Security Policy Selection Based on Calculated Uncertainty and Predicted Resource Consumption
By employing a machine learning model to calculate IT security policies based on uncertainty and resource consumption, the method addresses the inefficiencies in existing security policy implementations, offering a more streamlined and risk-aligned solution.
Patent Information
- Application Number
- JP2024521911
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-11-18
- Filing Date
- 2023-02-23
- Publication Date
- 2025-06-18
- Estimated Expiration
- 2043-02-23
AI Technical Summary
Existing methods for implementing IT security policies in dynamic IT environments are time-consuming and resource-intensive, often lacking understanding of the actual impact of changing security settings among clients, application owners, and IT staff.
A computer-implemented method using a trained machine learning model to analyze IT information and calculate a security policy based on calculated uncertainty and predicted resource consumption, with the results presented on a dashboard for user clients.
This approach significantly reduces the time and resources required for implementing IT security policies, providing tailored security measures that align with client risk appetites without overwhelming business operations.
Smart Images

Figure 0007695477000001 
Figure 0007695477000002 
Figure 0007695477000003
Abstract
Description
Technical Field
[0001] The present invention relates to security policies applied in an information and technology (IT) environment. More specifically, the present invention relates to calculating the security policy based on the calculated uncertainty and the predicted amount of resource consumption respectively associated with the application of the recommended security policy.
Background Art
[0002] An IT environment may include a series of applications on top of IT components such as server systems, computer networks, networking devices, and computer devices communicating with at least one other computer device. Further, these applications may include any known type of business application that can be managed by a business administrator. Within such an IT environment, IT components may be decomposed into subgroups of IT components, each associated with and managed by different actors such as clients, administrators, businesses, etc.
[0003] The IT environment is constantly changing, for example, due to human interaction, due to system-to-system interaction, due to security threats to one or more deployments in the evolving IT environment, etc. To keep the IT environment secure, a series of IT security policies are typically applied to the IT environment to minimize the security risk that an inappropriate or vulnerable configuration may result in or enable a situation that can be exploited by an attacker within the IT environment.
[0004] These security policies are intended to provide a customized level of security that is valuable for an IT infrastructure tailored to the business operated by an enterprise. It is not easy to identify all security issues that an IT infrastructure can bring to business applications, such as malware, a situation where custom data is accessible to unauthorized parties, phishing attacks, compliance laws, etc. Furthermore, depending on security issues and potential ways in which those issues can be exploited, the risks that these issues pose to such applications or infrastructure or both can be relatively low or relatively high. Therefore, an enterprise aims to implement an IT security policy that can surely keep security risks low and does not affect the business operations of the enterprise.
Summary of the Invention
[0005] According to one embodiment, a computer-implemented method includes receiving a request to perform a security policy implementation analysis for a first deployment associated with a first client in an IT environment. IT information associated with the first deployment is collected. The method further includes applying a trained machine learning model to analyze the IT information of the first client to calculate a security policy for the first deployment. The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment. The indication of the security policy is an output for presentation on a dashboard of a user device of the first client.
[0006] A computer program product, according to another embodiment, includes a computer-readable storage medium having program instructions embodied therein. The program instructions are executable by a computer to cause the computer to perform the aforementioned method.
[0007] A system, according to another embodiment, includes a hardware processor and logic integrated with the processor, the logic being executable by the processor or integrated with and executable by the processor. The logic is configured to perform the aforementioned method.
[0008] Other aspects and embodiments of the present invention will become apparent from the following detailed description, which illustrates the concepts of the present invention by way of example in conjunction with the drawings.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 3C
Figure 3D
Figure 3E
Figure 4
Figure 5
Figure 6
Embodiments for Carrying Out the Invention
[0010] The following description is made for the purpose of explaining the general principles of the present invention and does not mean to limit the concept of the invention claimed in this specification. Further, the specific features described in this specification can be used in combination with each of the other described features in various possible combinations and permutations.
[0011] Unless otherwise specifically defined in this specification, all terms are given the broadest possible interpretation, including the meaning derived from this specification and the meaning understood by those skilled in the art or defined in a dictionary, academic paper, etc., or both.
[0012] Also, note that when used in this specification and the appended claims, the singular forms "a", "an", and "the" include references to the plural unless otherwise specified. The term "comprises" or "comprising" or both, when used in this specification, specifies the presence of the described feature, integer, step, operation, element, or component, or a combination thereof, but does not further exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof, or a combination thereof.
[0013] The following description discloses some preferred embodiments of a system, method, and computer program product for calculating the above security policy based on the calculated uncertainty and predicted amount of resource consumption respectively associated with the application of the recommended security policy.
[0014] In one general embodiment, a computer-implemented method includes receiving a request to perform a security policy implementation analysis for a first deployment associated with a first client in an IT environment. IT information associated with the first deployment is collected. The method further includes applying a trained machine learning model to analyze the IT information of the first client and calculate a security policy for the first deployment. The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment. The indication of the security policy is output for presentation on a dashboard on a display of a user device of the first client.
[0015] In another general embodiment, a computer program product includes a computer-readable storage medium having program instructions embodied therein. The program instructions are executable by a computer to cause the computer to perform the aforementioned method.
[0016] In another general embodiment, a system includes a hardware processor and logic integrated with the processor, the logic being executable by or integrated with the processor and configured to perform the aforementioned method.
[0017] FIG. 1 illustrates an architecture 100 according to one embodiment. As shown in FIG. 1, a plurality of remote networks 102 are provided including a first remote network 104 and a second remote network 106. A gateway 101 may be coupled between the remote network 102 and the proximal network 108. In the context of architecture 100 here, networks 104 and 106 may each take any form including, but not limited to, a local area network (LAN), a wide area network (WAN) such as the Internet, a public switched telephone network (PSTN), an international telephone network, and the like.
[0018] In use, the gateway 101 serves as an entry point from the remote network 102 to the proximal network 108. Thus, the gateway 101 may function as a router capable of directing a given data packet arriving at the gateway 101, and as a switch supplying an actual path in and out of the gateway 101 for a given packet.
[0019] Further included is at least one data server 114 coupled to the proximal network 108 and accessible from the remote network 102 via the gateway 101. It should be noted that the data server 114 may include any type of computing device / groupware. Coupled to each data server 114 are a plurality of user devices 116. The user devices 116 may also be directly connected through one of the networks 104, 106, and 108. Such user devices 116 may include a desktop computer, a laptop computer, a handheld computer, a printer, or any other type of logic. It should be noted that in one embodiment, the user device 111 may also be directly coupled to any network.
