Workload-Aware Security Patch Management for Hybrid Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems in hybrid cloud environments fail to holistically secure workloads from security vulnerabilities across infrastructure resources, often installing all patches simultaneously, which can stall the workload and not address the entire vulnerability landscape effectively.

Innovation Solution

A patch management system evaluates the criticality of new patches based on workload weightage, resource age, and actual criticality, installing patches in an order of dependency across multiple layers of infrastructure resources to secure the entire workload from security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all patches are installed simultaneously to secure infrastructure resources, then security coverage is improved, but workload availability deteriorates due to stalling

Engineering Contradiction:
Improvesecurity coverageVSAvoidworkload availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the patch installation process by evaluating and prioritizing patches based on multiple parameters (security criticality, infrastructure resource dependency, workload impact). Instead of installing all patches simultaneously, the system divides them into ordered groups and installs them sequentially, starting with critical patches that have minimal workload impact. This segmentation resolves the contradiction by maintaining security coverage through systematic patch application while preventing workload stalling through controlled installation timing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary evaluation and prioritization of patches before installation. The system assesses security criticality, infrastructure resource dependencies, and workload impact in advance, creating an installation order that pre-determines which patches should be applied first. This preliminary action allows the system to prepare mitigation strategies ahead of time, ensuring that critical security patches are installed while minimizing disruption to workload availability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If patches are installed in order of dependency across multiple layers, then holistic security is improved, but system complexity increases

Engineering Contradiction:
Improveholistic securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the infrastructure into multiple layers (hardware, firmware, operating system, application) and evaluates patches within each layer based on dependency relationships. By dividing the complex multi-layer infrastructure into manageable segments and assessing patch criticality at each level, the system achieves holistic security coverage without being overwhelmed by overall system complexity. Each layer can be patched independently according to its specific requirements and dependencies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary patch evaluation system that mediates between security requirements and system complexity. This intermediary layer assesses patches based on multiple parameters including security criticality, infrastructure resource dependencies, and workload impact, then translates these assessments into a prioritized installation order. The intermediary simplifies the complexity by providing a structured evaluation framework that systematically handles multi-layer dependencies without requiring manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If critical patches are prioritized for installation, then business downtime is reduced, but security coverage may be compromised

Engineering Contradiction:
Improvebusiness downtimeVSAvoidsecurity coverage
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent changes the evaluation parameters for patch prioritization by considering multiple factors simultaneously: security criticality, infrastructure resource dependency, and workload impact. Instead of prioritizing solely based on security severity or solely on workload impact, the system dynamically adjusts the prioritization parameters to balance both security coverage and business continuity. This multi-parameter approach ensures that critical security patches are installed promptly while maintaining comprehensive security coverage across all infrastructure resources.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors workload performance and security status during patch installation. Based on this feedback, the system can adjust the installation order of remaining patches, ensuring that security coverage is maintained while minimizing business downtime. The feedback loop allows the system to learn from each patch installation outcome and optimize subsequent patching decisions to balance security and availability requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11562077B2Workload aware security patch management
Publication Date: 2023.01.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11562077B2 patent drawing
  • US11562077B2 patent drawing
  • US11562077B2 patent drawing

AI summary

Example implementations relate to method and system for securing a workload from a security vulnerability based on management of critical patches for the workload. The method includes obtaining information of existing patches for each of a plurality of infrastructure resources that are required to execute the workload, where the infrastructure resources are segregated as multiple layers. The method further includes determining dependency of the infrastructure resources across the multiple layers and identifying the security vulnerability related to the infrastructure resources. The method further includes evaluating perceived criticalities of first and second new patches for the security vulnerability based a workload weightage, a resource age of the infrastructure resources, and an actual criticality of the first and second new patches. Further, the method includes installing the first new patch followed by the second new patch on the infrastructure resources based on the perceived criticalities, in an order of the determined dependency.