Runtime Resource Mapping to Development Asset Hierarchies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an efficient method to automatically identify and map runtime resources to a hierarchy of assets during code development, making it difficult to address security vulnerabilities and enhance computing system security.
Innovation Solution
A system that automatically identifies and maps runtime resources to a hierarchy of assets, including hierarchical levels such as builds, repositories, and projects, to facilitate early detection and remediation of security vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual tracing of security vulnerabilities from runtime resources to development assets is performed, then accuracy in identifying vulnerability sources is improved, but time consumption and labor costs increase
Solution Approach 1:
The system performs preliminary actions by automatically establishing mapping relationships between runtime resources and development assets during the deployment process. Metadata is captured and stored in advance, creating pre-computed linkage information that eliminates the need for manual tracing during security vulnerability investigations.
Solution Approach 2:
The patent introduces an intermediary mapping mechanism that connects runtime resources to development assets through metadata and identification links. This intermediary layer automatically translates security issues at runtime to their corresponding development-stage assets, enabling accurate vulnerability source identification without manual intervention.
2Difficulty of detecting and measuring
If comprehensive monitoring of runtime resources is implemented, then detection capability for security vulnerabilities is improved, but system complexity and resource requirements increase
Solution Approach 1:
The system extracts only the essential mapping information and metadata needed for vulnerability detection, rather than implementing comprehensive monitoring of all runtime resource attributes. By taking out only the critical linkage data between runtime resources and development assets, the system achieves effective detection while minimizing added complexity.
Solution Approach 2:
The mapping mechanism serves multiple functions: it enables vulnerability detection, provides audit trails, supports compliance verification, and facilitates root cause analysis. This multi-functionality allows the system to enhance detection capability without proportionally increasing complexity, as a single mapping infrastructure supports multiple security and operational needs.
3Productivity
If automatic mapping of runtime resources to development assets is implemented, then productivity in vulnerability remediation is improved, but implementation complexity increases
Solution Approach 1:
The system performs preliminary mapping actions automatically during the deployment pipeline, establishing relationships between runtime resources and development assets before security issues arise. This pre-computed mapping infrastructure enables rapid vulnerability remediation productivity while the complexity is hidden within the automated deployment process rather than requiring separate complex implementation.
Solution Approach 2:
The mapping system is self-service in that it automatically establishes and maintains relationships between runtime resources and development assets without requiring manual configuration or complex setup. The system serves itself by capturing metadata and creating mappings as part of the natural deployment process, thereby achieving high remediation productivity with minimal implementation complexity.
Data Source
AI summary
Techniques are described herein that are capable of performing an action based on mapping of a runtime resource to a hierarchy of assets utilized during development of code. A hierarchy of assets that are utilized during development of code on a user machine is identified (e.g., automatically identified). The assets in the hierarchy are included in respective hierarchical levels that correspond to respective asset types. A runtime resource, which is created by deployment of the code on a server machine that is coupled to the user machine via a network, is mapped (e.g., automatically mapped) to the assets in the hierarchy. An action is performed with regard to an identified asset, which is included among the assets in the hierarchy, based at least on the runtime resource being mapped to the identified asset.


