IP Library Granted Patent US 9,172,717
Granted Patent B2
US 9,172,717 · App. 13/968,594 · Granted Oct 27, 2015

Security-aware admission control of requests in a distributed system

Inventors: Ashish Kundu (Elmsford, NY); Ajay Mohindra (Yorktown Heights, NY); Sambit Sahu (Hopewell Junction, NY)
Assignee: International Business Machines Corporation
H04L63/1441G06F21/604G06F21/6218H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,717
App. No.
13/968,594
Granted
Oct 27, 2015
Kind
B2
Abstract

Systems and articles of manufacture for security-aware admission control of requests in a distributed system include identifying a request dropped by a first application component in a distributed system, determining one or more actions to take with respect to the dropped request, said determining comprises identifying one or more policies of the first application component responsible for the dropped request and identifying one or more additional application components in the distributed system to be affected based on the identified one or more policies, and executing said one or more actions to control admission of one or more requests associated with the dropped request at the one or more additional application components.

Claims (40)

1. An article of manufacture comprising a non-transitory computer readable storage medium having computer readable instructions tangibly embodied thereon which, when implemented, cause a computer to carry out a plurality of method steps comprising:

identifying a request dropped by a first application component in a distributed system;

determining one or more actions to take with respect to the dropped request, said determining comprises:

identifying one or more policies of the first application component responsible for the dropped request; and

identifying one or more additional application components in the distributed system to be affected based on the identified one or more policies;

executing, at each of the one or more additional application components, a distinct one of said one or more actions to temporarily preclude admission of all requests of a given type associated with the dropped request at each of the one or more additional application components subsequent to a predetermined number of multiple instances of the request dropped by the first application;

enacting a change to the identified one or more policies of the first application component, wherein the change renders the request dropped by the first application component allowable by the first application component; and

transmitting a notification to the one or more additional application components to allow admission of one or more requests associated with the dropped request.

2. The article of manufacture of claim 1 , wherein said executing said one or more actions comprises executing said one or more actions until the one or more policies responsible for the dropped request are determined to be consistent across the first application component and the one or more additional application components.

3. The article of manufacture of claim 1 , wherein said one or more actions comprise recording the one or more requests associated with the dropped request.

4. The article of manufacture of claim 1 , wherein said one or more actions comprise throttling the one or more requests associated with the dropped request.

5. The article of manufacture of claim 1 , wherein said one or more actions comprise dropping the one or more requests associated with the dropped request.

6. The article of manufacture of claim 1 , wherein said one or more actions comprise forwarding the one or more requests associated with the dropped request to a replica of the first application component.

7. The article of manufacture of claim 1 , wherein said determining one or more actions to take comprises determining if credential information used by the first application component is the same credential information for the one or more additional application components.

8. The article of manufacture of claim 1 , wherein said determining one or more actions to take comprises determining if credential information used by the dropped request to utilize a service of the first application component has expired and/or been revoked.

9. The article of manufacture of claim 1 , wherein said determining one or more actions to take comprises determining if a session to which the dropped request refers is valid.

10. The article of manufacture of claim 1 , wherein said determining one or more actions to take comprises determining if the one or more additional application components have received a pre-determined number of requests similar to the dropped request within a pre-determined time period.

11. The article of manufacture of claim 1 , wherein said determining one or more actions to take comprises determining if the one or more policies of the one or more additional application components have been altered.

12. The article of manufacture of claim 1 , wherein the method steps comprise:

generating one or more alerts to one or more system administrators pertaining to the execution of the one or more actions.

13. The article of manufacture of claim 1 , wherein the method steps comprise:

storing one or more session attributes and one or more credentials of the dropped request.

14. The article of manufacture of claim 1 , wherein the method steps comprise:

storing a reason for which the dropped request was not authorized.

15. The article of manufacture of claim 14 , wherein said reason comprises one or more of a lack of credentials, a value of one or more parameters that leads to an overflow of a buffer, an input that injects malicious code, and/or a parameter of the request that contributes to detection of a potential security violation.

16. A system comprising:

at least one distinct software module, each distinct software module being embodied on a tangible computer-readable medium;

a memory; and

at least one processor coupled to the memory and operative for:

identifying a request dropped by a first application component in a distributed system;

determining one or more actions to take with respect to the dropped request, said determining comprises:

identifying one or more policies of the first application component responsible for the dropped request; and

identifying one or more additional application components in the distributed system to be affected based on the identified one or more policies;

executing, at each of the one or more additional application components, a distinct one of said one or more actions to temporarily preclude admission of all requests of a given type associated with the dropped request at each of the one or more additional application components subsequent to a predetermined number of multiple instances of the request dropped by the first application;

enacting a change to the identified one or more policies of the first application component, wherein the change renders the request dropped by the first application component allowable by the first application component; and

transmitting a notification to the one or more additional application components to allow admission of one or more requests associated with the dropped request.

17. The system of claim 16 , wherein said one or more actions comprise recording the one or more requests associated with the dropped request.

18. The system of claim 16 , wherein said one or more actions comprise throttling the one or more requests associated with the dropped request.

19. The system of claim 16 , wherein said one or more actions comprise dropping the one or more requests associated with the dropped request.

20. The system of claim 16 , wherein said one or more actions comprise forwarding the one or more requests associated with the dropped request to a replica of the first application component.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 044677/0133 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2017
From: KUNDU, ASHISH; MOHINDRA, AJAY; SAHU, SAMBIT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041601/0408 →
Continuity (2)
Continuation 13790040 · Mar 8, 2013
Related Publication 20140259091A1 · Sep 11, 2014