Cloud Security Rule Dispatch via Composition Application Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud environments, configuring and managing security rules for multiple servers deployed across diverse and dynamic topologies is cumbersome and time-consuming, making it difficult to effectively prevent attacks like XSS and SQL injection.

Innovation Solution

A method and apparatus for automatically generating and dispatching security rules to server-side firewalls based on a composition application model and topology model, allowing for transparent operation without code modification and enabling rapid updates in response to vulnerability feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security rules are manually configured for each server in cloud environment, then security protection coverage is ensured, but configuration time and administrative burden increase significantly

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a composition application model that serves as a template representing the application and its deployment requirements. This model is then copied and instantiated across multiple servers in the cloud environment, automatically generating and dispatching security rules to each server instance without requiring manual configuration for each individual server.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system enables automated self-service by having the composition application model automatically generate security rules and dispatch them to relevant servers. The model itself contains the logic and information needed to configure security policies, eliminating the need for manual administrative intervention on each server while ensuring comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If security rules are individually configured for each server, then specific server requirements are met, but operational complexity and error probability increase

Engineering Contradiction:
Improveserver-specific configuration capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The composition application model serves as a universal template that can represent different application types and their security requirements in a standardized format. This single model structure can be applied across diverse server environments and application scenarios, providing adaptability while reducing configuration complexity through reuse of the same modeling approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By copying the validated composition application model to multiple servers, the system ensures that each server receives appropriately configured security rules without requiring individual manual configuration. This maintains server-specific requirements while dramatically reducing operational complexity and the probability of configuration errors.

Inventive Principle:
Principle #26Copying

3Ease of operation

If manual security rule configuration is performed across multiple servers, then security policies can be customized, but time consumption and resource expenditure increase

Engineering Contradiction:
Improvesecurity rule customizationVSAvoidconfiguration efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The composition application model enables security rule customization through automated self-service. Administrators define the security requirements once in the model, and the system automatically generates and dispatches customized security rules to all relevant servers. This maintains full customization capability while dramatically improving configuration efficiency by eliminating repetitive manual work.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-defining the security policy requirements in the composition application model before deployment. This preliminary configuration captures all customization needs in advance, allowing the automated system to efficiently generate and distribute the appropriate security rules across multiple servers without requiring time-consuming manual customization for each server.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9444787B2Non-intrusive method and apparatus for automatically dispatching security rules in cloud environment
Publication Date: 2016.09.13 GLOBALFOUNDRIES US INC
  • US9444787B2 patent drawing
  • US9444787B2 patent drawing
  • US9444787B2 patent drawing

AI summary

The present invention relates to a non-intrusive method and apparatus for automatically dispatching security rules in a cloud environment. The method comprises: forming a composition application model of an application in the cloud environment, said composition application model including at least types of various servers for deploying said application; generating a topology model of said various servers in the cloud environment; automatically generating security rules to be adopted by the server-side firewalls of respective servers based on the application context of said application, said composition application model and said topology model; and dispatching said security rules to each server-side firewall based on said composition application model and topology model.