Template-Driven Intent-Based Security for Cloud Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face significant security challenges due to the proliferation of network attacks and malicious content, with attackers breaching internal networks and public clouds to steal critical data by exploiting East-West traffic flows, necessitating enhanced security measures to protect valuable company and customer information.

Innovation Solution

The implementation of a template-driven, intent-based security system that uses a graph database to identify nodes and edges representing workloads and their relationships, applying security templates to produce rules for security policies that manage communications between workloads, thereby enhancing security controls and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security policies are manually configured for each workload, then security coverage can be comprehensive, but the complexity of security management increases significantly and cannot keep pace with dynamic cloud environments

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables security policies to be automatically generated and updated based on workload relationships detected in the graph database. The security manager autonomously processes workload changes, identifies affected security requirements, and updates policies without manual intervention, allowing the system to self-adapt to cloud environment dynamics while maintaining comprehensive security coverage

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security policy system transitions from static manual configuration to dynamic automatic generation. Policies are continuously updated based on real-time workload relationships, entropy levels, and security templates, enabling the security management system to adapt automatically to changing cloud environments without increasing operational complexity

Inventive Principle:
Principle #15Dynamics

2Reliability

If security policies are updated frequently to match changing workload relationships, then security effectiveness improves, but the time and resources required for policy management increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidpolicy update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security templates define security requirements and policy structures in advance for different workload relationship patterns and entropy levels. When workload changes are detected, the system can quickly generate appropriate policies by applying pre-defined templates rather than creating policies from scratch, significantly reducing policy update time while maintaining security effectiveness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors workload relationships, entropy levels, and security policy effectiveness. This feedback loop enables the security manager to identify when policy updates are actually needed based on real conditions rather than on a fixed schedule, optimizing the balance between security effectiveness and update overhead by updating only when necessary

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security monitoring is implemented across all workloads, then data protection improves, but the computational resources and system overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The graph database enables the system to focus security monitoring and analysis on specific workload relationships and nodes that are relevant to current security risks. Instead of uniformly monitoring all workloads, the system identifies and prioritizes monitoring of critical workload relationships based on entropy levels and security templates, reducing unnecessary computational overhead while maintaining strong data protection for high-risk areas

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system divides the cloud environment into discrete workload nodes and relationships represented in the graph database. This segmentation allows security monitoring to be applied selectively to specific segments based on their risk profiles and entropy levels, rather than treating the entire environment uniformly, thereby reducing overall computational resource requirements while maintaining comprehensive data protection where needed

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11290493B2Template-driven intent-based security
Publication Date: 2022.03.29 GRYPHO5 LLC
  • US11290493B2 patent drawing
  • US11290493B2 patent drawing
  • US11290493B2 patent drawing

AI summary

Methods and systems for managing security in a cloud computing environment are provided. Exemplary methods include: receiving a target, the target specifying workloads of a plurality of workloads to be included in the security policy, the plurality of workloads being associated with the cloud computing environment; identifying nodes and edges in the graph database using the target, the graph database representing the plurality of workloads as nodes and relationships between the plurality of workloads as edges; getting a security intent, the security intent including a high-level security objective in a natural language; obtaining a security template associated with the security intent; and applying the security template to the identified nodes and edges to produce security rules for the security policy, the security rules at least one of allowing and denying communications between the target and other workloads of the plurality of workloads.