Application Self-Hardening via Internal Security Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods are inadequate for accurately detecting and defending against security attacks on software applications, particularly due to vulnerabilities and misconfigurations in security defenses, which can lead to breaches.

Innovation Solution

A computerized method for hardening application security involves modifying instructions to include sensors that capture information snapshots, analyzing these snapshots to detect security defense mechanisms, and invoking appropriate hardening actions to enhance security, such as adding or enabling defenses, within the application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security defenses are implemented in application software, then basic security protection is provided, but vulnerabilities and misconfigurations remain undetected leading to security breaches

Engineering Contradiction:
Improvesecurity protectionVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The application software automatically instruments itself with sensors and performs self-analysis to detect security vulnerabilities and misconfigurations. The system modifies its own instructions to include monitoring capabilities, enabling the application to autonomously identify and report security issues without external intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring where sensors capture information snapshots, analysis modules evaluate security posture, and results feed back to invoke hardening actions. This closed-loop feedback mechanism enables real-time detection and response to security vulnerabilities, improving both detection accuracy and overall security reliability.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If security sensors and analysis modules are added to monitor application behavior, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security monitoring components (sensors, analysis modules, hardening actions) are merged directly into the application's existing instruction set and execution flow. By instrumenting the application code itself rather than adding separate external monitoring systems, the solution improves detection capability while minimizing structural complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If comprehensive security monitoring is implemented within the application, then security vulnerabilities can be detected, but performance overhead increases

Engineering Contradiction:
Improvesecurity defense mechanismVSAvoidapplication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security sensors operate continuously in the background, capturing information snapshots during normal application execution without interrupting the application's primary functionality. The continuous monitoring is integrated into the application's existing execution flow, maintaining security defense while minimizing performance impact.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10839052B2Method and system of hardening applications against security attacks
Publication Date: 2020.11.17 CONTRAST SECURITY
  • US10839052B2 patent drawing
  • US10839052B2 patent drawing
  • US10839052B2 patent drawing

AI summary

In one aspect, computerized method for hardening security of an application includes the step of modifying a set of instructions of an application to include at least one sensor adapted to capture a set of information snapshots from within the application in a running state. The method includes the step of analyzing, from within the application, the set of information snapshots from the at least one sensor. The method includes the step of detecting a presence, a status, and a configuration of a security defense mechanism based on an analysis of the information snapshots; invoking an appropriate hardening action to improve the security defense mechanism of the application.