Computer systems, computer programs and methods (utilizing and training artificial intelligence models for control identification)
AI models are used to traverse relationship maps to correlate controls across varying standards, addressing inconsistencies and enhancing compliance verification by improving the accuracy and efficiency of control identification and training.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-26
- Publication Date
- 2026-03-04
AI Technical Summary
The language of security and privacy control specifications varies across different standards, leading to inconsistencies and differing interpretations, which complicates compliance verification and hinders the effective utilization of AI models in identifying and training controls.
A system and method utilizing AI models to identify candidate controls by traversing relationship maps that correlate controls across different standards, enhancing the training process to improve accuracy and consistency.
Enhances the ability of AI models to accurately map and train controls, reducing duplicate checks and improving compliance verification by leveraging standardized relationships between security and privacy controls.
Smart Images

Figure 0007824002000001 
Figure 0007824002000002 
Figure 0007824002000003
Abstract
Description
[Technical Field]
[0001] The present embodiments relate to systems, computer program products, and methods for leveraging artificial intelligence (AI) models to identify controls, such as security and privacy controls, and training of AI models, to improve their technical effectiveness. [Background technology]
[0002] Security and privacy compliance is the process of ensuring that appropriate levels of security- and privacy-related requirements are met. Such requirements are typically set forth in regulations, although requirements can also be found in other sources, such as laws, executive orders, directives, policies, guidelines, and standards. In a typical (but not exhaustive) scenario, a regulation or other legal requirement is issued by a government body, typically an executive branch or a (federal or state) legislature, prescribing requirements (e.g., technical requirements) related to such matters as protecting public and private sector organizational operations and assets (e.g., data) from security and privacy risks. Such security and privacy risks may result from, for example, vulnerabilities in information technology systems and products, passive threats such as natural disasters, power outages, and human error, and from threatening parties attempting to exploit other threats, both external and internal. Compliance with such legal requirements is wise, cost-effective prevention and is often mandatory to avoid violations of laws and other legal requirements.
[0003] Information, security, and privacy standards are often approved by recognized private or public sector standards bodies or organizations. Cybersecurity standards, for example, describe technical specifications for data protection and information security practices. Compliance with such standards is highly desirable or even required for industry acceptance. Standards are typically organization-specific (e.g., NIST, HIPAA, etc.). Examples of standards include, for example, National Institute of Standards and Technology (NIST) standards, Health Insurance Portability and Accountability Act (HIPAA) standards, Payment Card Industry Data Security Standard (PCI-DSS), International Organization for Standardization (ISO) standards, General Data Protection Regulation (GDPR) standards, and others.
[0004] Ensuring compliance with the various security- and privacy-related requirements that may apply to a given organization requires not only implementing sufficient protections but also performing due diligence, maintaining and updating such protections as regulations, laws, and the like are amended, rewritten, revoked, and published, and new exploitative attack vectors are identified. To meet these requirements, security and privacy controls (hereinafter collectively referred to as "controls") have been developed and implemented by organizations and individuals in both the private and public sectors to safeguard information technology and other systems, computing platforms, devices, and products. Organizations or individuals select and implement controls to meet the security- and privacy-related requirements.
[0005] Controls have been described as technical, administrative, or physical safeguards and protective capabilities that can detect, avoid, mitigate, or prevent security risks, such as a threatening party's ability to exploit vulnerabilities, or a combination thereof. For example, the National Institute of Standards and Technology (NIST) provides access via its website to the publication "Security and Privacy Controls for Information Systems and Organizations," NIST Special Publication 800-53, Rev. 5 (September 2020). The publication discloses a control structure that includes a base controls section (which specifies the security and / or privacy features to be implemented), a discussion section, an associated controls section, a control enhancements section, and a criteria section.
[0006] Standards from one standardization organization may be mapped to standards from one or more other standardization organizations. For example, controls map directly to standards because control tests are designed to measure aspects of how the standard is implemented in practice. A control check is the verification of compliance with one or more controls across one or more standards.
[0007]
[0003] Often, multiple standards are developed by different standardization organizations or bodies regarding the same (or similar) security or privacy requirements. As a result, a control in a given standard from one standardization organization may share similarities with one or more controls in another standard from another standardization organization. Therefore, it would be advantageous to provide a system, computer program product, and method for identifying security and privacy controls and incorporating standards mapping into the training of AI models to facilitate the utilization of artificial intelligence (AI) models to advance and improve the technical effectiveness of the AI models. [Prior art documents] [Non-patent literature]
[0008] [Non-Patent Document 1] Security and Privacy Controls for Information Systems and Organizations” NIST Special Publication 800-53, Rev.5 (September 2020) Summary of the Invention [Problem to be solved by the invention]
[0009] The language of the target specifications varies across standards even though similar content exists, and is often subject to different interpretations due to being text-based. [Means for solving the problem]
[0010] Embodiments include systems, computer program products, and methods for leveraging artificial intelligence (AI) models to identify controls, such as security and privacy controls, and training of AI models to improve their technical effectiveness. This Summary is provided to introduce a selection of representative concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used in any way to limit the scope of the claimed subject matter.
[0011] In one aspect, a computer system is provided that includes a processor operably coupled to a memory and a platform in communication with the processor and the memory. The platform includes an artificial intelligence (AI) manager, a mapping manager, and a training manager. The AI model manager is configured to utilize an AI model with respect to a target specification of a target standard. The AI model is configured to identify at least one candidate control associated with the corresponding standard. The mapping manager is configured to traverse a map having an original control and a target control. The traversal includes identifying at least one candidate control in the map and traversing the original control and the target control of the map to identify at least one mapped control associated with the target standard. The training manager is configured to selectively train the AI model using the mapped control and the target standard.
[0012] In another aspect, a computer program product is provided for facilitating mapping controls to target specifications utilizing artificial intelligence (AI) and a corresponding AI model. The computer program product includes a computer-readable storage medium having program code embodied thereon. The program code is executable by a processor configured to utilize the AI model with respect to target specifications of the target specifications. The AI model is configured to identify at least one candidate control associated with the corresponding specification. The program code is further executable by the processor to traverse a map having the original control and the target control. The traversal includes identifying at least one candidate control in the map and traversing the original control and the target control of the map to identify at least one mapped control associated with the target specification. The program code is further executable by the processor to selectively train the AI model using the mapped control and the target specification.
[0013] In yet another aspect, a method is provided that includes utilizing an artificial intelligence (AI) model with respect to a target specification of a target standard. The AI model identifies at least one candidate control associated with the corresponding standard. A map having an original control and a target control is traversed. The traversal includes at least identifying the candidate controls in the map and traversing the original control and the target control of the map to identify at least one mapped control associated with the target standard. The AI model is selectively trained using the mapped control and the target standard.
[0014] According to yet another aspect, a computer system is provided that includes a processor operably coupled to a memory and a platform in communication with the processor and the memory. The platform includes an artificial intelligence (AI) manager, a mapping manager, and a training manager. The AI model manager is configured to utilize an AI model with respect to a target specification of a target standard. The AI model is configured to identify at least one candidate control associated with the corresponding standard. The mapping manager is configured to traverse a map having an original control and a target control. The traversal includes identifying at least one candidate control in the map and traversing the original control and the target control of the map to identify at least one mapped control associated with the target standard. The mapping manager is configured to identify an amount of the identified mapped control. In response to the amount of the identified mapped control being outside a predetermined range or not satisfying a predetermined limit, the mapping manager is configured to modify parameters of the traversal and re-traverse the original control and the target control of the map using the modified parameters. The training manager is configured to selectively train the AI model using the mapped control and the target standard.
