Neural Network Scanning Infrastructure as Code Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software development processes lack effective early-stage security measures for infrastructure as code, particularly due to the diversity of coding languages and flavors used across cloud providers, making it challenging to apply security policies early in the development lifecycle.

Innovation Solution

A deep neural network is trained to classify infrastructure as code based on cloud provider policies, providing a policy vector score and scanning infrastructure as code during continuous integration and deployment pipelines, with continuous updating based on user interactions and actual deployment results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security checking methods are used for infrastructure as code, then security policies can be enforced, but the diversity of coding languages and flavors makes it difficult to apply security measures early in the development lifecycle

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidcomplexity of applying security measures across multiple languages
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical security checking methods with a deep neural network model that automatically classifies infrastructure as code across multiple cloud provider languages and flavors. The neural network learns policy compliance patterns from training data and can accurately assess code security without requiring manual configuration for each language type, thereby reducing complexity while maintaining reliable security enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service security assessment by allowing the neural network model to autonomously classify and score infrastructure as code against security policies. The model continuously learns from deployment results and user feedback, improving its accuracy over time without requiring constant human intervention or customization for different coding languages.

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If security checking is performed early in the development process, then quality and compliance improve, but existing tools lack the capability to handle diverse interface languages and flavors effectively

Engineering Contradiction:
Improvecompliance accuracyVSAvoidsupport for multiple interface languages and flavors
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal neural network model that can classify and assess infrastructure as code across multiple cloud provider languages and flavors (such as AWS, Azure, GCP, and various coding frameworks) using a single unified approach. The model is trained on diverse training data representing different interface languages, enabling it to accurately enforce security policies early in development without requiring separate specialized tools for each language or platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If manual security assessment is performed for each code change, then detailed compliance checking is possible, but the process is time-consuming and slows down continuous integration and deployment

Engineering Contradiction:
Improvecompliance measurement accuracyVSAvoidtime for security assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces time-consuming manual security assessment with an automated deep neural network model that instantly classifies and scores infrastructure as code changes. The model processes code against security policies in real-time during continuous integration and deployment pipelines, providing accurate compliance measurement without manual intervention, thereby eliminating the trade-off between assessment accuracy and time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20220309337A1Policy security shifting left of infrastructure as code compliance
Publication Date: 2022.09.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20220309337A1 patent drawing
  • US20220309337A1 patent drawing
  • US20220309337A1 patent drawing

AI summary

In an approach for policy security shifting left of infrastructure as code compliance, a processor trains a neural network model to classify a code per policy and provide a policy vector score for the code associated with one or more policies. A processor enables the neural network model to scan and score a new code during a continuous integration and continuous deployment pipeline. A processor outputs a scanned score of the new code to a user. A processor retrains the neural network model by capturing a continuous integration and continuous deployment change and run-time compliance posture that occurs as a response by the user.