[0020] Peripheral device 120 or a series of peripheral devices 120, such as a facsimile device, a printer, a networked or local storage unit or system, or both, may be coupled to one or more of networks 104, 106, and 108. It should be noted that a database or additional component or both are utilized in conjunction with or integrated within any type of network element coupled to networks 104, 106, and 108. In the context of this description, a network element may refer to any component of a network.
[0021] According to some approaches, the methods and systems described herein may be implemented by, or on, or both, a virtual system, or a system that emulates one or more other systems, or both. The other systems may be, for example, a UNIX (registered trademark) system that emulates an IBM (registered trademark) z / OS (registered trademark) environment (IBM and all IBM-based trademarks and logos are trademarks or registered trademarks of International Business Machines Corporation or its affiliates), a UNIX (registered trademark) system that effectively hosts a known operating system environment, an operating system that emulates an IBM (registered trademark) z / OS (registered trademark) environment, etc. This virtualization or emulation or both may be enhanced in some embodiments through the use of VMware (registered trademark) software.
[0022] In still more approaches, one or more of the networks 104, 106, and 108 may represent a cluster of systems referred to as a "cloud." In cloud computing, shared resources such as processing power, peripheral devices, software, data, servers, etc. are provided to any system within the cloud on an on-demand basis, thereby enabling access and distribution of services across a number of computing systems. Cloud computing typically includes an Internet connection between the systems operating within the cloud, although other techniques for connecting those systems may also be used.
[0023] FIG. 2 shows a representative hardware environment associated with the user device 116 or the server 114 or both of FIG. 1 according to one embodiment. Such a figure shows a typical hardware configuration of a workstation having a central processing unit 210, such as a microprocessor, and a plurality of other units interconnected via a system bus 212.
[0024] The workstation shown in FIG. 2 includes a random access memory (RAM) 214, a read only memory (ROM) 216, an input / output (I / O) adapter 218 for connecting peripheral device units such as a disk storage unit 220 to the bus 212, a user interface adapter 222 for connecting other user interface devices or combinations thereof such as a keyboard 224, a mouse 226, a speaker 228, a microphone 232, or a touch screen and a digital camera (not shown) to the bus 212, a communication adapter 234 for connecting the workstation to a communication network 235 (e.g., a data processing network), and a display adapter 236 for connecting the bus 212 to a display device 238.
[0025] The workstation has a resident operating system thereon, such as, for example, the Microsoft Windows® operating system (OS), macOS®, UNIX® OS, etc. It will be appreciated that the preferred embodiments may also be implemented on platforms and operating systems other than those described. The preferred embodiments may be written in accordance with object-oriented programming methodologies using, for example, eXtensible Markup Language (XML), C, and / or C++ language, or other programming languages. Object-oriented programming (OOP), which is becoming increasingly used to develop complex applications, may be used.
[0026] The present invention can be a system, method, or computer program product, or a combination thereof, at any possible technical detail level of integration. The computer program product can include a computer-readable storage medium having computer-readable program instructions for causing a processor to implement aspects of the present invention.
[0027] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction-executing device. The computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following, namely, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disks (DVD), memory sticks, floppy (registered trademark) disks, punch cards, or mechanical encoding devices such as raised structures within grooves in which instructions are recorded, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed to be a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.
[0028] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to respective computing / processing devices, or to an external computer or external storage device via a network, such as, for example, the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. Each computing / processing device's network adapter card or network interface receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage on a computer-readable storage medium within the respective computing / processing device.
[0029] Computer-readable program instructions for carrying out the operation of the present invention may be source code or object code written in any combination of one or more programming languages, including assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk® and C++, and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially executed on the user's computer as a stand-alone software package, partially executed on the user's computer and a remote computer respectively, or executed entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to implement aspects of the present invention, an electronic circuit, including for example a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to customize the electronic circuit.
[0030] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products in accordance with embodiments of the invention. It will be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0031] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a means for causing the instructions executed via the processor of the computer or other programmable data processing apparatus to implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, a programmable data processing apparatus, or other devices to function in a particular manner, such that the medium storing the instructions constitutes a product including instructions for implementing the aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0032] The computer-readable program instructions may also be loaded onto a computer, other programmable apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0033] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible embodiments of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, segment, or portion of a module that includes one or more executable instructions for implementing the specified logical function. In some alternative embodiments, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may in fact be accomplished as one step, executed simultaneously, substantially simultaneously, or in a partially or wholly temporally overlapping manner, or the blocks may sometimes be executed in the reverse order depending on the functionality involved. It should also be noted that each block of the block diagram or flowchart diagram, or both, and combinations of blocks in the block diagram or flowchart diagram, or both, can be implemented by a dedicated hardware-based system that performs the specified function or operation or implements a combination of dedicated hardware and computer instructions.
[0034] Furthermore, systems according to various embodiments include a processor and logic that may be integrated with the processor or executable by the processor or both, the logic being configured to perform one or more of the process steps described herein. The processor may be any configuration as described herein, such as a separate processor or processing circuit including a number of components such as processing hardware, memory, I / O interfaces, etc. Being integrated means that the processor has logic embedded as hardware logic therewith, for example, an application specific integrated circuit (ASIC), FPGA, etc. Being executable by the processor means that the above logic is either hardware logic, or software logic such as firmware, a part of the operating system, a part of an application program, etc., or some combination of hardware and software logic that is accessible by the processor and configured to cause the processor to perform some functions. The software logic may be stored in local or remote or both memories of any memory type known in the art. Any processor known in the art may be used, for example, a software processor module, or a hardware processor such as an ASIC, FPGA, central processing unit (CPU), integrated circuit (IC), graphics processing unit (GPU), etc.
[0035] As described elsewhere above, an IT environment may include a series of applications on top of IT components such as server systems, computer networks, networking devices, and computer devices communicating with at least one other computer device. Further, these applications may include any known type of business application that can be managed by a business administrator. Within such an IT environment, the IT components may be broken down into subgroups of IT components that are each associated with and managed by different actors such as clients, administrators, businesses, etc.
[0036] The IT environment is constantly changing, for example, due to human interaction, due to system-to-system interaction, due to security threats to one or more deployments in the evolving IT environment, etc. To ensure the security of the IT environment, a series of IT security policies are typically applied to the IT environment to minimize the security risk that an inappropriate or vulnerable configuration could result in or enable a situation where it is exploited by an attacker within the IT environment.
[0037] These security policies are intended to provide a customized level of security that is valuable for an IT infrastructure that aligns with the business operated by an enterprise. It is not easy to identify all security issues such that the IT infrastructure can bring into business applications, for example, malware, a state where custom data is accessible to unauthorized parties, phishing attacks, compliance laws, and so on. Further, depending on security issues and potential ways in which those issues can be exploited, the risk that these issues pose to such applications or infrastructure or both can be relatively low or relatively high. Therefore, an enterprise aims to implement an IT security policy that surely keeps security risks low and does not affect the business operations of the enterprise.
