IP Library › Granted Patent US 12,107,837
Granted Patent B2
US 12,107,837 · App. 17/715,650 · Granted Oct 1, 2024

Cloud based machine learning notebook data loss prevention

Inventors: Hari Bhaskar Sankaranarayanan (Bangalore, IN); Jean-Rene Gauthier (Temecula, CA)
Assignee: Oracle International Corporation
H04L63/04G06F21/602G06N5/022H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,837
App. No.
17/715,650
Granted
Oct 1, 2024
Kind
B2
Abstract

Embodiments secure data on a cloud based network that comprises one or more machine learning (“ML”) notebooks. Embodiments monitor activity on each of the ML notebooks, the activity including one or more commands. Embodiments classify each of the commands, the classifying including generating input parameters. Based on the input parameters, embodiments determine a risk score for each of the ML notebooks. When the risk score exceeds a predetermined threshold, embodiments generate an alert.

Claims (42)

1. A method of securing data on a cloud based network that comprises one or more machine learning (ML) notebooks, the method comprising:

monitoring activity on each of the ML notebooks, wherein each of the ML notebooks comprise an interactive ML software environment with a plurality of cells, the activity comprising one or more commands executed within one or more of the plurality of cells;

classifying each of the commands, the classifying comprising generating input parameters, the input parameters comprising at least one of a type of command, a type of data used in the command, or a type of activity;

based on the input parameters, determining a data security risk score for each of the ML notebooks; and

when the data security risk score exceeds a predetermined threshold, generating a data security alert.

2. The method of claim 1 , the input parameters comprise, for each command, the type of command, the type of data used in the command, and the type of activity.

3. The method of claim 2 , wherein the type of command comprises at least one of transform, convert or extract.

4. The method of claim 1 , the monitoring activity comprising monitoring each of the cells.

5. The method of claim 4 , further comprising:

receiving an ML notebook with one or more of the cells designated as a masked cell when the risk score exceeds the predetermined threshold;

encrypting the masked cells;

hashing the masked cell using a corresponding hash; and

storing the hashed masked cell with a corresponding one or more identities of users who can use the hash to execute the masked cell.

6. The method of claim 1 , the classifying further comprising determining whether each command is a feature engineering command or an ML library command.

7. The method of claim 1 , the determining the risk score comprises weighting the input parameters.

8. The method of claim 1 , wherein the ML notebooks are hosted on the cloud based network, and the monitoring, classifying, determining the risk score and generating the alert are executed by a plugin of the ML notebooks.

9. A non-transitory computer readable medium having instructions stored thereon that, when executed by one or more processors on a cloud infrastructure, cause the processors to secure data on a cloud based network that comprises one or more machine learning (ML) notebooks, the securing comprising:

monitoring activity on each of the ML notebooks, wherein each of the ML notebooks comprise an interactive ML software environment with a plurality of cells, the activity comprising one or more commands executed within one or more of the plurality of cells;

classifying each of the commands, the classifying comprising generating input parameters, the input parameters comprising at least one of a type of command, a type of data used in the command, or a type of activity;

based on the input parameters, determining a data security risk score for each of the ML notebooks; and

when the data security risk score exceeds a predetermined threshold, generating a data security alert.

10. The computer readable medium of claim 9 , the input parameters comprise, for each command, the type of command, the type of data used in the command, and the type of activity.

11. The computer readable medium of claim 10 , wherein the type of command comprises at least one of transform, convert or extract.

12. The computer readable medium of claim 9 , the monitoring activity comprising monitoring each of the cells.

13. The computer readable medium of claim 12 , the securing further comprising:

receiving an ML notebook with one or more of the cells designated as a masked cell when the risk score exceeds the predetermined threshold;

encrypting the masked cells;

hashing the masked cell using a corresponding hash; and

storing the hashed masked cell with a corresponding one or more identities of users who can use the hash to execute the masked cell.

14. The computer readable medium of claim 9 , the classifying further comprising determining whether each command is a feature engineering command or an ML library command.

15. The computer readable medium of claim 9 , the determining the risk score comprises weighting the input parameters.

16. The computer readable medium of claim 9 , wherein the ML notebooks are hosted on the cloud based network, and the monitoring, classifying, determining the risk score and generating the alert are executed by a plugin of the ML notebooks.

17. A cloud infrastructure comprising:

one or more machine learning (ML) notebooks; and

a plugin for the ML notebooks for securing data on the cloud infrastructure, the securing comprising:

monitoring activity on each of the ML notebooks, wherein each of the ML notebooks comprise an interactive ML software environment with a plurality of cells, the activity comprising one or more commands executed within one or more of the plurality of cells;

classifying each of the commands, the classifying comprising generating input parameters, the input parameters comprising at least one of a type of command, a type of data used in the command, or a type of activity;

based on the input parameters, determining a data security risk score for each of the ML notebooks; and

when the data security risk score exceeds a predetermined threshold, generating a data security alert.

18. The cloud infrastructure of claim 17 , the input parameters comprise, for each command, the type of command, the type of data used in the command, and the type of activity.

19. The cloud infrastructure of claim 17 , the monitoring activity comprising monitoring each of the cells.

20. The cloud infrastructure of claim 17 , the classifying further comprising determining whether each command is a feature engineering command or an ML library command.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2022
From: SANKARANARAYANAN, HARI BHASKAR; GAUTHIER, JEAN-RENE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059535/0144 →
Continuity (1)
Related Publication 20230328037A1 · Oct 12, 2023