IP Library Patent Application 15433098
Patent Application
App. No. 15/433,098

AUTONOMOUS SECURITY POLICY DECISION AND IMPLEMENTATION ACROSS HETEROGENEOUS IT ENVIRONMENTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/433,098
Abstract

The disclosure is directed to an autonomous method for dynamically providing a security policy. A method in accordance with an embodiment includes: determining an existence of a new Internet-based security threat; proposing a security threat update to an existing security policy in response to the existence of the new Internet-based security threat; determining a change in a set of business rules; proposing a business rules update to the existing security policy in response to the change in the set of business rules; combining the security threat update and the business rules update into a consolidated security policy update; and updating the existing security policy based on the consolidated security update.

Claims (53)

1 . An autonomous method for dynamically providing a security policy, comprising:

determining an existence of a new Internet-based security threat;

proposing a security threat update to an existing security policy in response to the existence of the new Internet-based security threat;

determining a change in a set of business rules;

proposing a business rules update to the existing security policy in response to the change in the set of business rules;

combining the security threat update and the business rules update into a consolidated security policy update; and

updating the existing security policy based on the consolidated security update.

2 . The autonomous method for dynamically providing a security policy according to claim 1 , further comprising:

determining an existence of at least one additional new Internet-based security threat;

proposing an additional security threat update to the existing security policy in response to the existence of each additional new Internet-based security threat; and

including each additional security threat update in the consolidated security policy update.

3 . The autonomous method for dynamically providing a security policy according to claim 1 , wherein the proposing the security threat update occurs immediately after the determination of the new Internet-based security threat.

4 . The autonomous method for dynamically providing a security policy according to claim 1 , further comprising:

determining an existence of at least one additional change in the set of business rules;

proposing an additional business rules update to the existing security policy in response to the existence of each additional change business rules update; and

including each additional business rules update in the consolidated security policy update.

5 . The autonomous method for dynamically providing a security policy according to claim 1 , wherein the proposing the business rules update occurs immediately after the determination of the change in the set of business rules.

6 . The autonomous method for dynamically providing a security policy according to claim 1 , wherein the determining the new Internet-based security threat further comprises continuously monitoring at least one repository containing security exposures and security issues.

7 . The autonomous method for dynamically providing a security policy according to claim 1 , wherein the determining the new Internet-based security threat further comprises continuously monitoring the set of business rules for any changes.

8 . The autonomous method for dynamically providing a security policy according to claim 1 , further comprising:

implementing the updated security policy in a security automation tool; and

scanning, using the security automation tool, at least one resource of an IT environment using the updated security policy.

9 . An autonomous system for dynamically providing a security policy, comprising:

an autonomous security policy engine configured to:

determine an existence of a new Internet-based security threat;

propose a security threat update to an existing security policy in response to the existence of the new Internet-based security threat;

determine a change in a set of business rules;

propose a business rules update to the existing security policy in response to the change in the set of business rules;

combine the security threat update and the business rules update into a consolidated security policy update; and

update the existing security policy based on the consolidated security update.

10 . The autonomous system for dynamically providing a security policy according to claim 9 , further comprising a security automation tool for implementing the updated security policy and scanning at least one resource of an IT environment using the updated security policy.

11 . The autonomous system for dynamically providing a security policy according to claim 9 , further comprising at least one repository containing security exposures and security issues, wherein the autonomous security policy engine is configured to determine the new Internet-based security threat by continuously monitoring the at least one repository.

12 . A computer program product comprising program code embodied in at least one computer-readable storage medium, which when executed, enables a computer system to implement an autonomous method for dynamically providing a security policy, the method comprising:

determining an existence of a new Internet-based security threat;

proposing a security threat update to an existing security policy in response to the existence of the new Internet-based security threat;

determining a change in a set of business rules; proposing a business rules update to the existing security policy in response to the change in the set of business rules;

combining the security threat update and the business rules update into a consolidated security policy update; and

updating the existing security policy based on the consolidated security update.

13 . The computer program product according to claim 12 , the method further comprising:

determining an existence of at least one additional new Internet-based security threat;

proposing an additional security threat update to the existing security policy in response to the existence of each additional new Internet-based security threat; and

including each additional security threat update in the consolidated security policy update.

14 . The computer program product according to claim 12 , wherein the proposing the security threat update occurs immediately after the determination of the new Internet-based security threat.

15 . The computer program product according to claim 12 , the method further comprising:

determining an existence of at least one additional change in the set of business rules;

proposing an additional business rules update to the existing security policy in response to the existence of each additional change business rules update; and

including each additional business rules update in the consolidated security policy update.

16 . The computer program product according to claim 12 , wherein the proposing the business rules update occurs immediately after the determination of the change in the set of business rules.

17 . The computer program product according to claim 12 , wherein the determining the new Internet-based security threat further comprises continuously monitoring at least one repository containing security exposures and security issues.

18 . The computer program product according to claim 12 , wherein the determining the new Internet-based security threat further comprises continuously monitoring the set of business rules for any changes.

19 . The computer program product according to claim 12 , further comprising:

implementing the updated security policy; and

scanning at least one resource of an IT environment using the updated security policy.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 058213/0912 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE SEVENTH INVENTORS LAST NAME. PREVIOUSLY RECORDED ON REEL 041260 FRAME 0487. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 16, 2017
From: BRISKI, CAIO E.; CREMASCO, RODRIGO A.; DANIN, SERGIO AUGUSTO S.; LIMA, DANIEL K.; NASCIMENTO, LUIZ G.; PARAISO, MARCOS V.L.; SANTOS, KLALTER DE ABREU; SILVA, EMANNUEL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041740/0903 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2017
From: BRISKI, CAIO E.; CREMASCO, RODRIGO A.; DANIN, SERGIO AUGUSTO S.; LIMA, DANIEL K.; NASCIMENTO, LUIZ G.; PARAISO, MARCOS V.L.; SANTO, KLALTER DE ABREU; SILVA, EMANNUEL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041260/0487 →