[0038] To implement these security policies, it is useful to understand the entire IT environment, such as the technology of the IT environment, the products included in the IT environment, the industry, the purpose of business applications, etc. Using this information, IT security policies may be selected and applied to one or more deployments within the IT environment. However, the problem with this approach is that it is a time-consuming activity and does not consider the fact that there is often a lack of understanding among clients, application owners, and IT staff about the actual impact of changing IT security settings in the IT environment. Clients typically understand the need and importance of IT security policies. However, when it comes to the deployment of security policies, there are typically a very large number of barriers commonly raised. Therefore, in some cases, security policies are deployed sporadically, but doing so consumes a significant amount of resources from the entire organization, such as labor, cost, time, potential processing power, etc. Therefore, there has been a long-standing need to deploy a predictive method for mapping and identifying the entire landscape, analyzing IT information to determine a way to match the client's business applications, and constructing IT security policies that can meet the client's security needs and be implemented without imposing any burden on the client.
[0039] In sharp contrast to the above-described deficiencies, the various embodiments and approaches described herein are intended to change and transform how IT security policies are evaluated and implemented. Machine learning algorithms are implemented to verify the client environment, analyze executable IT security actions, and evaluate the risks and effort associated with each such action. Next, the client's uncertainty level is identified, and IT policies that can be applied based on the client's desires for risk are proposed. Using these approaches, the time consumed in applying IT security policies constructed for the client's business can be significantly reduced, and as a result, the client's costs can be saved while reducing IT intervention. In context, a "security policy" may be defined as a set of hardening parameters that can be implemented and configured in any type of technical system in an IT environment, for example, as the password length for accessing an application on a mobile phone. Thus, in some approaches, a security policy is a document that describes the technical measurements and controls that can be implemented in an environment to guarantee a certain level of security for data and systems. Further, the "uncertainty" of a security policy may be defined, such that the client purchases a security policy without knowing the risk of applying certain parameters, such as the compatibility of the policy with the existing features of the application.
[0040] Next, referring to FIG. 3, a flowchart of method 300 is shown according to one embodiment. Method 300 may be implemented according to the present invention in any of the environments illustrated in FIGS. 1-6, among other embodiments. Of course, as will be understood by those skilled in the art upon reading this description, method 300 may include more or fewer operations than specifically described in FIG. 3.
[0041] Each step of method 300 may be performed by any suitable component of the operating environment. For example, in various embodiments, method 300 may be performed, in whole or in part, by a computer or by a plurality of other devices having one or more processors therein. A processor implemented in hardware or software or both, preferably having at least one hardware component, such as a processing circuit, chip, or module, or combinations thereof, may be utilized in any device to perform one or more steps of method 300. Illustrative processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art.
[0042] It may be preferable for method 300 to include a novel approach for calculating the security policy based on the calculated uncertainty and predicted amount of resource consumption respectively associated with the application of the recommended security policy. These approaches may be deployed as a service, or incorporated into a security product, or both. More specifically, these approaches include automatically evaluating and identifying such IT security policies. Also, a predictive machine learning model is used to identify uncertainties and deploy security actions or security fixes. Further, a predictive machine learning model is used to determine the effort and time required to apply a security fix, and a genetic algorithm is used to calculate an optimized IT security policy that can be marked on a client's user device. As described in more detail elsewhere in this specification, the benefits of these approaches include reducing the time spent by the infrastructure support team, functional teams, and business areas that analyze the impact of each IT security policy action. This is because uncertainties are calculated and provided to the user before the user purchases or instructs the application of such a policy. These approaches may be used additionally or alternatively or both to properly evaluate the costs and effort consumed at the time of deploying an IT security policy and associated with that deployment.
[0043] Method 300 may preferably include a training portion 302 for training a machine learning algorithm, more specifically a training phase for patches related to a machine learning model. Method 300 further includes an application portion 304 for applying the trained machine learning algorithm.
[0044] Referring first to the training portion 302 of FIG. 3, operation 306 includes reading a list of regulatory and industry standards. More specifically, such reading is performed on an external source that lists all regulatory and industry standards applicable to the deployment of clients that require security policy implementation analysis. A client deployment is, for example, one or more applications or physical systems or both of an IT environment that are managed or provided as one or more IT security policies, business solutions, product interfaces, storage platforms, computing resources, etc. currently deployed in the IT environment. A client deployment may have one or more IT security policies that protect that deployment. Further, in some approaches, an IT environment includes multiple deployments. Each deployment within this multiple may be protected by one or more IT security policies, which may be specifically designed for one or more of the above deployments. In some approaches, at least one IT security policy may be applied to multiple deployments. It is important to note that, in order to operate a deployment in accordance with the listed regulatory and industry standards, these IT security policies may cause one or more IT security actions to be performed. In this context, the list of regulatory and industry standards read may, in some preferred approaches, be the regulatory and industry standards applicable to client deployments in an IT environment. In some other approaches, since the training portion 302 of method 300 is performed to train a machine learning model, one or more regulatory and industry standards may not be applicable to client deployments.
[0045] The above list may be an external database of regulatory and industry standards, which, in some approaches, inputs regulatory and industry requirements 308 received from one or more resources, such as laws, decrees, statutes, administrator requirements, client requirements, communication forums, websites, etc. According to some approaches, the list of regulatory and industry standards may include unstructured textual fields. For example, in one such approach, the unstructured textual field may include a title and description indicating the purpose of the regulatory standard and the industry / field. In another such approach, the unstructured textual field may include a list, such as a list of certain important security measures. In yet another such approach, the unstructured textual field may include detailed security implementations. Such implementations may provide a detailed description of one or more security actions and regulatory actions that are to be deployed to ensure compliance with one or more standards. According to some other approaches, the list of regulatory and industry standards may additionally or alternatively or both include structured data. For example, in one such approach, the structured data may be products and versions that provide information about the version of the standard.
[0046] Operation 310 includes extracting descriptive security configurations from products. Note that the information for Operation 310 may be extracted from known sources of technology and product security best practices 303. In this step, information regarding the IT security configurations available for each product in the IT environment is extracted. In some suitable approaches, the extracted information includes unstructured text fields or structured data or both. For example, unstructured text fields may include, for example, titles and descriptions giving information about the product, lists of important security measures, detailed security implementations showing detailed descriptions of security configuration settings, etc. Structured data may, in some illustrative approaches, include, for example, product, version, and security identifications.
