Software Deployment Security Level Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems face vulnerabilities that can be exploited by malicious software, leading to attacks and damage, especially in cloud environments where shared resources increase the risk of impact across multiple users, and existing countermeasures often degrade system performance.

Innovation Solution

A method is deployed to calculate a program security indicator for software programs based on component security indicators, allowing for the selection of computing systems with matching or higher security levels for deployment, thereby isolating less secure programs and implementing additional security measures without affecting more secure ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional security measures are implemented on computing systems to protect against malicious software attacks, then security level is improved, but system performance is degraded

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing security measures selectively based on the security level of individual software programs. Instead of uniformly applying security measures to all systems, the patent calculates a program security indicator for each software program and deploys it to computing systems with matching or higher security indicators. This ensures that additional security measures are applied only where necessary, protecting security-critical programs while avoiding performance degradation on less sensitive systems.

Inventive Principle:
Principle #3Local quality

2Reliability

If security measures are applied to all computing systems uniformly, then overall security is improved, but performance of all systems is degraded

Engineering Contradiction:
Improveoverall securityVSAvoidperformance of all systems
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements parameter changes by using a program security indicator as a dynamic parameter to determine the appropriate security level for deployment. The security indicator is calculated based on component security indicators of the software program's components, and this parameter is used to match the program with computing systems having compatible or higher security indicators. This parameter-driven approach allows the system to adapt security measures to the specific needs of each program, avoiding uniform performance degradation across all systems.

Inventive Principle:
Principle #35Parameter changes

3Speed

If software programs are deployed without security level matching, then deployment speed is improved, but security risk increases

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by calculating the program security indicator and determining the appropriate computing system for deployment before the actual deployment occurs. The system evaluates the security indicators of software components, calculates the overall program security indicator, and identifies suitable computing systems in advance. This preliminary security assessment ensures that security risk is managed before deployment, while the automated matching process maintains efficient deployment speed without manual intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11775272B1Deployment of software programs based on security levels thereof
Publication Date: 2023.10.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11775272B1 patent drawing
  • US11775272B1 patent drawing
  • US11775272B1 patent drawing

AI summary

A solution is proposed for deploying software programs. A corresponding method comprises calculating a program security indicator of each software program according to corresponding component security indicators of software components being used by the software program. A computing system (or more) is selected for deploying the software program according to a comparison between the program security indicator and corresponding system security indicators of a plurality of available computing systems. A computer program and a computer program product for performing the method are also proposed. Moreover, a corresponding system is proposed.