Application Analysis Tool for Automated Security Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security partitioning in computer systems requires manual trial and error for users to determine the correct security characteristics and privileges of applications, making it inefficient and prone to errors in isolating applications with appropriate resources and permissions.

Innovation Solution

An application analysis tool that checks databases and file systems to determine the required system resources, security requirements, and partition rules for applications, recommending optimal security partitions and automating the configuration process using a partition manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual trial and error method is used to determine security characteristics, then user can place applications in security partitions, but the process is time-consuming and prone to errors

Engineering Contradiction:
Improveease of placing applications in security partitionsVSAvoidtime required for manual search and examination
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The application analysis tool automatically inspects application binaries and extracts security characteristics without requiring manual user intervention. The tool performs self-service by autonomously analyzing executables, reading symbols, and determining security requirements, thereby eliminating the time-consuming manual trial and error process while maintaining accurate application placement in security partitions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of application security characteristics before the applications are actually placed in security partitions. By pre-inspecting binaries and extracting security information in advance, the system prepares all necessary security configuration data beforehand, enabling rapid and accurate partition assignment without subsequent manual adjustment or trial and error

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual examination of security characteristics is performed, then applications can be configured in security partitions, but the process requires extensive user effort and expertise

Engineering Contradiction:
Improveaccuracy of security partition configurationVSAvoidcomplexity of manual security characteristic determination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The application analysis tool serves as an intermediary between the application binaries and the security partitioning system. It automatically extracts security characteristics from application executables and translates them into configuration parameters for the partition manager, eliminating the need for users to manually examine complex security attributes while ensuring accurate and reliable partition configuration

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the manual mechanical process of examining security characteristics with an automated computational analysis mechanism. The application analysis tool uses programmatic inspection of binary files and symbol table analysis to extract security information, substituting human effort with automated software that reliably determines security requirements without requiring user expertise

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated application analysis tool is used, then security partition configuration is streamlined, but additional software components are required

Engineering Contradiction:
Improveefficiency of security partition configurationVSAvoidnumber of software components
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The application analysis tool is integrated as a component within the existing partitioning workflow, merging its functionality with the partition manager system. Rather than standing as a completely separate system, the tool combines with the existing security partitioning infrastructure to streamline configuration while minimizing the addition of standalone software components

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7895409B2Application inspection tool for determining a security partition
Publication Date: 2011.02.22 VALTRUS INNOVATIONS LTD
  • US7895409B2 patent drawing
  • US7895409B2 patent drawing
  • US7895409B2 patent drawing

AI summary

An embodiment of the invention provides an apparatus and method for determining a security partition in a computer for an application. The apparatus and method can determine required system resources, security requirements, and partition rules for an application, can determine allocated system resources, security characteristics, and partitions rules for each security partition in the computer, and can identify at least one proposed security partition for the application.