IP Library Granted Patent US 11,063,983
Granted Patent B2
US 11,063,983 · App. 16/440,918 · Granted Jul 13, 2021

Componentized security policy generation

Inventors: Ernesto DiGiambattista (Lynnfield, MA); Michael D. Kail (Los Gatos, CA); Alex Manelis (Palo Alto, CA); Salvatore Sclafani (Revere, MA)
Assignee: ZeroNorth, Inc.
H04L63/20G06N5/048G06N20/00H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,063,983
App. No.
16/440,918
Granted
Jul 13, 2021
Kind
B2
Abstract

A continuous security delivery fabric is disclosed. One or more security functions, comprising one or more tasks to be performed by a security tool, utility or service is encapsulated in a componentized security policy. A target list comprising of one or more items in an information technology installation is received. One or more security functions capable of being performed on at least one item in the received target list are selected. A componentized security policy encapsulating one or more security routines orchestrating the performance of at least one of the selected security functions is then created.

Claims (57)

1. A method to remediate information technology installation security issues, comprising:

receiving data identifying an item in an information technology installation;

selecting a security function capable of being performed on the item in the information technology installation;

creating a componentized security policy encapsulating one or more security routines orchestrating the performance of the security function;

executing the one or more encapsulated security routines against a shadow environment that is a mirror instance of the information technology installation;

receiving results from the execution of the one or more encapsulated security routines against the shadow environment; and

based on the results, determining whether a security issue exists.

2. The method of claim 1 ,

wherein the componentized security policy is configured to be used in conjunction with at least one other componentized security policy.

3. The method of claim 1 ,

wherein the componentized security policy is configured to create an output report where results of the componentized security policy are integrated with results of at least one other componentized security policy.

4. The method of claim 1 ,

wherein the componentized security policy includes any combination of:

a code scan policy;

an application scan policy; and

a development security operations policy.

5. The method of claim 1 , wherein the security function is configured to be executed via a microservice.

6. The method of claim 1 , further comprising scheduling a time for the one or more encapsulated security routines to be executed.

7. A system, comprising:

one or more processors; and

memory including a plurality of computer-executable components that are executable by the one or more processors to perform a plurality of acts, the plurality of acts comprising:

receiving data identifying an item in an information technology installation;

selecting a security function capable of being performed on the item in the information technology installation;

creating a componentized security policy encapsulating one or more security routines orchestrating the performance of the security function;

executing the one or more encapsulated security routines against a shadow environment that is a mirror instance of the information technology installation;

receiving results from the execution of the one or more encapsulated security routines against the shadow environment; and

based on the results, determining whether a security issue exists.

8. The system of claim 7 ,

wherein the componentized security policy is configured to be used in conjunction with at least one other componentized security policy.

9. The system of claim 7 ,

wherein the componentized security policy is configured to create an output report where results of the componentized security policy are integrated with results of at least one other componentized security policy.

10. The system of claim 7 ,

wherein the componentized security policy includes any combination of:

a code scan policy;

an application scan policy; and

a development security operations policy.

11. The system of claim 7 , wherein the security function is configured to be executed via a microservice.

12. The system of claim 7 , wherein the plurality of acts further comprise scheduling a time for the one or more encapsulated security routines to be executed.

13. One or more non-transitory computer-readable media storing computer-executable instructions that upon execution cause one or more processors to perform acts comprising:

receiving data identifying an item in an information technology installation;

selecting a security function capable of being performed on the item in the information technology installation;

creating a componentized security policy encapsulating one or more security routines orchestrating the performance of the security function;

executing the one or more encapsulated security routines against a shadow environment that is a mirror instance of the information technology installation;

receiving results from the execution of the one or more encapsulated security routines against the shadow environment; and

based on the results, determining whether a security issue exists.

14. The one or more non-transitory computer-readable media of claim 13 ,

wherein the componentized security policy is configured to be used in conjunction with at least one other componentized security policy.

15. The one or more non-transitory computer-readable media of claim 13 ,

wherein the componentized security policy is configured to create an output report where results of the componentized security policy are integrated with results of at least one other componentized security policy.

16. The one or more non-transitory computer-readable media of claim 13 ,

wherein the componentized security policy includes any combination of:

a code scan policy;

an application scan policy; and

a development security operations policy.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the security function is configured to be executed via a microservice.

18. The method of claim 1 ,

wherein the information technology installation includes one or more software systems that automate operations of an enterprise.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0915 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0701 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 069387/0816 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 069387/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: PROJECT PROTECT MERGER SUB II, LLC
To: HARNESS INC.
Reel/Frame 067979/0848 →
MERGER Recorded Jul 10, 2024
From: ZERONORTH, INC.; PROJECT PROTECT MERGER SUB II, LLC
To: PROJECT PROTECT MERGER SUB II, LLC
Reel/Frame 067954/0404 →
MERGER Recorded Mar 8, 2024
From: ZERONORTH, INC.; PROJECT PROTECT MERGER SUB 1
To: ZERONORTH, INC.
Reel/Frame 066769/0327 →
CHANGE OF NAME Recorded Nov 21, 2019
From: CYBRIC INC.
To: ZERONORTH, INC.
Reel/Frame 051089/0779 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2019
From: DIGIAMBATTISTA, ERNESTO; KAIL, MICHAEL D.; MANELIS, ALEX; SCLAFANI, SALVATORE
To: CYBRIC INC.
Reel/Frame 049465/0143 →
Continuity (3)
Division 15430386 · Feb 10, 2017
Provisional Application 62294141 · Feb 11, 2016
Related Publication 20190297117A1 · Sep 26, 2019