Cloud Application Detection via Guard Agent Integrity Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) for cloud applications face challenges in recognizing all intrusion actions, leading to false negatives and difficulty in ensuring real-time and flexible security protection, especially due to system or hardware faults not caused by abnormal intrusion actions.

Innovation Solution

A cloud application detection method and apparatus that updates and compares characteristic values of cloud applications deployed on a PaaS platform, using guard agents to extract and record integrity values, determining security vulnerabilities by ensuring consistency across application instances, thereby enhancing security service capabilities and user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection system (IDS) is used to detect attack actions, then security protection capability is improved, but false negative cases occur and not all intrusion actions can be successfully recognized

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the detection task into multiple independent guard agents, each responsible for monitoring specific application instances. Each guard agent independently extracts characteristic values and performs detection, allowing parallel detection across multiple components without interfering with each other, thereby improving both coverage and accuracy while maintaining reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a characteristic value database as an intermediary between guard agents and the central detection system. Guard agents store extracted characteristic values in this database, which then serves as a reference for comparison and anomaly detection, improving detection precision without compromising the overall security protection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If intrusion detection system (IDS) is used for security protection, then attack detection is improved, but system flexibility and real-time response to non-intrusion issues (such as hardware faults) are reduced

Engineering Contradiction:
Improveattack detection capabilityVSAvoidresponse flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs guard agents with multi-functional capabilities: they can detect both intrusion actions and non-intrusion issues such as hardware faults and system errors. The same characteristic value extraction and comparison mechanism serves multiple detection purposes, allowing the system to respond flexibly to various types of anomalies while maintaining reliable attack detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic characteristic value updates in the database, allowing the detection criteria to adapt to changing system states and new types of threats. The system can dynamically adjust what constitutes an anomaly based on updated characteristic values, improving response flexibility to both intrusion and non-intrusion issues while maintaining detection reliability

Inventive Principle:
Principle #15Dynamics

3Productivity

If characteristic values are updated during cloud application running, then real-time security monitoring is improved, but system complexity increases

Engineering Contradiction:
Improvereal-time monitoring capabilityVSAvoiddetection system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service characteristic value extraction through guard agents that automatically monitor and extract characteristic values from application instances without external intervention. The guard agents autonomously update the characteristic value database and trigger anomaly detection, enabling real-time monitoring while keeping the system architecture relatively simple through automation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs periodic characteristic value updates at predetermined time intervals rather than continuous monitoring. This periodic action maintains real-time monitoring capability by regularly refreshing the characteristic values, while reducing system complexity by avoiding the need for continuous data collection and processing operations

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11176244B2Cloud application detection method and cloud application detection apparatus
Publication Date: 2021.11.16 HUAWEI TECH CO LTD
  • US11176244B2 patent drawing
  • US11176244B2 patent drawing
  • US11176244B2 patent drawing

AI summary

Embodiments of this application disclose a cloud application detection method, including: obtaining at least one application instance corresponding to a to-be-detected cloud application, where the application instance corresponds one-to-one to a guard agent; extracting, by using the guard agent, a first characteristic value corresponding to each application instance; updating the first characteristic value to a second characteristic value when the to-be-detected cloud application meets a preset characteristic value update condition; and determining the to-be-detected cloud application as a target cloud application with security vulnerability if second characteristic values are inconsistent. This application further discloses a cloud application detection apparatus. integrity protection during running can be provided for a cloud application deployed on a platform as a service. Therefore, the cloud application and a running environment of the cloud application are prevented from being maliciously tampered with or from abnormal running, user experience is improved.