Cloud-Native Security Analytics via Containerized Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing systems are inefficient due to the reuse of tools designed for static computing devices and lack a native system interface, making them inefficient and difficult to manage in rapidly changing cloud environments.

Innovation Solution

The implementation of a system that provides cloud-native extensibility by embedding an encapsulated security application into a container image as an extended analytic script, allowing it to be applied to a simulated system state for scanning operations, thereby facilitating seamless and secure extensions across various cloud systems, including virtual machines, containers, and bare-metal systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional tools designed for static computing devices are reused in cloud environments, then device compatibility is maintained, but system efficiency and adaptability deteriorate

Engineering Contradiction:
ImproveadaptabilityVSAvoidsystem efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a simulated system state that copies the essential characteristics of the target computing device without requiring the actual device. This simulation layer allows security applications to interact with a replicated environment, achieving adaptability across different device types while maintaining efficient processing through standardized interfaces.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a simulated system state as an intermediary layer between the security application and the actual computing device. This mediator translates device-specific operations into standardized forms, enabling conventional tools to work efficiently in cloud environments while maintaining adaptability to various device types.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security applications are tightly coupled with specific system interfaces, then system integration is improved, but portability and ease of deployment deteriorate

Engineering Contradiction:
Improveease of deploymentVSAvoidsystem integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The simulated system state provides a universal interface that can represent multiple different computing device types through a single standardized model. This allows security applications to be deployed across diverse environments (virtual machines, containers, bare-metal systems) without modification, improving ease of deployment while the simulation layer handles the complexity of system integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If legacy applications are modified to run in cloud environments, then cloud optimization is improved, but application compatibility and reliability deteriorate

Engineering Contradiction:
Improvecloud optimizationVSAvoidapplication compatibility
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Instead of modifying legacy applications to adapt to cloud environments, the patent inverts the approach by adapting the cloud environment to match the legacy applications. The simulated system state replicates the original system interface that legacy applications expect, allowing them to run unchanged with full compatibility while still benefiting from cloud infrastructure.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS10778709B2Cloud-native extensibility provided to security analytics
Publication Date: 2020.09.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10778709B2 patent drawing
  • US10778709B2 patent drawing
  • US10778709B2 patent drawing

AI summary

Techniques facilitating cloud-native extensibility provided to security analytics are provided. A system comprises a memory that stores, and a processor that executes, computer executable components. The computer executable components can comprise a security component that implements an instance of an encapsulated security application. The encapsulated security application can be embedded into a container image as an extended analytic script. The computer executable components can also comprise an execution component that applies the instance of the encapsulated security application to a simulated system state of a computing device during subsequent scanning operations that result in respective analytics for scanning operations of the subsequent scanning operations.