilities by automating protection policy modification across large scale and multiple vendors. One or more embodiments of the present invention take a given vulnerability identifier or vulnerability keyword, associate it with protection rules from multiple vendors, and then query customer devices to determine whether they are currently protected. Based on data from the vulnerability information repository, such as severity, access vector, and system impact, one or more embodiments of the present invention determine which risks to prioritize.

[0025] Additionally, one or more embodiments of the present invention gather information from scan data (i.e., data obtained by scanning computer assets to identify their presence and their characteristics / context) to determine which systems are vulnerable and apply the appropriate recommended protections. One or more embodiments of the present invention then automatically apply the fixes (signatures) to the customer's gateway device, such as updating the gateway device's signatures from the vendor and / or enabling the signatures in the associated profile.

[0026] In one or more embodiments of the present invention, the rules databases of vendors' intrusion prevention systems (IPS) are aggregated such that CVEs are associated with each vendor's internal identifier (ID) for the associated rules. Each set of CVEs and vendor IDs is stored with metadata, such as description, severity, device impact, and updated versions in which each vendor introduced rules to protect it. In one or more embodiments of the present invention, the data used to populate this store of aggregated databases is supplied from each vendor's physical devices and / or using the vendor's online application program interfaces (APIs). The data is stored centrally, so only one database needs to be generated for all users of the software, thereby reducing the amount of time required to update records. Thus, in one or more embodiments of the present invention, records are updated only when each vendor pushes changes to its IPS rule set.

[0027] After collecting a central database of threat protection rules, one or more embodiments of the present invention allow a user to query this central database by CVE or keyword. Rule IDs are then returned for the appropriate vendor based on the vendor used by the customer. Correlating this rule ID with data stored in the online CVE repository, one or more embodiments of the present invention assess the potential risk level of the vulnerability and the importance of blocking exploitation of the vulnerability at the network level. In one or more embodiments of the present invention, this process uses factors such as the access vector (e.g., ignoring attacks that require physical access rather than using remote access) and the application / operating system affected (e.g., not prioritizing vulnerabilities in a first type of operating system over a firewall / gateway protecting a second type of operating system machine). After compiling this information, one or more embodiments of the present invention make a decision on the optimal IPS policy for the rule (block, log, allow, etc.) while providing context on the priority level and time sensitivity of the issue. If the system / user / analyst accepts the proposed configuration, one or more embodiments of the present invention proceed to automatically install new policies (i.e., signatures) or modify existing policies / signatures. Additionally, one or more embodiments of the present invention also check the version of the IPS database being installed and prompt the user / system / analyst to install the latest one, should an update exist.

[0028] As used in this patent application, a "weakness" for a computing asset is defined as a characteristic of the computing asset that makes the computing asset vulnerable to malicious activity. For example, a new code version may not generally protect a particular port on a network router, thereby making that particular port "weak." Thus, the Common Weakness Enumeration (CWE) is a standard used to describe such identified / discovered weaknesses.

[0029] As used in this patent application, a "vulnerability" is defined as a specific weakness of a computer asset caused by a weakness. For example, if a new code version does not protect a specific port of a network router, that specific port is vulnerable to malicious attack, thus making that specific port obviously open ("vulnerable") to attack. Thus, Common Vulnerability Exposure (CVE) is a standard used to describe such specifically identified or discovered vulnerabilities.

[0030] Thus, a "weakness" describes a general level of vulnerability to malicious attack, while a "vulnerability" describes exposure to a particular type of malicious attack.

[0031] As used in this patent application, the term "intrusion" is defined as a malicious attack on a computer asset. Examples of intrusions include, but are not limited to, malware such as viruses, unauthorized keystroke recorders, and unauthorized data extraction programs.

[0032] As used in this patent application, the term "Intrusion Prevention System" or IPS is defined as a system, such as a firewall or gateway, that prevents intrusions from reaching protected computer assets. Such firewalls / gateways may be implemented in hardware, software, or a combination of hardware and software, or any combination thereof.

[0033] As used in this patent application, the term "signature" is defined as protective code that, when installed in an IPS, prevents an intrusion from reaching the protected computer asset.

[0034] 1, there is shown a block diagram of an exemplary system and network that may be utilized by and / or in the implementation of one or more embodiments of the present invention. It should be noted that some or all of the exemplary architecture, including both the illustrated hardware and software, shown for and in computer 102 may be utilized by neural network 124 or software deploying server 150 or intrusion prevention system (IPS) signature provider system 152 or combinations thereof, IPS 154, or computer assets 156, or combinations thereof.

[0035] The exemplary computer 102 includes a processor 104 coupled to a system bus 106. The processor 104 may utilize one or more processors, each having one or more processor cores. A video adapter 108, which drives / supports a display 110, is also coupled to the system bus 106. The system bus 106 is coupled to an input / output (I / O) bus 114 via a bus bridge 112. An I / O interface 116 is coupled to the I / O bus 114. The I / O interface 116 provides communication with various I / O devices, including a keyboard 118, a mouse 120, a media tray 122 (which may include a storage device, such as a CD-ROM drive, a multimedia interface, etc.), a neural network 124, and an external USB port 126. The format of the ports connected to the I / O interface 116 may be any known to those skilled in the art of computer architecture, but in one embodiment, some or all of these ports are Universal Serial Bus (USB) ports.

[0036] As shown, computer 102 can communicate with neural network 124, software deployment server 150, IPS signature provider system 152, IPS 154, and / or computer assets 156 using network interface 130 to network 128. Network interface 130 is a hardware network interface such as a network interface card (NIC). Network 128 can be an external network such as the Internet, or an internal network such as Ethernet or a virtual private network (VPN).

[0037] A hard drive interface 132 is also coupled to the system bus 106. The hard drive interface 132 interfaces with a hard drive 134. In one embodiment, the hard drive 134 feeds into a system memory 136, which is also coupled to the system bus 106. The system memory is the volatile memory within the computer 102. This volatile memory includes additional levels of memory (not shown), including but not limited to cache memory, registers, and buffers. Data fed into the system memory 136 includes an operating system (OS) 138 and application programs 144 of the computer 102.

