IP Library › Granted Patent US 11,763,005
Granted Patent B2
US 11,763,005 · App. 16/762,284 · Granted Sep 19, 2023

Dynamic security policy

Inventors: Mark Shackleton (London, GB); Fadi El-Moussa (London, GB)
Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
G06F21/577G06F9/45558G06F18/214G06F21/54G06N20/00G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,763,005
App. No.
16/762,284
Filed
May 7, 2020
Granted
Sep 19, 2023
Kind
B2
Art Unit
2494
USPC
726/25
Abstract

A computer implemented method to generate training data for a machine learning algorithm for determining security vulnerabilities of a virtual machine (VM) in a virtualized computing environment is disclosed. The machine learning algorithm determines the vulnerabilities based on a vector of configuration characteristics for the VM.

Claims (20)

1. A computer implemented method to generate training data for a machine learning algorithm for determining security vulnerabilities of a virtual machine (VM) in a virtualized computing environment, the machine learning algorithm determining the security vulnerabilities based on a vector of configuration characteristics for the VM, the method comprising:

receiving a plurality of VM configuration vectors for each of one or more training VMs, each of the plurality of VM configuration vectors including attributes of a configuration of a VM and having a temporal indication;

receiving a security occurrence identification being referable to a VM configuration vector for a training VM based on a temporal indication of the security occurrence identification,

the security occurrence identification including information defining a temporally corresponding vector of vulnerabilities for the training VM associated with the referenced VM configuration vector, and

pairing the referenced VM configuration vector with the temporally corresponding vector of vulnerabilities as a first training example;

identifying one or more further VM configuration vectors for the training VM, each of the further VM configuration vectors having temporal indications preceding that of the referenced VM configuration vector and no preceding security occurrence identification; and

pairing a modified form of the vector of vulnerabilities with each of the further VM configuration vectors as further training examples, the vector of vulnerabilities being modified for each further VM configuration vector by a reverse decay function such that each temporally earlier VM configuration vector is associated with a modified vector of vulnerabilities indicating vulnerability to a lesser degree.

2. The method of claim 1 , wherein the reverse decay function is a 0.5 kt function based on an increasing time past (t) for a chronologically earlier VM configuration vector and a constant (k).

3. The method of claim 1 , further comprising training the machine learning algorithm based on the training examples to classify a configuration vector for a VM to a vector of vulnerabilities.

4. The method of claim 1 , wherein a vector of configuration characteristics includes an indicator of a state of each of a plurality of configuration characteristics for a VM.

5. The method of claim 1 , wherein a vector of vulnerabilities includes an indicator of each of a plurality of security vulnerabilities of a VM.

6. A computer system comprising:

a processor and memory storing computer program code for generating training data for a machine learning algorithm for determining security vulnerabilities of a virtual machine (VM) in a virtualized computing environment, the machine learning algorithm determining the security vulnerabilities based on a vector of configuration characteristics for the VM, by:

receiving a plurality of VM configuration vectors for each of one or more training VMs, each of the plurality of VM configuration vectors including attributes of a configuration of a VM and having a temporal indication;

receiving a security occurrence identification being referable to a VM configuration vector for a training VM based on a temporal indication of the security occurrence identification,

the security occurrence identification including information defining a temporally corresponding vector of vulnerabilities for the training VM associated with the referenced VM configuration vector, and

pairing the referenced VM configuration vector with the temporally corresponding vector of vulnerabilities as a first training example;

identifying one or more further VM configuration vectors for the training VM, each of the further VM configuration vectors having temporal indications preceding that of the referenced VM configuration vector and no preceding security occurrence identification; and

pairing a modified form of the vector of vulnerabilities with each of the corresponding VM configuration vectors as further training examples, the vector of vulnerabilities being modified for each further VM configuration vector by a reverse decay function such that each temporally earlier VM configuration is associated with a modified vector of vulnerabilities indicating vulnerability to a lesser degree.

7. A non-transitory computer-readable storage element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to perform the method as claimed in claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2020
From: SHACKLETON, MARK; EL-MOUSSA, FADI
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 054346/0866 →
Priority Claims (1)
EP 17200478 · Nov 7, 2017 · regional
Continuity (1)
Related Publication 20210182404A1 · Jun 17, 2021