IP Library Granted Patent US 10,484,402
Granted Patent B2
US 10,484,402 · App. 15/677,322 · Granted Nov 19, 2019

Security in virtualized computing environments

Inventors: Fadi El-Moussa (London, GB); Ian Herwono (London, GB)
Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
H04L63/1416G06F9/45558G06F21/53G06F21/55G06N20/00G06F2009/45587G06F2221/2149H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,402
App. No.
15/677,322
Granted
Nov 19, 2019
Kind
B2
Abstract

A computer implemented method to identify one or more parameters of a configuration of a target virtual machine (VM) in a virtualized computing environment used in a security attack against the target VM, the security attack exhibiting a particular attack characteristic, is disclosed.

Claims (20)

1. A computer implemented method to identify one or more parameters of a configuration of a target virtual machine (VM) in a virtualized computing environment used in a security attack against the target VM, the security attack exhibiting a particular attack characteristic, the method comprising:

training a machine learning algorithm as a classifier based on a plurality of training data items, each training data item corresponding to a training VM and including a representation of parameters for a configuration of the training VM and a representation of characteristics of security attacks for the training VM;

generating a first data structure for storing one or more relationships between VM configuration parameters and attack characteristics, wherein the first data structure is generated by sampling the trained machine learning algorithm to identify the one or more relationships;

receiving a second data structure storing a directed graph representation of one or more sequences of VM configuration parameters for achieving the particular attack characteristic of the security attack, the VM configuration parameters in the directed graph being determined based on the first data structure; and

determining a subset of sequences in the directed graph corresponding to VM configuration parameters of the target VM to identify VM configuration parameters of the target VM used in the security attack.

2. The method of claim 1 , wherein each of the attack characteristics has associated a protective measure, the method further comprising, in response to the identification of an attack characteristic to which the target VM is susceptible, implementing the protective measure so as to protect the VM from attacks having the attack characteristic.

3. The method of claim 2 wherein each protective measure is a configuration parameter or a change to a configuration parameter for a VM to protect against an attack characteristic.

4. The method of claim 1 , wherein the machine learning algorithm is a restricted Boltzmann machine.

5. The method of claim 4 wherein the restricted Boltzmann machine includes a plurality of hidden units and a plurality of visible units, and sampling the trained machine learning algorithm includes generating sample inputs for the hidden units to determine values of the visible units.

6. The method of claim 5 wherein each generated sample input is a vector of binary values wherein each binary value is determined using a randomization algorithm.

7. The method of claim 1 , wherein the characteristics of security attacks include an indication of the consequence of a security attack executing in the training VM.

8. The method of claim 1 , wherein each training data item comprises a vector of binary values indicating each indicating a presence or absence of a configuration feature and an attack characteristic of a corresponding training VM.

9. The method of claim 1 , wherein the data structure is a matrix data structure for mapping VM configuration parameters against attack characteristics.

10. A non-transitory computer-readable storage medium storing a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer to perform the method as claimed in claim 1 .

11. A computer system comprising:

a processor and memory storing computer program code to identify one or more parameters of a configuration of a target virtual machine (VM) in a virtualized computing environment used in a security attack against the target VM, the security attack exhibiting a particular attack characteristic by:

training a machine learning algorithm as a classifier based on a plurality of training data items, each training data item corresponding to a training VM and including a representation of parameters for a configuration of the training VM and a representation of characteristics of security attacks for the training VM;

generating a first data structure for storing one or more relationships between VM configuration parameters and attack characteristics, wherein the first data structure is generated by sampling the trained machine learning algorithm to identify the one or more relationships;

receiving a second data structure storing a directed graph representation of one or more sequences of VM configuration parameters for achieving the particular attack characteristic of the security attack, the VM configuration parameters in the directed graph being determined based on the first data structure; and

determining a subset of sequences in the directed graph corresponding to VM configuration parameters of the target VM to identify VM configuration parameters of the target VM used in the security attack.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2019
From: EL-MOUSSA, FADI; HERWONO, IAN
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 048066/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2018
From: EL-MOUSSA, FADI; HERWONO, IAN
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 048102/0709 →
Priority Claims (2)
EP 16184384 · Aug 16, 2016 · regional
GB 1614016.2 · Aug 16, 2016 · national
Continuity (1)
Related Publication 20180054451A1 · Feb 22, 2018