[0015] According to a further aspect, a method is provided that includes utilizing an artificial intelligence (AI) model with respect to a target specification of a target standard. The AI model identifies at least one candidate control associated with the corresponding standard. A map having an original control and a target control is traversed. The traversal includes at least identifying the candidate control in the mapping and traversing the original control and the target control of the mapping to identify at least one mapped control associated with the target standard. A quantity of the identified mapped control is identified. In response to the quantity of the identified mapped control being outside a predetermined range or not meeting a predetermined limit, parameters of the traversal are modified. The original control and the target control of the map are re-traversed using the modified parameters. The AI model is selectively trained using the mapped control and the target specification.
[0016] These and other features and advantages will become apparent from the following detailed description of exemplary embodiments, taken in conjunction with the accompanying drawings, which describe and illustrate various systems, subsystems, devices, apparatus, models, processes and methods in additional aspects. [Brief explanation of the drawings]
[0017] The drawings referred to herein form part of this specification and are hereby incorporated by reference. The features shown in the drawings are intended to illustrate only some embodiments and not all embodiments, unless explicitly indicated.
[0018] [Figure 1] 1 shows a schematic diagram of a computer system that supports and enables leveraging and training AI models for control identification.
[0019] [Figure 2] FIG. 2 shows a block diagram illustrating AI platform tools and their associated application program interfaces (APIs) as shown and described in FIG. 1.
[0020] [Figure 3A] 1 shows a flowchart illustrating an embodiment of a method for utilizing and training an AI model for control identification. [Figure 3B] 1 summarizes a flowchart illustrating an embodiment of a method for utilizing and training an AI model for control identification.
[0021] [Figure 4] 3C shows a flowchart illustrating a modified embodiment of the flowchart of FIGS. 3A and 3B.
[0022] [Figure 5] 1 illustrates a fragmented view of an example relationship map according to an embodiment.
[0023] [Figure 6] FIG. 6 shows a block diagram illustrating an example computer system / server of a cloud-based support system that implements the systems and processes described above with respect to FIGS. 1-5.
[0024] [Figure 7] 1 shows a block diagram illustrating a cloud computing environment.
[0025] [Figure 8] 1 shows a block diagram illustrating a set of functional abstraction model layers provided by a cloud computing environment. DETAILED DESCRIPTION OF THE INVENTION
[0026] It will be readily understood that the components of the exemplary embodiments, as generally described and illustrated in the Figures herein, could be arranged and designed in a wide variety of different configurations. Thus, the following detailed description of embodiments of the systems, computer program products, and methods and other aspects described herein, as set forth in this description and the accompanying figures, is not intended to limit the scope of the embodiments as claimed, but is merely representative of selected embodiments.
[0027] Throughout this specification, references to "selected embodiments," "one embodiment," or "an embodiment" mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, the appearances of the phrases "selected embodiments," "in one embodiment," or "an embodiment" in various places throughout this specification do not necessarily refer to the same embodiment. It should be understood that various embodiments may be combined with each other, and that any one embodiment may be used to modify another embodiment.
[0028] The illustrated embodiments are best understood by referring to the drawings, in which like parts are designated with like numerals throughout. The following description is for purposes of illustration only and merely illustrates certain selected embodiments of devices, systems and processes consistent with the embodiments as claimed herein.
[0029] In the field of information technology (IT), compliance aims to protect information by implementing appropriate controls. Internal compliance revolves around policies, goals, and organizational structure. External compliance aims to protect data and internal structures while satisfying clients or end users. For example, IT compliance utilizes rules and standards that IT systems must follow to protect the underlying organization or structure, both from a security and privacy perspective. Compliance risk assesses the extent of vulnerabilities a system or system component may have, for example, regarding hostile attacks, natural disasters, power outages, human error, etc., because an organization is not complying with a set of rules or standards. Risk management aims to mitigate and manage risk through one or more controls.
[0030] Referring to FIG. 1, a schematic diagram of a platform computing system (100) is shown. In an exemplary embodiment, the platform includes or incorporates an artificial intelligence (AI) platform. As shown, a server (110) is provided that communicates with multiple computing devices (180), (182), (184), (186), (188), and (190) via a network connection (105). The server (110) is comprised of a processing unit (also referred to herein as a processor) (112) that communicates with memory (116) via a bus (114). The server (110) is shown with an artificial intelligence (AI) platform (150) for cognitive computing, including natural language processing (NLP) and machine learning (ML), that communicates with one or more of the computing devices (180), (182), (184), (186), (188), and (190) via the network (105). More specifically, computing devices 180, 182, 184, 186, 188, and 190 communicate with each other and with other devices or components via one or more wired and / or wireless data communication links, each of which may comprise one or more of a wire, a router, a switch, a transmitter, a receiver, or the like. In this network arrangement, server 110 and network connections 105 enable communication detection, recognition, and resolution. Other embodiments of server 110 may be used with components, systems, subsystems, or devices, or combinations thereof, other than those shown herein.
[0031] An AI platform 150 is shown, and is configured herein with tools that utilize the AI models 140 to predict controls, such as security and privacy controls, for regulatory or other requirements, and to train the AI models 140 to improve their performance. The tools include, but are not limited to, an AI model manager 152, a mapping manager 154, a score manager 156, and a training manager 158. While FIG. 1 shows each of the tools 152, 154, 156, and 158 as part of the AI platform 150, it should be understood that in embodiments, the mapping manager 154, score manager 156, training manager 158, or any combination thereof, are not necessarily part of the AI platform 150 or the AI being operated, and may be in operative communication with the processor 112 and memory 116 separately.
[0032] Artificial intelligence (AI) is the field of computer science that focuses on computers and their behavior as they relate to humans. AI refers to intelligence when machines can make informed decisions, maximizing their chances of success in a given topic. More specifically, AI enables machines to learn from data sets to solve problems and provide relevant recommendations. For example, in the field of artificial intelligence computer systems, natural language systems (e.g., IBM Watson® artificial intelligence computer systems or other natural language question-answering systems) process natural language based on system-acquired knowledge. To process natural language, systems may be trained using data derived from a knowledge database or corpus, but the resulting outcomes may be inappropriate or inaccurate for various reasons.
[0033] Machine learning (ML), a subset of artificial intelligence (AI), uses algorithms to learn from data and create perspectives based on the data. AI refers to intelligence when a machine can make informed decisions, maximizing its chances of success in a given topic. More specifically, AI allows it to learn from datasets to solve problems and provide relevant recommendations. Cognitive computing is a blend of computer science and cognitive science. Cognitive computing uses self-supervised algorithms that use minimal data, vision, and natural language processing to solve problems and optimize human processing.
