Application Discovery Graphs for Accurate Security Posture Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security management systems lack comprehensive computing logic and infrastructure for effective application discovery in computing environments, leading to stale or deficient mapping data, human errors, and increased risk of unauthorized access and malicious operations due to inaccurate application mapping.
Innovation Solution
An application discovery engine generates an annotated application discovery graph using configuration, support-text, and access log data to identify and map applications, providing security posture management by integrating security data triangulation and graph-based analysis to enhance accuracy and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual maintenance of application mapping data is used, then ease of operation is improved, but reliability deteriorates due to human errors and stale data
Solution Approach 1:
The system performs self-service through automated application discovery operations that continuously monitor and update application mappings without human intervention. The discovery engine automatically executes operations to identify applications, extract their characteristics, and maintain accurate mappings, eliminating reliance on manual maintenance while ensuring data freshness and accuracy.
Solution Approach 2:
The patent replaces manual mechanical processes with automated computational systems. Instead of human operators manually maintaining mapping data, the system uses an application discovery engine that executes automated discovery operations, processes application data, and updates mappings programmatically, thereby eliminating human errors while maintaining operational efficiency.
2Ease of operation
If configuration-based application mapping is used, then ease of operation is improved, but measurement precision deteriorates due to excessive irrelevant resources
Solution Approach 1:
The discovery engine extracts only the relevant characteristics and attributes needed for accurate application identification from the configuration data. Instead of relying on complete configuration sets that include irrelevant resources, the system selectively extracts key identifying features, thereby improving measurement precision while maintaining operational simplicity.
Solution Approach 2:
The system applies local quality by focusing discovery operations on specific application components and characteristics that are most relevant for identification. Rather than processing all configuration data uniformly, the engine targets specific local attributes of applications, improving accuracy while reducing the overhead of processing irrelevant resources.
3Device complexity
If support-text-based application discovery is used, then device complexity is reduced, but measurement precision deteriorates due to errors from reliance on application owner knowledge
Solution Approach 1:
The system implements feedback mechanisms where the discovery engine continuously monitors application behavior, access patterns, and operational data to validate and correct application mappings. This feedback loop enables the system to self-correct errors and improve accuracy over time without increasing system complexity, as the feedback is integrated into the existing discovery operations.
Solution Approach 2:
The discovery engine performs multiple functions using a single unified system: it discovers applications, extracts characteristics, validates mappings, and updates configurations. This multi-functionality eliminates the need for separate manual processes while maintaining reasonable system complexity, thereby improving accuracy without proportionally increasing complexity.
4Reliability
If comprehensive application discovery operations are implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The comprehensive application discovery process is segmented into distinct operational phases: initial application identification, characteristic extraction, mapping generation, validation, and continuous monitoring. Each segment handles a specific aspect of discovery, making the overall complex process manageable and maintainable while ensuring high reliability through systematic coverage of all necessary discovery tasks.
Data Source
AI summary
Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment. A security posture visualization that includes an application discovery graph annotation is generated. The security posture visualization is communicated to cause display of the security posture visualization.


