Workload security rings
Patent Information
- Application Number
- IN202347074387
- Authority / Receiving Office
- IN · IN
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-04-10
- Filing Date
- 2023-11-01
- Publication Date
- 2026-08-07
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Current distributed computing networks face challenges in isolating workloads with varying security requirements, leading to inadequate security and poor resource utilization, as existing software isolation solutions are insufficient against attacks and fail to provide scalability.
Implementing workload security rings, where computing devices are assigned to physically isolated subsets, with a security ring controller determining the security level of each workload and assigning it to eligible security rings, allowing for dynamic resource adjustment and compliance with specific security requirements.
This approach enhances security by isolating workloads based on their sensitivity and security posture, improving resource utilization and scalability, while minimizing maintenance costs and preventing attacks by limiting the 'blast radius' of potential threats.
Abstract
Description
TECHNICAL FIELD
[0001] This disclosure relates to workload security rings.BACKGROUND
[0002] Distributed computing networks (i.e., "cloud computing") are increasinglypopular due to price, scalability, and flexibility. These computing networkssimultaneously manage an incredible number of varying workloads. For instance, someworkloads may be experimental, other workloads may process user data, while yet otherworkloads may process mission critical fleet management information. Each differentworkload type demands different requirements regarding security, maintainability, andflexibility.SUMMARY
[0003] One aspect of the disclosure provides a computer-implemented method forworkload security rings that, when executed by data processing hardware causes the dataprocessing hardware to perform operations. The operations include receiving a pluralityof workloads. Each workload is associated with respective security criteria andscheduled for execution on a distributed computing system. The distributed computingsystem is divided into a plurality of security rings and each security ring of the pluralityof security rings is associated with a respective subset of computing devices of the distributed computing system that is physically isolated from the respective subset ofcomputing devices of the distributed computing system associated with each othersecurity ring of the plurality of security rings. For each respective workload of theplurality of workloads, the method includes determining, using the respective securitycriteria, a security level of the respective workload and identifying, using the securitylevel of the respective workload, one or more of the plurality of security rings that areeligible for executing the respective workload. The method also includes executing therespective workload on one or more computing devices selected from one of therespective subsets of computing devices associated with the identified one or more of theplurality of security rings eligible for executing the respective workload.
[0004] Implementations of the disclosure may include one or more of the followingoptional features. In some implementations, the operations further include, for eachsecurity ring in the plurality of security rings, determining resource utilization for therespective subset of computing devices associated with the security ring and adjusting,using the determined resource utilization, a number of computing devices in therespective subset of computing devices associated with the security ring. Optionally, foreach security ring in the plurality of security rings, the security ring is associated with arespective security requirement and each computing device in the respective subset ofcomputing devices associated with the security ring complies with the respective securityrequirement of the security ring
[0005] In some examples, the respective security requirement for each security ringin the plurality of security rings includes a different level of physical security than therespective security requirement for each other security ring in the plurality of securityrings. The operations may further include, prior to receiving the plurality of workloads,for each respective computing device of the distributed computing system, obtaining a setof parameters characterizing a security posture of the respective computing device andassigning, using the set of parameters, the respective computing device to one of theplurality of security rings.
[0006] In some implementations, the respective security criteria for each respectiveworkload of the plurality of workloads includes a sensitivity of the respective workload.The respective security criteria for each respective workload of the plurality of workloadsmay include a security posture of the respective workload. In this implementation, thesecurity posture may include an audit of the respective workload.
[0007] Optionally, the plurality of security rings include a low-security ring and ahigh-security ring. In some examples, the determined security level for the respectiveworkload includes one of a low-security level, a middle security level, or a high-securitylevel. When the determined security level for the respective workload includes the low-security level, only me low-security ring may be eligible for executing the respectiveworkload. When the determined security level for the respective workload includes thehigh-security level, only the high-security ring may be eligible for executing therespective workload. In some examples, when the determined security level for therespective workload includes the middle security level, both the low-security ring and thehigh-security ring are eligible for executing the respective workload.
[0008] Another aspect of the disclosure provides a system for workload security ringsthat includes data processing hardware and memory hardware in communication with thedata processing hardware. The memory hardware stores instructions that when executedon the data processing hardware cause the data processing hardware to performoperations. The operations include receiving a plurality of workloads. Each workload isassociated with respective security criteria and scheduled for execution on a distributedcomputing system. The distributed computing system is divided into a plurality ofsecurity rings and each security ring of the plurality of security rings is associated with arespective subset of computing devices of the distributed computing system that isphysically isolated from the respective subset of computing devices of the distributedcomputing system associated with each other security ring of the plurality of securityrings. For each respective workload of the plurality of workloads, the method includesdetermining, using the respective security criteria, a security level of the respectiveworkload and identifying, using the security level of the respective workload, one ormore of the plurality of security rings that are eligible for executing the respectiveworkload. The method also includes executing the respective workload on one or morecomputing devices selected from one of the respective subsets of computing devicesassociated with the identified one or more of the plurality of security rings eligible for executing the respective workload.