[0034] At the core of AI and related reasoning lies the concept of similarity. The process of understanding natural language and intent requires reasoning from a relational perspective, which can be challenging. Structures, including static and dynamic structures, dictate determined outputs or actions for given decision inputs. More specifically, the determined outputs or actions are based on representations or inherent relationships within the structures. Appropriate datasets are relied upon to build these structures.
[0035] An AI platform (150) is shown and is configured herein to receive input (102) from various sources. For example, the AI platform (150) may receive input, such as target specifications for target standards, from one or more of a plurality of computing devices (180), (182), (184), (186), (188), and (190) via a network (105). Additionally, as shown herein, the AI platform (150) is operably coupled to a knowledge base (160), also referred to herein as a corpus or database.
[0036] In an exemplary embodiment, the AI model manager 152 utilizes an AI model 140 for control identification. In an exemplary embodiment, the AI model 140 is, for example, a classification model or a text similarity-based search model. In an exemplary embodiment, the AI model 140 is, for example, a machine learning model, a neural network, or a support vector machine. In an exemplary embodiment, the AI model 140 receives a target specification (e.g., minimum password length must be 7 characters) and a target standard (e.g., PCI / DSS) and is pre-trained using existing categorized control descriptions to identify at least one candidate control associated with a corresponding standard (e.g., NIST IA-5(1)) and a corresponding score (also referred to herein as a “first score”). The candidate control may include, for example, a control correlation identifier (CCI), a base control section, a discussion section, a related control section, a control enhancement section, and a criteria section. The AI model 140 may consider any combination or all of the sections of the candidate control.
[0037] In many cases, multiple candidate controls are identified by the AI model 140. One reason for the identification of multiple candidate controls is that the language of the target specifications varies across standards despite the presence of similar content, and is often subject to different interpretations due to being text-based. In practice, the level of granularity also varies across different standards. Furthermore, verifying compliance with standards often results in duplicate control checks.
[0038] In an exemplary embodiment, at least one candidate control, and often multiple candidate controls, identified by the AI model (140) share one or more characteristics or otherwise have one or more similarities to the input target specification. According to an exemplary embodiment, the similarity may be text-based or meta-database based, or both. According to an exemplary embodiment, identifying a corresponding score by the AI model (140) includes evaluating the corresponding score. For example, the score may be a confidence score reflecting the similarity between the target specification and at least one identified candidate control (or any portion of the control structure of the candidate control, such as the CCI or discussion section of the control structure). Cosine similarity may be used to measure the similarity between a vector of the target specification (generated by known vectorization techniques) and the candidate control for purposes of evaluating the score. In an exemplary embodiment, semantic similarity is evaluated.
[0039] According to an embodiment, (i) the confidence score (e.g., 0.7) identified by the AI model manager (152) is greater than a predetermined first threshold (e.g., 0.5) and therefore satisfies the first threshold, and (ii) the standard (e.g., PCI / DSS) associated with the candidate control (e.g., 8.2.3) matches the target standard (e.g., PCI / DSS), and the candidate control (e.g., 8.2.3) is deemed an acceptable match to the target standard. Because the candidate control is an acceptable match, the candidate control is accepted as output without utilizing a relationship map.
[0040] On the other hand, if the candidate control is not an acceptable output, a mapping manager (154) is used to traverse one or more relationship maps (described in further detail below with respect to FIG. 5) that include the original and target controls. According to an exemplary embodiment, a relationship map (or multiple relationship maps) is a collection of known, predetermined relationships of controls between and across standards.
[0041] As shown in Figure 1, the AI platform (150) is further shown in communication with a knowledge base (160), also referred to herein as a corpus. While only one knowledge base (160) is shown in Figure 1, it should be understood that the system (100) may include additional knowledge bases. The illustrated knowledge base (160) is shown with Relationship Map 0 (162), Relationship Map 1 (164), ..., and Relationship Map 2 (166). N-1 (166), where N may be any integer. While three relationship maps are shown in FIG. 1, it should be understood that knowledge base (160) may include fewer or additional relationship maps. In an exemplary embodiment, a single relationship map is accessed. Multiple relationship maps are shown and described herein for illustrative purposes.
[0042] According to embodiments, a candidate control (identified by AI model 140) may be deemed an unacceptable match to the target specification if the candidate control is associated with a corresponding standard that is different from the target standard. By way of example, AI model 140 may output a candidate control (e.g., IA-5(1)) that is associated with a standard (e.g., NIST) that is different from the target standard (e.g., PCI / DSS) input to AI model 140.
[0043] According to another embodiment, a candidate control (identified by the AI model (140)) may be deemed to be an unacceptable match to the target specifications, and the AI model (140) identifies a first score for the candidate control that does not meet a first threshold. For example, if the first score for a given candidate control is relatively low, e.g., 0.3, and a predetermined threshold is greater than the first score, e.g., the threshold is 0.5, then the candidate control is not an acceptable match to the target specifications.
[0044] In the event that a candidate control is not an acceptable match to the target specification, for example due to mismatched specifications or a low first score or both, the system uses the mapping manager (154) to traverse the relationship map to find a "mapped" control.
[0045] The mapping manager (154) is configured to traverse the relationship map having the source control and the target control, including identifying at least one candidate control in the map, and traversing the source control and the target control in the map to identify at least one mapped control associated with the target specification.
[0046] According to an embodiment, the mapping manager (154) is configured to identify at least one candidate control in the relationship map having an original control and a target control, and to traverse the original control and the target control in the relationship map to identify at least one mapped control associated with the target specification. The identified candidate control may correspond to the original control or the target control in the relationship map. For example, in an embodiment, if the identified candidate control is an original control in the relationship map, the traversal involves identifying a target control that matches the original control. On the other hand, if the identified candidate control is a target control in the relationship map, the traversal involves identifying an original control that matches the target control in accordance with an embodiment.
[0047] 5, a fragmented view of an embodiment of a relationship map 500 is shown, according to various embodiments. According to various embodiments, the relationship map 500 may be prepared by one or more subject matter experts (SMEs), by other people, by an automated program, or by a combination thereof.
[0048] The relationship map (500) of Figure 5 is embodied as a data structure, and in an embodiment, as shown herein, is in the form of a table with four columns, although it should be understood that relationship maps with fewer or more columns or structures other than the tabular structure shown in Figure 5 may be used. The columns include an original column (502) containing the original control and associated standard, a target column (504) containing the target control and associated standard, a reliability column (506), and a relationship type column (508). The relationship map (500) further includes multiple rows (5100), (5101), ... (5102) representing a mapping of the original control / standard (502) to the target control / standard (504). N-1 ), where N can be an integer between 1 and infinity, typically 100, 1000, or 1 million.
[0049] For illustrative purposes, an example is provided in row 5100 where a source control / standard NIST:1A-5(1) is mapped to a destination control / standard PCI / DSS:8.2.3. (The terms "source" and "destination") apply arbitrarily between matching pairs; i.e., PCI / DSS:8.2.3 may be the source control / standard and NIST:1A-5(1) may be the destination control / standard.) Other standards that may be included in rows of relationship map 500 may include, for example, HIPPA, ISO, GDPR, Defense Information Systems Agency (DISA), Security Technical Implementation Guides (STIG), and various other standards. Confidence column 506 represents a value associated with the similarity or relationship between the source and destination pair for a given row that demonstrates the corresponding relationship. For example, for row 5100, the assessed confidence level is "high" for the relationship between NIST:1A-5(1) and PCI / DSS:8.2.3. Alternatively, confidence column 506 may record a number (e.g., between 0 and 1), a grade, or other value or index representing the confidence level. Relationship type column 508 represents the relationship between the source and target pair for a given row. According to an exemplary embodiment, the relationship refers to the hierarchical structure of the standard, e.g., relationships such as parent, child, sibling, adjacent, etc. In row 5100 of FIG. 5, the relationship type represents "adjacent."