[0038] The OS 138 includes a shell 140 for providing transparent user access to resources such as application programs 144. Generally, the shell 140 is a program that provides an interpreter and interface between a user and the operating system. More specifically, the shell 140 executes commands that are entered into a command line user interface or from a file. Thus, the shell 140, also referred to as a command processor, is generally the highest level of the operating system software hierarchy and acts as a command interpreter. The shell provides a system prompt, interprets commands entered by keyboard, mouse, or other user input medium, and sends the interpreted commands to the appropriate lower level of the operating system (e.g., kernel 142) for processing. It should be noted that while the shell 140 is a text-based, line-oriented user interface, the present invention equally well supports other user interface modes such as graphical, speech, gesture, etc.

[0039] As shown, OS 138 also includes a kernel 142, which contains the lower level functionality for OS 138, including providing essential services required by other parts of OS 138 and application programs 144, including memory management, process and task management, disk management, and mouse and keyboard management.

[0040] The application programs 144 include a renderer, shown in an exemplary manner as a browser 146. The browser 146 includes program modules and instructions that enable a World Wide Web (WWW) client (i.e., computer 102) to send and receive network messages to the Internet using HyperText Transfer Protocol (HTTP) messaging, thereby enabling communication with a software deployment server 150 and other computer systems.

[0041] The application programs 144 in the system memory of the computer 102 (and the system memory of the software deployment server 150) also include an intrusion prevention system (IPS) signature management logic (IPSSML) 148. The IPSSML 148 includes code for implementing the processes described below, including those described in Figures 2-7. In one embodiment, the computer 102 is capable of downloading the IPSSML 148 from the software deployment server 150, including on an on-demand basis, such that the code in the IPSSML 148 is not downloaded until needed for execution. It is further noted that in one embodiment of the present invention, the software deployment server 150 performs all of the functionality associated with the present invention (including execution of the IPSSML 148), thereby freeing the computer 102 from having to execute the IPSSML 148 using its own internal computing resources.

[0042] Also connected to computer 102 (or alternatively as part of computer 102) is a neural network 124. In one or more embodiments of the invention, neural network 124 is a deep neural network (see FIG. 6), a convolutional neural network, or another type of heuristic artificial intelligence.

[0043] Also connected to (or alternatively as part of) computer 102 is IPS signature provider system 152, which is a system used by an IPS signature vendor (e.g., IPS signature vendor 202 and / or IPS signature vendor 204 shown in FIG. 2). As defined herein, a "signature" is defined as code that is matched to a particular intrusion binary such that the "signature" prevents the intrusion binary from reaching a computer asset (e.g., computer asset 224 and / or computer asset 226 shown in FIG. 2) that is protected by an IPS gateway, such as IPS 220 and / or IPS 222 shown in FIG. 2.

[0044] 1 is similar to exemplary IPS 220 and / or IPS 222 shown in FIG. 2, and computer asset 156 is similar to exemplary computer asset 224 and / or computer asset 226 shown in FIG. 2.

[0045] It should be noted that the hardware elements depicted in computer 102 are not intended to be exhaustive, but rather are depicted to highlight the essential components required by the present invention. For example, computer 102 may include alternative memory storage devices, such as magnetic cassettes, digital versatile disks (DVDs), Bernoulli cartridges, etc. These and other variations are intended to be within the scope of the present invention.

[0046] Referring now to FIG. 2, there is shown a high level overview of the components of one or more embodiments of the present invention.

[0047] In describing FIG. 2, the terms intrusion prevention system (IPS), gateway, firewall, and IPS gateway are used interchangeably to describe exemplary IPS 220 and IPS 222.

[0048] As shown in FIG. 2, one or more signature vendors (e.g., IPS signature vendor 202 or IPS signature vendor 204 or both) provide signatures for use by one or more customers (e.g., customer 216 or customer 218 or both) via implementation engine 214.

[0049] A signature vendor (e.g., IPS signature vendor 202 and / or IPS signature vendor 204) sends new / updated signatures (i.e., code that, when implemented in a firewall / gateway, such as IPS 220 and / or IPS 222, provides protection from newly identified intrusions) to database updater 206.

[0050] A database updater 206 performs new signatures over time by querying data sources for signature-specific metadata and then inserts the extracted metadata into a centralized database 208. That is, signatures from a signature vendor (e.g., IPS signature vendor 202 and / or IPS signature vendor 204) include metadata about such signatures. This metadata is then used to associate vulnerabilities (e.g., Common Vulnerabilities and Exposures (CVEs)) with specific gateways (e.g., IPS 220) through the use of vulnerabilities found in a vulnerability database 212 that are then applied to vulnerability-to-IPS signature lookups 210.

[0051] Vulnerability-to-IPS signature lookup 210 is a lookup system that matches metadata about a particular IPS signature to a particular vulnerability. That is, given a particular CVE identifier for a particular computer asset, vulnerability-to-IPS signature lookup 210 matches that particular CVE identifier to known vendor IPS signatures and information about such known IPS signatures. One or more of these known vendor IPS signatures and their associated information are sent to implementation engine 214 for sending the appropriate signature to the appropriate gateway (e.g., IPS 220 and / or IPS 222).

[0052] However, for purposes of illustration, assume that IPS 220 is capable of loading signatures from either IPS signature vendor 202 or IPS signature vendor 204, and that IPS 222 is capable of loading signatures from either IPS signature vendor 202 or IPS signature vendor 204, even though computer asset 224 and computer asset 226 are different types of computer assets (e.g., different types of hosts, running on different types of operating systems, using different types of databases, etc.).

[0053] For example, assume that computer asset 224 is a program using database structure A that runs on a first type of OS. Further assume that computer asset 226 is a program using database structure B that runs on a second type of OS. Further assume that the new signature is specific to assets that run only on the first type of OS. However, end user 234 often does not know any details about computer asset 224 or computer asset 226. Thus, without the present invention, end user 234 would instruct implementation engine 214 via user interface 232 to install a new signature received from IPS signature vendor 202 on both IPS 220 and IPS 222, even though it is not useful for IPS 222 (which is assigned to protect only computer asset 226 that runs on the second type of OS). This excessive installation causes unnecessary signatures to be installed on the IPSes, thereby degrading their performance.

[0054] One or more embodiments of the present invention solve this problem through the use of a context database 230 and an analysis engine 228 .

[0055] Context database 230 includes information describing a particular computer asset, such as computer asset 224. For example, in one or more embodiments of the present invention, assume that a context entry for computer asset 224 in context database 230 provides information about the infrastructure of computer asset 224. If computer asset 224 is a file, the infrastructure includes other files that form a file cluster with computer asset 224, applications used with the file, operating systems used with the applications, host systems that hold the file and / or applications, etc.

