IP Library Patent Application 17316296
Patent Application
App. No. 17/316,296

INTELLIGENT SERVICE SECURITY ENFORCEMENT SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/316,296
Abstract

A method and system are described. The method includes determining, in a development phase of a software service, whether the software service complies with a first policy in response to a request. The method also monitors, in at least one of a testing phase or a production phase of the software service, whether operation of the software service complies with a second policy. Based on the determining and the monitoring, an indication of a service vulnerability is generated in response to the software service failing to comply with the first policy in the development phase or failing to comply with the second policy in the at least one of the testing phase or the production phase.

Claims (63)

1 . A method, comprising:

determining, in a development phase of a software service, whether the software service complies with a first policy in response to a request;

monitoring, in at least one of a testing phase or a production phase of the software service, whether operation of the software service complies with a second policy; and

generating, based on the determining and the monitoring, an indication of a service vulnerability in response to the software service failing to comply with the first policy in the development phase or failing to comply with the second policy in the at least one of the testing phase or the production phase.

2 . The method of claim 1 , further comprising:

storing security information for the software service, the security information including the service vulnerability.

3 . The method of claim 1 , wherein the determining further includes:

detecting a tag for the first policy in the software service;

identifying the first policy based on the tag; and

determining whether the software service complies with the first policy.

4 . The method of claim 1 , wherein the determining further includes:

analyzing the software service to identify a plurality of properties for the software service;

determining whether the plurality of properties match a plurality of characteristics corresponding to the first policy; and

determining whether the software service complies with the first policy in response to the plurality of properties matching the plurality of characteristics.

5 . The method of claim 4 , wherein the determining the match further includes:

accessing a database including security information for a plurality of software services.

6 . The method of claim 1 , wherein the monitoring further includes:

inspecting a log for the software service, the log being generated during operation of the software service in the at least one of the testing phase or production phase; and

determining, based on the log, whether the software service complies with the second policy.

7 . The method of claim 1 , wherein the first policy and the second policy are the same.

8 . The method of claim 1 , further comprising:

enforcing the first policy in response to the software service failing to comply with the first policy in the development phase; and

enforcing the second policy in response to the software service failing to comply with the second policy in the at least one of the testing phase or the production phase.

9 . A system, comprising:

a memory; and

a processor coupled to the memory and configured to:

determine, in a development phase of a software service, whether the software service complies with a first policy in response to a request;

monitor, in at least one of a testing phase or a production phase of the software service, whether operation of the software service complies with a second policy; and

generate, based on the determination and the monitoring, an indication of a service vulnerability in response to the software service failing to comply with the first policy in the development phase or failing to comply with the second policy in the at least one of the testing phase or the production phase.

10 . The system of claim 9 , wherein the processor is further configured to:

store security information for the software service, the security information including the service vulnerability.

11 . The system of claim 9 , wherein to determine whether the software service complies with the first policy, the processor is further configured to:

detect a tag for the first policy in the software service;

identify the first policy based on the tag; and

determine whether the software service complies with the first policy.

12 . The system of claim 9 , wherein to determine whether the software service complies with the first policy, the processor is further configured to:

analyze the software service to identify a plurality of properties for the software service;

determine whether the plurality of properties match a plurality of characteristics corresponding to the first policy; and

determine whether the software service complies with the first policy in response to the is plurality of properties matching the plurality of characteristics.

13 . The system of claim 12 , wherein to determine the match, the processor is further configured to:

access a database including security information for a plurality software services.

14 . The system of claim 9 , wherein to monitor, the processor is further configured to:

inspect a log for the software service, the log being generated during operation of the software service in the at least one of the testing phase or production phase; and

determine, based on the log, whether the software service complies with the second policy.

15 . The system of claim 9 , wherein the first policy and the second policy are the same.

16 . The system of claim 9 , wherein the processor is further configured to:

enforce the first policy in response to the software service failing to comply with the first policy in the development phase; and

enforce the second policy in response to the software service failing to comply with the second policy in the at least one of the testing phase or the production phase.

17 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining, in a development phase of a software service, whether the software service complies with a first policy in response to a request;

monitoring, in at least one of a testing phase or a production phase of the software service, whether operation of the software service complies with a second policy; and

generating, based on the determining and the monitoring, an indication of a service vulnerability in response to the software service failing to comply with the first policy in the development phase or failing to comply with the second policy in the at least one of the testing phase or the production phase.

18 . The computer program product of claim 17 , further comprising computer instructions for:

storing security information for the software service, the security information including the service vulnerability.

19 . The computer program product of claim 17 , further comprising computer instructions for:

enforcing the first policy in response to the software service failing to comply with the first policy in the development phase; and

enforcing the second policy in response to the software service failing to comply with the second policy in the at least one of the testing phase or the production phase.

20 . The computer program product of claim 17 , wherein the instructions for determining further include instructions for:

analyzing the software service to identify a plurality of properties for the software service;

determining whether the plurality of properties match a plurality of characteristics corresponding to the first policy; and

determining whether the software service complies with the first policy in response to the plurality of properties matching the plurality of characteristics; and wherein the instructions for monitoring further include instructions for

inspecting a log for the software service, the log being generated during operation of the software service in the at least one of the testing phase or production phase; and

determining, based on the log, whether the software service complies with the second policy.

Assignments (1)
CHANGE OF NAME Recorded Nov 19, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058214/0351 →