Granular Security Management for Cloud Intrusion Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management tools in cloud computing environments struggle to effectively detect and address network-based security attacks, often relying on quarantine approaches that are not user-friendly or designed for average users to actively secure their resources.

Innovation Solution

A method that assigns security sensitivity levels to components in a networked computing environment, detects intrusions, determines threat levels, and addresses them based on pre-configured rules, allowing for granular management and isolation of sensitive systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing security management tools use quarantine approaches, then security threats can be contained, but the tools are not user-friendly and difficult for average users to operate

Engineering Contradiction:
Improveuser-friendliness of security management toolsVSAvoideffectiveness of intrusion detection and response
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system automatically assigns security sensitivity levels to components and responds to intrusions based on pre-configured rules without requiring user intervention. The security management system serves itself by autonomously detecting intrusions, determining threat levels, and addressing them according to assigned sensitivity levels and stored rules, making it accessible to average users while maintaining reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security sensitivity levels and response rules are assigned and configured in advance before intrusions occur. This preliminary configuration enables the system to automatically respond to intrusions based on pre-established criteria, eliminating the need for users to make real-time security decisions while ensuring consistent and reliable response actions

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If security management is implemented at domain level, then broad coverage is achieved, but granular control and optimization are lost

Engineering Contradiction:
Improvegranular control of security managementVSAvoidcomplexity of security management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides the networked computing environment into individual components, each assigned a specific security sensitivity level. This segmentation allows granular control over security responses for each component based on its assigned level, enabling tailored security management while maintaining overall system coherence through centralized rule-based automation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A single security management system performs multiple functions: assigning sensitivity levels, detecting intrusions, determining threat levels, and executing response actions. This multi-functional approach provides granular control across diverse components while consolidating complexity into one unified system rather than requiring separate management mechanisms for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automatic response rules are configured for security threats, then response time is reduced, but system complexity increases

Engineering Contradiction:
Improvespeed of intrusion responseVSAvoidcomplexity of rule configuration and management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Response rules and security sensitivity levels are configured in advance before intrusions occur. This preliminary setup enables instantaneous automatic responses based on pre-established criteria, achieving rapid productivity improvement while containing complexity during the operational phase since no real-time configuration decisions are needed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically detects intrusions, determines threat levels, and executes response actions based on feedback from the detection process. This closed-loop feedback mechanism enables rapid automated responses while the system learns and adapts to different intrusion patterns, managing complexity through systematic feedback processing rather than manual intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9998490B2Security management in a networked computing environment
Publication Date: 2018.06.12 KYNDRYL INC

AI summary

An approach for addressing (e.g., preventing) detected network intrusions in a virtualized/networked (e.g., cloud) computing environment is provided. In a typical embodiment, users may group components/systems of an environment/domain according to a range of security sensitivity levels/classifications. The users may further configure rules for responding to security threats for each security sensitivity level/classification. For example, if a “highly dangerous” security threat is detected in or near a network segment that contains highly sensitive systems, the user may configure rules that will automatically isolate those systems that fall under the high security classification. Such an approach allows for more granular optimization and/or management of system security/intrusion prevention that may be managed at a system level rather than at a domain level.