[0056] In one or more embodiments of the invention, if an end user 234 (e.g., a computer system such as computer 102 shown in FIG. 1 and / or an analyst using user interface 232) determines that a particular computer system does not have all of these characteristics (e.g., is a particular type of file, or uses a particular type of application, or runs on a particular operating system, or a combination thereof), then the new signature is not executed / implemented. That is, the new signature is only for computer assets that run on a first type of OS, but if an enterprise only runs applications on a second type of OS, then there is no need to install the new signature on any IPS gateways used by the enterprise. Thus, the implementation of the new signature is blocked from being sent to any IPS gateways used by the enterprise.

[0057] However, if the new signature is designed to protect a computer asset contained within the enterprise (e.g., computer asset 224) when installed on its gateway (e.g., IPS 220), then end user 234 installs the new signature on IPS 220 rather than IPS 222 (assuming there are no assets within computer assets 226 that would be protected by the new signature even if it were installed on IPS 222).

[0058] In one or more embodiments of the present invention, the decision as to whether to implement a particular signature is based on multiple factors (other than the type of OS running by the asset, as described in the example above) as evaluated by the analysis engine 228 using information from the context database 230.

[0059] That is, in one or more embodiments of the present invention, the analysis engine 228 uses the CVE scoring (i.e., a score for the vulnerability of a particular asset, such as computer asset 224, to an attack), the attack vector (i.e., which channel / port, etc. the intrusion is designed to use when attacking a particular asset), a history of when, where, and how often the intrusion has hit other computer assets, and / or a record of the effectiveness of signatures provided by the signature vendor in thwarting past attacks against other computer assets, to determine whether and / or in which IPS to install the newly received signature.

[0060] In one or more embodiments of the present invention, the scan data (e.g., information describing the computer asset and / or how an intrusion has previously affected other systems and their components) is also used to validate the impact of the intrusion on the riskiness of the current computer asset. This information, in one or more embodiments of the present invention, is used by the implementation engine 214 in determining whether and / or in which IPS to install a newly received signature.

[0061] In one or more embodiments of the present invention, the analysis engine 228 also uses the IPS context for a particular IPS gateway, such as computer asset 224, from a context database 230 that contains information about IPS 220 so that policies can be implemented. That is, in one or more embodiments of the present invention, the analysis engine 228 not only considers the context of the computer asset (e.g., computer asset 224), but also the context of the protection gateway (e.g., IPS 220). Thus, when determining whether and / or on which IPS to install a newly received signature, the analysis engine 228 uses the IPS CVE scoring (i.e., the score of the vulnerability of a particular IDS gateway, such as IPS 220, to the attack), the IPS attack vector (i.e., which channel / port, etc., the intrusion is designed to use when attacking a particular IPS gateway), the history of when, where, and how often the intrusion hit other computer IPS gateways, and / or the record of the effectiveness of the signature provided by the signature vendor in thwarting past attacks against other computer assets by other IPS gateways, or a combination thereof.

[0062] Thus, in one or more embodiments of the present invention, FIG. 2 illustrates how a particular IPS signature may be selectively implemented in a particular IPS based on what type of computer asset is protected by the particular IPS signature, the asset context of the computer asset, or the IPS context of the particular IPS, or a combination thereof.

[0063] Referring now to FIG. 3, a data grabber process used in one or more embodiments of the present invention for receiving new signatures is presented.

[0064] After start block 301, an IPS signature vendor (e.g., IPS signature vendor 202 shown in FIG. 2) updates records of new IPS signatures generated by the IPS signature vendor (in response to new intrusions detected) and reports from customers of updates to Common Vulnerabilities and Exposures (CVEs), as shown in block 303.

[0065] As indicated in block 305, this information is sent to a centralized database, such as vulnerability database 212 shown in FIG.

[0066] As shown in block 307, a client / customer (e.g., customer 216 and / or end user 234) requests CVE protection (e.g., IPS signatures) from the centralized database.

[0067] If the requested CVE protection is not in the centralized database, as shown in query block 309, the requested CVE protection is obtained from the vendor and added to the centralized database (see block 311). On the other hand, if the requested CVE protection is in the centralized database, configuration data from a particular endpoint device (e.g., IPS 220) is obtained by the customer, as shown in block 313.

[0068] As shown in query block 315, the customer determines whether the local IPS rule base (i.e., rules for the types of computer assets protected by a particular IPS and / or the IPS signature vendor's product used by that particular IPS) is up to date. If not, then as shown in block 317, the local definitions for those IPS (i.e., gateways, firewalls, etc.) are updated by scanning them for descriptions of their components (e.g., looking up the Universally Unique Identifier (UUID) associated with each component from a database or either a Radio Frequency Identifier (RFID) chip attached to the device, an identifier in software associated with the component / asset, etc.). On the other hand, if the local IPS rule base is up to date, the customer's current CVEs are associated with the IPS protection vendor's internal identifier (ID) (see block 319).

[0069] As shown in query block 321, a query is made as to which IPS gateway protects which particular computer asset and whether rules are enabled for which IPS protection should be used. That is, not only must the customer's system know which particular IPS protects which computer asset with a particular IPS signature vendor, but the system must be enabled (configured) to associate a particular IPS signature with a particular IPS and a particular computer asset with a particular IP signature, and the particular IPS must be authorized to install the particular IPS signature. If these conditions are already met, the user is notified that this particular IPS signature will be installed on the particular IPS (block 323), thereby causing the process to end at end block 333.

[0070] However, if the rule is not enabled (query block 321), the customer's end user and / or analytics (e.g., analytics engine 228 shown in FIG. 2) generates a score as to whether the rule should be enabled, as shown in block 325. That is, a high score indicates that the rule should be enabled and a low score indicates that the rule should not be enabled. Such a score is based on heuristics such as those described in the asset context description as well as other factors presented in FIG. 2 above and FIG. 6 below.

[0071] In this manner, the customer's system and / or analyst determines whether the rule should be enabled at query block 327. If it should not be enabled, the user is notified as shown in block 329 (along with the reason the rule should not be enabled, such as installing new and as yet unnecessary rules resulting in overcrowding of rules already in the particular IPS), and the process ends at end block 333.

