Application Deployment Security via Configuration Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing deployments in virtualized environments are susceptible to security attacks, and existing methods lack effective measures to mitigate these threats.

Innovation Solution

A computer-implemented method that receives configuration information for an application, identifies matching configuration descriptors associated with known security attacks, evaluates risk scores based on these descriptors, and adjusts the application configuration to reduce the risk of attacks by selecting a compatible alternative configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If application configuration is optimized for functionality and performance, then application productivity is improved, but security vulnerability to attacks increases

Engineering Contradiction:
Improveapplication deployment efficiencyVSAvoidsecurity attack risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security risk assessment by comparing application configuration parameters against a database of known attack patterns before deployment. Configuration descriptors encode attack conditions and probabilities, allowing the system to proactively identify and mitigate security risks in advance, resolving the contradiction between deployment efficiency and security by preventing attacks before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces configuration descriptors as an intermediary layer between application configuration and security assessment. These descriptors encode attack patterns and probabilities, serving as a mediator that translates configuration parameters into security risk evaluations, enabling automated security checks without compromising deployment productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are enhanced to mitigate attacks, then security reliability is improved, but application deployment complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidconfiguration assessment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system transforms security assessment from a complex qualitative analysis into a quantitative parameter-based evaluation. By encoding attack patterns as configuration descriptors with associated probabilities and evaluating risk scores through mathematical operations (such as product of probabilities), the system simplifies security assessment into computable parameters, improving reliability without significantly increasing deployment complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates simplified copies of attack scenarios through configuration descriptors that encode essential attack characteristics without requiring full reproduction of complex attack vectors. These descriptor copies enable efficient security evaluation by representing attack patterns in a standardized, computationally manageable format

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12093395B2Application deployment
Publication Date: 2024.09.17 BRITISH TELECOM PLC
  • US12093395B2 patent drawing
  • US12093395B2 patent drawing
  • US12093395B2 patent drawing

AI summary

A computer implemented method of improved security of an application for deployment to a virtualized computing environment, the method including receiving configuration information for the application; accessing a set of configuration descriptors for a known security attack, each descriptor encoding at least a portion of an application configuration so as to identify one or more descriptors matching at least part of the configuration information, each descriptor in the set having a probability that the security attack will occur in a deployed application having a configuration consistent with the descriptor; evaluating a risk score for a risk of occurrence of the security attack, the risk score evaluated from the probabilities associated with the identified descriptors; identifying a set of compatible alternative configurations for the application; evaluating a risk score for a risk of occurrence of the security attack for each alternative configuration; selecting an alternative configuration having a risk score meeting a predetermined threshold; and adjusting the application configuration information to implement the selected alternative configuration.