Cloud Application Detection via Guard Agent Integrity Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems (IDS) for cloud applications face challenges in recognizing all intrusion actions, leading to false negatives and difficulty in ensuring real-time and flexible security protection, especially due to system or hardware faults not caused by abnormal intrusion actions.
Innovation Solution
A cloud application detection method and apparatus that updates and compares characteristic values of cloud applications deployed on a PaaS platform, using guard agents to extract and record integrity values, determining security vulnerabilities by ensuring consistency across application instances, thereby enhancing security service capabilities and user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If intrusion detection system (IDS) is used to detect attack actions, then security protection capability is improved, but false negative cases occur and not all intrusion actions can be successfully recognized
Solution Approach 1:
The patent segments the detection task into multiple independent guard agents, each responsible for monitoring specific application instances. Each guard agent independently extracts characteristic values and performs detection, allowing parallel detection across multiple components without interfering with each other, thereby improving both coverage and accuracy while maintaining reliability
Solution Approach 2:
The patent introduces a characteristic value database as an intermediary between guard agents and the central detection system. Guard agents store extracted characteristic values in this database, which then serves as a reference for comparison and anomaly detection, improving detection precision without compromising the overall security protection capability
2Reliability
If intrusion detection system (IDS) is used for security protection, then attack detection is improved, but system flexibility and real-time response to non-intrusion issues (such as hardware faults) are reduced
Solution Approach 1:
The patent designs guard agents with multi-functional capabilities: they can detect both intrusion actions and non-intrusion issues such as hardware faults and system errors. The same characteristic value extraction and comparison mechanism serves multiple detection purposes, allowing the system to respond flexibly to various types of anomalies while maintaining reliable attack detection
Solution Approach 2:
The patent implements dynamic characteristic value updates in the database, allowing the detection criteria to adapt to changing system states and new types of threats. The system can dynamically adjust what constitutes an anomaly based on updated characteristic values, improving response flexibility to both intrusion and non-intrusion issues while maintaining detection reliability
3Productivity
If characteristic values are updated during cloud application running, then real-time security monitoring is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service characteristic value extraction through guard agents that automatically monitor and extract characteristic values from application instances without external intervention. The guard agents autonomously update the characteristic value database and trigger anomaly detection, enabling real-time monitoring while keeping the system architecture relatively simple through automation
Solution Approach 2:
The patent employs periodic characteristic value updates at predetermined time intervals rather than continuous monitoring. This periodic action maintains real-time monitoring capability by regularly refreshing the characteristic values, while reducing system complexity by avoiding the need for continuous data collection and processing operations
Data Source
AI summary
Embodiments of this application disclose a cloud application detection method, including: obtaining at least one application instance corresponding to a to-be-detected cloud application, where the application instance corresponds one-to-one to a guard agent; extracting, by using the guard agent, a first characteristic value corresponding to each application instance; updating the first characteristic value to a second characteristic value when the to-be-detected cloud application meets a preset characteristic value update condition; and determining the to-be-detected cloud application as a target cloud application with security vulnerability if second characteristic values are inconsistent. This application further discloses a cloud application detection apparatus. integrity protection during running can be provided for a cloud application deployed on a platform as a service. Therefore, the cloud application and a running environment of the cloud application are prevented from being maliciously tampered with or from abnormal running, user experience is improved.


