IP Library Patent Application 18371469
Patent Application
App. No. 18/371,469

PREDICTIVE PRIORITIZATION AND ADAPTIVE SECURITY OF INFRASTRUCTURE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/371,469
Abstract

Techniques associated with adaptive infrastructure security are disclosed. Information regarding a plurality of threat events from one or more source systems is received. For each of the plurality of threat events, a probability of a target system being exploited can be computed. A threat event can be selected at a first time from the plurality of threat events associated with a first probability that meets a threshold. Remedial actions performed to address the threat event at a respective source system can be received, and a guardrail to apply to the target system can be determined based on the remedial actions. The guardrail can then be applied to the target system.

Claims (51)

1 . A method, comprising:

receiving information regarding two or more threat events that occurred at one or more source systems;

computing, for each of the two or more threat events, a probability of a target system being exploited by the threat event;

selecting, at a first time, a first threat event from the two or more threat events, the first threat event associated with a first probability that meets a threshold;

receiving information regarding one or more remedial actions performed to address the first threat event at a respective source system where the first threat event occurred;

determining, based on the one or more remedial actions, a policy to apply to the target system; and

applying the policy to the target system.

2 . The method of claim 1 , further comprising:

selecting, at a second time later than the first time, a second threat event from the two or more threat events, the second threat event associated with a second probability that is less than the first probability;

receiving information regarding one or more second remedial actions performed to address the second threat event at a respective source system where the second threat event occurred;

determining, based on the one or more second remedial actions, a second policy to apply to the target system; and

applying the second policy to the target system.

3 . The method of claim 1 , wherein determining the policy comprises selecting a guardrail from a set of pre-existing guardrails.

4 . The method of claim 3 , wherein selecting the guardrail from the set of pre-existing guardrails comprises invoking a machine learning model trained on remediation data associated with historical threat events.

5 . The method of claim 1 , wherein determining the policy comprises generating a guardrail automatically.

6 . The method of claim 5 , wherein generating the guardrail comprises invoking a machine learning model trained to generate the guardrail based on remediation data associated with historical threat events.

7 . The method of claim 1 , wherein computing, for each of the two or more threat events, the probability comprises computing a predictive risk score with a weighted equation of two or more input scores.

8 . The method of claim 7 , wherein the input scores are one or more of a vulnerability assessment tool (VAT) score, a common vulnerability scoring system (CVSS) score, an asset score, a national vulnerability database (NVD) score, a social media score, or a deep web score.

9 . A system, comprising:

one or processors coupled to one or more memories that store instructions, that when executed by the one or more processors, cause the system to perform operations comprising:

receiving information regarding two or more threat events that occurred at one or more source systems;

computing, for each of the two or more threat events, a probability of a target system being exploited by the threat event;

selecting, at a first time, a first threat event from the two or more threat events, the first threat event associated with a first probability that meets a threshold;

receiving information regarding one or more remedial actions performed to address the first threat event at a respective source system where the first threat event occurred;

determining, based on the one or more remedial actions, a policy to apply to the target system; and

applying the policy to the target system.

10 . The system of claim 9 , wherein the operations further comprise:

selecting, at a second time later than the first time, a second threat event from the two or more threat events, the second threat event associated with a second probability that is less than the first probability;

receiving information regarding one or more second remedial actions performed to address the second threat event at a respective source system where the second threat event occurred;

determining, based on the one or more second remedial actions, a second policy to apply to the target system; and

applying the second policy to the target system.

11 . The system of claim 9 , wherein determining the policy comprises selecting a guardrail from a set of pre-existing guardrails.

12 . The system of claim 11 , wherein selecting the guardrail from the set of pre-existing guardrails comprises invoking a machine learning model trained on remediation data associated with historical threat events.

13 . The system of claim 9 , wherein determining the policy comprises generating a guardrail automatically.

14 . The system of claim 13 , wherein generating the guardrail comprises invoking a machine learning model trained to generate the guardrail based on remediation data associated with historical threat events.

15 . The system of claim 9 , wherein computing, for each of the two or more threat events, the probability comprises computing a predictive risk score with a weighted equation of two or more input scores.

16 . The system of claim 15 , wherein the input scores are one or more of a vulnerability assessment tool (VAT) score, a common vulnerability scoring system (CVSS) score, an asset score, a national vulnerability database (NVD) score, a social media score, or a deep web score.

17 . One or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations comprising:

receiving information regarding two or more threat events that occurred at one or more source systems;

computing, for each of the two or more threat events, a probability of a target system being exploited by the threat event;

selecting, at a first time, a first threat event from the two or more threat events, the first threat event associated with a first probability that meets a threshold;

receiving information regarding one or more remedial actions performed to address the first threat event at a respective source system where the first threat event occurred;

determining, based on the one or more remedial actions, a policy to apply to the target system; and

applying the policy to the target system.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein the operations further comprise:

selecting, at a second time later than the first time, a second threat event from the two or more threat events, the second threat event associated with a second probability that is less than the first probability;

receiving information regarding one or more second remedial actions performed to address the second threat event at a respective source system where the second threat event occurred;

determining, based on the one or more second remedial actions, a second policy to apply to the target system; and

applying the second policy to the target system.

19 . The one or more non-transitory computer-readable media of claim 17 , wherein determining the policy comprises selecting a guardrail from a set of pre-existing guardrails.

20 . The one or more non-transitory computer-readable media of claim 17 , wherein determining the policy comprises invoking a machine learning model trained on remediation data associated with historical threat events.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: BURLE, SIDDHARTH; MEENA, AMIT; GOKHALE, GEETA
To: VMWARE, INC.
Reel/Frame 064991/0613 →