IP Library Granted Patent US 12,423,438
Granted Patent B2
US 12,423,438 · App. 17/904,079 · Granted Sep 23, 2025

Security automation system

Inventors: Harri Hakala (Turku, FI); Anu Puhakainen (Espoo, FI)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
G06F21/577G06F21/566H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,438
App. No.
17/904,079
Filed
Aug 11, 2022
Granted
Sep 23, 2025
Kind
B2
Art Unit
2439
USPC
726/1
Abstract

A Security automation system ( 100; 400; 500 ) configured for security management of an Information Technology (IT) system ( 200 ), the security automation system using machine learning (ML). The system comprises a Threat engine ( 110 ), a Risk engine ( 120 ), a Policy engine ( 130 ) and a Security Adaptation engine ( 140 ). The Threat engine ( 110 ) comprises a threat catalog and detection rules for identifying threat events, wherein the detection rules are automatically adjusted and modified based on information collected from the managed IT system.

Claims (33)

1. A security automation system configured for security management of an information technology (IT) system, the security automation system comprising:

a data storage system comprising one or more memories, wherein the data storage system stores:

a threat catalog with detection rules;

a vulnerability catalog comprising a database storing generic and known vulnerabilities of the IT system;

a risk catalog comprising a database storing potential risks and identified risks for the IT system; and

a policy catalog with security policies; and

processing circuitry, wherein the security automation system is configured to perform a method comprising:

identifying threat events;

using a machine learning algorithm for collecting information in the risk catalog and in the vulnerability catalog, in order to detect malicious events and security weaknesses in the IT system;

adapting one or more security policies from the policy catalog based on a risk evaluation, wherein the adapting comprises adjusting the one or more security policies in order to mitigate security risks; and

adjusting one or more of the detection rules based on information collected from the IT system.

2. The security automation system of claim 1 , wherein the security automation system is adapted to use results from on-line risk evaluation for dynamically adjusting the detection rules of the threat catalog.

3. The security automation system of claim 1 , wherein the security automation system is adapted to further monitor and analyze identified threat events, and after a specified period sending information for risk evaluation and risk rating.

4. The security automation system of claim 1 , wherein the risk catalog is updated dynamically during operations of the IT system for achieving a risk-driven and automatic security management.

5. The security automation system of claim 3 , wherein the identified risks in the risk catalog are re-rated dynamically.

6. The security automation system of claim 1 , wherein the security policies of the policy catalog are associated with the detection rules of the threat catalog.

7. The security automation system of claim 1 , wherein the risk catalog, the vulnerability catalog, the threat catalog, and the policy catalog are interconnected.

8. The security automation system of claim 1 , wherein the security automation system is adapted for analyzing threat events based on IT specific pre-defined detection rules in the threat catalog.

9. The security automation system of claim 1 , wherein the IT system comprises interacting components, wherein each component is associated with at least one operational asset, and wherein each operational asset is organized in at least one security domain according to a system topology.

10. The security automation system of claim 1 , wherein the security automation system further comprises processing circuitry and memory, the memory comprising instructions executable by the processing circuitry, whereby the security automation system is operative to perform security management of the IT system.

11. A network entity of a communication system or network comprising a security automation system configured for security management of an information technology (IT) system, the security automation system comprising:

a data storage system comprising one or more memories, wherein the data storage system stores:

a threat catalog with detection rules;

a vulnerability catalog comprising a database storing generic and known vulnerabilities of the IT system;

a risk catalog comprising a database storing potential risks and identified risks for the IT system; and

a policy catalog with security policies; and

processing circuitry, wherein the security automation system is configured to perform a method comprising:

identifying threat events;

using a machine learning algorithm for collecting information in the risk catalog and in the vulnerability catalog, in order to detect malicious events and security weaknesses in the IT system;

adapting one or more security policies from the policy catalog based on a risk evaluation, wherein the adapting comprises adjusting the one or more security policies in order to mitigate security risks; and

adjusting one or more of the detection rules based on information collected from the IT system.

12. The network entity of claim 11 , wherein the network entity is a network node or a cloud-based network device.

13. A method for security management of an information technology (IT) system having a number of interacting system components, each system component being associated with one or more operational assets relevant to the operation of the system component, wherein the operational assets are organized in one or more security domains according to a system topology, whereby the security automation system of claim 1 is operative to perform security management of the IT system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: HAKALA, HARRI; PUHAKAINEN, ANU
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 060916/0495 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 060916/0697 →
Continuity (2)
Provisional Application 62975889 · Feb 13, 2020
Related Publication 20230071264A1 · Mar 9, 2023
References Cited (27)
US 8966639B1 · Roytman · 2015 [cited by examiner]
US 9401926B1 · Dubow · 2016 [cited by examiner]
US 10021138B2 · Gill · 2018 [cited by examiner]
US 10691796B1 · Stolte · 2020 [cited by examiner]
US 10873595B1 · Oliphant · 2020 [cited by examiner]
US 20130191919A1 · Basavapatna · 2013 [cited by examiner]
US 20130347116A1 · Flores · 2013 [cited by examiner]
US 20150222656A1 · Haugsnes · 2015 [cited by examiner]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20170346846A1 · Findlay · 2017 [cited by examiner]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20180124072A1 · Hamdi · 2018 [cited by examiner]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20190098037A1 · Shenoy, Jr. · 2019 [cited by examiner]
US 20190207968A1 · Heckman · 2019 [cited by examiner]
US 20190236661A1 · Hogg · 2019 [cited by examiner]
US 20190319945A1 · Levy · 2019 [cited by examiner]
US 20200167705A1 · Risoldi · 2020 [cited by examiner]
US 20200412758A1 · Trivellato · 2020 [cited by examiner]
US 20210019423A1 · DuBois · 2021 [cited by examiner]
CN 109962891A · 2019 [cited by applicant]
EP 3528462A1 · 2019 [cited by applicant]
WO 2019211592A1 · 2019 [cited by applicant]
WO 2021028060A1 · 2021 [cited by applicant]
International Search Report and Written Opinion with Transmittal dated Apr. 8, 2021 in International Application No. PCT/EP2021/052592 (13 pages). [cited by applicant]
International Preliminary Report on Patentability dated Jun. 14, 2022 in International Application No. PCT/EP2021/052592 (13 pages). [cited by applicant]
Written Opinion of the International Preliminary Examining Authority dated Feb. 9, 2022 in International Application No. PCT/EP2021/052592 (6 pages). [cited by applicant]