Security Incident Manager for Cloud Workload Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in dynamically relocating workloads to secure locations due to varying security profiles across different hosting sites, necessitating effective detection, evaluation, and migration of workloads to ensure optimal security.

Innovation Solution

A comprehensive security system comprising an incident detection module, risk evaluator, location determination module, and workload manager that generates security scores for locations, prioritizes security incidents, and migrates workloads to the most secure site, utilizing CVE factors and asset databases to assess and mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If workloads are dynamically relocated across various locations to optimize security, then security reliability is improved, but system complexity increases due to multiple security profiles and migration coordination

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security incident manager is introduced as an intermediary component that receives security incidents, evaluates risks, generates security scores for multiple locations, and coordinates workload migration. This mediator simplifies the complex interactions between security incidents, locations, and workload management by centralizing the decision-making process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where security incidents are detected, risk evaluations are performed, security scores are generated for locations, and workload migration decisions are made based on this feedback loop. The security incident manager continuously monitors and adjusts workload placement based on security conditions.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If security scores are generated for multiple locations to enable informed workload migration, then security evaluation accuracy is improved, but computational resources are consumed

Engineering Contradiction:
Improvesecurity evaluation accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system generates security scores for multiple locations, but focuses computational effort on evaluating and migrating workloads only when security incidents are detected and risk thresholds are exceeded. Not all locations are continuously evaluated at maximum precision - only when necessary based on security conditions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11297090B2Security evaluation for computing workload relocation
Publication Date: 2022.04.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11297090B2 patent drawing
  • US11297090B2 patent drawing
  • US11297090B2 patent drawing

AI summary

A security incident is detected at a first location; a risk of the security incident is evaluated. A first security scores is generated for the first location. A set of security scores are generated for a set of alternative locations; the set of security scores excludes the first security score. A second security score within the set of security scores is determined to be the best security score among a plurality of security scores; the plurality of security scores comprises the set of security scores and the first security score. A workload associated with the first location is migrated to a second location, where the second location is associated with the second security score.