[0009] This aspect may include one or more of the following optional features. Insome implementations, the operations further include, for each security ring in theplurality of security rings, determining resource utilization for the respective subset ofcomputing devices associated with the security ring and adjusting, using the determinedresource utilization, a number of computing devices in the respective subset of computingdevices associated with the security ring. Optionally, for each security ring in theplurality of security rings, the security ring is associated with a respective securityrequirement and each computing device in the respective subset of computing devicesassociated with the security ring complies with the respective security requirement of thesecurity ring,
[0010] Iii some examples, the respective security requirement for each security ringin the plurality' of security rings includes a different level of physical security than therespective security requirement for each other security ring in the plurality of securityrings. The operations may further include, prior to receiving the plurality of workloads,for each respective computing device of the distributed computing system, obtaining a setof parameters characterizing a security posture of the respective computing device andassigning, using the set of parameters, the respective computing device to one of theplurality of security rings.
[0011] In some implementations, the respective security criteria for each respectiveworkload of the plurality of workloads includes a sensitivity of the respective workload.The respective security criteria for each respective workload of the plurality of workloadsmay include a security posture of the respective workload. In this implementation, thesecurity posture may include an audit of the respective workload.
[0012] Optionally, the plurality of security rings include a low-security ring and ahigh-security ring, fa some examples, the determined security level for the respectiveworkload includes one of a low-security level, a middle security level or a high-securitylevel. When the determined security level for the respective workload includes the low-security level, only the low-security ring may be eligible for executing the respectiveworkload. When the determined security level for the respective workload includes thehigh-security level, only the high-security ring may be eligible for executing therespective workload. In some examples, when the determined security level for therespective workload includes the middle security level, both the low-security ring and thehigh-security ring are eligible for executing the respective workload.
[0013] The details of one or more implementations of the disclosure are set forth inthe accompanying drawings and the description below. Other aspects, features, andadvantages will be apparent from the description and drawings, and from the claims.DESCRIPTION OF DRAWINGS
[0014] FIG. 1 is a schematic view of an example system for implementing workloadsecurity rings.
[0015] FIGS. 2Aand 2B are schematic views ofrebalancing the security rings ofFIG. 1.
[0016] FIG. 3 is a schematic view of assigning computing devices to the securityrings.
[0017] FIG. 4 is a schematic view of assigning workloads to security rings of thesystem ofFIG 1.
[0018] FIG. 5 is a flowchart of an example arrangement of operations for a method ofimplementing workload security rings.
[0019] FIG. 6 is a schematic view of an example computing device that may be usedto implement the systems and methods described herein.
[0020] Like reference symbols in the various drawings indicate like elements.DETAILED DESCRIPTION
[0021] As distributed computing networks (commonly referred to as "cloudcomputing") are increasingly used for a wide variety of workloads, it becomes more andmore important to isolate some workloads from others. For example, some workloadsmay be experimental and prone to instability and / or attacks while other workloads mayinclude highly sensitive user data. It is undesirable to co-schedule such workloads.However, current software isolation solutions are inadequate for a variety of attacks (e.g.,software attacks, zero day attacks, kernel attacks, compromised credentials, etc.). Once amachine is compromised, all workloads executing on that machine are susceptible.However, conventional physical isolation techniques suffer from poor resourceutilization, and thus, fail to provide the scalability necessary for modern distributedcomputing networks.
[0022] Some workloads require elevated security. This elevated security may imposerequirements such as prevention of other workloads from running on the same machine(i.e., isolation) or usage ofspecial hardware components (eg., dedicated cryptographichardware). These workloads may require special means of security hardening anddemand special access restrictions (e.g., denying certain protocol connections to themachine such as Secure Shell (SSH)) or special maintenance requirements. In a typicaldistributed computing system, a workload may be assigned to any computing device withcapacity and thus may be co-scheduled with unsafe or high risk workloads. A commonsolution to this problem is assigning sensitive workloads to execute on a computingdevice alone, however, this technique tails to offer any sort ofscaling as it provides verypoor utilization rate as the computing device typically can execute a number ofworkloads and is instead limited to executing only a single workload.
[0023] Implementations herein are directed toward a distributed processing orcomputing system or network that includes a plurality ofworkload security rings. Eachcomputing device of the distributed processing system is assigned to one of the securityrings. Each computing device of each security rings is physically isolated fromcomputing devices of different security rings. A security ring controller determines asecurity level of each workload destined for execution on the distributed processingsystem. Based on the determined security level, the workload executes on one of thesecurity rings eligible to execute the workload.
[0024] Referring to FIG. 1, in some implementations, an example system 100 mayinclude a user device 10 associated with a respective user 12 in communication with aremote system 140 via a network 112. The user device 10 may correspond to anycomputing device, such as a desktop workstation, a laptop workstation, or a mobiledevice (i.e., a smart phone). The user device 10 includes computing resources 18 (e.g.,data processing hardware) and / or storage resources 16 (e.g., memory hardware).
