Implementing security control practice omission decisions from service emulation indications
A system, method, computer program product, and carrier are described for obtaining an indication of an emulation of a service in a first environment with a first security control practice or obtaining one or more gradational norms of software performance in an emulation environment; and signaling a decision whether to allow a software object to execute in another environment at least partly as a result of whether the software object apparently performed in conformity with the one or more gradational norms of software performance in the emulation environment or signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice.
1 . A method comprising:
obtaining an indication of an emulation of a service in a first environment with a first security control practice; and
signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice.
2 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
emulating the service with an instruction sequence and with the first security control practice in response to an insufficient trust level relating to the instruction sequence.
3 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
causing the first environment to emulate a first portion of the service and to execute a second portion of the service natively.
4 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
implementing the first security control practice as one or more of a data integrity policy or a transaction integrity policy.
5 . The method of claim 1 in which signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
causing the second environment to use the first security control practice in response to the indication relating to the first security control practice.
6 . The method of claim 1 in which signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
requesting the decision whether to use the second environment without the first security control practice.
7 . The method of claim 1 in which signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
obtaining status information about the second environment.
8 . (canceled)
9 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
including at least state information from the emulation in the indication of the emulation of the service in the first environment.
10 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
obtaining status information about the first environment.
11 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
obtaining current status information about the service.
12 . The method of claim 1 in which obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
receiving an indication that a transaction protocol has been circumvented.
13 . The method of claim 1 in which signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
deciding not to host the service in the second environment without a second security control practice at least partly in response to the indication signaling an incorrect outcome from the performance of the service in the emulation environment with the first security control practice.
14 . (canceled)
15 . The method of claim 1 in which signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
deciding to configure the second environment with a second security control practice in response to the indication signaling an anomaly from the performance of the service in the emulation environment with the first security control practice.
16 . A system comprising:
circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice; and
circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice.
17 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for emulating the service with an instruction sequence and with the first security control practice in response to an insufficient trust level relating to the instruction sequence.
18 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for causing the first environment to emulate a first portion of the service and to execute a second portion of the service natively.
19 . (canceled)
20 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for causing the second environment to use the first security control practice in response to the indication relating to the first security control practice.
21 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for requesting the decision whether to use the second environment without the first security control practice.
22 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for obtaining status information about the second environment.
23 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for deciding whether to perform any of the service.
24 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for including at least state information from the emulation in the indication of the emulation of the service in the first environment.
25 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for obtaining status information about the first environment.
26 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for obtaining current status information about the service.
27 . The system of claim 16 in which the circuitry for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
circuitry for receiving an indication that a transaction protocol has been circumvented.
28 . (canceled)
29 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for configuring the second environment without the first security control practice.
30 . The system of claim 16 in which the circuitry for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
circuitry for deciding to configure the second environment with a second security control practice in response to the indication signaling an anomaly from the performance of the service in the emulation environment with the first security control practice.
31 . A system comprising:
means for obtaining an indication of an emulation of a service in a first environment with a first security control practice; and
means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice.
32 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for emulating the service with an instruction sequence and with the first security control practice in response to an insufficient trust level relating to the instruction sequence.
33 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for causing the first environment to emulate a first portion of the service and to execute a second portion of the service natively.
34 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for implementing the first security control practice as one or more of a data integrity policy or a transaction integrity policy.
35 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for causing the second environment to use the first security control practice in response to the indication relating to the first security control practice.
36 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for requesting the decision whether to use the second environment without the first security control practice.
37 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for obtaining status information about the second environment.
38 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for deciding whether to perform any of the service.
39 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for including at least state information from the emulation in the indication of the emulation of the service in the first environment.
40 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for obtaining status information about the first environment.
41 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for obtaining current status information about the service.
42 . The system of claim 31 in which the means for obtaining an indication of an emulation of a service in a first environment with a first security control practice comprises:
means for receiving an indication that a transaction protocol has been circumvented.
43 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for deciding not to host the service in the second environment without a second security control practice at least partly in response to the indication signaling an incorrect outcome from the performance of the service in the emulation environment with the first security control practice.
44 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for configuring the second environment without the first security control practice.
45 . The system of claim 31 in which the means for signaling a decision whether to use a second environment without the first security control practice in performing at least a portion of the service as a result of the indication of the emulation of the service in the first environment with the first security control practice comprises:
means for deciding to configure the second environment with a second security control practice in response to the indication signaling an anomaly from the performance of the service in the emulation environment with the first security control practice.
46 . A method comprising:
obtaining one or more gradational norms of software performance in an emulation environment; and
signaling a decision whether to allow a software object to execute in another environment at least partly as a result of whether the software object apparently performed in conformity with the one or more gradational norms of software performance in the emulation environment.
47 - 54 . (canceled)
55 . A system comprising:
circuitry for obtaining one or more gradational norms of software performance in an emulation environment; and
circuitry for signaling a decision whether to allow a software object to execute in another environment at least partly as a result of whether the software object apparently performed in conformity with the one or more gradational norms of software performance in the emulation environment.
56 - 58 . (canceled)
59 . The system of claim 55 in which the circuitry for signaling a decision whether to allow a software object to execute in another environment at least partly as a result of whether the software object apparently performed in conformity with the one or more gradational norms of software performance in the emulation environment comprises:
circuitry for deciding whether to allow the software object to execute in the other environment as a result of whether a leakage larger than a threshold occurred in the emulation environment while hosting the software object.
60 - 72 . (canceled)