[0050] According to another embodiment, the computer system (100), more specifically the server (110), is configured to target the traversal of the relationship map for at least one parameter or constraint. According to an embodiment, the parameter has a relationship confidence (or level). For example, to identify a mapped control as an output, the parameter may require a relationship with at least "high" confidence in the confidence column (506) in FIG. 5. For example, if a "high" confidence level identifies too few mapped controls, the acceptable confidence level may need to be changed, such as to "medium." According to an embodiment, the mapping manager (154) changes the confidence level.
[0051] According to another embodiment, parameters or constraints for the traversal of the relationship map include a limit on the number of intermediate nodes between the source control and the target control in the hierarchical structure to identify the mapped control as output. For example, in a hierarchical structure, not all nodes are directly connected to each other by a single edge. Rather, there may be one, two, three, four, or more intermediate nodes between adjacent relationship pairs (each with two, three, four, five, or more corresponding edges). For example, in the case of a source node representing a great-grandchild and a target node representing a great-grandfather, there are two intermediate nodes. The source node representing the great-grandchild is connected to the first intermediate node representing the parent by a first edge, the first intermediate node representing the parent is connected to the second intermediate node representing the grandparent by a second edge, and the second intermediate node representing the grandparent is connected to the target node representing the great-grandfather by a third edge. Thus, there are two intermediate nodes between the great-grandchild source node and the great-grandchild target node. In this example, if the limit on the amount of intermediate nodes is set to 1 or less, a relationship between the great-grandchild node (characterized by two intermediate nodes) and the great-grandfather target node will not be identified. On the other hand, if the limit on the amount of intermediate nodes is set to 2 or less, a relationship between the great-grandchild node (characterized by two intermediate nodes) and the great-grandfather target node will be identified. According to an embodiment, the mapping manager 154 changes the allowable amount of intermediate nodes.
[0052] An exemplary embodiment of pseudocode for traversing the relationship map is set forth as follows: Input: technical specification (s), target regulatory standard (t), confidence = high, relationship map (map) traversal_list = [] for relationship(r) in map: rule_map = traverse(r, t, confidence) Note: r is r s , r d , r c and r t Contains r s is the original regulatory standard, and r d is the target regulatory standard, and r c is the relationship trust, and r t is the relationship type traversal_list.append(rule_map) return traversal_list The pseudocode for traverse(r, t, reliability) is given below. if r c ==confidence: if t == r s : rule_map = fund entry for rule r d in knowledge base if t == r d : rule_map = fund entry for rule r s in knowledge base return rule_map
[0053] The traversal_list is a list of possible mappings. If the returned traversal_list is empty, relationships may need to be re-evaluated, including, in embodiments, setting or resetting confidence levels in a more inclusive manner with respect to considerations.
[0054] According to an embodiment, referring to the platform computing system (100) of FIG. 1 , the score manager (156) is configured to evaluate a second score representing the similarity between at least one mapped control output by the mapping manager (154) and the target specification. According to an exemplary embodiment, the similarity is calculated based on an embedding vector derived from the text. Embedding techniques, such as word2vec or language modeling techniques (e.g., transformers), may be used to derive the vector from the text. Typically, the score manager (156) evaluates an additional score (also referred to herein as the “second score”); the “first score” is described above with respect to the AI model (140) utilized for the multiple mapped controls output by the mapping manager (154). According to an embodiment, the score manager (156) is further configured to rank the mapped controls based on the second score. An example of pseudocode for ranking is set forth as follows: input: target specification string (s), traversal_list unique_result = get unique results from the traversal list map<string, float> similarity_rank for result in unique_result: similarity_rank.append(result, similarity(result, s)) sort similarity_rank output: top ranked result.
[0055] As shown in line 5 of the pseudocode, in embodiments, a score is generated that may utilize one of many similarity measures. In an exemplary embodiment, the similarity is a text-based measure that may use a cosine similarity measure of the control and target specifications.
[0056] According to an embodiment, the score manager (156) determines whether the score, also referred to herein as the second score, of each mapped control is above or below a threshold. According to an embodiment, if the second score (e.g., 0.7) is equal to or greater than, and therefore satisfies, a predetermined second threshold (e.g., 0.5), the mapped control is deemed an acceptable match to the target specification. According to an embodiment, if the second score (e.g., 0.3) is less than, and therefore does not satisfy, the predetermined second threshold (e.g., 0.5), the mapped control is deemed an unacceptable match to the target specification.
[0057] In the event that the mapped control has an acceptable score or other confidence level that qualifies the mapped control as an acceptable match to the target specification, the score manager 156 accepts the mapped control as output. The target specification is mapped to the mapped control.
[0058] In the event that a mapped control is found to lack an acceptable score or other confidence level that qualifies the mapped control as an acceptable match to the target specification, a validation of this finding may be performed. According to an embodiment, the validation may be performed by an expert, e.g., an SME.
[0059] If validation reveals that the mapped controls are an acceptable match to the target specifications, the training manager (158) is configured to selectively train the AI model (140) using the mapped controls and the target specifications. If validation reveals that the mapped controls are not an acceptable match to the target specifications, the training manager chooses not to use the match to train the AI model (140).
[0060] The data source for the AI model (140) is a knowledge base k. As explained in further detail below, the following is pseudocode for enhancing the knowledge base for the AI model (140), e.g., training the AI model (140): Input: tech spec(s), knowledge base (k) Result = top ranked result from AI model with string s as the input if similarity(s, result) < 1. k ENRICHED = k.add(s) Output: k ENRICHED
[0061] In some exemplary embodiments, the server 110 may be an IBM Watson® system available from International Business Machines Corporation of Armonk, New York, enhanced with mechanisms of the exemplary embodiments described below. An AI model manager 152, and optionally one or more of a mapping manager 154, a score manager 156, and a training manager 158, collectively referred to as tools, are shown embodied in or integrated within the AI platform 150 of the server 110. In embodiments, the tools may be implemented in a separate computing system (e.g., server 190) connected to the server 110 via the network 105. Whenever embodied, the tools serve to support the utilization and training of AI models for control identification. The tools serve to select the “best” matching control and further train the AI models.