[0072] On the other hand, if the customer's system and / or analyst determines that the rule should be enabled, a user (e.g., end user 234 shown in FIG. 2) is notified as shown in block 331. This allows the end user / analyst to manually enable the rule by implementing a signature in the IPS via implementation engine 214 shown in FIG. 2, or authorize a heuristic system (e.g., deep neural network 624 shown in FIG. 6) to automatically enable the rule, thereby installing the signature in the IPS and terminating the process in end block 333.

[0073] Referring now to FIG. 4, a high level flow chart illustrates a signature ticket issuance flow in accordance with one or more embodiments of the present invention.

[0074] After start block 402, a customer (e.g., customer 216 shown in FIG. 2) requests a signature for intrusion protection (i.e., intrusion protection to be installed in a gateway / firewall, such as IPS 220 shown in FIG. 2), as shown in block 404.

[0075] As shown in inquiry block 406, an inquiry is made as to whether a ticket (work order) exists for the request made in block 404. If a ticket does not exist, a new ticket is created (see block 408). However, if a ticket already exists for the request made in block 404, an inquiry is made (see inquiry block 410) as to whether an authorized party (e.g., end user 234 and / or customer 216) has granted approval to implement the changes listed in the ticket. If not, no changes are applied to the IPS protected by the signature listed in the ticket (block 412), and the ticket is closed (block 416), resulting in the end of the process (end block 418). On the other hand, if the appropriate party has approved the ticket (inquiry block 410), the implementation engine 214 shown in FIG. 2 applies the changes to the appropriate IPS (i.e., the signature is installed in the appropriate IPS, such as IPS 220), as shown in block 414, resulting in the closing of the ticket (block 416) and the end of the process (end block 418).

[0076] Referring now to FIG. 5, a schematic flow chart illustrates recommendation engine flow according to one or more embodiments of the present invention.

[0077] After start block 501, a request for a signature to address a particular intrusion is received (e.g., through an application program interface (API)), as shown in block 503. For example, end user 234 and / or analysis engine 228 shown in FIG. 2 interfaces with the API (e.g., via user interface 232 shown in FIG. 2, where the requester is end user 234) to request a signature (i.e., protection for the IPS gateway / firewall from a particular intrusion).

[0078] A query is made (e.g., by analysis engine 228 shown in FIG. 2) to determine whether the signature and / or the specific intrusion is in a common threat database (e.g., vulnerability database 212 shown in FIG. 2), as indicated in query block 505. If not, then the database is updated to include the signature and / or a description of the specific intrusion, or the intrusion binary itself, as indicated in block 507.

[0079] If the signature and / or the particular intrusion is found in the common threat database, a query is made to inquire whether the CVE score meets the threshold value discussed above (query block 509). If the threshold value is not met, no further action is taken (block 511) and the process ends (end block 535).

[0080] On the other hand, if the CVE score meets or exceeds the configured threshold, a query is made as to whether a component of the network (e.g., computer asset 224 shown in FIG. 2) is under attack (query block 513). If not, no further action is taken (block 511) and the process ends (end block 535).

[0081] On the other hand, if the network component is under attack, an asset context (as described above) is obtained for the computer asset (block 515). This leads to determining whether the scan data (i.e., a description of the computer asset, such as computer asset 224 shown in FIG. 2) indicates that the asset is in fact vulnerable to intrusion, as shown in query block 517. If not, no further action is taken (block 511) and the process ends (end block 535).

[0082] On the other hand, if the scan data indicates that the computer asset is or may be vulnerable to an intrusion, then an inquiry is made as to whether the vendor (e.g., IPS signature vendor 202) is trustworthy to provide a sufficient / appropriate signature (inquiry block 519). If the impact of the intrusion is so great that the signature vendor is not / is not trustworthy enough to provide an appropriate signature (e.g., based on previous experience with that signature vendor) or if the signature is of low fidelity simply by looking at the code within the signature (block 523), then the customer (e.g., end user 234) is notified as such and the process ends at end block 535.

[0083] On the other hand, if the vendor is deemed capable of dealing with this particular intrusion (query block 519), a query is made to ask whether the IPS gateway already has sufficient protection (e.g., from another signature) to protect its computer assets from this particular intrusion (query block 525). If so, the customer is notified (block 527) and the process ends (end block 535). On the other hand, if there is not already sufficient protection from the intrusion at the IPS level, the implementation engine 214 shown in FIG. 2 prepares the appropriate syntax to utilize the signature (block 529), notifies the customer that approval is required to install the signature (block 531), and then transmits the change (signature) to the appropriate IPS via the implementation engine 214 shown in FIG. 2 with the appropriate customer approval (block 533). Again, the process ends at end block 535.

[0084] In one or more embodiments of the invention, a deep neural network (DNN) determines which IPSs should receive a particular IPS signature. Figure 6 shows an example DNN 624 (similar to the neural network 124 shown in Figure 1) that is trained to determine which IPSs / gateways should receive that particular signature.

[0085] Neural networks, as the name suggests, loosely mimic biological neural networks (e.g., the human brain). Biological neural networks consist of a set of interconnected neurons that influence each other. For example, a first neuron may be electrically connected to a second neuron by a synapse through the release of neurotransmitters (from the first neuron) that are received by the second neuron. These neurotransmitters may excite or inhibit the second neuron. Patterns of exciting / inhibiting interconnected neurons ultimately lead to biological effects including thought, muscle movement, memory retrieval, etc. This description of biological neural networks is highly simplified, but the high-level overview is that one or more biological neurons influence the behavior of one or more other biologically electrically connected biological neurons.

[0086] Electronic neural networks are similarly composed of electronic neurons, however unlike biological neurons, electronic neurons are never technically "inhibitory" but are only more or less "excitatory".

[0087] A node in a neural network, such as DNN 624, may represent a hardware processor, a virtual processor, a software algorithm, or a combination of hardware processors, virtual processors, and / or software algorithms.

[0088] In a deep neural network (DNN), such as DNN 624, electronic neurons are arranged in layers called input, hidden, and output layers. Thus, electronic neurons (also referred to herein simply as "neurons" or "nodes") in DNN 624 are arranged in an input layer 603, hidden layer 605, and output layer 607. Input layer 603 contains neurons / nodes that take input data and send it to a series of hidden layers of neurons (e.g., hidden layer 605), where neurons from one layer in the hidden layer are interconnected with all neurons in the next layer in hidden layer 605. The last layer of hidden layer 605 then outputs the computation results to output layer 607, which is often a single node to hold vector information.

