US 12,323,448 B2
System and method for identifying security threats based on compliance failures and infrastructure activity
Stav Sapir, Beer Sheba (IL); and Maxim Balin, Gan-Yavne (IL)
Assigned to Dell Products L.P., Round Rock, TX (US)
Filed by Dell Products L.P., Round Rock, TX (US)
Filed on Apr. 21, 2023, as Appl. No. 18/304,796.
Prior Publication US 2024/0356946 A1, Oct. 24, 2024
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) [H04L 63/20 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for managing computing infrastructure, the method comprising:
obtaining a compliance information element for an infrastructure component of the computing infrastructure;
dynamically processing the compliance information element to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;
obtaining, using the updated cross-standard compliance coverage model, standard compliance data for a security standard enforced on the infrastructure;
making a determination, based on the standard compliance data obtained using the updated cross-standard compliance coverage model, a confidentiality-integrity-availability classifications for the infrastructure, and a rating system, whether the infrastructure has undergone a change in compliance with the security standard; and
in an instance of the determination made based on the standard compliance data obtained using the updated cross-standard compliance coverage model where the infrastructure has undergone a change in compliance with the security standard resulting in a compliance failure specified by the standard compliance data:
obtaining logs for the infrastructure component;
identifying a chain of actions that lead to the compliance failure and that caused the change in compliance with the security standard; and
performing an action set to manage an impact of the change in compliance with the security standard, the action set being based at least in part of the chain of actions that was identified.