[0025] The remote system 140 includes a distributed system (e.g., a cloudenvironment) having scalable / elastic computing resources 144 (e.g., data processinghardware) and / or storage resources 142 (e.g., memory hardware). A data store 146 (i.e.,a remote storage device 146) may be overlain on the storage resources 142 to allowscalable use of the storage resources 142 by one or more of the client or computingresources 144. The distributed system is divided into a plurality of security rings 160,160a-n with each security ring 160 including a subset of computing devices 162, I62aa162nn. That is, the remote system 140 includes a plurality of computing devices 162 thatare each assigned to one of the security rings 160. T he remote system 140 may includeany number of security rings 160 that each include any number of computing devices162, Each computing device 162 includes computing resources and memory resourcesnecessary to execute workloads 102, 1,02a--n. Each workload 102 represents a processingtask to be executed on one or more computing devices 162 within the same security ring160. In some examples, the workloads 102 are received from the user device 10 or otherremote devices (e.g., servers). In other examples, the workloads 102 originate from theremote system 140. The workloads 102 may include any sort of processing task, such asa software application.
[0026] A software application (i.e, a software resource) may refer to computersoftware that causes a computing device to perform a task. In some examples, a softwareapplication may be referred to as an "application,'' an "app," or a "program." Exampleapplications include, but are not limited to, system diagnostic applications, systemmanagement applications, system maintenance applications, word processingapplications, spreadsheet applications, messaging applications, media streamingapplications, social networking applications, and gaming applications.
[0027] Each computing device 162 is assigned or associated with a single securityring 160 such that each security ring 160 is associated with a respective subset ofcomputing devices 162 of the distributed computing network of the remote system 140.In some examples, each security ring 160 is associated with a respective subset ofcomputing devices 162 of the remote system 140 that is physically isolated from therespective subset of computing devices 162 of the remote system 140 associated witheach other security ring 160. For example, each computing device 162 of a particularsecurity ring 160 is located within a server that is physically isolated from eachcomputing device 162 of the other security rings 160. Put another way, two computingdevices 162 assigned to two different security rings 160 cannot share the same physicaldevice (e.g., server). Additional isolation techniques may be used to further separate thesecurity rings 160 (e.g,, network isolation, power isolation, etc.).
[0028] The remote system 140 executes a security ring controller 150. The securityring controller 150 receives the workloads 102 (e.g., from the user 12) and associatedsecurity criteria 104. As discussed in more detail below, the security criteria 104associated with each workload 102 includes information relating to a security posture ofthe workload 102 (i.e., how secure the workload 102 is) and / or a sensitivity of theworkload 102 (i.e., how critical or sensitive the workload 102 and / or the data theworkload 102 processes is). The security ring controller 150, for each workload 102 tobe executed on the computing devices 162 of the security rings 160, determines a securitylevel 410 (FIG. 4) of the respective workload 102 using the associated security criteria104. The security ring controller 150 identities, using the security level 410 of therespective workload 102, one or more of the plurality of security rings 160 that areeligible for executing the respective workload 102.
[0029] That is, in some implementations, each security ring 160 (i.e., the computingdevices 162 that are assigned to the respective security ring 160) is eligible to executeworkloads 102 assigned one or more particular security levels 410. In. one example, theremote system 140 may include three different security rings 160 and each security ring160 may be eligible to execute one ofthree different security levels 410. As discussed inmore detail with regards to FIG. 4, in other examples, a security ring 160 is eligible toexecute workloads 102 assigned to two or more different security levels 410.
[0030] After the security ring controller 150 identifies or determines the securitylevel 410 for a given workload 102, the given workload 102 may then execute on one ormore of the computing devices 162 eligible to execute workloads 102 with the identifiedsecurity level 410. In this way, each computing device 162 only executes workloads 102that correspond to security levels 410 that the computing device 162 is eligible to executeand workloads 102 only share computing devices 162 (i.e., execute simultaneously) withother workloads 102 that have an appropriate security level 410. Thus, the security ringcontroller 150 may split a large number of workloads 102 into multiple different securityequivalence classes (i.e., security levels 410) and isolate each class at machineboundaries (i.e., physically isolated computing devices 162). In this way, the workloadsecurity rings 160 address typical isolation threats (e.g., hardware and software exploitsand denial-oftservice attacks) by limiting the "blast radius" of potential attacks.