[0089] As discussed above, each node of the illustrated DNN 624 represents an electronic neuron, such as the illustrated neuron 609. As indicated in block 611, in one or more embodiments of the invention, each neuron (including neuron 609) functionally includes at least four characteristics: an algorithm, an output value, a weight, and a bias value.

[0090] An algorithm is a mathematical formula for processing data received from one or more upstream neurons. For example, assume that one or more of the neurons shown in the intermediate hidden layer 605 send data values ​​to neuron 609. Neuron 609 then processes these data values ​​by executing the algorithm shown in block 611 to generate one or more output values. The one or more output values ​​are then sent to another neuron in the hidden layer 605 or to another neuron, such as neuron 606 in the output layer 607. Each neuron also has a weight that is specific to that neuron or other connected neurons or both and indicates the importance of the output from that neuron. That is, downstream neurons may ignore outputs from upstream neurons with light weightings, but must accept and process data from upstream neurons with heavy weightings. Additionally, the output values ​​are added to bias values ​​that increase or decrease the raw output values, allowing the DNN 624 to be further "fine-tuned."

[0091] For example, assume that neuron 613 is sending the analysis result of a piece of data to neuron 609. Neuron 609 has a first weight that defines the importance of the data coming from neuron 613 in particular. If the data is important, the data coming from neuron 613 is weighted more heavily and / or increased by its bias value, thereby causing the algorithm within neuron 609 to generate an output that is more heavily weighted and / or has a higher value, which has a corresponding influence on the neurons in the output layer 607. That is, if neuron 613 is determined to be important to the operation of neuron 609, the weight and / or bias of neuron 613 is increased such that neuron 609 receives a high level of importance due to the output of the algorithm of neuron 613. Alternatively, the output of neuron 609 may be minimized by decreasing the weight and / or bias used to influence the output of neuron 609. These weights / biases can be adjusted for one, some, or all of the neurons of the DNN 624 so that reliable outputs come from the output layer 607.

[0092] When asset context 600 (e.g., a description of a particular computer asset) and IPS signature 602 (e.g., a particular signature generated by an IPS signature vendor for use by an IPS gateway to block passage of a particular intrusion to that particular computer asset) are input into a trained version of DNN 624, the identity of the particular IPS on which the IPS signature should be installed is identified in output 604 from DNN 624. In order to provide this functionality, DNN 624 must first be trained.

[0093] Thus, in one or more embodiments of the present invention, known training asset context (shown as asset context 600 during training of DNN 624) and known IPS signatures (shown as IPS signatures 602 during training of DNN 624) are input to DNN 624 to train DNN 624 using a manual process and / or a backpropagation process.

[0094] When manually adjusted during training of the DNN 624, the algorithms, output values, weights, and / or biases are iteratively adjusted by a user, sensor logic, etc. until the output from the output layer 607 matches expectations. For example, the input layer 603 receives training inputs describing a known particular type of asset context and known IPS signatures. By manually and iteratively adjusting the algorithms, output values, weights, and biases in one or more of the electronic neurons in the DNN 624, the DNN 624 becomes a trained DNN that correctly outputs a vector / value to the output layer 607, which indicates that the neuron 606 describes a particular solution for installing the signature in the appropriate IPS, which is presented as output 604.

[0095] When automatically adjusted, the weights (or algorithms or bias values, or a combination thereof) are adjusted using "backpropagation," in which the neuron's weight values, algorithms, and / or bias values ​​are adjusted by using a "gradient descent" method to determine the direction in which each weight / bias / algorithm should be adjusted. This gradient descent process moves each neuron's weights and / or biases in a direction and / or changes the algorithms themselves until the output from the output layer 607 improves (e.g., accurately describes the IPS in which the signature should be installed).

[0096] Thus, in one or more embodiments of the present invention, the DNN 624 is now trained to determine which IPS / gateway should receive a particular signature based on the IPS signature itself (denoted at run-time as IPS signature 602) and the description of the computer asset (denoted at run-time as asset context 600, which is an asset context as described above with reference to FIG. 2).

[0097] Thus, in one or more embodiments of the invention, the DNN 624 is first trained by inputting known training asset context data (shown in FIG. 6 as asset context 600) and known training IPS signature data (shown in FIG. 6 as IPS signature 602) to generate expectations in neurons 606 of the output layer 607. For example, assume that the known training asset context data describes a particular computer asset (e.g., a database system) and the known training IPS signature data describes a certain type of signature (e.g., for use with an IPS gateway protecting that type of database system). Using the manual or backpropagation process described above, the DNN 624 is adjusted until the contents of the neurons 606 describe that particular type of IPS gateway on which this type of IPS signature should be installed.

[0098] The training process then goes through other combinations of known training asset context descriptions and known training IPS signature data until the DNN 624 becomes a trained DNN capable of matching a particular type of IPS signature to a particular type of IPS gateway.

[0099] The trained DNN624 can then evaluate other asset context and IPS signatures to determine which, if any, IPS gateways in a customer's inventory should receive a particular IPS signature.

[0100] DNN 624 is an exemplary type of neural network that may be used in one or more embodiments of the present invention. Other neural networks that may be used in one or more embodiments of the present invention include convolutional neural networks (CNNs) and other forms of deep learning neural networks.

[0101] Referring now to FIG. 7, a high level flowchart of one or more steps performed in accordance with one or more embodiments of the present invention is presented.

[0102] After start block 701, a customer (e.g., end user 234 or implementation engine 214 or analysis engine 228 or customer 216, or a combination thereof, as shown in FIG. 2) receives a plurality of signatures, as described in block 703. In one or more embodiments of the present invention, different signatures from the plurality of signatures are specific to different types of gateways that protect different types of computer assets. That is, assume that IPS signature vendor 202, as shown in FIG. 2, sends a set of multiple signatures to end user 234. However, only one of these signatures is used by IPS 220 to protect computer asset 224. Therefore, there is no reason to install this signature on IPS 222, since only IPS 220 needs that signature.

[0103] As depicted in block 705, the analysis engine 228 depicted in FIG. 2 identifies a specific signature from the plurality of signatures. The specific signature is specific to a specific type of computer asset (e.g., computer asset 224). As described herein, the specific signature is code that causes a specific gateway to block an intrusion from reaching a specific computer asset of a specific type of computer asset. Thus, the specific computer asset has a specific asset context that is specific to the specific computer asset.

[0104] As depicted in block 707, the analysis engine 228 depicted in FIG. 2 extracts the particular signature from the plurality of signatures based on a particular asset context, i.e., the analysis engine 228 determines that the particular signature protects a particular computer asset (e.g., computer asset 224 depicted in FIG. 2).

