IP Library Granted Patent US 10,063,589
Granted Patent B2
US 10,063,589 · App. 15/134,327 · Granted Aug 28, 2018

Microcheckpointing as security breach detection measure

Inventors: Gary David Cudak (Wake Forest, NC); Ajay Dholakia (Cary, NC); Scott Kelso (Cary, NC); Fred Allison Bower, III (Durham, NC)
Assignee: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
H04L63/1441H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,063,589
App. No.
15/134,327
Granted
Aug 28, 2018
Kind
B2
Abstract

A method includes: deploying at least one shadow system in association with each of one or more components of a network environment; periodically recording a state map of each active component of the network environment and a corresponding state map of the shadow system(s) associated therewith; periodically comparing the recorded state map of each active component with the corresponding recorded state map of the shadow system(s) associated therewith; determining whether a deviation exists with respect to the recorded state map of each active component and the corresponding recorded state map of the shadow system(s) associated therewith; determining whether the deviation is greater than a predetermined deviation threshold; and declaring a security breach regarding the active component(s) for which the deviation was determined to be greater than the predetermined deviation threshold. Corresponding systems and computer program products are also disclosed.

Claims (57)

1. A computer program product, comprising: a non-transitory computer readable medium having stored thereon computer readable program instructions configured to cause a computer system to:

deploy at least one shadow system in association with each of one or more components of a network environment;

periodically record a state map of each active component of the network environment and a corresponding state map of the at least one shadow system associated therewith;

periodically compare the recorded state map of each active component with the corresponding recorded state map of the at least one shadow system associated therewith;

determine whether a deviation exists with respect to the recorded state map of each active component and the corresponding recorded state map of the at least one shadow system associated therewith;

in response to determining the deviation exists, determine whether the deviation is greater than a predetermined deviation threshold;

in response to determining the deviation is greater than the predetermined deviation threshold, declare a security breach regarding the active component(s) for which the deviation was determined to be greater than the predetermined deviation threshold; and

replace the active component with one of the at least one shadow systems associated therewith in response to declaring the security breach.

2. The computer program product as recited in claim 1 , wherein recording the state maps comprises a microcheckpointing process configured to determine and log the state map of each active component of the network environment and the corresponding state map of the at least one shadow system associated therewith.

3. The computer program product as recited in claim 1 , comprising providing duplicate inputs to the at least one shadow system as the inputs provided to the active component with which the at least one shadow system is associated.

4. The computer program product as recited in claim 1 , wherein determining whether the deviation exists is based at least in part on comparing one or more performance metrics of the at least one shadow system and the active component with which the at least one shadow system is associated.

5. The computer program product as recited in claim 4 , wherein the one or more performance metrics are selected from a group consisting of:

execution time associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith;

progress of the one or more duplicate workloads on the active component and the shadow system associated therewith;

memory usage associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith; and

network behavior associated with performing the one or more duplicate workloads on the active component and the shadow system associated therewith.

6. The computer program product as recited in claim 1 , wherein determining whether the deviation exists employs a Bloom filter.

7. The computer program product as recited in claim 1 , wherein determining whether the deviation exists is based at least in part on comparing one or more performance metrics of the at least one shadow system and the active component with which the at least one shadow system is associated; and

wherein the one or more performance metrics are selected from a group consisting of:

an execution time associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith;

a progress of the one or more duplicate workloads on the active component and the shadow system associated therewith;

a memory usage associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith; and

a network behavior associated with performing the one or more duplicate workloads on the active component and the shadow system associated therewith.

8. A method, comprising:

deploying at least one shadow system in association with each of one or more components of a network environment;

periodically recording a state map of each active component of the network environment and a corresponding state map of the at least one shadow system associated therewith;

periodically comparing the recorded state map of each active component with the corresponding recorded state map of the at least one shadow system associated therewith;

determining whether a deviation exists with respect to the recorded state map of each active component and the corresponding recorded state map of the at least one shadow system associated therewith;

in response to determining the deviation exists, determining whether the deviation is greater than a predetermined deviation threshold;

in response to determining the deviation is greater than the predetermined deviation threshold, declaring a security breach regarding the active component(s) for which the deviation was determined to be greater than the predetermined deviation threshold; and

replacing the active component with one of the at least one shadow systems associated therewith in response to declaring the security breach.

9. The method as recited in claim 8 , wherein recording the state maps comprises a microcheckpointing process configured to determine and log the state map of each active component of the network environment and the corresponding state map of the at least one shadow system associated therewith.

10. The method as recited in claim 8 , comprising providing duplicate inputs to the at least one shadow system as the inputs provided to the active component with which the at least one shadow system is associated.

11. The method as recited in claim 8 , wherein determining whether the deviation exists is based at least in part on comparing one or more performance metrics of the at least one shadow system and the active component with which the at least one shadow system is associated.

12. The method as recited in claim 11 , wherein the one or more performance metrics are selected from a group consisting of:

execution time associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith;

progress of the one or more duplicate workloads on the active component and the shadow system associated therewith;

memory usage associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith; and

network behavior associated with performing the one or more duplicate workloads on the active component and the shadow system associated therewith.

13. The method as recited in claim 8 , wherein determining whether the deviation exists employs a Bloom filter.

14. A system, comprising a hardware processor configured to:

deploy at least one shadow system in association with each of one or more components of a network environment;

periodically record a state map of each active component of the network environment and a corresponding state map of the at least one shadow system associated therewith;

periodically compare the recorded state map of each active component with the corresponding recorded state map of the at least one shadow system associated therewith;

determine whether a deviation exists with respect to the recorded state map of each active component with and the corresponding recorded state map of the at least one shadow system associated therewith;

in response to determining the deviation exists, determine whether the deviation is greater than a predetermined deviation threshold; and

in response to determining the deviation is greater than the predetermined deviation threshold, declare a security breach regarding the active component(s) for which the deviation was determined to be greater than the predetermined deviation threshold.

15. The system as recited in claim 14 , wherein recording the state maps comprises a microcheckpointing process configured to determine and log the state map of each active component of the network environment and the corresponding state map of the at least one shadow system associated therewith.

16. The system as recited in claim 14 , wherein the processor is configured to provide duplicate inputs to the at least one shadow system as the inputs provided to the active component with which the at least one shadow system is associated.

17. The system as recited in claim 14 , wherein determining whether the deviation exists is based at least in part on comparing one or more performance metrics of the at least one shadow system and the active component with which the at least one shadow system is associated.

18. The system as recited in claim 17 , wherein the one or more performance metrics are selected from a group consisting of:

execution time associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith;

progress of the one or more duplicate workloads on the active component and the shadow system associated therewith;

memory usage associated with performing one or more duplicate workloads on the active component and the shadow system associated therewith; and

network behavior associated with performing the one or more duplicate workloads on the active component and the shadow system associated therewith.

19. The system as recited in claim 14 , wherein determining whether the deviation exists employs a Bloom filter.

20. The system as recited in claim 14 , wherein the processor is configured to replace the active component with one of the at least one shadow systems associated therewith in response to declaring the security breach.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LIMITED
To: LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 069869/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
To: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LTD
Reel/Frame 050311/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2016
From: CUDAK, GARY DAVID; DHOLAKIA, AJAY; KELSO, SCOTT; BOWER, FRED ALLISON, III
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 038736/0568 →
Continuity (1)
Related Publication 20170310701A1 · Oct 26, 2017