Methods and systems for reinforcement learning of post-attack security hardening passes
Various embodiments of methods, systems and computer program products described herein are directed to a Security Engine. The Security Engine provides for post-attack security upgrades of an application by selecting specific security hardening passes to be applied to a pre-attack state of the application. According to various embodiments, the Security Engine receives a pre-attack state of a first instance of an application in response to an action by an attack source. The Security Engine selects one or more security hardening passes to be applied to the pre-attack state. The Security Engine sends an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state.
1. A computer-implemented method, comprising:
receiving a pre-attack state of a first instance of an application in response to an action by an attack source;
selecting one or more security hardening passes to be applied to the pre-attack state; and
sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,
wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:
selecting a first security hardening pass associated with a first type of program efficiency benchmark;
applying the first security hardening pass to the pre-attack state; and
validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.
2. The computer-implemented method of claim 1 , further comprising:
based on satisfying the first application performance threshold:
selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;
applying the second security hardening pass to the pre-attack state with the first security hardening pass; and
validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.
3. The computer-implemented method of claim 1 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:
receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.
4. The computer-implemented method of claim 3 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:
receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.
5. The computer-implemented method of claim 4 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and
wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:
sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source.
6. The computer-implemented method of claim 4 , wherein the parent process diversified the memory used by the first process prior to the memory access violation.
7. A system comprising one or more processors, and a non-transitory computer-readable medium including one or more sequences of instructions that, when executed by the one or more processors, cause the system to perform operations comprising:
receiving a pre-attack state of a first instance of an application in response to an action by an attack source;
selecting one or more security hardening passes to be applied to the pre-attack state; and
sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,
wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:
selecting a first security hardening pass associated with a first type of program efficiency benchmark;
applying the first security hardening pass to the pre-attack state; and
validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.
8. The system of claim 7 , further comprising:
based on satisfying the first application performance threshold:
selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;
applying the second security hardening pass to the pre-attack state with the first security hardening pass; and
validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.
9. The system of claim 7 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:
receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.
10. The system of claim 9 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:
receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.
11. The system of claim 10 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and
wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:
sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source.
12. The system of claim 10 , wherein the parent process diversified the memory used by the first process prior to the memory access violation.
13. A computer program product comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein to be executed by one or more processors, the program code including instructions to:
receiving a pre-attack state of a first instance of an application in response to an action by an attack source;
selecting one or more security hardening passes to be applied to the pre-attack state; and
sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,
wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:
selecting a first security hardening pass associated with a first type of program efficiency benchmark;
applying the first security hardening pass to the pre-attack state; and
validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.
14. The computer program product of claim 13 , further comprising:
based on satisfying the first application performance threshold:
selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;
applying the second security hardening pass to the pre-attack state with the first security hardening pass; and
validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.
15. The computer program product of claim 13 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:
receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.
16. The computer program product of claim 15 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:
receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.
17. The computer program product of claim 16 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and
wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:
sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source, wherein the parent process diversified the memory used by the first process prior to the memory access violation.