IP Library Granted Patent US 9,871,822
Granted Patent B2
US 9,871,822 · App. 14/555,741 · Granted Jan 16, 2018

Deployment using a context-based cloud security assurance system

Inventors: Nataraj Nagaratnam (Cary, NC); Jeffrey Robert Hoy (Southern Pines, NC); Sreekanth Ramakrishna Iyer (Bangalore, IN); Sridhar R. Muppidi (Austin, TX)
Assignee: International Business Machines Corporation
H04L63/20G06F7/76G06Q10/0635G06Q10/06315H04L63/0272H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,822
App. No.
14/555,741
Granted
Jan 16, 2018
Kind
B2
Abstract

A cloud infrastructure is enhanced to provide a context-based security assurance service to enable secure application deployment. The service inspects network and cloud topologies to identify potential security capabilities and needs. Preferably, these options are then surfaced to the user with easy-to-understand, pre-configured templates representing security assurance levels. When a template (e.g., representing a pre-configured assurance level) is selected by the user, the system then applies specific capabilities and controls to translate the user-selected generalized specification (e.g., “high security”) into granular requirements for a specific set of security resources. Preferably, the identification of these security resources is based on system configuration, administration, and information associated with the pre-configured template.

Claims (39)

1. A method for context-based security assurance in a cloud application environment, comprising:

as an application is being deployed in the cloud application environment, presenting a set of templates in an editor, wherein a template is pre-defined and includes therewith a security assurance level that is specified by a set of general security requirements that have been discovered for the cloud application environment in an automated manner, at least one of the set of general security requirements being specified in a manner that does not expose at least some specific security tooling requirements necessary to implement the security assurance level security requirement;

in response to receipt of a selection of a template, and based at least in part on a security context of the deployment, automatically applying configuration changes, via automation, to a set of security resources present in the cloud application environment to create a cloud application zone, the set of security resources including the at least one specific tooling requirement necessary to implement the security assurance level security requirement, the configuration changes including one of: a missing cofiguration, and a missing product; and

upon receipt of an indication that the set of security resources have been configured, completing the deployment of the application into the cloud application zone;

wherein the presenting, configuring and deploying steps are carried out in software executing in a hardware element.

2. The method as described in claim 1 further including receiving information on a set of security capabilities available in the cloud application environment and, in response, to define the security context.

3. The method as described in claim 1 wherein the set of templates are provided to an end user via user interface tooling associated with the cloud application environment.

4. The method as described in claim 1 wherein the set of security resources are configured remotely via a REST-based interface.

5. The method as described in claim 1 further including:

in response to receipt in the editor of a selection of a second template and an instruction to wire the second template to the template, enforcing a security restriction with respect to at least one of the templates.

6. The method as described in claim 1 wherein the set of templates presented in the editor is based at least in part on one of: the application being deployed, availability of security software in the cloud application environment, and one or more properties of middleware in the cloud application environment.

7. The method as described in claim 1 further including:

in response to receipt in the editor of a query with details about the application being deployed, providing information about one or more available security resources appropriate for the application.

8. Apparatus, comprising:

a processor;

computer memory holding computer program instructions executed by the processor to provide context-based security assurance in a cloud application environment, the computer program instructions comprising:

program code, operative as an application is being deployed in the cloud application environment, to present a set of templates in an editor, wherein a template is pre-defined and includes a security assurance level that is specified by a set of general security requirements that have been discovered for the cloud application environment in an automated manner, at least one of the set of general security requirements being specified in a manner that does not expose at least some specific security tooling requirements necessary to implement the security assurance level security requirement;

program code, operative in response to receipt of a selection of a template, and based at least in part on a security context of the deployment, to automatically apply configuration changes, via automation, to a set of security resources present in the cloud application environment to create a cloud application zone, the set of security resources including the at least one specific tooling requirement necessary to implement the security assurance level security requirement, the configuration changes including one of: a missing configuration, and a missing product; and

program code operative upon receipt of an indication that the set of security resources have been configured, to complete the deployment of the application into the cloud application zone.

9. The apparatus as described in claim 8 wherein the computer program instructions further include program code operative to receive information on a set of security capabilities available in the cloud application environment and, in response, to define the security context.

10. The apparatus as described in claim 8 wherein the set of templates are provided to an end user via user interface tooling associated with the cloud application environment.

11. The apparatus as described in claim 8 wherein the set of security resources are configured remotely via a REST-based interface.

12. The apparatus as described in claim 8 wherein the computer program instructions further include:

program code operative in response to receipt in the editor of a selection of a second template and an instruction to wire the second template to the template, to enforce a security restriction with respect to at least one of the templates.

13. The apparatus as described in claim 8 wherein the set of templates presented in the editor is based at least in part on one of: the application being deployed, availability of security software in the cloud application environment, and one or more properties of middleware in the cloud application environment.

14. The apparatus as described in claim 8 wherein the computer program instructions further include:

program code operative in response to receipt in the editor of a query with details about the application being deployed, to provide information about one or more available security resources appropriate for the application.

15. A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions executed by the data processing system to provide context-based security assurance in a cloud application environment, the computer program instructions comprising:

program code, operative as an application is being deployed in the cloud application environment, to present a set of templates in an editor, wherein a template is pre-defined and includes a security assurance level that is specified by a set of general security requirements that have been discovered for the cloud application environment in an automated manner, at least one of the set of general security requirements being specified in a manner that does not expose at least some specific security tooling requirements necessary to implement the security assurance level security requirement;

program code, operative in response to receipt of a selection of a template, and based at least in part on a security context of the deployment, to automatically apply configuration changes, via automation, to a set of security resources present in the cloud application environment to create a cloud application zone, the set of security resources including the at least one specific tooling requirement necessary to implement the security assurance level security requirement, the configuration changes including one of: a missing configuration, and a missing product; and

program code operative upon receipt of an indication that the set of security resources have been configured, to complete the deployment of the application into the cloud application zone.

16. The computer program product as described in claim 15 wherein the computer program instructions further include program code operative to receive information on a set of security capabilities available in the cloud application environment and, in response, to define the security context.

17. The computer program product as described in claim 15 wherein the set of templates are provided to an end user via user interface tooling associated with the cloud application environment.

18. The computer program product as described in claim 15 wherein the set of security resources are configured remotely via a REST-based interface.

19. The computer program product as described in claim 15 wherein the computer program instructions further include:

program code operative in response to receipt in the editor of a selection of a second template and an instruction to wire the second template to the template, to enforce a security restriction with respect to at least one of the templates.

20. The computer program product as described in claim 15 wherein the set of templates presented in the editor is based at least in part on one of: the application being deployed, availability of security software in the cloud application environment, and one or more properties of middleware in the cloud application environment.

21. The computer program product as described in claim 15 wherein the computer program instructions further include:

program code operative in response to receipt in the editor of a query with details about the application being deployed, to provide information about one or more available security resources appropriate for the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2014
From: NAGARATNAM, NATARAJ; HOY, JEFFREY ROBERT; IYER, SREEKANTH RAMAKRISHNA; MUPPIDI, SRIDHAR R.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 034276/0430 →
Continuity (1)
Related Publication 20160156662A1 · Jun 2, 2016