[0062] The types of information processing systems that can utilize the AI platform 150 range from small handheld devices, e.g., handheld computers / cell phones 180, to large mainframe systems, e.g., mainframe computers 182. Examples of handheld computers 180 include personal digital assistants (PDAs), personal entertainment devices, e.g., MP4 players, portable televisions, and compact disc players. Other examples of information processing systems include pen or tablet computers 184, laptop or notebook computers 186, personal computer systems 188, and servers 190. As shown, various information processing systems can be networked together using a computer network 105. Types of computer networks 105 that can be used to interconnect various information processing systems include local area networks (LANs), wireless local area networks (WLANs), the Internet, public switched telephone networks (PSTNs), other wireless networks, and any other network topology that can be used to interconnect information processing systems. Many information handling systems include a non-volatile data store, such as a hard drive or non-volatile memory, or both. Some information handling systems include a non-volatile data store (190 A ) and a separate non-volatile data store (e.g., server (190) and non-volatile data store (182) A A mainframe computer (182) utilizing a non-volatile data store (182) may be used. A ) may be components that may be external to the various information handling systems or may be internal to one of the information handling systems.
[0063] The information processing system used to support the AI platform (150) may take many forms, several of which are shown in FIG. 1. For example, the information processing system may take the form of a desktop, server, portable, laptop, notebook, or other form factor computer or data processing system. The information processing system may also take other form factors, such as a personal digital assistant (PDA), gaming device, ATM machine, portable telephone device, communications device, or other device that includes a processor and memory. The information processing system may also embody a northbridge / southbridge controller architecture, although it will be understood that other architectures may also be used.
[0064] An application program interface (API) is understood in the art as a software intermediary between two or more applications. With respect to the (AI) platform 150 shown and described in Figure 1, one or more APIs may be utilized to support one or more of the tools 152, 154, 156, and 158 and their associated functionality. Referring to Figure 2, a block diagram 200 is provided illustrating the tools 152, 154, 156, and 158 and their associated APIs. As shown, multiple tools are embedded within the (AI) platform 205, including an AI model manager 252 associated with API 0 (212), a mapping manager 254 associated with API 1 (222), a score manager 256 associated with API 2 (232), and a training manager 258 associated with API 3 (242). Each of the APIs may be implemented in one or more languages and interface specifications.
[0065] As shown, API 0 (212) is configured to support and enable the functionality represented by AI Model Manager (252): API 0 (212) provides functional support for accessing pre-trained AI models, inputting target specifications along with associated target specifications into the AI models, and generating one or more candidate controls, API 1 (222) provides functional support for utilizing a relationship map and traversing the map to identify one or more mapped controls, API 2 (232) provides functional support for scoring and / or ranking the mapped controls, and API 3 (242) provides functional support for selectively training AI models. As shown, each of APIs 212, 222, and 232 is operably coupled to API orchestrator 260, otherwise known as an orchestrator layer, which is understood in the art to function as an abstraction layer that threads transparently with the separate APIs. In embodiments, the functionality of the separate APIs may be concatenated or combined. In alternative embodiments, the functionality of the separate APIs may be further divided into additional APIs. As such, the organization of APIs shown herein should not be considered limiting. Accordingly, the functionality of the tools may be embodied or supported by their respective APIs, as shown herein.
[0066] 3A and 3B collectively, a flowchart (300) is provided illustrating an embodiment of a process (or method) for leveraging an AI model and a relationship map to identify one or more controls and train the AI model.
[0067] In Figure 3A, a target standard (e.g., PCI / DSS) and a target specification (e.g., "minimum password length 7 characters") are input into a pre-trained AI model (302). The AI model generates output in the form of one or more candidate controls, each with an associated standard and a corresponding first score (304). The first score may be a numerical value, a confidence level (e.g., high), or some other quantitative or qualitative score. The amount of the output candidate control is identified and used to calculate a variable X TOTAL (306) and the corresponding candidate control count variable X is initialized (308). X A determination (310) is made as to whether the target is associated with a corresponding specification that matches the target specification input to the AI model. A negative response to the determination (310) causes the process (300) to jump to step (316), described below. A positive response to the determination (310) causes the CandidateControl X This is followed by another decision (312) as to whether the first score satisfies a first threshold, which may be a quantitative or qualitative threshold. An affirmative response to decision (312) is X is interpreted as indicating an acceptable match to the target specification, and X is output (314), after which the candidate control count variable (X) is incremented (336), as shown in Figure 3B. Alternatively, a non-affirmative response to the decision (312) is followed by a traversal (316) of the map. In an exemplary embodiment, the map is used to traverse the CandidateControl count variable (X) to identify one or more mapped controls with corresponding specifications that match the target specification. X The amount of control mapped is traversed using the assigned value Y TOTAL (318).
[0068] As shown in Figure 3B, the process (300) continues with ranking (320) of the mapped controls, followed by initialization of a mapped control count variable Y (322). In an exemplary embodiment, the ranking is performed using the corresponding "first scores" identified by the AI model (140) (in Figure 1) utilized to traverse the map. MappedControl Y A determination (324) is made, e.g., determined by a score manager, whether the second score associated with the MappedControl satisfies a second threshold. Like the first threshold, the second threshold may be quantitative or qualitative. For example, the second threshold may be a minimum score between zero (0) and one (1). In the exemplary embodiment described above, if the second score (e.g., 0.7) is equal to or greater than, and therefore satisfies, a predetermined second threshold (e.g., 0.5), the mapped control is deemed an acceptable match to the target specification. A positive response to the determination (324) is made by determining whether the MappedControl satisfies a second threshold. Y is interpreted as an acceptable match to the target specification, and the MappedControl Y is output (326). According to embodiments, if the second score (e.g., 0.3) is lower than, and therefore does not meet, a predetermined second threshold (e.g., 0.5), the mapped control is deemed an unacceptable match to the target specification, resulting in a non-positive response in decision (324). According to embodiments, if the second score (e.g., 0.3) is lower than, and therefore does not meet, a predetermined second threshold (e.g., 0.5), the mapped control is deemed an unacceptable match to the target specification, resulting in a non-positive response in decision (324).
[0069] A non-positive response to the decision (324) is YThis is followed by a decision (328) as to whether the MappedControl is an acceptable match to the target specification. The decision (328) may be made manually, such as by an SME. In the event of a non-affirmative response to the decision (328), the variable Y is incremented (332). In the event of a positive response to the decision (328), the MappedControl Y is used to train the AI model (330), and the variable Y is incremented (332). The incremented value of Y is then TOTAL A determination (334) is made as to whether or not the candidate control count variable X is greater than X. A non-affirmative response to the determination (334) returns to step (324). In the event of an affirmative response to the determination (334), the candidate control count variable X is incremented (336) and the incremented value of X is set to X. TOTAL A determination 338 is made as to whether or not the value is greater than the value 310. A negative response to the determination 338 returns to step 310. A positive response to the determination 338 ends the process 300.
[0070] Referring to Figure 4, flowchart 400 illustrates an embodiment with modifications (or additions) to process 300 of Figures 3A and 3B. Steps 416, 418, 420, and 422 correspond to steps 316, 318, 320, and 322, respectively, of Figures 3A and 3B. For brevity, the above descriptions of steps 316, 318, 320, and 322 are incorporated herein with respect to steps 416, 418, 420, and 422. Steps 442, 444, 446, and 448 of Figure 4 are additional steps that may be included in process 300.
[0071] As shown, following step (418), the amount of mapped control Y TOTALA determination (442) is made as to whether Y is lower than a minimum result parameter, which may represent a predetermined minimum input of the mapping control. A positive response to determination (442) returns to step (416) for a new traversal of the relationship map, followed by an expansion of the mapping parameters (e.g., acceptable confidence level, relationship type, etc.). TOTAL This was followed by the decision (418).
