Application and Data Protection Layer for Host Security Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Scaled-out applications in data centers are vulnerable to breaches due to the lack of awareness among applications about the security status of the hosts or servers they run on, leading to potential data theft and malware exposure, as endpoint protection agents do not share security information with the applications.
Innovation Solution
The implementation of an Application and Data Protection Layer (ADPL) that receives and provides security results from endpoint protection agents to local applications, enabling informed security decisions and protecting data exchanges by sharing security profiles across hosts and servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint protection agents (EPPAs) are deployed to protect hosts and servers, then security monitoring capability is improved, but security information is not shared with applications leading to data breach vulnerability
Solution Approach 1:
An intermediary component is introduced between the EPPA and the applications to bridge the information gap. This intermediary receives security information from the EPPA, processes and standardizes it, then distributes it to applications that need it. This resolves the contradiction by enabling information flow without requiring direct integration between EPPA and multiple applications.
Solution Approach 2:
The security information distribution system is segmented into distinct functional components: an EPPA module for security monitoring, an intermediary processing module for information standardization, and application-specific client modules for receiving and acting on security information. This segmentation allows each component to focus on its specific function while maintaining overall system reliability and information availability.
2Productivity
If applications communicate freely in East-West direction within data center, then productivity and data exchange efficiency are improved, but vulnerability to malware and data theft increases
Solution Approach 1:
Security checks and profile verification are performed preliminarily before applications exchange data in the East-West direction. The system proactively establishes security profiles for all participating applications and continuously monitors them during data exchange operations. This preliminary security preparation enables efficient data exchange while preventing malware communication.
Solution Approach 2:
A feedback mechanism is implemented where security information about applications is continuously monitored and fed back to the applications themselves and to the data exchange control system. Applications receive real-time security status information about their communication partners, enabling them to make informed decisions about data exchange and allowing the system to dynamically adjust security policies based on observed threats.
3Ease of operation
If applications are unaware of host security status, then ease of operation is maintained, but ability to make informed security decisions deteriorates
Solution Approach 1:
Applications are equipped with self-service security client modules that automatically receive, process, and act on security information without requiring manual configuration or intervention. These clients autonomously make security decisions based on received profiles, such as blocking communication with compromised applications or alerting operators to potential threats. This maintains operational simplicity while enabling sophisticated security decision-making.
Data Source
AI summary
In one embodiment, a system includes a processing circuit and logic integrated with and/or executable by the processing circuit. The logic is configured to cause the processing circuit to receive security results, using an application and data protection layer (ADPL) operating on a first host, from an end point protection agent (EPPA) configured to protect the first host. The logic is also configured to cause the processing circuit to provide the security results to one or more local applications operating on the first host. According to another embodiment, a method includes receiving security results, using an ADPL operating on a first host, from an EPPA configured to protect the first host. The method also includes providing the security results to one or more local applications operating on the first host. Other systems, methods, and computer program products are described in accordance with more embodiments.