[0047] As seen, for example, in Operation 312, IT security risk mapping may be received. In some approaches, the IT security risk mapping is received from a type of security risk management engine that would be apparent to one of ordinary skill in the art upon reading the description herein. As seen, for example, in Operation 314, the level of IT security risk may be read for each mapped configuration. In this reading step, the reading may be performed for each IT security action and the level of impact (or criticality) of each risk that may occur in the IT environment. For example, a File Transfer Protocol (FTP) enabling the IT environment may be considered a relatively high-risk action, while the fact that such a protocol is disabled may be considered a relatively low-risk action. These levels of IT security risk may be read from unstructured text fields identified to include, for example, descriptions and levels of one or more security risks.
[0048] Training a machine learning model may additionally or alternatively or both include reading IT information associated with the deployment of a training IT environment. In some other approaches, as seen for example in application 304, training a machine learning model may additionally or alternatively or both include reading IT information from the IT environment in which the trained model is to be applied. For example, in at least one such approach, information may be received from a client IT environment, as seen for example in "from the client IT environment". In another example, as seen for example in operation 316, information is read from the client IT environment to be analyzed, additionally or alternatively or both. In some approaches, this information is read from client IT tools. This information may include information related to business applications, IT systems deployed per application, deployed products, system configurations, importance matrices, application code deployed on each system, etc. In some approaches, this information may be read from unstructured text fields. For example, one or more of these unstructured text fields may include component names and configuration settings, which may detail a list of configuration settings related to security or IT security policies or both available for deployment in the IT environment, for example in one or more deployments of the IT environment. In some other approaches, this information may be read from structured data, which may include a list of business applications, applications, IT components, and products deployed for each component within the IT environment, etc.
[0049] Reading IT information to train a machine learning model may additionally or alternatively or both include reading application mappings associated with at least one deployment of a training IT environment. For example, operation 318 includes reading application mappings and importance levels of business systems from a client IT environment. This reading operation may include reading a list of business applications installed in the IT environment and the importance levels of each application and mapping of all IT components deployed for each application. In some approaches, this information may be read from unstructured text fields, such as titles, and descriptions such as lists of business applications and importance matrices. In some other approaches, this information may be read from structured data, such as mapping lists of business systems, applications, and IT components.
[0050] Information about the servers and products associated with the deployment may be received additionally or alternatively or both for training a machine learning model. For example, operation 320 includes reading information about the servers and products deployed in the IT environment. Here, an inventory list of IT components installed in the client part of the environment is read, for example, the client deployment and the details of each product installed therein. This information, in some approaches, is read from unstructured text fields, such as titles and descriptions that may provide information about the product, lists including important security measures, detailed security implementations that may provide detailed descriptions of each security configuration setting, etc. This information, in some other approaches, is read from structured data, such as products or versions or both, and support packages that may provide information about the versions of the products, etc. Application code associated with the deployment of the IT environment may be read additionally or alternatively or both for training a machine learning model. For example, operation 322 includes reading the deployed application code from the IT environment. More specifically, operation 322, in some approaches, includes reading all the application code deployed on each server to identify programming practices that deviate from a set of predetermined best security practices, such as hard-coded IP addresses or certificates. The application code may include unstructured text fields, such as programming code that may identify hard-coded programming steps that do not consider predetermined best security practices. The application code may additionally or alternatively or both include structured data, such as programs associated with each IT component, etc.
[0051] Method 300 may, in some approaches, include calculating risk-level errors derived from components and applications deployed in an IT environment. For example, operation 324 includes identifying all risk-level errors of each IT security-mapped ID derived from the analyzed IT components. In this step, the risk-level errors of each IT security action related to the IT component are identified. For example, the chmod of a defined proper file system, or the level of risk when widely open, e.g., when being vulnerable beyond a predetermined risk threshold, or both may be determined.
[0052] IT information may be converted into a training data set for training a machine learning model. For example, operation 326 includes converting IT information into a training data set of variables to train at least one machine learning model, e.g., preferably a machine learning model of an uncertainty level. In some approaches, this conversion may include calculating variables by calculating risk-level errors of each IT security action related to the IT component, such as the chmod of a defined proper file system and the level of risk when widely open, to train a machine learning model of an uncertainty level.
[0053] Operation 328 includes adopting natural language processing (NLP) techniques for text fields. More specifically, in this step, a predetermined natural language process (NLP) algorithm may be used to remove any unimportant words from the unstructured text fields shown in the IT information of Operation 310. Thereafter, preferably, a predetermined bag-of-words process is adopted to obtain a vector representation of the unstructured text information of the workflow. At this point, the dataset has the vector representation and the structured data as inputs and has an output including acceptance and time for installing variables, for example, those installed for deploying IT security policies.
[0054] As can be seen in Operation 330 as an example, dimensionality reduction techniques that will be apparent to those skilled in the art upon reading the description herein may be adopted for text fields. In some approaches, these may include dimensionality reduction techniques for the space formed by the sparse matrix of bag-of-words vectors. This step is extremely important for combining the vector representation obtained in Operation 328 with structured variables in order to avoid loss of the fitness of the structured fields when facing the high dimensionality of the vector representation of the unstructured text fields. In one possible approach, the application of the dimensionality reduction technique may include principal component analysis (PCA) or latent semantic analysis (LSA) or both.
[0055] In Operation 332, the risk-level error of each IT security mapped ID derived from the analyzed IT component is calculated. In this step, it is preferable that the risk-level error of each IT security action related to each analyzed component is calculated.
[0056] As seen in operation 334 for example, the risk level error of each business application, e.g., those derived from application and importance mapping, may be calculated additionally or alternatively or both. More specifically, in some approaches, the risk level error of each business application based on the risk level identified in operation 332 and the importance matrix may be calculated.
[0057] As seen in operation 336 for example, assemble a data set for training a machine learning model of an uncertainty level. In this step, the data set may be formed by all regulatory criteria read in operation 306, data of technologies and technology-by-technology security best practices and related risks read in operations 310 and 314, and IT environment information data read in operations 316, 318, 320, and 322 and calculated in operations 324, 326, 332, and 334. This data set may be characterized as having inputs of unstructured text fields read in operations 306, 310, 314, and 316 and converted in operations 328 and 330, and inputs of structured data read in operations 314, 316, 318, 320, and 322.
[0058] Operation 338 includes, for example, training an uncertainty level prediction machine learning model to analyze IT information using the data set assembled in operation 336. In some suitable approaches, a supervised machine learning technique may be employed to infer an uncertainty prediction machine learning model that maps the input and output variables described in operation 336. Assuming that the input and output variables are either separate or countable, or can be converted to this format, some possible approaches to supervised machine learning techniques are naive bayes, support vector machine (SVM), and standard neural network (multilayer perceptron). As a result of this training, the uncertainty level prediction machine learning model is preferably trained to calculate the uncertainty of the effects that can be caused by applying security policies to the deployment.