[0031] Referring now to FIGS. 2A and 2B, in some implementations, the securityring controller 150 includes a ring rebalancer 210. From each workload security ring160, the ring rebalancer 210 receives respective resource statistics 220, 220a-n and, usingthe resource statistics 220, determines a resource utilization 222, 222a-n for eachworkload security ring 160. Using the determined resource utilizations 222, the ringrebalancer 210 may adjust a number of computing devices 162 in. one or more of thesecurity rings 160 (i.e., adjust the number of computing devices 162 in the subset ofcomputing devices 162 associated with a particular security ring 160). In the specificexample of FIG. 2A, schematic view 200a shows a low-security ring 160, 160L and ahigh-security ring 160, 160H, although it is understood that the remote system 140 mayinclude any number of security rings 160. Here, each security ring 160L, 1.60H includesfive computing devices 162. The low-security ring 160L (with five computing devices162) is operating at 95% capacity and the high-security ring 160H (with a different fivecomputing devices 162) is operating at 25% capacity. That is, the low-security ring 160Lis operating at a high percentage of utilization (i.e., cannot easily execute additionalworkloads 100) while the high-security ring 160H is operating at a low percentage ofutilization (i.e., can easily execute additional workloads 100).
[0032] Referring now to FIG. 2B, schematic view 200b shows the ring rebalancer 210 reassigning one of the computing devices 162 from the high-security ring 160H tothe low-security ring 160L. After adjusting or reassigning the computing device 162from the high-security ring 160H to the low-security ring 160L, the high-security ring160H has four computing devices 162 (from the original five) and the low-security ring160L has six computing devices 162 (from the original five). This rebalancing results inupdated resource statistics 220 that indicate that the low-security ring 160L has a.utilization rate of 80% and the high-security ring 160H has a utilization rate of 35%.Thus, the security ring controller 150 may dynamically adjust and / or reassign computingdevices 162 from one security ring 160 to a different security ring 160 based on resourcestatistics 220. For example, when a large number of workloads 102 are scheduled toexecute on a particular security ring 160, the security ring controller 150 mayautomatically reassign additional computing devices 162 to the particular security ring160 to manage the increase in resource need.
[0033] The security ring controller 150 may take steps to ensure that reassignedcomputing devices 162 are properly sanitized prior to switching to the newly assignedsecurity ring 160. For example, the security ring controller 150 may perform memorywipes, reinstallations, and / or other procedures to ensure that no remnants of priorworkloads 102 exist on the computing device 162 to ensure the isolation between thesecurity rings 160.
[0034] Referring now to FIG. 3, in some implementations, each security ring 160 isassociated with respective security requirements 310 and each computing device 162 inthe respective subset of computing devices 162 of each security ring 160 complies withthe respective security requirement 310 of the respective security ring 160. For example,schematic view 300 includes the high-security ring 160H and the low-security ring 160L.Based on the security requirements 310 and security parameters 320 of an unassignedcomputing device 162U, the security ring controller 150 may determine which securityring 160L, 1601Ito assign the unassigned computing device 162U The respectivesecurity requirement 310 for each security ring 160 may include a different level ofphysical security than the respective security requirement 310 for each other security ring160. For example, the high-security ring 160H may have security requirements 310 thatrequire that assigned computing devices 162 have certain physical security characteristicssuch as a secure geographical location, a secure facility (e.g., in a locked room or case,security surveillance, etc.), or specific hardware. The security requirements 310 mayinclude software requirements as well, such as types ofsoftware, versions ofsoftware,etc. Put another way, the security requirements 310 may define a minimum threshold ofsecurity in a number of different categories required for a computing device 162 to beeligible to execute workloads 102 for a respective security ring 160.
[0035] A computing device 162 may be eligible to be assigned to multiple securityrings 160. For example, a highly secure computing device 162 may meet the securityrequirements 310 of the high-security ring 160II and the low-security ring 160L and maybe assigned to either security ring 160 based on other factors (e.g., resource utilization).The ring rebalancer 210 (FIGS. 2A and 2B), in some examples, only reassigns computingdevices 162 to different security rings 160 that are eligible (based on the securityrequirements 310 and the security parameters 320) for multiple security rings 160. Thus,in some implementations, prior to receiving the plurality of workloads 102, for eachrespective computing device 162 of the remote system 140, the security ring controller150 obtains the security parameters 320 characterizing a security posture of the respectivecomputing device 162. The security ring controller 150 assigns, using the securityparameters 320, the respective computing device 162 to one of the plurality of securityrings 160.
[0036] The security criteria 104 for each workload 102 may include a sensitivity ofthe workload 102. That is, the security criteria 10'4 may include parameters that indicatehow damaging an attack or loss of the workload 102 may be. For example, a workload102 that processes important data (e.g., user data, government data, etc. ) may be verysensitive while a workload 102 that processes less important data (e.g., weather data) maynot be very sensitive. The security ring 160 selected for a respective workload 102 maybe at least partially dependent on the sensitivity. For example, a sensitive workload 102may be more likely to execute on a more secure security ring 160 (e.g, more physicalsecurity, hardware security, software security, etc.) than a non-sensitive workload 102.However, due to a variety offactors (e.g., current utilization), a workload 102 with a lowsensitivity may still execute on a higher security ring 160. For example, when a low-securityring 160 is fully utilized but a high-security ring 160 has capacity, a non-sensitive workload102 may be assigned to the high-security ring 160. I he sensitivity ofthe workload may be defined by an owner of the workload and / or determinedautomatically by the security ring controller 150 and / or determined by a third-party. Forexample, the owner may set one or more flags or parameters when compiling ortransmitting the workload 102 to the security ring controller 150.
