Application-Level Cloud Security for Custom Web Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face significant security risks when using cloud-based services due to the mismatch between enterprise-level controls and third-party cloud environments, particularly with IaaS and PaaS, where applications and data are vulnerable to insider or third-party attacks, hindering adoption.
Innovation Solution
Implementing an application-level cloud security method that monitors and classifies cloud activities, mapping them into categories for policy enforcement, providing security measures at the application and data level, decoupled from application development, and deployable through various methods including container-level deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises use third-party cloud-based services, then access to computing resources and scalability is improved, but security control and compliance are worsened due to mismatch between enterprise-level controls and cloud environments
Solution Approach 1:
The patent introduces a cloud security manager as an intermediary component that sits between the enterprise and cloud service providers. This manager enforces security policies, monitors cloud activities, and ensures compliance without preventing the use of cloud services. The intermediary captures cloud activities from multiple providers, evaluates them against enterprise policies, and blocks non-compliant activities while allowing legitimate operations to proceed.
2Adaptability or versatility
If enterprises deploy custom applications in cloud instances, then application functionality and flexibility are improved, but security risk is worsened due to vulnerabilities to insider or third-party attacks
Solution Approach 1:
The cloud security manager provides self-service security enforcement by automatically monitoring, evaluating, and blocking cloud activities based on enterprise-defined policies. The system autonomously detects security risks in custom applications deployed in cloud instances and applies compensating controls without requiring manual intervention. This allows enterprises to maintain flexible custom applications while the system independently manages security risks.
3Reliability
If enterprises implement strict security controls in private data networks, then data protection and compliance are improved, but ease of operation and accessibility are worsened
Solution Approach 1:
The patent applies different security control levels to different cloud activities and data types. The cloud security manager evaluates each cloud activity against enterprise policies and applies selective blocking or monitoring. This allows sensitive operations to have strict controls while less critical operations maintain easier access, creating localized security quality that protects data without uniformly restricting all operations.
Data Source
AI summary
A cloud security method implement web security at the application level by monitoring network traffic and detecting cloud activities related to web applications, and then classifying the detected cloud activities to map certain security-related cloud activities into activity categories to enable security policy to be applied. The application-level cloud security method enables policy enforcement rules to be established for cloud activity categories. The security policies are then applied based on activity categories.