[0059] Operation 340 includes assembling a data set and training a labor machine learning model. In some approaches, the data set can be formed by all regulatory criteria read in operation 306, data on technologies and technology-by-technology security best practices and associated risks read in operations 310 and 314, and IT environment information data read in operations 316, 318, 320, and 322 and calculated in operations 324, 326, 332, and 334. This data set may have the characteristic of having inputs including unstructured text fields read in operations 306, 310, 314, and 316 and converted in operations 328 and 330, and inputs including structured data read in operations 314, 316, 318, 320, and 322.
[0060] As seen in operation 342 for example, the second machine learning model is trained using the training data set developed in operation 340. In some approaches, this training may employ a supervised machine learning technique to infer an acceptance prediction machine learning model that maps the input and output variables described in operation 340. Assuming that the time to install the output variable is continuous, possible approaches to the supervised machine learning technique are support vector machines (SVMs) and standard neural networks (multilayer perceptrons). The second machine learning model is a labor prediction machine learning model trained to predict the resource consumption resulting from applying a security policy to a deployment.
[0061] Operation 344 includes storing the trained machine learning model in a predetermined database, such as a database of an IT environment. In some approaches, the trained machine learning model is stored in a predetermined repository that is later used in application part 304 of method 300 to apply the trained machine learning algorithm to determine a security policy for deployment of the IT environment.
[0062] In some approaches, the machine learning model should be noted to be able to (at least partially) progress during training part 302 of method 300, using a supervising specialist, for example, one or more confirmations by a subject matter expert (SME), until a decision is made that the machine learning model exceeds a predetermined accuracy threshold for analyzing the client's IT information to calculate a security policy for a first deployment. Refer to application part 304 of method 300 below, which includes various operations for applying the trained machine learning algorithm.
[0063] Operation 346 includes receiving, from a user device used by a first client of the IT environment, a request to perform a security policy implementation analysis on a first deployment associated with the first client in the IT environment. In some approaches, the first deployment, the IT environment, or both may be based on when the machine learning model was trained. The first deployment may include at least one application that operates on at least one device such as a server in the IT environment. In some approaches, IT information, such as IT information associated with at least the first deployment, may be collected, as seen, for example, in Operation 348. In some other approaches, the IT information may be received along with the above request, as referenced, for example, in Operation 352, received after issuing a query to the user device, and accessed in a predetermined database, etc. In some preferred approaches, this IT information is of the same type as the information described in one or more of Operations 318, 320, and 322, or information using a similar approach described in such operations, or both. As seen, for example, in Operation 350, an indication of the level of risk that can be tolerated during the operation of one or more business applications deployed in the first deployment of the IT environment, for example, that the first deployment can currently support in the IT environment, may be received, for example, the criteria or desires of the client's IT risk. For example, such criteria or desires of the client's IT risk can be, for example, high, medium, and low levels, where medium has a relatively higher risk criteria or desire than low, and high has a relatively higher risk criteria or desire than medium.
[0064] Operation 354 includes reading out the uncertainty prediction machine learning model trained in Operation 338. Apply the trained uncertainty prediction machine learning model to analyze the IT information of the deployment of the first client and calculate the security policy of the first deployment. More specifically, Operation 356 includes applying, for example, executing the trained prediction uncertainty machine learning model to predict the level of uncertainty. In context, "uncertainty" preferably correlates with the calculated uncertainty of the effects that can be caused by applying the IT security policy to the first deployment. For example, these effects may include, in some approaches, unknown amounts of processing resources resulting from applying the security policy, secondary effects resulting from applying the security policy, etc. The effects that can be caused by applying the security policy to the first deployment may additionally or alternatively or both include, for example, secondary effects caused by the security policy on the customer characteristics provided by the application of the first deployment, private customer information that is becoming inadvertently accessible, loss of access events to applications via login, loss of functionality of the components of the first deployment, etc. Thus, in some approaches, the level of uncertainty is, for example, deeply uncertain, uncertain, dangerous, clear, etc., and is based on inputting at least some IT information into the trained uncertainty prediction machine learning model, and the level of uncertainty is generated as the output of the trained prediction uncertainty machine learning model. It should be noted that an IT security policy with a relatively high level of uncertainty, for example, deeply uncertain, is predicted to have the potential to cause a greater degree of unknown effects in the deployment as a result of being applied in the IT environment, while an IT security policy with a relatively low level of uncertainty, for example, clear, is predicted to have the potential to cause a smaller degree of unknown effects in the deployment as a result of being applied in the IT environment.
[0065] As seen in operation 358 for example, a second machine learning model trained in operation 338, e.g., a trained labor prediction machine learning model, may be additionally or alternatively or both read out. Further, a trained predictive uncertainty machine learning model may be applied to analyze the IT information of the deployment of the first client and calculate a security policy for the first deployment. More specifically, operation 360 includes predicting the labor, e.g., the amount of resources of the first deployment, that will be consumed by applying a security policy to the first deployment using a trained machine learning model. The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of the resources of the first deployment that will be consumed by applying the security policy to the first deployment. The security policy may be calculated based on, additionally or alternatively or both, the predicted amount of the resources of this first deployment that will be consumed by applying the security policy to the first deployment. This amount of resources may be predicted by applying, e.g., executing, a trained labor prediction machine learning model.For example, in some approaches, these resources are consumed by, for example, incorporating the update of existing security policies in an IT environment, such as processing resources, a certain amount of time taken by applying security policies, a certain degree of supervision or time or both required of the deployment administrator, a certain amount of output consumed by applying security policies in an IT environment, a certain amount of additional physical resources required by the deployment to apply security policies in an IT environment, a certain amount of logical resources required by the deployment to apply security policies in an IT environment, the cost borne by the first client, the consultation of a content area subject matter expert (SME), the processing operations dedicated to troubleshooting operations, the time spent on updating the application associated with the first deployment, etc. Therefore, in some approaches, the predicted amount of resources may include, for example, more resources than currently available in the deployment, approximately the same amount of resources as currently available in the deployment, fewer resources than currently available in the deployment, etc., and based on inputting at least some IT information into a trained labor prediction machine learning model, the predicted amount of resources is generated as output.