[0105] As depicted in block 709, the analysis engine 228 shown in FIG. 2 identifies a particular gateway (eg, the IPS 220 shown in FIG. 2) that protects a particular computer asset.

[0106] As described in block 711, the implementation engine 214 shown in FIG. 2 then installs only the specific signature extracted from the plurality of signatures only on the particular gateway. That is, of the plurality of signatures received by the customer / end user, only the extracted specific signature that is specific to the computer asset that is actually part of the customer's system is used. More specifically, since the extracted specific signature specifically protects the computer asset 224, the extracted specific signature is installed only on the IPS 220 and not on the IPS 222. Therefore, the IPS 222 is not burdened with a copy of the extracted specific signature because the IPS 222 does not need it. In this way, the extracted specific signature is installed only on the particular gateway and not on other gateways.

[0107] In one or more embodiments of the present invention, the end user or customer and / or implementation engine specifically blocks any other signatures from the plurality of signatures from being installed on that particular gateway, other than the particular signature that was extracted.

[0108] The flowchart ends at end block 713 .

[0109] In one or more embodiments of the present invention, the particular computer asset is a database system. A database system is a particular type of database management system that supports database programs designed to run on that database management system. Thus, the particular asset context describes the vulnerability level of the database system, the identity of the database system, the hostname of the host computer on which the database system runs, and the operating system used by the database system. In one or more embodiments of the present invention, all of this information is used (e.g., by DNN 624 shown in FIG. 6) in determining which IPS should install the particular extracted signature.

[0110] In one or more embodiments of the present invention, the particular computer asset is a database program. This database program runs on a particular type of database system (e.g., the database management system just described). Thus, the particular asset context describes the vulnerability level of the database program, the identity of the database program, the host name of the host computer on which the database program runs, the database system used by the database program, and the operating system used by the database system. In one or more embodiments of the present invention, all of this information is used (e.g., by DNN 624 shown in FIG. 6) in determining which IPS should install the particular extracted signature.

[0111] In one or more embodiments of the invention, the method further includes performing a natural language processing (NLP) analysis on the set of vulnerabilities describing vulnerabilities that apply to a particular gateway to extract risk-related information, the risk-related information including a list of vulnerable network resources that are protected by the particular gateway and are vulnerable to intrusion.

[0112] For example, consider vulnerability database 212 shown in Figure 2. Assume vulnerability database 212 contains information about a particular type of intrusion, including the types of computer assets that are vulnerable to that type of intrusion. Additionally, the information in vulnerability database 212 also includes which types of computer assets are protected by which types of gateways. Thus, vulnerability database 212 contains information about 1) the types of computer assets that are vulnerable (can be affected) by a particular type of intrusion, 2) the types of IPS gateways that protect that type of computer assets, and 3) a description of a signature that, when installed on that type of IPS gateway, will prevent that type of computer asset from being affected by that particular type of intrusion.

[0113] To ascertain all of this information, the NLP analysis examines text in vulnerability database 212 that describes this information to ascertain: 1) the type of computer asset that is vulnerable (can be affected) by a particular type of intrusion, 2) the type of IPS gateway that protects that type of computer asset, and 3) a description of the signature that, when installed on that type of IPS gateway, will prevent that particular type of intrusion from reaching that type of computer asset.

[0114] In one or more embodiments of the invention, the vulnerability of a particular computer asset to intrusion is from a set of identified vulnerabilities (e.g., found in vulnerability database 212 shown in FIG. 2). The set of identified vulnerabilities are identified in a Common Vulnerabilities and Exposures (CVE) list, which is generated by a third party that monitors vulnerabilities for multiple computer systems.

[0115] In one or more embodiments of the present invention, a user and / or a computer system (e.g., implementation engine 214 shown in FIG. 2) trains a deep neural network (DNN) to identify specific gateways by inputting known training signatures and known training asset contexts into the DNN, as described in FIG. 6. Also, as described in FIG. 6, once the DNN is trained to recognize a type of signature and asset context, it identifies specific gateways that should receive the extracted specific signatures by inputting the specific asset context and the extracted specific signatures into the trained DNN.

[0116] In one or more embodiments, the present invention is implemented using cloud computing. Nevertheless, although the present disclosure includes detailed descriptions of cloud computing, it should be understood in advance that implementations of the teachings set forth herein are not limited to a cloud computing environment. Rather, embodiments of the present invention can be implemented in conjunction with any other type of computing environment now known or later developed.

[0117] Cloud computing is a model of service delivery for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with a service provider. This cloud model includes at least five characteristics, at least three service models, and at least four deployment models.

[0118] The characteristics are as follows:

[0119] On-Demand Self-Service: Cloud consumers can unilaterally provision computing capabilities such as server time and network storage automatically as needed, without the need for human interaction with the service provider.

[0120] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin-client or thick-client platforms (e.g., cell phones, laptops, and PDAs).

[0121] Resource Sharing: Provider computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated according to demand. Location independence is implied in that consumers generally have no control or knowledge over the exact location of the resources provided, although they can still specify the location at a higher level of abstraction (e.g., country, state, or data center).

[0122] Rapid Scalability: Capabilities can be quickly and elastically provisioned, in some cases automatically, to instantly scale out, and quickly released to instantly scale in. To the consumer, the capabilities available for provisioning often appear unlimited and can be purchased in any quantity at any time.

[0123] Services are meterable: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of the services being used.

[0124] Software as a Service (SaaS): The capability provided to the consumer is the use of the provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through thin-client interfaces such as web browsers (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

[0125] Platform as a Service (PaaS): The capability provided to the consumer is to deploy consumer-created or consumer-acquired applications, written using programming languages ​​and tools supported by the provider, onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but does have control over the deployed applications and, to the extent possible, the application hosting environment configuration.

[0126] Infrastructure as a Service (IaaS): The capability provided to the consumer is the supply of processing, storage, networking, and other basic computing resources on which the consumer can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but does have control over the operating systems, storage, deployed applications, and possibly limited control over select networking components (e.g., host firewalls).

[0127] The deployment model is as follows:

[0128] Private Cloud: The cloud infrastructure is operated solely for an organization. In one or more embodiments, the cloud infrastructure is managed by the organization or a third party and is on-premise or off-premise, or both.

