Generating security permissions for cloud computing assets in cloud platforms
An online system determines security specification for cloud computing assets of a cloud computing platform. The system initializes a security specification and monitors execution of an application over a time interval to receive information describing application programming interface (API) invocations performed by the application. For each action performed by the API invocation, the system determines whether the security specification allows the actions performed by the API invocation with the cloud computing asset. The system modifies the security specification if necessary to allow the application to perform the particular action with the particular cloud computing asset. The system enforces security permissions for applications running on cloud computing platform based on the generated security specification.
1 . A computer-implemented method comprising:
receiving a request to generate security specification for cloud computing assets of a cloud platform;
initializing a security specification;
receiving, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;
for each action performed by the application that accesses a cloud computing asset, determining whether the security specification allows the action;
responsive to identifying a particular action performed by the application that is not allowed by the security specification, modifying the security specification to allow the application to perform the particular action; and
enforcing security permissions for applications running on cloud computing platform based on the security specification.
2 . The computer-implemented method of claim 1 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.
3 . The computer-implemented method of claim 1 , further comprising:
sending the generated security specification for display via a user interface for approval; and
responsive to receiving an approval, enforcing security permissions for applications running on cloud computing platform using the modified security specification.
4 . The computer-implemented method of claim 1 , wherein an action performs one of:
reading an object, adding an object, modifying an object, or deleting an object.
5 . The computer-implemented method of claim 1 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.
6 . The computer-implemented method of claim 1 , wherein the application is instrumented to provide metadata describing API invocations.
7 . The computer-implemented method of claim 1 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.
8 . A non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to:
receive a request to generate security specification for cloud computing assets of a cloud platform;
initialize a security specification;
receive, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;
for each action performed by the application that accesses a cloud computing asset, determine whether the security specification allows the action;
responsive to identifying a particular action performed by the application that is not allowed by the security specification, modify the security specification to allow the application to perform the particular action; and
enforce security permissions for applications running on cloud computing platform based on the security specification.
9 . The non-transitory computer readable storage medium of claim 8 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.
10 . The non-transitory computer readable storage medium of claim 8 , wherein the instructions further cause the computer processor to:
sending the generated security specification for display via a user interface for approval; and
responsive to receiving an approval, enforcing security permissions for applications running on cloud computing platform using the modified security specification.
11 . The non-transitory computer readable storage medium of claim 8 , wherein instructions for an action cause the computer processor to:
read an object, add an object, modify an object, or delete an object.
12 . The non-transitory computer readable storage medium of claim 8 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.
13 . The non-transitory computer readable storage medium of claim 8 , wherein the application is instrumented to provide metadata describing API invocations.
14 . The non-transitory computer readable storage medium of claim 8 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.
15 . A computer system comprising:
a computer processor; and
a non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to:
receive a request to generate security specification for cloud computing assets of a cloud platform;
initialize a security specification;
receive, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;
for each action performed by the application that accesses a cloud computing asset, determine whether the security specification allows the action;
responsive to identifying a particular action performed by the application that is not allowed by the security specification, modify the security specification to allow the application to perform the particular action; and
enforce security permissions for applications running on cloud computing platform based on the security specification.
16 . The computer system of claim 15 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.
17 . The computer system of claim 15 , wherein instructions for an action cause the computer processor to:
read an object, add an object, modify an object, or delete an object.
18 . The computer system of claim 15 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.
19 . The computer system of claim 15 , wherein the application is instrumented to provide metadata describing API invocations.
20 . The computer system of claim 15 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.