Security-Sensitivity Scoring for Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing systems face significant security risks due to improperly managed permissions, particularly in virtualized environments, where unused permissions can increase the attack surface and damage potential, making it challenging to identify and prioritize security threats effectively.

Innovation Solution

A system and method for dynamically calculating a security-sensitivity status score based on attributes like size, activity level, sensitivity, and security level of virtualized environments, allowing for comparison and prioritization using normalized scores to identify and address the highest risk factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If permissions are granted to users for accessing restricted resources, then access capability is improved, but security risk increases due to potential unauthorized access and attacks

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic permission management where permissions are not static but adapt based on current security context, user behavior, and risk assessment. The system continuously evaluates permission necessity and revokes or modifies permissions when they are no longer needed or when security risks increase, transforming the static permission model into a dynamic one that balances access capability with security protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of permission management by introducing multiple dimensions for evaluating permissions: damage potential scores, sensitivity levels, usage frequency, and risk metrics. Instead of treating all permissions equally, the system assigns different weightings and priorities to various permission parameters, allowing selective restriction or enhancement of specific permissions based on their calculated risk profiles.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the number and variety of permissions are increased to support diverse applications, then functionality is improved, but difficulty in managing and assessing security risks increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by treating different permissions with different management approaches rather than applying a uniform management model. Each permission is evaluated and managed according to its specific characteristics: damage potential, sensitivity, usage patterns, and associated risks. High-risk permissions receive more stringent controls and monitoring, while low-risk permissions are managed more loosely, optimizing the balance between functionality and security management complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system creates a composite permission management framework that combines multiple evaluation criteria (damage potential scores, sensitivity levels, usage frequency, risk metrics) into an integrated assessment model. This composite approach allows the system to handle diverse permission types by synthesizing multiple factors into a unified risk evaluation, simplifying the management of complex permission sets across diverse applications.

Inventive Principle:
Principle #40Composite materials

3Ease of operation

If manual prioritization of environments is performed, then resource allocation is simplified, but accuracy in identifying highest risk factors decreases

Engineering Contradiction:
Improveresource allocation simplicityVSAvoidrisk assessment accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system implements automated feedback loops that continuously monitor permission usage, security events, and risk metrics across virtualized environments. This feedback is processed to automatically update risk assessments and prioritize environments based on actual security conditions rather than manual estimates. The feedback mechanism ensures that resource allocation decisions are based on precise, real-time data about actual security risks and threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces the manual mechanical process of prioritization with an automated computational system that calculates risk scores and environment priorities algorithmically. Instead of human operators manually assessing and ranking environments, the system uses automated analysis of security data, permission patterns, and threat intelligence to objectively determine priority levels, significantly improving measurement precision while maintaining ease of operation through automated reporting and dashboard interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If normalized damage potential scores are calculated for permissions, then comparison between different permissions is improved, but computational complexity increases

Engineering Contradiction:
Improvepermission comparison capabilityVSAvoidcalculation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the calculation of damage potential scores into distinct modular components: base score calculation, sensitivity adjustments, usage pattern modifiers, and risk factor multipliers. Each component handles a specific aspect of the evaluation, allowing the system to calculate comprehensive scores through a series of manageable steps rather than a single complex calculation. This segmentation improves measurement precision while making the computational process more tractable and maintainable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11140194B2Measuring and comparing security efficiency and importance in virtualized environments
Publication Date: 2021.10.05 CYBER ARK SOFTWARE LTD
  • US11140194B2 patent drawing
  • US11140194B2 patent drawing
  • US11140194B2 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for measuring and comparing security efficiency and importance in virtualized environments. Techniques include identifying a plurality of virtualized computing environments and calculating, for a first of the plurality of virtualized computing environments, a security-sensitivity status, the security-sensitivity status being based on at least: a size attribute of the first virtualized computing environment; an activity level of the first virtualized computing environment; a sensitivity level of the first virtualized computing environment; and a security level of the first virtualized computing environment. Further techniques include accessing a reference security-sensitivity status corresponding to the first virtualized computing environment; comparing the security-sensitivity status of the first virtualized computing environment with the reference security-sensitivity status; and identifying, based on the comparing, a security-sensitivity status gap.