[0129] Community Cloud: The cloud infrastructure is shared by multiple organizations to support a particular community with shared concerns (e.g., mission, security requirements, policy, and compliance considerations). In one or more embodiments, the cloud infrastructure is managed by the organizations or a third party and / or resides on-premise or off-premise.

[0130] Public Cloud: The cloud infrastructure is made available to the general public or large industry organizations and is owned by an organization that sells cloud services.

[0131] Hybrid Cloud: The cloud infrastructure is a composite of two or more clouds (private, community, or public) that remain a unique entity but are joined by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).

[0132] A cloud computing environment is stateless, low-coupling, modular, and service-oriented with a focus on semantic interoperability. At the heart of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0133] Referring now to FIG. 8, an exemplary cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers, such as personal digital assistants (PDAs) or cell phones 54A, desktop computers 54B, laptop computers 54C, and / or automotive computer systems 54N, communicate. The nodes 10 further communicate with each other. In one embodiment, the nodes are physically or virtually grouped in one or more networks, such as a private cloud, a community cloud, a public cloud, or a hybrid cloud, as described above, or a combination thereof (not shown). This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service without the cloud consumer having to maintain resources on the local computing device. It should be understood that the types of computing devices 54A-54N shown in FIG. 8 are intended to be exemplary only, and that the computing node 10 and cloud computing environment 50 may communicate with any type of computerized device via any type of network and / or network addressable connections (e.g., using a web browser).

[0134] Referring now to Figure 9, a set of functional abstraction layers provided by cloud computing environment 50 (Figure 8) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 9 are intended to be merely illustrative, and that embodiments of the present invention are not limited thereto. As shown, the following layers and corresponding functions are provided:

[0135] Hardware and software layer 60 includes hardware and software components. Examples of hardware components include mainframe 61, Reduced Instruction Set Computer (RISC) architecture based servers 62, servers 63, blade servers 64, storage devices 65, and networks and networking components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0136] The virtualization layer 70 provides an abstraction layer within which the following examples of virtual entities are provided in one or more embodiments: virtual servers 71, virtual storage 72, virtual networks including virtual private networks 73, virtual applications and operating systems 74, and virtual clients 75.

[0137] In one example, management layer 80 may provide the functionality described below. Resource provisioning 81 provides dynamic procurement of computing and other resources utilized to execute tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking as resources are utilized within the cloud computing environment and provides billing or invoicing for the consumption of these resources. In one example, these resources include application software licenses. Security provides protection for data and other resources as well as identity verification for cloud consumers and tasks. User portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 provides cloud computing resource allocation and management so that requested service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides pre-positioning and procurement of cloud computing resources where future requirements are anticipated according to SLAs.

[0138] Workload tier 90 provides examples of functions for which a cloud computing environment is used in one or more embodiments. Examples of workloads and functions provided from this tier include mapping and navigation 91, software development and lifecycle management 92, virtual classroom instructional delivery 93, data analytics processing 94, transaction processing 95, and vulnerability response processing 96, which perform one or more of the features of the invention described herein.

[0139] In one or more embodiments, the invention is a system, method, and / or computer program product at any possible level of technical detail of integration. In one or more embodiments, the computer program product includes a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform aspects of the invention.

[0140] A computer readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer readable storage media includes portable computer diskettes, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge structures in grooves that allow instructions to be recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through a fiber optic cable), or electrical signals transmitted through an electrical wire.

[0141] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to the respective computing / processing device or to an external computer or storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical transmission fiber, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium in the respective computing / processing device.

[0142] In one or more embodiments, the computer readable program instructions for carrying out the operations of the present invention include either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state setting data, or source or object code written in any combination of one or more programming languages, including object oriented programming languages ​​such as Java®, Smalltalk®, C++, and traditional procedural programming languages ​​such as the "C" programming language or similar programming languages. In one or more embodiments, the computer readable program instructions execute completely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or completely on a remote computer or server. In the latter scenario and in one or more embodiments, the remote computer is connected to the user's computer through any type of network, including a local area network (LAN) or wide area network (WAN), or the connection is made to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), executes computer readable program instructions by individualizing the electronic circuitry using state information of the computer readable program instructions to perform aspects of the invention.

[0143] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0144] In one or more embodiments, these computer readable program instructions are provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams to produce a machine. In one or more embodiments, these computer readable program instructions are also stored on a computer readable storage medium such that the computer readable storage medium in which the instructions are stored includes an article of manufacture including instructions that perform aspects of the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams, in one or more embodiments directing a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner.

[0145] In one or more embodiments, the computer readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to produce a computer-implemented process that causes the computer, other programmable apparatus, or other device to perform a series of operational steps, such that the instructions, which execute on the computer, other programmable apparatus, or other device, perform the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams.

[0146] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram represents a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions described in the blocks occur out of the order described in the drawings. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may be executed in the reverse order depending on the functionality involved. It should also be noted that in one or more embodiments of the present invention, each block in the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, are implemented by a dedicated hardware-based system that performs the specified functions or operations, or executes a combination of dedicated hardware and computer instructions.

[0147] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It is further understood that the terms "comprises" and / or "comprising", as used herein, specify the presence of stated features, integers, steps, operations, elements, or components, or combinations thereof, and do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or sets thereof, or combinations thereof.

[0148] The corresponding structure, material, acts, and equivalents of all means-plus-function or step-plus-function elements in the following claims are intended to include any structure, material, or acts for performing a function in combination with other claimed elements as specifically claimed. The description of various embodiments of the present invention has been presented for purposes of illustration and description, but is not intended to be exhaustive or to limit the invention to the disclosed forms. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the invention. The embodiments have been selected and described in order to best explain the principles and practical applications of the invention, and to enable others skilled in the art to understand the invention in its various embodiments with various modifications suitable for the particular uses contemplated.

[0149] In one or more embodiments of the present invention, any of the methods described in this disclosure are implemented through the use of VHDL (VHSIC Hardware Description Language) programs and VHDL chips. VHDL is an exemplary design entry language for field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), and other similar electronic devices. Thus, in one or more embodiments of the present invention, any of the software-implemented methods described herein are emulated by a hardware-based VHDL program that is then applied to a VHDL chip, such as an FPGA.

[0150] Thus, while the embodiments of the invention of this application have been described in detail and with reference to exemplary embodiments thereof, it will be apparent that modifications and variations are possible without departing from the scope of the invention as defined in the appended claims.