[0066] The calculated security policy may include known types of security parameter recommendations for an IT environment that will be apparent to those skilled in the art upon reading the description herein. For example, the security policy may recommend these by, for example, closing physical ports or logical ports or both, increasing access credential strengths such as by increasing the required password length, requiring devices to comply with a given security protocol, disabling a given protocol, modifying encryption criteria, setting a retry countdown for access credentials when access is granted, etc. In some preferred approaches, it should be noted that the calculated security policy recommends security parameter updates that reduce one or more current threats to the IT environment while minimizing the amount of such effort by applying the calculated security policy. However, this ideal balance of enhancing security while minimizing effort is not always possible. This is because the calculation of the security policy preferably takes into account the indication of the degree of risk as described above, for example, IT risk criteria or requirements. For example, for a client having a deployment with a relatively very low indicated requirement for risk, the calculated security policy may recommend the addition of a relatively broad range of security protocols, even though it is predicted that applying it will require relatively significant effort. According to a more specific example, the calculated security policy may include, for example, a proposal to change the password length from the current 4 characters to 10 characters, assuming that the deployment application is programmed to handle only passwords of 8 characters or less. It is also assumed that it is determined that the client is associated with a deployment with a relatively very low requirement for risk.Since the deployed application is programmed to handle only passwords of eight characters or less, the application of the calculated security policy is expected to consume a relatively large amount of processing, to the extent that it is necessary to change the application to handle passwords of more than eight characters. Although such an excessive amount of effort is expected to be required for the application of the calculated security policy, the calculated security policy includes a proposal to enforce a password length of 10 characters, for example, to satisfy one or more IT security rules considered by a trained machine learning model and furthermore to satisfy a relatively very low appetite for risk. On the other hand, assuming the same fact but that the client has a relatively very high appetite for risk, the calculated security policy is likely to not include a proposal to enforce a password length of 10 characters. This is because the client's appetite for risk is much higher, which indicates, for example, that the client may tolerate not satisfying the IT security rules. In some approaches, multiple parameters of the calculated security policy may be stratified, additionally or alternatively or both, according to the amount of effort expected to be consumed to apply the calculated security policy.
[0067] Decision 362 includes determining whether more systems are to be analyzed. Such a decision may be made in some approaches where it is considered for multiple systems in the IT environment to determine, for example, to calculate security policies such as multiple different deployments, multiple systems within a first deployment, etc. In response to a determination that more systems are to be analyzed, the method continues to operation 354, as seen, for example, in the "yes" logical path of decision 362. In contrast, in response to a determination that no more systems are to be analyzed, the method continues to operation 364, as seen, for example, in the "no" logical path of decision 362.
[0068] In some approaches, the security policy is calculated from a plurality of possible security actions identified from the results of applying a trained machine learning model. For example, operation 364 assembles a list of security actions that install with the uncertainty and value predicted in operations 356 and 360, respectively, and the effort to install. These possible security actions may be refined, for example, filtered through a filter before output. For example, this possible security action may be used as input to a given genetic algorithm used in the calculation of the security policy, as seen in operation 366 by way of example in some approaches.
[0069] Operation 368 includes outputting an indication of the optimal security policy to be applied. In some suitable approaches, the indication of the security policy is an output for presentation on a dashboard on the display of the user device of the first client. As referred to by way of example in FIG. 6, such a dashboard is described in further detail elsewhere in this specification.
[0070] The indication of a security policy may, in some approaches, include multiple recommended security parameters. Each of the recommended security parameters is stratified according to how well the recommended security parameter conforms to the degree of risk, and may, for example, form multiple different levels of strata. For example, a security parameter that is stratified to form a first level conforms to the degree of risk with relatively smaller parameters than the recommended security parameters that are stratified to form a second level and the recommended security parameters that are stratified to form a third level (the most recommended), and as a result is the least recommended. In such an example, the recommended security parameters that are stratified to form a third level conform to the degree of risk with relatively larger parameters than the recommended security parameters that are stratified to form a first level and the recommended security parameters that are stratified to form a second level, and as a result are the most recommended.
[0071] The indication of the security policy may additionally or alternatively or both include a breakdown of a plurality of applications associated with the IT information within the first deployment. More specifically, in some such approaches, this breakdown may include, for each application, a security competency challenge and a challenge-specific uncertainty level. The calculated uncertainty of the effect that can be caused by applying the security policy to the first deployment is based on each of the challenge-specific uncertainty levels. This ensures that client-side resources provide application-specific solutions, for example, based on challenges and uncertainties, as to why the calculated security policy parameters will enhance performance within the deployment. This is used by these client-side resources to determine, for example, one or more third-party companies or services or both that supply IT environment security services and packages to contract to adopt the indicated security policy. In contrast, such a determination may be made, additionally or alternatively or both, with respect to the client, and the result of such a determination may be provided to the client. For example, an optional operation of method 300 includes determining an IT service provider that supplies a service having at least a predetermined degree of similarity to the calculated security policy. The indication of the determined IT service provider may be output to the user device, for example, with the same output as the output of the security policy or with a different output operation.
[0072] As a result of utilizing the techniques described herein to calculate the security policies based on the calculated uncertainties and predicted amounts of resource consumption respectively associated with the application of the recommended security policies, various benefits become possible. For example, the performance of the computer architecture within the deployment of the IT environment improves for several reasons. First, security policies are identified that match the needs of the deployment, for example, as determined from the analyzed IT information. These policies would otherwise not be understood without such analysis being performed over a relatively wide range of processing operations, such as trial and error. Further, security inspections that would otherwise be performed to determine whether the current policies are accurately preventing threats from penetrating the deployment within the IT environment are excluded, and as a result, the processing performed within the IT environment is directly simplified. This is because the client can instead apply the calculated security policies that are specifically tailored to the deployment associated with the client within the IT environment, for example, in accordance with the client's risk-based requirements or based on the IT information associated with the deployment, where such adaptation has been pre-ensured. Also, it should be noted that while there has been a long-standing need to deploy a prediction method for mapping and identifying the entire landscape, analyzing IT information to determine how to match it to the client's business applications, and constructing an IT security policy that can meet the client's security needs and be implemented without imposing any burden on the client, using machine learning models to train and apply to calculate the recommended security policies based on the calculated uncertainties and predicted amounts of resource consumption has not been considered in conventional IT environments until now. Therefore, the inventive and innovative disclosure herein goes against conventional wisdom.
[0073] Next, referring to FIG. 4, a flowchart of method 400 is shown by one embodiment. In various embodiments, method 400 may be implemented in accordance with the present invention in any suitable environment shown in FIGS. 1-6, among others. Of course, as will be understood by those skilled in the art upon reading this description, method 400 may include more or fewer operations than specifically described in FIG. 4.
[0074] Each step of method 400 may be implemented by any suitable component of the operating environment. For example, in various embodiments, method 400 may be implemented, in part or in whole, by a computer or some other device having one or more processors therein. A processor implemented in hardware or software or both, preferably having at least one hardware component, such as a processing circuit, chip, or module, or a combination thereof, may be utilized in any device to implement one or more steps of method 400. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art.
