IP Library Granted Patent US 10,382,491
Granted Patent B2
US 10,382,491 · App. 15/430,386 · Granted Aug 13, 2019

Continuous security delivery fabric

Inventors: Ernesto DiGiambattista (Lynnfield, MA); Michael D. Kail (Los Gatos, CA); Alex Manelis (Palo Alto, CA); Salvatore Sclafani (Revere, MA)
Assignee: CYBRIC, Inc.
H04L63/20G06N5/048G06N20/00H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,491
App. No.
15/430,386
Granted
Aug 13, 2019
Kind
B2
Abstract

A continuous security delivery fabric is disclosed. One or more security functions, comprising one or more tasks to be performed by a security tool, utility or service is encapsulated in a componentized security policy. The componentized security policies may be scheduled to run against one or more shadow environments, which are substantive copies of an information technology installation. One or more componentized security policies are scheduled as to run substantively continuously with results of the execution of the componentized security policies against the shadow aggregated. Based on automated analysis which may include machine learning, security issues in the actual information technology installation are inferred, and remediation either recommended or automatically executed. Various embodiments, including a microservices infrastructure embodiment are disclosed.

Claims (34)

1. A method to remediate information technology installation security issues, comprising:

receiving a selection of a componentized security policy, wherein the componentized security policy includes one or more encapsulated security routines orchestrating a performance of at least one security function;

executing one or more encapsulated security routines of the componentized security policy against a shadow environment that is a mirror instance of an enterprise installation instance, in which the enterprise installation instance includes one or more software systems that automate operations of an enterprise;

receiving results from performance of the at least one security function orchestrated by the one or more encapsulated security routines included in the componentized security policy; and

inferring an existence of at least one security issue based at least on the results.

2. The method of claim 1 , further comprising scheduling a time for the one or more encapsulated security routines of the componentized security policy to be executed.

3. The method of claim 1 , further comprising receiving a selection of a second componentized security policy and executing one or more additional encapsulated security routines of the second componentized security policy against the shadow environment.

4. The method of claim 3 , further comprising scheduling a plurality of times for the one or more encapsulated security routines of the componentized security policy and the one or more encapsulated security routines of the second componentized security policy to be performed such that one or more security functions orchestrated by at least one encapsulated security routine of either the componentized security policy or the second componentized security policy is performed against the shadow environment a majority of the time.

5. The method of claim 4 , wherein the one or more encapsulated security routines of the componentized security policy and the one or more encapsulated security routines of the second componentized security policy to be performed are such that security functions orchestrated by encapsulated security routines of the componentized security policy and the second componentized security policy are performed against the shadow environment on a continuous basis.

6. The method of claim 4 , further comprising aggregating the results of the one or more encapsulated security routines of the componentized security policy and additional results of the one or more additional encapsulated security routines of the second componentized security policy in an analytics data store.

7. The method of claim 6 , further comprising generating at least one recommended remediation based on analyzing the results and the additional results aggregated in the analytics data store.

8. The method of claim 7 , further comprising automatically performing the at least one recommended remediation.

9. The method of claim 7 , wherein the at least one recommended remediation is taken from a set of responses stored in a response data store.

10. The method of claim 7 , comprising receiving a selection to automatically perform the at least one recommended remediation, and storing the selection in a selection data store.

11. The method of claim 7 , wherein at least one machine learning algorithm is applied against the results and the additional results aggregated in the analytics data store to determine a malfunction of the shadow environment.

12. A system, comprising:

one or more processors; and

memory including a plurality of computer-executable components that are executable by the one or more processors to perform a plurality of acts, the plurality of acts comprising:

receiving a selection of a componentized security policy, wherein the componentized security policy includes a plurality of encapsulated security routines orchestrating a performance of multiple security functions;

executing the plurality of encapsulated security routines of the componentized security policy against a shadow environment that is a mirror instance of an enterprise installation instance, in which the enterprise installation instance includes one or more software systems that automate operations of an enterprise;

receiving results from performance of the multiple security functions orchestrated by the plurality of encapsulated security routines included in the componentized security policy; and

inferring an existence of at least one security issue based at least on the results.

13. The system of claim 12 , wherein the plurality of acts further comprise scheduling a time for the plurality of encapsulated security routines of the componentized security policy to be executed.

14. The system of claim 12 , wherein the plurality of acts further comprise receiving a selection of a second componentized security policy and executing one or more additional encapsulated security routines of the second componentized security policy against the shadow environment.

15. The system of claim 14 , further comprising scheduling a plurality of times for the plurality of encapsulated security routines of the componentized security policy and the plurality of encapsulated security routines of the second componentized security policy to be performed such that at least one security functions orchestrated by at least one encapsulated security routine of either the componentized security policy or the second componentized security policy is performed against the shadow environment a majority of the time.

16. The system of claim 14 , wherein the plurality of encapsulated security routines of the componentized security policy and the plurality of encapsulated security routines of the second componentized security policy to be performed are such that individual security functions orchestrated by individual encapsulated security routines of the componentized security policy and the second componentized security policy are performed against the shadow environment on a continuous basis.

17. A method to remediate information technology installation security issues, comprising:

receiving a selection of a componentized security policy, wherein the componentized security policy includes one or more encapsulated security routines orchestrating a performance of at least one security function;

executing the one or more encapsulated security routines of the componentized security policy against a shadow environment that is a mirror instance of an enterprise installation instance, in which the enterprise installation instance includes one or more software systems that automate operations of an enterprise;

receiving results from performance of the at least one security function orchestrated by the one or more encapsulated security routines included in the componentized security policy; and

inferring an existence of at least one security issue based at least on the results.

18. The method of claim 17 , further comprising scheduling a time for the one or more encapsulated security routines of the componentized security policy to be executed.

19. The method of claim 17 , further comprising receiving a selection of a second componentized security policy and executing one or more additional encapsulated security routines of the second componentized security policy against the shadow environment.

20. The method of claim 19 , further comprising scheduling a plurality of times for the one or more encapsulated security routines of the componentized security policy and the one or more encapsulated security routines of the second componentized security policy to be performed such that one or more security functions orchestrated by at least one encapsulated security routine of either the componentized security policy or the second componentized security policy is performed against the shadow environment on a continuous basis.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0915 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0701 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 069387/0816 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 069387/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: PROJECT PROTECT MERGER SUB II, LLC
To: HARNESS INC.
Reel/Frame 067979/0848 →
MERGER Recorded Jul 10, 2024
From: ZERONORTH, INC.; PROJECT PROTECT MERGER SUB II, LLC
To: PROJECT PROTECT MERGER SUB II, LLC
Reel/Frame 067954/0404 →
MERGER Recorded Mar 8, 2024
From: ZERONORTH, INC.; PROJECT PROTECT MERGER SUB 1
To: ZERONORTH, INC.
Reel/Frame 066769/0327 →
CHANGE OF NAME Recorded Nov 21, 2019
From: CYBRIC INC.
To: ZERONORTH, INC.
Reel/Frame 051089/0563 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2017
From: DIGIAMBATTISTA, ERNESTO; KAIL, MICHAEL D.; MANELIS, ALEX; SCLAFANI, SALVATORE
To: CYBRIC INC.
Reel/Frame 041735/0470 →
Continuity (2)
Provisional Application 62294141 · Feb 11, 2016
Related Publication 20170237778A1 · Aug 17, 2017
Cited By (6)
US 12,229,275 US 12,341,816 US 12,452,290 US 12,483,541 US 12,572,354 US 12,719,914