Automated Security Scope Definition via TF-IDF Feature Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for computing environments, including machine learning environments, rely heavily on manual registration and administration by skilled IT administrators, which is inefficient and prone to errors, especially in complex and dynamically changing environments, leading to potential gaps in protection and improper assignment of security scopes and services.

Innovation Solution

The implementation of a Term Frequency-Inverse Document Frequency (TF-IDF) Model that automatically determines the importance and classification of machines or components within a computing environment, allowing for automated feature selection and security protection without the need for manual intervention, focusing on monitoring intended states and raising alarms for anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual registration of machines or components is performed by IT administrators, then security protection can be provided to registered components, but the process is highly dependent on administrator knowledge and experience, leading to potential gaps in protection and improper assignment of security scopes

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidmanual registration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically discovers machines and components within the computing environment and registers them with the security system without requiring manual intervention. The security system autonomously identifies important features and determines appropriate security scopes, eliminating dependency on administrator knowledge and experience while ensuring comprehensive protection coverage.

Inventive Principle:
Principle #25Self-service

2Quantity of substance

If the number of machines or components in the computing environment increases, then the computing environment becomes more complex and valuable, but the likelihood of administrators missing or forgetting to register certain components increases

Engineering Contradiction:
Improvenumber of machines or componentsVSAvoidsecurity protection completeness
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system continuously monitors the computing environment for changes, automatically detecting newly added machines and components. This feedback mechanism ensures that as the environment grows in complexity and size, the security system adapts by automatically registering new components and adjusting security scopes, maintaining complete protection coverage without increasing administrative burden.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If conventional security systems require constant upgrading of agents for discovery and monitoring, then the system can adapt to new threats, but the complexity and maintenance burden increase significantly

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidagent upgrading complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs a universal discovery and monitoring approach that automatically adapts to different machines and components without requiring specialized agents for each type. The security system performs multiple functions including discovery, classification, and registration through a single integrated mechanism, eliminating the need for constant agent upgrading while maintaining high adaptability to new threats and environment changes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11847481B2Security in a computing environment by automatically defining the scope and services of components within the computing environment
Publication Date: 2023.12.19 VMWARE INC
  • US11847481B2 patent drawing
  • US11847481B2 patent drawing
  • US11847481B2 patent drawing

AI summary

A feature selection methodology is disclosed. In a computer-implemented method, components of a computing environment are automatically monitored, and have a feature selection analysis performed thereon. Provided the feature selection analysis determines that features of the components are well defined, a classification of the features is performed. Provided the feature selection analysis determines that features of the components are not well defined, a similarity analysis of the features is performed. Results of the feature selection methodology are generated.