Claims

1. 1. A method for protecting computer assets, comprising: receiving, by a computer, a plurality of signatures, different signatures from the plurality of signatures being characteristic of different types of computer assets; the computer identifying a particular signature from the plurality of signatures, the particular signature being specific to a particular type of computer asset, the particular signature being code that causes a particular gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset, the particular computer asset having a particular asset context that is specific to the particular computer asset; extracting, by the computer, the particular signature from the plurality of signatures based on the particular asset context; said computer identifying a particular gateway protecting said particular computer asset; installing the particular signature extracted from the plurality of signatures only on the particular gateway; A method comprising:

2. 2. The method of claim 1 , wherein the particular computer asset is a database system, and the particular asset context describes a vulnerability level of the database system, an identity of the database system, a hostname of a host computer on which the database system runs, and an operating system used by the database system.

3. 3. The method of claim 1 or claim 2, wherein the particular computer asset is a database program, and the particular asset context describes a vulnerability level of the database program, an identification of the database program, a host name of a host computer on which the database program runs, a database system used by the database program, and an operating system used by the database system.

4. A method according to any one of claims 1 to 3, further comprising the computer performing a natural language processing (NLP) analysis on a set of vulnerabilities to extract risk-related information, the set of vulnerabilities describing vulnerabilities that apply to the particular gateway, and the risk-related information including a list of vulnerable network resources that are vulnerable to the intrusion and are protected by the particular gateway.

5. 5. The method of claim 1, wherein the vulnerability of the particular computer asset to the intrusion is from a set of identified vulnerabilities, the set of identified vulnerabilities being identified in a Common Vulnerabilities and Exposures (CVE) list generated by a third party that monitors vulnerabilities for multiple computer systems.

6. The method includes: training a deep neural network (DNN) to identify the particular gateway by inputting known training signatures and known training asset context to the DNN; The computer identifies the particular gateway by inputting the particular asset context and the particular signature extracted into the trained DNN; The method of any of claims 1 to 5, further comprising:

7. A computer program product for causing a computer to execute the method according to any one of claims 1 to 6.

8. A computer-readable storage medium having the computer program of claim 7 recorded thereon.

9. The computer-readable storage medium of claim 8 , wherein the computer program is provided as a service in a cloud environment.

10. 1. A computer system comprising one or more processors, one or more computer readable memories, and one or more computer readable non-transitory storage media, wherein program instructions are stored in at least one of the one or more computer readable non-transitory storage media for execution by at least one of the one or more processors via at least one of the one or more computer readable memories, the stored program instructions comprising: receiving a plurality of Intrusion Prevention System (IPS) signatures, different IPS signatures from the plurality of IPS signatures being specific to different types of IPS gateways protecting different types of computer assets; identifying a particular IPS signature from the plurality of IPS signatures, the particular IPS signature being specific to a particular type of computer asset, the particular IPS signature being code that causes a particular IPS gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset, the particular computer asset having a particular asset context that is specific to the particular computer asset; extracting the particular IPS signature from the plurality of IPS signatures based on the particular asset context; identifying a particular IPS gateway protecting said particular computer asset; installing the particular IPS signature extracted from the plurality of IPS signatures only in the particular IPS gateway; A computer system configured to perform a method including:

11. 11. The computer system of claim 10, wherein the particular computer asset is a database system, and the particular asset context describes a vulnerability level of the database system, an identity of the database system, a hostname of a host computer on which the database system runs, and an operating system used by the database system.

12. 12. The computer system of claim 10 or claim 11, wherein the particular computer asset is a database program, and the particular asset context describes a vulnerability level of the database program, an identification of the database program, a host name of a host computer on which the database program runs, a database system used by the database program, and an operating system used by the database system.

13. The method further comprising:

13. The computer system of claim 10, further comprising: performing a natural language processing (NLP) analysis on a set of vulnerabilities to extract risk-related information, the set of vulnerabilities describing vulnerabilities that apply to the particular IPS gateway, the risk-related information including a list of vulnerable network resources that are vulnerable to the intrusion and are protected by the particular IPS gateway.

14. 14. The computer system of claim 10, wherein the vulnerability of the particular computer asset to the intrusion is from a set of identified vulnerabilities, the set of identified vulnerabilities being identified in a Common Vulnerabilities and Exposures (CVE) list generated by a third party that monitors vulnerabilities for multiple computer systems.

15. The method further comprising: training a deep neural network (DNN) to identify the particular IPS gateway by inputting known training signatures and known training asset context into the DNN; Identifying the particular IPS gateway by inputting the particular asset context and the particular IPS signature extracted into the trained DNN; 15. The computer system of claim 10, further comprising:

16. The computer system of claim 10 , wherein the program instructions are provided as a service in a cloud environment.

17. A method for protecting computer assets, comprising: the computer identifying a particular signature, the particular signature being specific to a particular type of computer asset, the particular signature being code that causes a particular gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset, the particular computer asset having a particular asset context that is specific to the particular computer asset; training a deep neural network (DNN) to identify a particular gateway by inputting known training signatures and known training asset context to the DNN; The computer identifies the particular gateway by inputting a particular asset context and a particular signature into the trained DNN; said computer installing said particular signature only on said particular gateway; A method comprising:

18. A computer program for causing a computer to execute the method according to claim 17.

19. A computer system comprising one or more processors, one or more computer-readable memories, and one or more computer-readable non-transitory storage media, wherein program instructions are stored in at least one of the one or more computer-readable non-transitory storage media for execution by at least one of the one or more processors via at least one of the one or more computer-readable memories, the stored program instructions comprising: identifying a particular signature, the particular signature being specific to a particular type of computer asset, the particular signature being code that causes a particular gateway to block an intrusion from reaching a particular computer asset of the particular type of computer asset, the particular computer asset having a particular asset context that is specific to the particular computer asset; training a deep neural network (DNN) to identify a particular gateway by inputting the known training signatures and the known training asset context into the DNN; Identifying the particular gateway by inputting a particular asset context and a particular signature into the trained DNN; Installing said particular signature only on said particular gateway; A computer system configured to perform a method including:

Citation Information

Patent Citations

  • Unauthorized access prevention program

    JP2003288282A

  • Threat analysis support method, threat analysis support device, and threat analysis support program

    JP2016218964A

  • Computer, selection method, and selection program

    JP2018045329A

  • Firewall device

    JP2019103039A

  • Brittleness information generator and brittleness evaluation device

    JP2019192101A