[0037] In some implementations, assignment of the workload is alternatively oradditionally dependent on the security posture of the workload 1.02. The security postureof the workload 102 represents a level of confidence in the security of the workload 102itself That is, the security posture may reflect a confidence in the likelihood of theworkload 102 affecting other workloads 102. For example, an experimental workload102 has a security posture that indicates less security than a production workload 102because an experimental workload 102 is more likely to crash and / or negatively affectother workloads 102 executing on the same computing device 162. Many parametersmay help define the security posture of a workload 102. For instance, when and how theworkload 102 was built (i.e., compiled), the author of the workload 102, and the originsof the workload 102 may all affect the security posture. In some implementations, thesecurity posture includes one or more audits or reviews (e.g., by a third party ) of therespective workload 102. For example, a workload 102 that has been audited by one ormore entities may have a more secure security posture than a workload 102 that has noaudits.
[0038] In some examples, the security posture affects which security rings 160 theworkload 102 is eligible to execute on. For example, a workload 102 with a poor securityposture (i.e., is more likely to negatively affect other workloads 102) may not be allowedto execute on a high-security ring 160 even ifthe workload 102 has a high sensitivity.For example, a workload 102 that was not compiled in a secure environment may processuser data, and thus have a high sensitivity that otherwise would qualify to execute on ahigh-security ring 160 may be restricted from executing on the high-security ring 160 dueto the risk the workload 102 poses to the other sensitive workloads 102 executing on thehigh-security ring 160. Thus, in some examples, the security rings 160 that are eligible toexecute a particular workload 102 is dependent on both the sensitivity of the workload102 and the security posture of the workload 102.
[0039] Referring now to FIG. 4, schematic view 400 includes the low-security ring160L and the high-security ring 160H. In some examples, these two are the only securityrings 160. Optionally, the workloads 102 are assigned one ofthree security levels 410: alow-security level 410L, a mid-security level 41064, or a high-security level 41 OH. Inthis example, when the determined security level 410 for the respective workload 102 isthe low-security level 410L, only the low-security ring 160L is eligible for executing therespective workload 102. Similarly, when the determined security level 410 for therespective workload 102 is the high-security level 41 OH, only the high-security ring160H is eligible for executing the respective workload 102. When the determinedsecurity level 410 for the respective workload 102 is the mid-security level 410M, boththe low-security ring and the high-security ring are eligible for executing the respectiveworkload 102. Thus, low-security workloads 102 must execute on the low-security ring160L and high-security workloads 102 must execute on the high-security ring 160H, butmid-security workloads 102 may execute on either the low-security ring 160L or thehigh- security ring 160H. This allows the security ring controller 150 to maintain a highutilization rate by dynamically assigning mid-security level workloads 102 to either thelow-security ring 160L or the high-security ring 160H (i.e., to the computing devices 162assigned to the respective security rings 160) as the situation warrants.
[0040] The low-security workloads 102 may represent unhardened workloads 102that have not taken the necessary precautions to be considered safe while high-securityworkloads 102 may represent hardened workloads 102 that have taken the necessaryprecautions to he considered safe and also include sensitive data. T he mid-securityworkloads 102 may be hardened but do not include sensitive data and thus may executeon either security ring 160. In some implementations, the security ring controller mayensure that unhardened workloads 102 (i.e., low-security workloads 102) that includesensitive data do not co-schedule on the same computing device as other unhardenedworkloads 102 with sensitive data.
[0041] FIG. 5 is a flowchart of an exemplary arrangement of operations for a method500 of providing workload security rings. The computer-implemented method 500, whenexecuted by data processing hardware 144 causes the data processing hardware 144 toperform operations. At operation 502, the method 500 includes receiving a plurality ofworkloads 102. Each workload 102 is associated with respective security criteria 104 andscheduled for execution on a distributed computing system 140. The distributedcomputing system 140 is divided into a plurality of security rings 160. Each security ring160 of the plurality of security rings 160 is associated with a respective subset ofcomputing devices 162 of the distributed computing system 140 that is physicallyisolated from the respective subset of computing devices 162 of the distributedcomputing system 140 associated with each other security ring 160 of the plurality ofsecurity rings 160
[0042] For each respective workload of the plurality of workloads, at operation 504,the method 500 includes determining, using the respective security criteria 104, a securitylevel 410 of the respective workload 102. At operation 506, the method 500 includesidentifying, using the security level 440 of the respective workload 102, one or more ofthe plurality of security rings 160 that are eligible for executing the respective workload102. The method 500, at operation 508, includes executing the respective workload 102on one or more computing devices 162 selected from one of the respective subsets ofcomputing devices 162 associated with the identified one or more of the plurality ofsecurity rings 160 eligible for executing the respective workload 102.
