Pluggable Cloud Security System for Legacy Application Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing technologies face challenges in efficiently and securely scaling legacy applications without requiring changes to underlying code, leading to resource wastage and security vulnerabilities.
Innovation Solution
A pluggable cloud security system that uses nodes with processors and memory to enforce rules for data communication between user applications and cloud-hosted applications, preventing invalid data and scaling resources automatically to conserve processing and memory resources while enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud-hosted applications are exposed to all user applications without filtering, then accessibility and ease of operation are improved, but security vulnerabilities and resource wastage increase
Solution Approach 1:
The patent introduces a cloud security system as an intermediary layer between user applications and cloud-hosted applications. This mediator evaluates incoming requests against stored rules, determining whether to allow or block communication based on source identification, channel validation, and criteria matching. This resolves the contradiction by maintaining open accessibility while filtering out harmful requests through the intermediary security layer.
2Reliability
If resources are allocated to handle all incoming communications, then service reliability is improved, but processing and memory resource consumption increase
Solution Approach 1:
The cloud security system performs preliminary evaluation of incoming requests before they reach the cloud-hosted applications. By pre-evaluating source identification, channel validity, and rule criteria matching, the system blocks invalid or malicious requests in advance. This prevents wasteful consumption of processing and memory resources on requests that would ultimately be rejected, while maintaining service reliability for legitimate requests.
3Ease of manufacture
If legacy applications are deployed without code modifications, then ease of manufacture and deployment are improved, but security and resource efficiency deteriorate
Solution Approach 1:
The patent implements a security intermediary that sits between user applications and legacy cloud-hosted applications without requiring any modifications to the legacy application code. The security system independently performs source identification, channel validation, and rule-based filtering, thereby protecting legacy applications from security risks and resource inefficiency while maintaining their original deployment simplicity.
4Adaptability or versatility
If all communication channels are allowed to access cloud infrastructure, then adaptability and versatility are improved, but identification of malicious attacks and resource overload worsen
Solution Approach 1:
The cloud security system implements feedback mechanisms by continuously monitoring incoming requests, evaluating them against stored rules, and adjusting its filtering decisions based on the evaluation results. The system provides feedback on source identification validity, channel authentication status, and rule criteria matching, enabling effective detection of malicious attacks and resource overload conditions while maintaining flexible communication channels for legitimate traffic.
Data Source
AI summary
A pluggable cloud security system includes a plurality of nodes. Each node has a memory and a processor. At least one memory is configured to store rules indicating criteria for allowing communication between user applications and a hosted application executed by a cloud infrastructure. At least one processor is configured to receive data to be communicated to the cloud application, determine a source of the received data as a first user application, determine a channel used to transmit the received data, and determine, using the rules, whether the source and the channel satisfy criteria for allowing communication between the first user application and the hosted application. If it is determined that the source satisfies the first criteria, transmission of the data is allowed. Otherwise, transmission of the data is prevented.


