Application Container Deployment Security via Environment Reconnaissance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional application container technologies increase the risk of data leaks and security threats by allowing sensitive applications to be executed outside of controlled environments, such as on personal devices or vulnerable cloud platforms.

Innovation Solution

The system analyzes the deployment environment to ensure it meets security thresholds before transferring an application, using reconnaissance analysis to identify properties and implement necessary security measures, and then monitors and regulates the application's actions to comply with deployment policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional application container technologies are used to enable flexible deployment and execution of applications across multiple computing environments, then usability and flexibility are improved, but security risk and data leak potential increase

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs a reconnaissance analysis of the deployment environment before transferring the application container, proactively identifying security properties and potential risks in advance. This preliminary assessment allows the system to determine whether the environment meets security thresholds before actual deployment occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security management system as an intermediary between the application container and the deployment environment. This intermediary performs reconnaissance analysis, monitors application execution, and regulates data flows, acting as a mediator that enables flexible deployment while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If application containers allow execution outside controlled environments, then ease of operation is improved, but loss of information increases

Engineering Contradiction:
Improveease of operationVSAvoiddata leak
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system continuously monitors the application container during execution and provides feedback about data flows and application actions. This feedback mechanism enables the system to detect potential data leaks and regulate application behavior in real-time, maintaining information security while preserving ease of operation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security management system acts as an intermediary that monitors and regulates data flows between the application container and external environments. It allows legitimate data access while blocking potentially harmful information transfers, thus preventing data leaks without restricting user operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If reconnaissance analysis and monitoring are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security management system performs multiple functions including reconnaissance analysis, environment assessment, application monitoring, and data flow regulation through a single integrated platform. This multi-functionality reduces overall system complexity by consolidating security operations rather than requiring separate tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9116768B1Systems and methods for deploying applications included in application containers
Publication Date: 2015.08.25 GEN DIGITAL INC
  • US9116768B1 patent drawing
  • US9116768B1 patent drawing
  • US9116768B1 patent drawing

AI summary

The disclosed computer-implemented method for deploying applications included in application containers may include (1) identifying an application container that includes an application and facilitates transferring the application to a deployment environment, (2) performing a reconnaissance analysis on the deployment environment by identifying one or more properties of the deployment environment, (3) determining, based at least in part on the reconnaissance analysis, that the deployment environment meets a predetermined threshold of requirements for securely executing the application, and then (4) transferring the application included in the application container to the deployment environment in response to determining that the deployment environment meets the predetermined threshold. Various other methods, systems, and computer-readable media are also disclosed.