[0043] Thus, the implementations described herein provide automated security ringbalancing with a minimal impact on workload scheduling and computing deviceutilization and efficiency while also minimizing maintenance costs. The security ringcontroller partitions a distributed computing network into a plurality of security rings thatare isolated at the machine boundary. The security ring controller divides workloads intodifferent security equivalence classes in order to ensure isolation between more secureand sensitive workloads from less secure and / or sensitive workloads The workloadsecurity rings provide a level of abstraction to workload i solation that prevents requiringa large number ofspecific profiles and configuration permutations to execute theworkloads and provides flexibility by allowing computing devices to change securityrings. The flexibility also allows for phasing out of outdated hardware or the introductionof new hardware easily and seamlessly. The security posture of the security rings may beadjusted (e.g., by adding or removing security requirements) without any action requiredby the owners of the workloads (i.e., to adjust configuration).
[0044] FIG. 6 is schematic view of an example computing device 600 that may beused to implement the systems and methods described In this document. The computingdevice 600 is intended to represent various forms of digital computers, such as laptops,desktops, workstations, personal digital assistants, servers, blade servers, mainframes,and other appropriate computers The components shown here, their connections andrelationships, and their functions, are meant to be exemplary only, and are not meant tolimit implementations of the inventions described and / or claimed in this document.
[0045] The computing device 600 includes a processor 610, memory 620, a storagedevice 630, a high-speed interface / controller 640 connecting to the memory 620 andhigh-speed expansion ports 650, and a low speed interface / controller 660 connecting to alow speed bus 670 and a storage device 630. Each of the components 610, 620, 630, 6d0,650, and 660, are interconnected using various busses, and may be mounted on acommon motherboard or in other manners as appropriate. The processor 610 can processinstructions for execution within the computing device 600, including instructions storedin the memory 620 or on the storage device 630 to display graphical information for agraphical user interface (GUI) on an external input / output device, such as display 680coupled to high speed interface 640. In other implementations, multiple processorsand / or multiple buses may be used, as appropriate, along with multiple memories andtypes ofmemory. Also, multiple computing devices 600 may be connected, with eachdevice providing portions of the necessary operations (e.g., as a server bank, a group ofblade servers, or a multi-processor system).
[0046] The memory 620 stores information non-transitorily within the computingdevice 600. The memory 620 may be a computer-readable medium, a volatile memoryunit(s), or non-volatile memory unit(s). The non-transitory memory 620 may be physicaldevices used to store programs (e.g., sequences ofinstructions) or data (e.g , programstate information) on a temporary or permanent basis for use by the computing device600. Examples of non-volatile memory include, but are not limited to, flash memory andread-only memory (ROM) / programmable read-only memory (PROM) / erasableprogrammable read-only memory (EPROM) / electronically erasable programmableread-only memory (EEPROM) (e.g., typically used for firmware, such as boot programs).Examples of volatile memory include, but are not limited to, random access memory(RAM), dynamic random access memory (DRAM), static random access memory(SRAM), phase change memory (PCM) as well as disks or tapes.
[0047] The storage device 630 is capable of provi ding mass storage for thecomputing device 600. In some implementations, the storage device 630 is a computer-readable medium. In various different implementations, the storage device 630 may be afloppy disk device, a hard disk device, an optical disk device, or a tape device, a flashmemory or other simi lar solid state memory device, or an array of devices, includingdevices in a storage area network or other configurations. In additional implementations,a computer program product is tangibly embodied in an information carrier. Thecomputer program product contains instructions that, when executed, perform one ormore methods, such as those described above. The information carrier is a computer- ormachine-readable medium, such as the memory 620, the storage device 630, or memoryon processor 610.
[0048] The high speed controller 640 manages bandwidth-intensive operations for thecomputing device 600, while the low speed controller 660 manages lower bandwidth-16intensive operations. Such allocation of duties is exemplary only. In someimplementations, the high-speed controller 640 is coupled to the memory 620, the display680 (e.g., through a graphics processor or accelerator), and to the high-speed expansionports 650, which may accept various expansion cards (not shown). In someimplementations, the low-speed controller 660 is coupled to the storage device 630 and alow-speed expansion port 690. The low-speed expansion port 690, which may includevarious communication ports (e.g., USB, Bluetooth, Ethernet, wireless Ethernet), may becoupled to one or more input / output devices, such as a keyboard, a pointing device, ascanner, or a networking device such as a switch or router, e.g., through a networkadapter.
[0049] The computing device 600 may be implemented in a number of differentforms, as shown in the figure. For example, it may be implemented as a standard server600a or multiple times in a group ofsuch servers 600a, as a laptop computer 600b, or aspart of a rack server system 600c.
