Tag-Based Security Policy Generation in Distributed Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a distributed computing environment, the rapid evolution of networks and security needs poses challenges for creating and maintaining effective security policies, as custom applications and services are increasingly deployed on network-accessible hardware, making it difficult for creators to anticipate and address all potential security risks, leading to emerging vulnerabilities.
Innovation Solution
A tag-based security policy creation system where an orchestration platform generates inventory events that include tags associated with service entities, which are then processed by a security management platform to identify policy rules and compute a security policy, allowing for dynamic updates and application within the computing environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If services are deployed on network-accessible hardware in a virtualized environment, then flexibility and scalability are improved, but security vulnerabilities increase due to network accessibility
Solution Approach 1:
The patent segments security policy management into modular components: service recipes define service configurations with associated security tags, the orchestration platform manages service deployment and generates inventory events, and the security management platform processes events and computes policies. This segmentation allows independent updates of security policies without affecting service deployment flexibility.
Solution Approach 2:
The patent implements preliminary action by computing security policies before services are deployed or modified. The security management platform receives inventory events, identifies affected services, determines applicable policy rules, and computes updated security policies in advance, ensuring security measures are ready before vulnerabilities can be exploited.
2Reliability
If security policies are updated in real-time in response to evolving threats, then security effectiveness is improved, but system complexity increases
Solution Approach 1:
The patent implements a feedback mechanism where the security management platform continuously monitors inventory events from the orchestration platform, processes security tag information, and computes updated security policies. This closed-loop feedback system enables real-time security policy updates in response to changing service inventories and emerging threats without manual intervention.
Solution Approach 2:
The system enables self-service by automatically generating security policies through the security management platform. When inventory events are received, the platform autonomously identifies affected services, retrieves applicable policy rules, computes updated policies, and delivers them to the computing environment without requiring security expert intervention for each update.
3Reliability
If comprehensive security policies are created for all possible risks, then security coverage is improved, but policy creation time increases
Solution Approach 1:
The patent uses parameter changes by dynamically adjusting security policies based on service-specific attributes and tags. Instead of creating static comprehensive policies for all possible risks, the system computes policies tailored to each service's actual configuration, enabling efficient policy generation that covers only relevant security requirements for deployed services.
Solution Approach 2:
The patent implements universality through reusable service recipes that define common service configurations with associated security tags. These recipes serve multiple functions: they standardize service deployment, automate inventory event generation, and enable consistent security policy application across similar services, reducing overall policy creation time while maintaining comprehensive coverage.
Data Source
AI summary
Concepts and technologies are disclosed herein for tag-based security policy creation in a distributed computing environment. A security management module can receive an inventory event that relates to instantiation of a service. The security management module can identify the service that was instantiated and obtain a tag set that relates to the service. The tag set can include security tags that include a string that identifies a communications link associated with the entities included in the service that was instantiated. The security management module can identify policy rules associated with the security tags. The policy rules can define security for the service that was instantiated. The security management module can compute a security policy for the service and can provide the security policy to the computing environment for implementation.


