Application Deployment Security via Configuration Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing deployments in virtualized environments are susceptible to security attacks, and existing methods lack effective measures to mitigate these threats.
Innovation Solution
A computer-implemented method that receives configuration information for an application, identifies matching configuration descriptors associated with known security attacks, evaluates risk scores based on these descriptors, and adjusts the application configuration to reduce the risk of attacks by selecting a compatible alternative configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If application configuration is optimized for functionality and performance, then application productivity is improved, but security vulnerability to attacks increases
Solution Approach 1:
The system performs preliminary security risk assessment by comparing application configuration parameters against a database of known attack patterns before deployment. Configuration descriptors encode attack conditions and probabilities, allowing the system to proactively identify and mitigate security risks in advance, resolving the contradiction between deployment efficiency and security by preventing attacks before they occur
Solution Approach 2:
The patent introduces configuration descriptors as an intermediary layer between application configuration and security assessment. These descriptors encode attack patterns and probabilities, serving as a mediator that translates configuration parameters into security risk evaluations, enabling automated security checks without compromising deployment productivity
2Reliability
If security measures are enhanced to mitigate attacks, then security reliability is improved, but application deployment complexity increases
Solution Approach 1:
The system transforms security assessment from a complex qualitative analysis into a quantitative parameter-based evaluation. By encoding attack patterns as configuration descriptors with associated probabilities and evaluating risk scores through mathematical operations (such as product of probabilities), the system simplifies security assessment into computable parameters, improving reliability without significantly increasing deployment complexity
Solution Approach 2:
The patent creates simplified copies of attack scenarios through configuration descriptors that encode essential attack characteristics without requiring full reproduction of complex attack vectors. These descriptor copies enable efficient security evaluation by representing attack patterns in a standardized, computationally manageable format
Data Source
AI summary
A computer implemented method of improved security of an application for deployment to a virtualized computing environment, the method including receiving configuration information for the application; accessing a set of configuration descriptors for a known security attack, each descriptor encoding at least a portion of an application configuration so as to identify one or more descriptors matching at least part of the configuration information, each descriptor in the set having a probability that the security attack will occur in a deployed application having a configuration consistent with the descriptor; evaluating a risk score for a risk of occurrence of the security attack, the risk score evaluated from the probabilities associated with the identified descriptors; identifying a set of compatible alternative configurations for the application; evaluating a risk score for a risk of occurrence of the security attack for each alternative configuration; selecting an alternative configuration having a risk score meeting a predetermined threshold; and adjusting the application configuration information to implement the selected alternative configuration.