[0050] Various implementations of the systems and techniques described herein canbe realized in digital electronic and / or optical circuitry, integrated circuitry, speciallydesigned ASICs (application specific integrated circuits), computer hardware, firmware,software, and / or combinations thereof These various implementations can includeimplementation in one or more computer programs that are executable and / orinterpretable on a programmable system including at least one programmable processor,which may be special or general purpose, coupled to receive data and instructions from,and to transmit data and instructions to, a storage system, at least one input device, and atleast one output device.
[0051] These computer programs (also known as programs, software, softwareapplications or code) include machine instructions for a programmable processor, and canbe implemented in a high-level procedural and / or object-oriented programming language,and / or in assembly / machine language. As used herein, the terms "machine-readablemedium" and "computer-readable medium" refer to any computer program product, non-transitory computer readable medium, apparatus and / or device (e.g., magnetic discs,optical disks, memory, Programmable Logic Devices (PLDs)) used to provide machineinstructions and / or data to a programmable processor, including a machine-readablemedium that receives machine instructions as a machine-readable signal. The term"machine-readable signal" refers to any signal used to provide machine instructionsand / or data to a programmable processor.
[0052] The processes and logic flows described in this specification can be performedby one or more programmable processors, also referred to as data processing hardware,executing one or more computer programs to perform functions by operating on inputdata and generating output. The processes and logic flows can also be performed byspecial purpose logic circuitry, e.g., an FPGA (field programmable gate array) or anASIC (application specific integrated circuit) Processors suitable for the execution of acomputer program include, by way of example, both general and special purposemicroprocessors, and any one or more processors of any kind of digital computer.Generally, a processor wilt receive instructions and data from a read only memory or arandom access memory or both. The essential elements of a computer are a processor forpe.rfbnn.ing instructions and one or more memory devices for storing instructions anddata. Generally, a computer will also include, or be operatively coupled to receive datafrom or transfer data to, or both, one or more mass storage devices for storing data, e.g.,magnetic, magneto optical disks, or optical disks. However, a computer need not havesuch devices. Computer readable media suitable for storing computer programinstructions and data include all forms of non-volatile memory, media and memorydevices, including by way of example semiconductor memory devices, e.g., EPROM,EEPROM, and flash memory devices; magnetic disks, e.g , internal hard disks orremovable disks; magneto optical disks; and CD ROM and DVD-ROM disks. Theprocessor and the memory can be supplemented by, or incorporated in, special purposelogic circuitry.
[0053] To provide for interaction with a user, one or more aspects of the disclosurecan be implemented on a computer having a display device, e.g., a CRT (cathode raytube), LCD (liquid crystal display) monitor, or touch screen for displaying information tothe user and optionally a keyboard and a pointing device, e.g., a mouse or a trackball, bywhich the user can provide input to the computer. Other kinds of devices can be used toprovide interaction with a user as well, for example, feedback provided to the user can beany form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile
Claims
1. A computer-implemented method (500) when, executed by data processing hardware (144) causes the data processing hardware (144) to perform operations comprising: receiving a plurality of workloads (102), each workload (102) associated with respective security criteria (104) and scheduled for execution on a distributed computing system (140), the distributed computing system (140) divided into a plurality of security rings (160), each security ring (160) of the plurality of security rings (160) associated with a respective subset of computing devices (162) of the distributed computing system (140) that is physically isolated from the respective subset of computing devices (162) of the distributed computing system (140) associated with each other security ring (160) of the plurality of security rings (160), and for each respective workload (102 ) of the plurality of workloads (102): determining, using the respective security criteria (104), a security level (410) of the respective workload (102); identifying, using the security level (410) of the respective workload (102 ), one or more of the plurality of security rings (160) that are eligible for executing the respective workload (102); and executing the respective workload (102) on one or more computing devices (162) selected from one of the respective subsets of computing devices (162) associated with the identified one or more of the plurality of security rings (160) eligible for executing the respective workload (102).
2. The method of claim 1, wherein the operations further comprise, for each security ring (160) in the plurality of security rings (160): determining resource utilization (222) for the respective subset of computing devices (162) associated with the security ring (160); and adjusting, using the determined resource utilization (222), a number of computing devices (162) in the respective subset of computing devices (162) associated with the security ring (160).
3. The method of claim I or 2, wherein, for each security ring (160) in the plurality of security rings (160): the security ring (160) is associated with a respective security requirement (310), and each computing device (162) in the respective subset of computing devices (162) associated with the security ring (160) complies with the respective security requirement (310 ) of the security ring (160 ).
4. The method of claim 3, wherein the respective security requirement (310) for each security ring (160) in the plurality of security rings (160) comprises a different level of physical security than the respective security requirement (310) for each other security ring (160) in the plurality of security rings (160).
