IP Library Granted Patent US 12,137,105
Granted Patent B2
US 12,137,105 · App. 17/091,877 · Granted Nov 5, 2024

Security management method and security management apparatus

Inventor: Zechao Meng (Shenzhen, CN)
Assignee: Huawei Cloud Computing Technologies Co., Ltd.
H04L63/1416G06F21/52G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,137,105
App. No.
17/091,877
Granted
Nov 5, 2024
Kind
B2
Abstract

A security management arrangement for monitoring to detect a targeted attack on an application. Operation of the arrangement includes receiving a suspected attack alarm issued by a centralized security monitoring apparatus. The arrangement determines an application associated with the suspected attack alarm. The arrangement further operates to obtain monitoring information obtained through monitoring of the application. The arrangement further determines, based on the monitoring information, the application has been attacked.

Claims (47)

1. A security management method carried out on behalf of an application deployable in a multi-machine operating environment, the method comprising:

receiving a suspected attack alarm from a centralized security monitoring apparatus;

extracting, from the suspected attack alarm, an identifier used to associate the application;

determining, in accordance with the identifier, the application associated with the suspected attack alarm;

issuing, in accordance with the receiving a suspected attack alarm and the determining the application associated with the suspected attack alarm, a request for a monitoring program to be deployed to an operating environment of the application, wherein the monitoring program is executed in the operating environment to generate a monitoring information during operation of the application;

obtaining, in accordance with the issuing the request and by executing the monitoring program deployed to and executed in the operating environment, the monitoring information of the application;

determining, in accordance with the obtaining and based on the monitoring information of the application, the application has been attacked;

stopping or isolating, in accordance with the determining the application has been attacked, the application; and

deleting, after the determining the application has been attacked, the monitoring program from the operating environment of the application.

2. The method according to claim 1 , wherein the identifier comprises at least one of the group consisting of:

an internet protocol (IP) address associated with the application,

a port number associated with the application, and

a uniform resource locator (URL) associated with the application.

3. A security management apparatus, comprising:

a processor,

a non-transitory memory comprising executable instructions that, when executed by the processor, facilitate carrying out the following operations on behalf of an application deployable in a multi-machine operating environment:

receiving a suspected attack alarm from a centralized security monitoring apparatus;

extracting, from the suspected attack alarm, an identifier used to associate the application;

determining, in accordance with the identifier, the application associated with the suspected attack alarm;

issuing, in accordance with the receiving a suspected attack alarm and the determining the application associated with the suspected attack alarm, a request for a monitoring program to be deployed to an operating environment of the application, wherein the monitoring program is executed in the operating environment to generate a monitoring information during operation of the application;

obtaining, in accordance with the issuing the request and by executing the monitoring program deployed to and executed in the operating environment, the monitoring information of the application;

determining, in accordance with the obtaining and based on the monitoring information of the application, the application has been attacked;

stopping or isolating, in accordance with the determining the application has been attacked, the application; and

deleting, after the determining the application has been attacked, the monitoring program from the operating environment of the application.

4. The apparatus according claim 3 , wherein the identifier comprises at least one of the group consisting of:

an internet protocol (IP) address associated with the application,

a port number associated with the application, and

a uniform resource locator (URL) associated with the application.

5. Anon-transitory computer-readable medium comprising computer-executable instructions that, when executed by a processor, facilitate carrying out the following operations on behalf of an application deployable in a multi-machine operating environment:

receiving a suspected attack alarm from a centralized security monitoring apparatus;

extracting, from the suspected attack alarm, an identifier used to associate the application;

determining, in accordance with the identifier, the application associated with the suspected attack alarm;

issuing, in accordance with the receiving a suspected attack alarm and the determining the application associated with the suspected attack alarm, a request for a monitoring program to be deployed to an operating environment of the application, wherein the monitoring program is executed in the operating environment to generate a monitoring information during operation of the application;

obtaining, in accordance with the issuing the request and by executing the monitoring program deployed to and executed in the operating environment, the monitoring information of the application;

determining, in accordance with the obtaining and based on the monitoring information of the application, the application has been attacked,

stopping or isolating, in accordance with the determining the application has been attacked, the application; and

deleting, after the determining the application has been attacked, the monitoring program from the operating environment of the application.

6. The non-transitory computer-readable medium according to claim 5 , wherein the identifier comprises at least one of the group consisting of:

an internet protocol (IP) address associated with the application,

a port number associated with the application, and

a uniform resource locator URL associated with the application.

7. The non-transitory computer-readable medium of claim 5 , wherein the multi-machine operating environment comprises a plurality of physical machines operating in a network.

8. The non-transitory computer-readable medium of claim 5 , wherein the multi-machine operating environment comprises a plurality of virtual machines.

9. The method of claim 1 , wherein the multi-machine operating environment comprises a plurality of physical machines operating in a network.

10. The method of claim 1 , wherein the multi-machine operating environment comprises a plurality of virtual machines.

11. The security management apparatus according to claim 3 , wherein the multi-machine operating environment comprises a plurality of physical machines operating in a network.

12. The security management apparatus according to claim 3 , wherein the multi-machine operating environment comprises a plurality of virtual machines.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: HUAWEI TECHNOLOGIES CO., LTD.
To: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.
Reel/Frame 059267/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2020
From: MENG, ZECHAO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 054303/0692 →