[0072] A non-positive response to decision (442) is the amount of mapped control Y TOTAL This is followed by another determination (446) of whether Y is greater than a minimum result parameter, which may represent a predetermined maximum population of mapping controls. A positive response to determination (444) is followed by restricting the mapping parameters (e.g., increasing the minimum confidence or level, or decreasing the intermediate node limits described above, or both), and returning to step (416) for a new traverse or relationship map, Y TOTAL A non-positive response to decision (446) is followed by a decision of the amount of mapped control Y TOTAL is interpreted as being shown to be acceptable, and the process (400) continues with a step (420) for ranking the mapped controls and a step (430) for applying a Y Total In an exemplary embodiment, the ranking (420) is performed using the corresponding "first scores" identified by the AI model (140) (in FIG. 1) utilized to traverse the mapping (416).
[0073] Aspects of utilizing an AI model for control identification and training the AI model are shown and described using the tools and APIs shown in Figures 1 and 2, respectively, and the processes shown in Figures 3A, 3B, and 4. Aspects of functional tools 152, 154, 156, and 158 and their associated functionality may be embodied in a computer system / server at a single location or, in embodiments, configured in a cloud-based system shared computing resource. With reference to Figure 6, a block diagram 600 is provided illustrating an example computer system / server 602, hereafter referred to as host 602, in communication with a cloud-based support system to implement the processes described above with reference to Figures 3A, 3B, and 4. The host 602 is operable with numerous other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, or configurations, or combinations thereof, that may be suitable for use with host 602 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputer systems, mainframe computer systems, and file systems (e.g., distributed storage environments and distributed cloud computing environments) that include any of the above systems, devices, and their equivalents.
[0074] The host 602 may be described in the general context of computer system-executable instructions, e.g., program modules, executed by a computer system. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. The host 602 may be implemented in a distributed cloud computing environment 610 where tasks are performed by remote processing devices that are linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media, including memory storage devices.
[0075] As shown in FIG. 6, the host (602) is depicted in the form of a general-purpose computing device. Components of the host (602) may include, but are not limited to, one or more processors or processing units (604), such as a hardware processor; system memory (606); and a bus (608) coupling various system components, including the system memory (606) and the processing unit (604). The bus (608) represents any one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. By way of example, and not limitation, such architectures include an Industry Standard Architecture (ISA) bus, a MicroChannel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus. The host (602) typically includes a variety of computer system-readable media. Such media can be any available media that is accessible by the host 602 and includes both volatile and non-volatile media, removable and non-removable media.
[0076] The system memory 606 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 630 or cache memory 632, or both. By way of example only, the storage system 634 may be provided to read from and write to non-removable, non-volatile magnetic media (not shown, typically referred to as a "hard drive"). Although not shown, a magnetic disk drive may be provided to read from and write to a removable, non-volatile magnetic disk (e.g., a floppy disk), and an optical disk drive may be provided to read from or write to a removable, non-volatile optical disk, such as a CD-ROM, DVD-ROM, or other optical media. In such an example, each may be connected to the bus 608 by one or more data media interfaces.
[0077] A program / utility (640) having a set (at least one) of program modules (642), by way of example and not limitation, may also be stored in system memory (606), including an operating system, one or more application programs, other program modules, and program data. Each of the operating system, one or more application programs, other program modules, and program data, or some combination thereof, may include an implementation of a networking environment. The program modules (642) generally perform the functionality and / or methodology of embodiments to support and enable reinforcement learning through random action replay for natural language (NL). For example, the set of program modules (642) may include tools (152), (154), (156), or (158), or a combination thereof, as described in FIG. 1 .
[0078] The host (602) may communicate with one or more external devices (614), such as a keyboard, a pointing device, a display (624), one or more devices that allow a user to interact with the host (602), or any device that allows the host (602) to communicate with one or more other computing devices (e.g., a network card, a modem, etc.), or a combination thereof. Such communication may occur through an input / output (I / O) interface (622). Furthermore, the host (602) may communicate with a local area network (LAN), a general wide area network (WAN), or a public network (e.g., the Internet), or a combination thereof, through a network adapter (620). The host 602 may communicate with one or more networks, such as a network adapter 620, a storage system, a network controller, a network bus, or a combination thereof. As shown, a network adapter 620 communicates with other components of the host 602 via a bus 608. In an embodiment, multiple nodes of a distributed file system (not shown) communicate with the host 602 via an I / O interface 622 or via the network adapter 620. Although not shown, it should be understood that other hardware or software components, or combinations thereof, may be used with the host 602. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archive storage systems.
[0079] In this document, the terms "computer program medium," "computer usable medium," and "computer readable medium" are used generally to refer to media such as system memory (606), including RAM (630), cache (632), and storage system (634), e.g., removable storage drives and hard disks installed in hard disk drives.
[0080] Computer programs (also called computer control logic) are stored in the system memory (606). The computer programs may be received via a communications interface, such as a network adapter (620). When executed, such computer programs enable the computer system to perform the features of the present embodiments as described herein. In particular, when executed, the computer programs enable the processing unit (604) to perform the features of the computer system. Thus, such computer programs represent the controller of the computer system.
[0081] In an embodiment, the host (602) is a node in a cloud computing environment. As known in the art, cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with the provider of the service. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models. Examples of such characteristics are:
[0082] On-Demand Self-Service: Cloud consumers can unilaterally provision computer capacity, such as server time and network storage, automatically as needed, without requiring human interaction with the provider of the service.
[0083] Broad Network Access: Functionality is available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (eg, cell phones, laptops, and PDAs).
[0084] Resource Pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated according to demand. While consumers generally have no control over or awareness of the exact location of the resources provided, there is a sense of location independence in that they may be able to specify a location at a higher abstraction layer (e.g., country, state, or data center).
[0085] Rapid Elasticity: Features can be rapidly released, provisioned quickly and elastically, in some cases automatically, to scale out quickly, and quickly scale in. To the consumer, the features available for provisioning often appear unlimited and can be purchased in any quantity at any time.
[0086] Metering Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at several layers of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of the services used.
[0087] The service model is as follows:
[0088] Software as a Service (SaaS): The functionality offered to the consumer is the use of a provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through a thin-client interface, e.g., a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functions, with the possible exception of limited user-specific application configuration settings.
[0089] Platform as a Service (PaaS): The functionality offered to consumers is the deployment of consumer-created or acquired applications written using programming languages and tools supported by the provider onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but does have control over the applications being deployed and, in some cases, the application hosting environment configuration.
[0090] Infrastructure as a Service (IaaS): The functionality provided to the consumer is provisioning processing, storage, networking, and other underlying computing resources, allowing the consumer to deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but does have control over the operating systems, storage, deployed applications, and possibly limited control over selected networking components (e.g., host firewalls).
[0091] The deployment model is as follows:
[0092] Private Cloud: Cloud infrastructure is operated exclusively for the organization. It may be managed by the organization or a third party and may exist on-premise or off-premise.