5. The method of any of claims 1-4, wherein the operations further comprise, prior to receiving the plurality of workloads (102), for each respective computing device (162) of the distributed computing system (140): obtaining a set of parameters (320) characterizing a security posture of the respective computing device (162); and assigning, using the set of parameters (320), the respective computing device (162) to one of the plurality of security rings (160).
6. The method of any of claims 1-5, wherein the respective security criteria (104) for each respective workload (102) of the plurality of workloads (102) comprises a sensitivity of the respective workload (102).
7. The method of any of claims 1-6, wherein the respective security criteria (104) for each respective workload (102) of the plurality of workloads (102) comprises a security posture of the respective workload (102).
8. The method of claim 5 or 7, wherein the security posture comprises an audit of the respective workload (102).
9. The method of any of claims 1-8, wherein the plurality of security rings (160) comprise a low-security ring (160L) and a high-security ring (16011).
10. The method of any of claims 1-9, wherein the determined security level (410} for the respective workload (102) comprises one of a low-security level (410L), a middle security level (410M), or a high-security level (410H).
11. The method of claim 10, wherein. when the determined security level (410) for the respective workload (102) comprises the low-security level (410L), only the low-security ring (160L) is eligible for executing the respective workload (102), when the determined security level (410) for the respective workload (102) comprises the high-security level (41 OH), only the high-security ring (16014) is eligible for executing the respective workload (102); and when the determined security level (410) for the respective workload (102) comprises the middle security level (410M), both the low-security ring (I60L) and the high-security ring (160H) are eligible for executing the respective workload (102).
12. A system (100) comprising: data processing hardware (144); and memory hardware (142) in communication with the data processing hardware (144), the memory hardware (142) storing instructions that when executed on the data processing hardware (144) cause the data processing hardware (144) to perform operations comprising: receiving a plurality of workloads (102), each workload (102) associated with respective security criteria (104) and scheduled for execution on a distributed computing system (140), the distributed computing system (140) divided into a plurality of security rings (160), each security ring (160) of the plurality of security rings (160) associated with a respective subset of computing devices (162) of the distributed computing system (140) that is physically isolated from the respective subset of computing devices (162) of the distributed computing system (140) associated with each other security ring (160) of the plurality of security rings (160); and for each respective workload (102) of the plurality of workloads (102): determining, using the respective security criteria (104), a security level (410) of the respective workload (102); identifying, using the security level (410) of the respective workload (102), one or more of the plurality of security rings (160) that are eligible for executing the respective workload (102); and executing the respective workload (102) on one or more computing devices (162) selected from one of the respective subsets of computing devices (162) associated with the identified one or more of the plurality of security rings (160) eligible for executing the respective workload (102).
13. The system of claim 12, wherein the operations further comprise, for each security ring (160) in the plurality of security rings (160): determining resource utilization (222) for the respective subset of computing devices (162) associated with the security ring (160); and adjusting, using the determined resource utilization (222), a number of computing devices (162) in the respective subset of computing devices (162) associated with the security ring (160).
14. The system of claim 12 or 13, wherein, for each security ring (160) in. the plurality of security rings (160): the security ring (160) is associated with a respective security requirement (310); and each computing device (162 ) in the respective subset of computing devices (162) associated with the security ring (160) complies with the respective security requirement (310) of the security ring (160).
15. The system of claim 14, wherein the respective security requirement (310) for each security ring (160) in the plurality of security rings (160) comprises a different level of physical security than the respective security requirement (310) for each other security ring (160) in. the plurality of security rings (160).
16. The system of any of claims 12-15, wherein the operations further comprise, prior to receiving the plurality of workloads (102), for each respective computing device (162) of the distributed computing system: obtaining a set of parameters (320) characterizing a security posture of the respective computing device (162); and assigning, using the set of parameters (320), the respective computing device (162) to one of the plurality of security rings (160).
17. The system of any of claims 12-16, wherein the respective security criteria (104) for each respective workload (102) of the plurality of workloads (102) comprises a sensitivity of the respective workload (102).
18. The system of any of claims 12-17, wherein the respective security criteria (104) for each respective workload (102) of the plurality of workloads (102) comprises a security posture of the respective workload (102).
19. The system of claim 16 or 18, wherein the security posture comprises an audit of the respective workload (102).
20. The system of any of claims 12-1.9, wherein the plurality of security rings (160) comprise a low-security ring (160L) and a high-security ring (160H).
21. The system of any of claims 12-20, wherein the determined security level (410) for the respective workload (102) comprises one of a low-security level (410L), a middle security level (410M), or a high-security level (410H).
22. The system of claim 21, wherein: when the determined security level (410) for the respective workload (102) comprises the low-security level (410L), only the low-security ring (160L) is eligible for executing the respective workload (102). when the determined security level (410) for the respective workload (102) comprises the high-security level (410H), only the high-security ring (160H) is eligible for executing the respective workload (102); and when the determined security level (410) for the respective workload (102) comprises the middle-security level (410M), only the low-security ring (160L) and the high-security ring (160H) are eligible for executing the respective workload (102).