[0075] The flowchart of FIG. 4 includes clients with long - standing needs 416. For example, the client needs a prediction method to be run on the client's IT environment 404 in order to know in advance the level of effort consumed, e.g., the level of reliability, by the application of supported security parameters, and to determine what the best overall policy is based on the client's security risk appetite. By executing method 408 using the techniques described herein, as referenced in various operations of method 300 by way of example, cost reduction and time savings are possible, and the potential impact that threats can cause to the availability and integrity of the client's IT environment 404 is dramatically reduced. For example, as seen in operation 406 by way of example, executing the above - mentioned method may include collecting IT environment information. This IT environment information may include, for example, technical information about the product, regulatory and standard references, client business service matrices, etc. The above - mentioned method may additionally or alternatively or both include building big data in a non - relational database, performing machine learning to apply the above - mentioned prediction method, determining the reliability against risk according to the above - mentioned method analysis, etc. Further, the above - mentioned method may include applying a trained machine learning model to analyze the client's IT information and calculate a security policy 410, where the security policy 410 is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to a first deployment, or the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment, or both. The indication of the security policy is, for example, an output for presentation on a dashboard on the display of the user device of the client 402, as referenced in operation 412. The above - mentioned indication is used to determine an IT service provider 418 that supplies services having at least a predetermined degree of similarity to the security policy.For example, client 402 may be determined to contact a third party, such as an IT service provider, with a security policy offering similar to that determined using method 400, as referenced in operation 414 for example.
[0076] Returning to FIG. 5, a flowchart of a method 500 according to one embodiment is shown. Method 500 may be implemented in accordance with the present invention in various embodiments, among others, in any of the environments shown in FIGS. 1 - 6. Of course, method 500 may include more or fewer operations than specifically described in FIG. 5, as will be understood by those skilled in the art upon reading this description.
[0077] Each step of method 500 may be implemented by any suitable component of the operating environment. For example, in various embodiments, method 500 may be implemented partially or wholly by a computer or some other device having one or more processors therein. A processor implemented in hardware or software or both, preferably having at least one hardware component, such as a processing circuit, chip, or module, or a combination thereof, may be utilized in any device to implement one or more steps of method 500. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art.
[0078] It may be more suitable to further specifically describe an overview of the operation architecture for method 500 to train a machine learning model, apply the trained machine learning model to analyze the IT information of a first client, and calculate security policies for the deployment of the IT environment. Method 500 may preferably include determining the level of risk reliability by grasping the actual security settings from the client's IT environment and the client's risk criterion requirements. Further, based on the analysis of the current environment deployed according to the risk criterion requirements provided by the client, the IT security policy is determined.
[0079] Method 500 includes machine learning built for client 502, which is optionally executed by teacher specialist 504. Method 500 includes collecting IT information in the IT environment. For example, in some approaches, the client workload 506 and the mapping 508 of the client's IT environment are collected from the IT environment as actual security information, as seen in operation 510 by way of example. Training the machine learning model 512 may include, as seen in operation 514 by way of example, understanding the IT information and using it for training. This IT information may be based on one or more, for example, business application matrices and importance 522, regulatory and industry standards 524, technical information regarding software (SW) 526, etc. Operation 518 includes building an ML calibration model, and this building uses techniques described elsewhere in this specification to build and train a machine learning model, as seen in method 300 by way of example. The ML calibration model is trained as seen in operation 516 by way of example, and once trained, is used as a prediction method 520 that includes the trained machine learning model.
[0080] The risk criteria / desires of client 502 are received as seen in operation 528 by way of example, and the level of risk reliability, e.g., the client's tolerance for risk, is determined as seen in operation 530 by way of example. Based on this, a trained machine learning model is applied, and for example, the IT information of client 502 is input into the trained model as seen in operation 532 by way of example to determine security settings for application based on the risk reliability.
[0081] FIG. 6 shows a dashboard representation 600 according to an embodiment. Optionally, the dashboard representation 600 here may be implemented in combination with features from any other embodiment listed herein, such as those described with reference to other figures. However, of course, such a dashboard representation 600 and other representations shown herein may be used in various applications and / or in permutations, or both, specifically described or not described in the exemplary embodiments listed herein. Further, the dashboard representation 600 shown herein may be used in any desired environment.
[0082] In one approach, the dashboard representation 600 includes a map-tree display that follows the size of the IT environment. The dashboard representation 600 includes a dial 602 that characterizes the overall uncertainty of the results of running the trained machine learning models described elsewhere in this specification, e.g., deeply uncertain, uncertain, risky, clear. A statistical measure 604 of the overall uncertainty is also included on the dashboard representation 600. The dashboard representation 600 also includes an environment breakdown 606 that details the deployments of the IT environment that were analyzed to compute security policies, such deployments being, for example, critical business applications, developer sandboxes, production non-high-availability, and internal systems. Information regarding critical business applications analyzed by the trained machine learning models is also provided in the dashboard representation 600; see, for example, the detailed display 608 for each selection. This dashboard will identify the level of uncertainty that the client would like to accept based on the information provided, the current environment deployed, and the security configuration settings deployed. More specifically, the breakdown 606 details, for each such application, the competency and the level of uncertainty, e.g., the security competency and the level of uncertainty.
[0083] The dashboard representation 600 may include an optimal IT security policy based on the client's security risk requirements and shows a recommended heat map of the security policy. For example, the recommended security parameters of the calculated security policy are also explained in the recommended heat map. These recommendations are based on a predictive methodology divided by the severity of the parameters to be applied. For example, in some approaches, each of the recommended security parameters is stratified into one of a plurality of different levels, such as high, medium, and low, according to how well the recommended security parameter matches the degree of risk. More specifically, the low level includes 20 recommended security parameters, the medium level includes 4 recommended security parameters, and the high level includes 2 recommended security parameters, such as disabling the FTP protocol, closing port 3839, and the like.
[0084] It will be apparent that various features of the foregoing system or methodology or both may be combined in any manner, thereby creating a plurality of combinations from the description presented above.
[0085] Furthermore, it will be recognized that embodiments of the present invention may be provided in the form of services deployed for a customer to provide services on demand.
[0086] The description of the various embodiments of the present invention has been provided for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terms used herein have been chosen to best explain the principles of the embodiments, the practical application, or a technical improvement found in the marketplace, or to enable other skilled artisans to understand the embodiments disclosed herein.
Claims
1. Receiving a request to perform a security policy implementation analysis on a first deployment associated with a first client in an IT environment, Collecting IT information associated with the first deployment, Applying a trained machine learning model to analyze the IT information of the first client and calculating a security policy for the first deployment, The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment, applying the trained machine learning model, Outputting a label of the security policy for presentation on a dashboard on a display of a user device of the first client A computer-implemented method comprising.
2. A method comprising training the machine learning model to analyze IT information and storing the trained machine learning model in a predetermined database, wherein training the machine learning model comprises reading IT information associated with a second deployment in a training IT environment, calculating a risk level error derived from the components of the second deployment and the applications of the second deployment, converting the IT information into a training data set for the machine learning model, training the first machine learning model using the first training data set, wherein the first machine learning model is trained to calculate uncertainty, training the second machine learning model using the second training data set, wherein the second machine learning model is trained to predict resource consumption, the method according to claim 1.