[0093] Community Cloud: Cloud infrastructure is shared by several organizations to support a specific community of shared interests (e.g., mission, security requirements, policies, and compliance considerations). It may be managed by the organization or a third party and may exist on-premises or off-premises.
[0094] Public Cloud: Cloud infrastructure is made available to the general public or large industry organizations and is owned by organizations that sell cloud services.
[0095] Hybrid Cloud: A cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain their own entities, but are bound together by standardized or proprietary technologies for data and application portability (e.g., cloud bursting for load balancing between clouds).
[0096] Cloud computing environments are service-oriented with an emphasis on statelessness, low coupling, modularity and semantic interoperability. At the heart of cloud computing is an infrastructure that comprises a network of interconnected nodes.
[0097] Referring now to FIG. 7, an exemplary cloud computing network 700 is shown. The cloud computing network 700 includes a cloud computing environment 750 having one or more cloud computing nodes 710 with which local computing devices used by cloud consumers may communicate. Examples of these local computing devices include, but are not limited to, a personal digital assistant (PDA) or mobile phone 754A, a desktop computer 754B, a laptop computer 754C, or an automobile computer system 754N, or combinations thereof. Individual nodes within the cloud computing node 710 may also communicate with each other. They may be physically or virtually grouped in one or more networks (not shown), such as private, community, public, or hybrid clouds, or combinations thereof, as described above. This enables the cloud computing environment 700 to provide infrastructure, platform, or software-as-a-service services, or combinations thereof, without requiring cloud consumers to maintain resources on their local computing devices. It will be understood that the types of computing devices (754A-N) shown in FIG. 7 are intended to be exemplary only, and that the cloud computing environment (750) can communicate with any type of computerized device via any type of network or network-addressable connection (e.g., using a web browser), or both.
[0098] Referring now to Figure 8, there is shown a set of functional abstraction layers (800) provided by the cloud computing network of Figure 7. It should be understood in advance that the components, layers, and functions shown in Figure 8 are intended to be exemplary only, and that the embodiments are not limited thereto. As shown, the following layers and corresponding functions are provided: a hardware and software layer (810), a virtualization layer (820), a management layer (830), and a workload layer (840).
[0099] The hardware and software layer (810) includes hardware and software components. Examples of hardware components include mainframes, in one example, IBM zSeries systems, i.e., servers based on RISC (reduced instruction set computing) architecture, in one example, IBM pSeries systems, IBM xSeries systems, and IBM BladeCenter systems, storage devices, networks, and networking components. Examples of software components include network application server software, in one example, IBM WebSphere application server software, and database software, in one example, IBM DB2 database software. (IBM, zSeries, pSeries, xSeries, BladeCenter, WebSphere, and DB2 are trademarks of International Business Machines Corporation, registered in many jurisdictions worldwide.)
[0100] The virtualization layer (820) may provide an abstraction layer at which the following examples of virtual entities are provided: virtual servers, virtual storage, virtual networks including virtual private networks, virtual applications and operating systems, and virtual clients.
[0101] In one example, the management layer (830) may provide the following functions: resource provisioning, metering and pricing, a user portal, service layer management, and SLA planning and fulfillment. Resource provisioning provides dynamic procurement of computing and other resources utilized to execute tasks within the cloud computing environment. Metering and pricing provides cost management as resources are utilized within the cloud computing environment and billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. A user portal provides access to the cloud computing environment for consumers and system administrators. Service layer management provides cloud computing resource allocation and management so that required service layers are met. Service layer agreement (SLA) planning and fulfillment provides proactive provisioning and procurement of cloud computing resources where future requirements are anticipated according to SLAs.
[0102] The workload layer (840) provides examples of functions for which a cloud computing environment may be utilized. Examples of workloads and functions that may be provided from this layer include, but are not limited to, mapping and navigation, software development and lifecycle management, virtual classroom instruction delivery, data analytics processing, transaction processing, and AI model control identification and AI model training.
[0103] While particular embodiments of the present invention have been shown and described, it will be apparent to those skilled in the art that, based on the teachings herein, changes and modifications can be made without departing from the embodiments and their broader aspects. Accordingly, the appended claims are intended to encompass within their scope all such changes and modifications as fall within the true spirit and scope of the embodiments. Moreover, it should be understood that the embodiments are defined solely by the appended claims. Where a specific number of introduced claim elements is intended, such intent will be expressly recited in the claim; in the absence of such recitation, it will be understood by those skilled in the art that no such limitation exists. As a non-limiting example and as an aid to understanding, the appended claims below include the use of the preambles "at least one" and "one or more" to introduce claim elements. However, the use of such phrases should not be construed as suggesting that the introduction of a claim element with the indefinite article "a" or "an" limits a particular claim including such introduced claim element to embodiments including only one of such elements. This is true even if the same claim includes the preface "one or more" or "at least one" and an indefinite article such as "a" or "an." The same applies to the use of definite articles within the claims. As used herein, the term "and / or" means either or both (any or all combinations of the referenced terms or expressions), e.g., "A, B and / or C" means A alone, B alone, C alone, A and B, A and C, B and C, and A, B and C.
[0104] The present embodiments may be systems, methods, or computer program products, or combinations thereof. Additionally, selected aspects of the present embodiments may take the form of entirely hardware embodiments, entirely software embodiments (including firmware, resident software, microcode, etc.), or entirely embodiments combining software or hardware aspects, or both, all generally referred to herein as "circuits," "modules," or "systems." Furthermore, aspects of the present embodiments may take the form of a computer program product embodied in a computer-readable storage medium (or media) having computer-readable program instructions for causing a processor to perform aspects of the present embodiments. Thus, the disclosed systems, methods, or computer program products, or combinations thereof, as embodied, operate to provide improvements to transfer learning operations.
[0105] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction-execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, dynamic or static random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), magnetic storage devices, portable compact disc read-only memory (CD-ROM), digital versatile discs (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge structures in a groove with recorded instructions, and any suitable combination of the foregoing. As used herein, computer-readable storage media are not, per se, to be construed as being transitory signals, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses traveling through a fiber optic cable), or electrical signals transmitted through electrical wires.
[0106] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer, or to an external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may comprise copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions to storage in a computer-readable storage medium within the respective computing / processing device.
[0107] The computer-readable program instructions for carrying out the operations of the present embodiments may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, or C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, as a standalone software package, partially on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server or server cluster. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, an electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuit to perform aspects of the present embodiments.
[0108] Aspects of the present embodiments are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to the embodiments. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0109] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus that produces a machine, such that the instructions, executing via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in a block or blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other device to function in a particular manner, such that the computer-readable storage medium having the instructions stored thereon comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0110] The computer-readable program instructions may also be loaded into a computer, other programmable data processing apparatus, or other device and executed on the computer, other programmable apparatus, or other device to produce a series of operational steps to generate a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device implement the functions / operations specified in the flowchart and / or block diagram blocks.
[0111] The flowcharts and block diagrams in these figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions, that implements the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may be executed in the reverse order, depending on the functionality involved. Additional blocks not shown in the figures may, for example, be included before, after, or concurrently with one or more of the illustrated blocks. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by a dedicated hardware-based system that performs the specified functions or operations or executes a combination of dedicated hardware and computer instructions.
