Cloud Application Security Analyzer for Mutual Attack Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing systems are inadequate in preventing mutual attacks between different applications on the same host or internal attacks, as they primarily focus on traffic detection and cleaning, which can impact normal applications and do not provide application-level security protection.
Innovation Solution
A method and apparatus involving a security analyzer, security processor, and policy manager that analyze application behavior data to detect and process attack behaviors in cloud applications, using rules to determine and respond to malicious activities, thereby providing application-level security protection and reducing impact on normal applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic detection and cleaning is performed by using a cloud host as a unit, then external attacks and inter-host attacks can be prevented, but all cloud applications on a target cloud host are affected and internal attacks between applications on the same host cannot be detected
Solution Approach 1:
The patent segments the security protection granularity from cloud host level to cloud application level. By deploying security detectors within individual cloud applications and analyzing behavior data at the application level, the system can identify and block malicious applications without affecting normal applications on the same host. This segmentation enables precise security enforcement that isolates threats to only the compromised application.
Solution Approach 2:
The patent implements local quality by applying different security analysis and processing actions to different cloud applications based on their specific behavior characteristics. The security analyzer evaluates each application's behavior data against security rules and applies targeted processing (allow, block, migrate, or terminate) only to the malicious application, while leaving normal applications unaffected. This localized approach ensures that security measures are precisely applied where needed without collateral damage to legitimate applications.
2Reliability
If traffic monitoring is performed at cloud host level, then system-wide security can be maintained, but application-level attack behaviors cannot be detected and all applications on the host are impacted
Solution Approach 1:
The patent divides the security monitoring function into application-level components. Each cloud application has its own security detector that collects behavior data specific to that application, and the security analyzer processes this data at the application level. This segmentation enables precise detection of attack behaviors within individual applications without requiring system-wide traffic monitoring that would impact all applications.
Solution Approach 2:
The patent introduces a security detector as an intermediary component deployed within each cloud application. This intermediary collects and analyzes behavior data locally at the application level, providing precise attack detection without requiring direct monitoring of all system-wide traffic. The security detector acts as a mediator between the cloud application and the security analyzer, enabling targeted security enforcement.
3Reliability
If cloud applications are isolated to prevent attacks, then security between applications is improved, but resource utilization and application interaction are reduced
Solution Approach 1:
The patent implements dynamic security isolation that adapts based on application behavior. The security analyzer continuously evaluates behavior data against security rules and dynamically adjusts isolation measures. Normal applications that pass security checks can operate with minimal isolation overhead and maintain full resource access and inter-application communication, while only malicious applications trigger isolation actions such as blocking, migration, or termination. This dynamic approach maintains high resource utilization for legitimate applications while providing security when needed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention discloses an apparatus for processing an attack behavior of a cloud application in a cloud computing system, including: a security analyzer, a security processor, and a policy manager, where the policy manager is configured to store a security determining rule and a malicious application processing rule; the security analyzer is configured to receive application behavior data sent by a security detector, determine, according to the application behavior data and the security determining rule, whether a cloud application running on a cloud host has an attack behavior, and when determining that the cloud application running on the cloud host has an attack behavior, send the application behavior data to the security processor; and the security processor is configured to invoke, according to the malicious application processing rule, an interface provided by a cloud controller in a cloud computing system, to process the cloud application having an attack behavior. In solutions of the present invention, security protection is performed based on an application level of cloud computing, which can prevent mutual attack between different applications on a same host, and reduce impact on a normal application.