Runtime Application Security Adaptation in Cloud VM Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in ensuring application security and regulatory compliance when traditional applications are migrated, as existing methods increase complexity and reduce flexibility by providing isolation at the virtual machine level, leading to inefficient resource utilization and increased costs.

Innovation Solution

The application runtime environment is notified of changes in its execution environment, allowing it to dynamically modify its behavior by disabling or enabling application modules based on their security attributes, querying a service registry for environment-specific modules, and using a trusted module registry for enhanced security, thereby adapting to virtualized or cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional applications are migrated to cloud computing environments with virtual machine level isolation, then application security is improved, but device complexity and resource management complexity increase

Engineering Contradiction:
Improveapplication securityVSAvoidresource management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an application runtime environment as an intermediary layer between the application and the virtual machine infrastructure. This runtime environment provides security and compliance enforcement at the application level rather than requiring complex virtual machine level isolation, thereby improving security while reducing resource management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The application runtime environment enables applications to self-manage their security and compliance requirements through dynamic modification of execution behavior based on security attributes. This self-service approach eliminates the need for external complex resource management and isolation mechanisms

Inventive Principle:
Principle #25Self-service

2Reliability

If virtual machine level isolation is implemented for application security, then security is improved, but productivity and resource utilization efficiency decrease

Engineering Contradiction:
Improveapplication securityVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By positioning the application runtime environment as an intermediary, the patent enables security enforcement without requiring resource-intensive virtual machine level isolation. This allows multiple applications to share the same infrastructure efficiently while maintaining security through the runtime's security policies

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent dynamically modifies execution parameters of applications based on their security attributes and the current execution environment. This allows the system to adapt security measures in real-time without permanently isolating applications, thereby maintaining productivity while ensuring security

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If applications are dynamically modified based on execution environment changes, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveapplication adaptabilityVSAvoidruntime environment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The application runtime environment is designed to automatically detect execution environment changes and dynamically modify application execution behavior without external intervention. This self-service capability provides high adaptability while keeping the runtime environment relatively simple by leveraging the application's own security attributes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9189619B2Runtime based application security and regulatory compliance in cloud environment
Publication Date: 2015.11.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9189619B2 patent drawing
  • US9189619B2 patent drawing
  • US9189619B2 patent drawing

AI summary

A mechanism is provided in a data processing system for runtime based application security. The application runtime environment executing within a virtual machine on the data processing system receives notification of a change in execution environment for the virtual machine. Responsive to determining the virtual machine is being migrated to a virtualized environment based on the notification of a change in execution environment, the application runtime environment dynamically modifies execution of an application in the application runtime environment, wherein the application comprises a set of application modules.