[0112] Although specific embodiments are described herein for illustrative purposes, it will be understood that various modifications may be made without departing from the spirit and scope of the embodiments. In particular, transfer learning operations may be performed by different computing platforms or across multiple devices. Furthermore, data storage and / or corpora may be localized, remote, or spread across multiple systems. Accordingly, the scope of protection of the embodiments is limited only by the following claims and their equivalents.
Claims
1. a processor operably coupled to the memory; a platform in communication with said processor and said memory; Equipped with The platform comprises: an artificial intelligence (AI) manager configured to utilize an AI model with respect to a target specification of a target standard, the AI model configured to identify at least one candidate control associated with the corresponding standard; a mapping manager configured to traverse a map having an original control and a target control, the mapping manager including identifying the at least one candidate control in the map and traversing the original control and the target control of the map to identify at least one mapped control associated with the target specification; a training manager configured to selectively train the AI model using the mapped control and target specifications; and A computer system comprising:
2. the AI model is configured to evaluate a score corresponding to the candidate control, the score representing a similarity between the target specification and the candidate control; 2. The computer system of claim 1, wherein the mapping manager is configured to traverse the map in response to the specification associated with the at least one candidate control being different from the specification of the target, or the corresponding score not meeting a first threshold, or both.
3. The computer system of claim 1 , wherein the mapping manager is further configured to target the traversal of the map to at least one parameter.
4. The computer system of claim 3 , wherein the at least one parameter comprises a relationship confidence, a limit on the amount of intermediate nodes between the original control and the target control, or a combination thereof.
5. 4. The computer system of claim 3, wherein the mapping manager is further configured to modify the at least one parameter and traverse the map in response to the modified parameter.
6. the mapping manager is further configured to map the at least one candidate control to a plurality of mapped controls associated with the target standard; The computer system of claim 1 , wherein the platform further comprises a score manager configured to rank the mapped controls.
7. 6. The computer system of claim 1, wherein the platform further comprises a score manager configured to evaluate a score representing a similarity between the at least one mapped control and the target specification.
8. The processor Utilizing an artificial intelligence (AI) model on a target specification of a target standard, the AI model configured to identify at least one candidate control associated with the corresponding standard; A procedure for traversing a map having an origin control and a target control, said traversal comprising: identifying at least the candidate control within the map; traversing the original and target controls of the map to identify at least one mapped control associated with the target specification; a step having selectively training the AI model using the mapped control and target specifications; and A computer program for executing
9. The step of utilizing the AI model includes a step of evaluating a score corresponding to the candidate control, the score representing a similarity between the target specification and the candidate control; 9. The computer program product of claim 8, wherein traversing the map comprises traversing the map in response to the specification associated with the at least one candidate control differing from the specification of the target, or the corresponding score not meeting a first threshold, or both.
10. the processor, 9. The computer program of claim 8, further comprising: a computer program for executing a procedure for directing the traversal of the map to at least one parameter.
11. The computer program product of claim 10 , wherein the at least one parameter comprises a relationship confidence, a limit on the amount of intermediate nodes between the original control and the target control, or a combination thereof.
12. the processor, 11. The computer program of claim 10, further comprising: modifying the at least one parameter; and executing a procedure that traverses the map in response to the modified parameter.
13. the processor, mapping the at least one candidate control to a plurality of mapped controls associated with the target standard; ranking the mapped controls; 13. A computer program product according to any one of claims 8 to 12, for causing the computer to execute the following:
14. the processor, 13. A computer program according to any one of claims 8 to 12, comprising the step of: evaluating a score representing a similarity between the at least one mapped control and the target specification.
15. Utilizing an artificial intelligence (AI) model on a target specification of a target standard, the AI model identifying at least one candidate control associated with the corresponding standard; traversing the map with the original control and the target control; Equipped with The traversing step includes: using a computer processor to at least identify the candidate controls in the map; using the computer processor to traverse the original and target controls of the map to identify at least one mapped control associated with the target specification; selectively training the AI model using the mapped control and target specifications; A method comprising:
16. The step of utilizing the AI model includes evaluating a score corresponding to the candidate control, the score representing a similarity between the target specification and the candidate control; 16. The method of claim 15, wherein traversing the map comprises traversing the map in response to the specification associated with the at least one candidate control differing from the specification of the target, or the corresponding score not meeting a first threshold, or both.
17. The method of claim 15 , wherein the step of traversing the map targets the traversal of the map with respect to at least one parameter.
18. The method of claim 17 , wherein the at least one parameter comprises a relationship confidence, a limit on the amount of intermediate nodes between the original control and the target control, or a combination thereof.
19. 18. The method of claim 17, further comprising using the computer processor to modify the at least one parameter and traverse the map in response to the modified parameter.
20. traversing the map includes mapping the at least one candidate control to a plurality of mapped controls associated with the target standard; 20. The method of claim 15, further comprising ranking the mapped controls.
21. 20. The method of any one of claims 15 to 19, further comprising evaluating a score representing a similarity between the at least one mapped control and the target specification.
22. a processor operably coupled to the memory; a platform in communication with said processor and said memory; Equipped with The platform comprises: an artificial intelligence (AI) manager configured to utilize an AI model with respect to a target specification of a target standard, the AI model configured to identify at least one candidate control associated with the corresponding standard; a mapping manager configured to traverse a map having an origin control and a target control, identifying the at least one candidate control in the map; traversing the original and target controls of the map to identify at least one mapped control associated with the target specification; identifying an amount of identified and mapped control; selectively modifying parameters of the traverse and re-traversing the original and target controls of the map using the modified parameters; a mapping manager including: a training manager configured to selectively train the AI model using the at least one mapped control and target specifications; and A computer system comprising:
23. the AI model is configured to evaluate a score corresponding to the candidate control, the score representing a similarity between the target specification and the candidate control; 23. The computer system of claim 22, wherein the mapping manager is configured to traverse the map in response to the specification associated with the at least one candidate control that differs from the target specification or the corresponding score not meeting a first threshold.
24. Utilizing an artificial intelligence (AI) manager on a target specification of a target standard, the AI model configured to identify at least one candidate control associated with the corresponding standard; traversing a map having an original control and a target control; identifying the at least one candidate control in the map; traversing the original control and the target control of the map to identify at least one mapped control associated with the target specification, wherein the at least one mapped control satisfies a first parameter; identifying an amount of identified and mapped control; selectively modifying parameters of the traverse and re-traversing the original and target controls of the map using the modified parameters; selectively training the AI model using the at least one mapped control and target specifications; Including, stages and A method for providing
25. The step of utilizing the AI model includes evaluating a score corresponding to the candidate control, the score representing a similarity between the target specification and the candidate control; 25. The method of claim 24, wherein traversing the map comprises traversing the map in response to the specification associated with the at least one candidate control differing from the specification of the target, or the corresponding score not meeting a first threshold, or both.
Citation Information
Patent Citations
Processing content determination device and processing content determination method
JP2009099030A
Method and system for machine-learning based optimization and customization of document similarity calculation
JP2012118977A
Advanced Rule Analyzer to Identify Similarities in Security Rules, Deduplicate Rules, and Generate New Rules
US20200272741A1
Artificial intelligence assisted rule generation
WO2020075011A1