3. receiving an indication of a level of risk that the first deployment can currently support in the IT environment, the indication of the security policy including a plurality of recommended security parameters, each of the recommended security parameters being stratified according to how well the recommended security parameter conforms to the level of risk, the computer-implemented method of claim 1.
4. The indication of the security policy includes a breakdown of a plurality of applications associated with the IT information, the breakdown including, for each of the applications, a security competency issue and an issue-specific uncertainty level, the calculated uncertainty of the effect that can be caused by applying the security policy to a first deployment being based on each of the issue-specific uncertainty levels, the computer-implemented method of claim 1.
5. The effect that can be caused by applying the security policy to the first deployment is selected from the group consisting of secondary effects caused to customer characteristics provided by the applications of the first deployment, private customer information becoming inadvertently accessible, loss of access events, and loss of functionality of components of the first deployment, the resources of the first deployment being selected from the group consisting of administrator time, costs borne by the first client, consultation by content area subject matter experts (SMEs), processing operations dedicated to troubleshooting operations, and time spent on updating applications associated with the first deployment, the computer-implemented method of claim 1.
6. The security policy is calculated from a plurality of possible security actions identified from the results of applying a trained machine learning model, and the possible security actions are used as inputs to a predetermined genetic algorithm used for the calculation of the security policy. The computer-implemented method according to claim 1.
7. Determining an IT service provider that supplies a service having at least a predetermined degree of similarity to the security policy, and outputting an indication of the determined IT service provider to the user device. The computer-implemented method according to claim 1.
8. A computer program having program instructions, the program instructions causing a computer to Receive, by the computer, a request to perform a security policy implementation analysis for a first deployment associated with a first client in an IT environment, Collect, by the computer, IT information associated with the first deployment, Apply, by the computer, a trained machine learning model to analyze the IT information of the first client and calculate a security policy for the first deployment, The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment. Applying the trained machine learning model, Output, by the computer, an indication of the security policy for presentation on a dashboard on a display of a user device of the first client To cause to be performed. A computer program.
9. The program instructions are executable by the computer to cause the computer to train the machine learning model to analyze IT information and store the trained machine learning model in a predetermined database by the computer. Training the machine learning model includes reading IT information associated with a second deployment of a training IT environment, calculating a risk level error derived from components of the second deployment and applications of the second deployment, converting the IT information into a training data set for the machine learning model, training the first machine learning model using the first training data set, where the first machine learning model is trained to calculate uncertainty, and training the second machine learning model using the second training data set, where the second machine learning model is trained to predict resource consumption. The computer program according to claim 8.
10. The program instructions are executable by the computer to cause the computer to receive an indication of the level of risk that the first deployment can currently support in the IT environment. The indication of the security policy includes a plurality of recommended security parameters, and each of the recommended security parameters is stratified according to how well the recommended security parameter conforms to the level of risk. The computer program according to claim 8.
11. The indication of the security policy includes a breakdown of a plurality of applications associated with the IT information. The breakdown includes, for each of the applications, a security competency issue and an issue-specific uncertainty level. The calculated uncertainty of the effect that can be caused by applying the security policy to the first deployment is based on each of the issue-specific uncertainty levels. The computer program according to claim 8.
12. The effects that can be caused by applying the security policy to the first deployment are selected from the group consisting of secondary effects caused by the security policy being applied to the customer characteristics provided by the application of the first deployment, private customer information that is becoming inadvertently accessible, loss of access events, and loss of functionality of the components of the first deployment. The resources of the first deployment are selected from the group consisting of administrator time, costs borne by the first client, consultation by content area subject matter experts (SMEs), processing operations dedicated to troubleshooting operations, and time spent on updating applications associated with the first deployment. The computer program according to claim 8.
13. The security policy is calculated from a plurality of possible security actions identified from the results of applying a trained machine learning model, and the possible security actions are used as inputs to a predetermined genetic algorithm used in the calculation of the security policy. The computer program according to claim 8.
14. The program instructions are executable by the computer to cause the computer to determine, by the computer, an IT service provider that supplies a service having at least a predetermined degree of similarity to the security policy, and to output, by the computer, an indication of the determined IT service provider to the user device. The computer program according to claim 8.
15. A hardware processor, logic integrated with the processor, the logic being executable by the processor or integrated with and executable by the processor, the logic Receiving a request to perform a security policy implementation analysis for a first deployment associated with a first client in an IT environment, Collecting IT information associated with the first deployment, Applying a trained machine learning model to analyze the IT information of the first client and calculating a security policy for the first deployment, The security policy is calculated based on the calculated uncertainty of the effects that can be caused by applying the security policy to the first deployment and the predicted amount of resources of the first deployment that will be consumed by applying the security policy to the first deployment, applying the trained machine learning model, Outputting an indication of the security policy for presentation on a dashboard on a display of a user device of the first client A system configured to perform.
16. The logic is configured to train the machine learning model to analyze IT information and store the trained machine learning model in a predetermined database. Training the machine learning model includes reading IT information associated with a second deployment in a training IT environment, calculating a risk level error derived from a component of the second deployment and an application of the second deployment, converting the IT information into a training data set for the machine learning model, training the first machine learning model using the first training data set, where the first machine learning model is trained to calculate uncertainty, and training the second machine learning model using the second training data set, where the second machine learning model is trained to predict resource consumption. The system according to claim 15, including the training.
17. The logic is configured to receive an indication of a degree of risk that the first deployment can currently support in the IT environment, the indication of the security policy includes a plurality of recommended security parameters, and each of the recommended security parameters is tiered according to how well the recommended security parameter conforms to the degree of risk. The system according to claim 15.
18. The indication of the security policy includes a breakdown of a plurality of applications associated with the IT information, the breakdown includes, for each of the applications, a security competency issue and an issue-specific uncertainty level, and the calculated uncertainty of the effect that can be caused by applying the security policy to the first deployment is based on each of the issue-specific uncertainty levels. The system according to claim 15.
19. The security policy is calculated from a plurality of possible security actions identified from the results of applying a trained machine learning model, and the possible security actions are used as inputs to a predetermined genetic algorithm used in the calculation of the security policy. The system according to claim 15.
20. The logic is configured to determine an IT service provider that supplies a service having at least a predetermined degree of similarity to the security policy, and output an indication of the determined IT service provider to the user device. The system according to claim 15.
Citation Information
Patent Citations
Method and system for managing cloud computing environment
JP2014142928A
Inferring Security Policies from Semantic Attributes
US20160352778A1
Security setting support device, security setting support method, and program
WO2022009274A1