IP Library Granted Patent US 11,722,512
Granted Patent B2
US 11,722,512 · App. 17/147,015 · Granted Aug 8, 2023

Framework to quantify security in DevOps deployments

Inventors: Mahadevan Vasudevan (Westborough, MA); Hanumesh Jojode (South Grafton, MA)
Assignee: EMC IP Holding Company LLC
H04L63/1433G06F8/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,512
App. No.
17/147,015
Granted
Aug 8, 2023
Kind
B2
Abstract

Techniques for providing a framework that quantifies security in DevOps deployments. The framework includes receiving parameters pertaining to specified factors relevant to security in multiple stages of a DevOps deployment, generating measurement values of the received parameters, calculating a score indicative of an overall level of security in the DevOps deployment based on an aggregation of the measurement values, and, in response to a comparison result of the calculated score against a predetermined threshold, detecting and identifying at least one security gap in the DevOps deployment. In this way, the detection and identification of potential gaps in DevOps security can be made earlier (or “shifted left”), allowing them to be addressed and/or mitigated with reduced DevOps downtime or failure.

Claims (42)

1. A method of providing a framework that quantifies security in software application development and deployment, comprising:

receiving, at a central computer, parameters pertaining to specified factors relevant to security in one or more stages of a lifecycle of the software application development and deployment;

generating, by the central computer, measurement values of the received parameters;

calculating, by the central computer, a score indicative of an overall level of security in the software application development and deployment based on an aggregation of the measurement values; and

in response to the calculated score exceeding a predetermined threshold, identifying at least one security gap in the software application development and deployment based at least on one or more of the received parameters,

wherein the receiving of the parameters pertaining to the specified factors relevant to security includes receiving the parameters pertaining to the specified factors relevant to security at a client level of the software application development and deployment, and

wherein the receiving of the parameters pertaining to the specified factors relevant to security further includes receiving the parameters pertaining to the specified factors relevant to security at a network level of the software application development and deployment.

2. The method of claim 1 wherein the receiving of the parameters pertaining to the specified factors relevant to security at the client level of the software application development and deployment includes receiving the parameters pertaining to the specified factors relating to one or more of role-based access control (RBAC), data-at-rest encryption, and configuration management at the client level.

3. The method of claim 1 wherein the receiving of the parameters pertaining to the specified factors relevant to security at the network level of the software application development and deployment includes receiving the parameters pertaining to the specified factors relating to one or more of data-in-flight encryption and security ports access at the network level.

4. The method of claim 1 wherein the receiving of the parameters pertaining to the specified factors relevant to security includes receiving the parameters pertaining to the specified factors relevant to security at an application level of the software application development and deployment.

5. The method of claim 4 wherein the receiving of the parameters pertaining to the specified factors relevant to security at the application level of the software application development and deployment includes receiving the parameters pertaining to the specified factors relating to one or more of firewall setup, certificates and code signing, data-at-rest encryption, access privileges, and anomaly-based intrusion detection at the application level.

6. The method of claim 4 wherein the generating of the measurement values of the received parameters includes generating the measurement values based on the client level, the network level, and the application level of the software application development and deployment from which the parameters were received.

7. The method of claim 6 wherein the generating of the measurement values of the received parameters includes generating the measurement values based on the specified factors relevant to software application development and deployment security at the client level, the network level, and the application level of the software application development and deployment.

8. A method of providing a framework that quantifies security in software application development and deployment, comprising:

receiving, at a central computer, parameters pertaining to specified factors relevant to security in one or more stages of a lifecycle of the software application development and deployment;

generating, by the central computer, measurement values of the received parameters;

calculating, by the central computer, a score indicative of an overall level of security in the software application development and deployment based on an aggregation of the measurement values;

in response to the calculated score exceeding a predetermined threshold, identifying at least one security gap in the software application development and deployment based at least on one or more of the received parameters,

wherein the identifying of the at least one security gap in the software application development and deployment includes performing an analysis of the received parameters;

having identified the at least one security gap in the software application development and deployment, generating one or more recommendations for remediation of the at least one security gap; and

generating a report containing at least the calculated score, the specified factors contributing to the calculated score, and the recommendations for remediation of the at least one security gap.

9. The method of claim 8 wherein the software application development and deployment is deemed to be compliant with specified audit regulations if the calculated score does not exceed the predetermined threshold, and wherein the method further comprises:

in response to performing remediation of the at least one security gap in the software application development and deployment, iteratively performing the receiving of the parameters, the generating of the measurement values, and the calculating of the score until the calculated score does not exceed the predetermined threshold.

10. A system for providing a framework that quantifies security in software application development and deployment, comprising:

a central computer communicably coupleable, over a network, to one or more client processing devices, one or more server processing devices, and one or more network processing devices,

wherein the central computer includes processing circuitry configured to execute program instructions out of a memory to:

receive parameters pertaining to specified factors relevant to security in one or more stages of a lifecycle of the software application development and deployment;

generate measurement values of the received parameters;

calculate a score indicative of an overall level of security in the software application development and deployment based on an aggregation of the measurement values; and

in response to the calculated score exceeding a predetermined threshold, identify at least one security gap in the software application development and deployment based at least on one or more of the received parameters,

wherein the processing circuitry is further configured to execute the program instructions out of the memory to receive the parameters pertaining to the specified factors relevant to security at a client level of the software application development and deployment, and

wherein the processing circuitry is further configured to execute the program instructions out of the memory to receive the parameters pertaining to the specified factors relevant to security at a network level of the software application development and deployment.

11. The system of claim 10 wherein the processing circuitry is further configured to execute the program instructions out of the memory to receive the parameters pertaining to the specified factors relevant to security at an application level of the software application development and deployment.

12. The system of claim 11 wherein the processing circuitry is further configured to execute the program instructions out of the memory to generate the measurement values based on the client level, the network level, and the application level of the software application development and deployment from which the parameters were received.

13. The system of claim 12 wherein the processing circuitry is further configured to execute the program instructions out of the memory to generate the measurement values based on the specified factors relevant to software application development and deployment security at the client level, the network level, and the application level of the software application development and deployment.

14. A computer program product including a set of non-transitory, computer-readable media having instructions that, when executed by processing circuitry, cause the processing circuitry to perform a method of providing a framework that quantifies security in software application development and deployment, the method comprising:

receiving, at a central computer, parameters pertaining to specified factors relevant to security in one or more stages of a lifecycle of the software application development and deployment;

generating, by the central computer, measurement values of the received parameters;

calculating, by the central computer, a score indicative of an overall level of security in the software application development and deployment based on an aggregation of the measurement values; and

in response to the calculated score exceeding a predetermined threshold, identifying at least one security gap in the software application development and deployment based at least on one or more of the received parameters,

wherein the receiving of the parameters pertaining to the specified factors relevant to security includes receiving the parameters pertaining to the specified factors relevant to security at a client level of the software application development and deployment, and

wherein the receiving of the parameters pertaining to the specified factors relevant to security further includes receiving the parameters pertaining to the specified factors relevant to security at a network level of the software application development and deployment.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2021
From: VASUDEVAN, MAHADEVAN; JOJODE, HANUMESH
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055391/0160 →