Dynamic Application Security Profile Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to dynamically manage and adjust application privileges according to changing workloads, leading to potential vulnerabilities and compliance issues.

Innovation Solution

A computer-implemented method for compliance profiling that creates an application security profile, associates source files with a running workload, captures a workload security profile, compares it with the application profile, and recommends changes to ensure optimal privilege settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application privileges are statically configured with high permissions, then application functionality is ensured, but security vulnerabilities increase due to excessive privileges

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic privilege management by monitoring application workloads in real-time and adjusting permissions based on actual needs. The system transitions from static privilege configuration to dynamic adjustment, where privileges are modified according to the current operational state and security profile of the application workload.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the permission parameters of applications based on workload analysis. By evaluating the security profile and comparing it against required functionality, the system adjusts privilege levels dynamically, changing parameters such as access rights and permission scopes to match actual operational requirements rather than maintaining fixed high-level permissions.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If application privileges are reduced to minimum levels, then security compliance is improved, but application functionality may be compromised

Engineering Contradiction:
Improvesecurity complianceVSAvoidapplication functionality
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent employs feedback mechanisms where the system continuously monitors application performance and security compliance. By analyzing the security profile and comparing it with workload requirements, the system receives feedback on whether privilege reductions are affecting functionality, and adjusts permissions accordingly to maintain both security compliance and operational reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary security profiling and workload analysis before making privilege adjustments. By预先 evaluating the application's security requirements and operational needs, the system can reduce privileges to appropriate levels without compromising functionality, as the preliminary analysis identifies the minimum necessary permissions required for each workload.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security profiles are manually configured and reviewed, then compliance accuracy is maintained, but system complexity and time consumption increase

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the system automatically generates, analyzes, and adjusts security profiles based on workload monitoring. The automated system performs security profiling, compares it with compliance requirements, and makes privilege adjustments without manual intervention, thereby maintaining compliance accuracy while reducing system complexity and time consumption associated with manual configuration and review processes.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If security permissions are dynamically adjusted, then vulnerability reduction is achieved, but system complexity and monitoring requirements increase

Engineering Contradiction:
Improvevulnerability reductionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges security profiling, workload monitoring, and privilege management functions into an integrated system. By combining these previously separate functions into a unified automated process, the system achieves dynamic privilege adjustment and vulnerability reduction while managing complexity through consolidation rather than adding separate monitoring and adjustment mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12204637B2Compliance profiling
Publication Date: 2025.01.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12204637B2 patent drawing
  • US12204637B2 patent drawing
  • US12204637B2 patent drawing

AI summary

A computer implemented method for compliance profiling, the method comprising creating an application security profile indicating a set of permissions enabled for a corresponding application, associating one or more source files corresponding to the application to a running workload, executing the running workload, capturing a workload security profile with respect to one or more operations executed by the running workload, wherein the workload security profile indicates a set of permissions utilized by the running workload, comparing the workload security profile and the application security profile to identify one or more differences, and recommending a change to the application security profile according to the identified one or more differences.