IP Library Granted Patent US 10,686,809
Granted Patent B2
US 10,686,809 · App. 16/404,236 · Granted Jun 16, 2020

Data protection in a networked computing environment

Inventors: Gregory J. Boss (Saginaw, MI); Rick A. Hamilton, II (Charlottesville, VA); Jeffrey R. Hoy (Gibsonia, PA); Agueda M. H. Magro (Zapopan, MX)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/1416G06F21/554G06F21/577H04L63/1433H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,809
App. No.
16/404,236
Granted
Jun 16, 2020
Kind
B2
Abstract

Approaches for providing data protection in a networked computing environment are provided. A method includes detecting, by at least one computer device, a breach of a first system in the networked computing environment. The method also includes generating, by the at least one computer device, a second system in the networked computing environment, wherein the second system includes a patch based on the breach. The method additionally includes converting, by the at least one computer device, the first system to a decoy system. The method further includes generating, by the at least one computer device, a third system in the networked computing environment, wherein the third system has reduced security relative to the first system.

Claims (43)

1. A method of providing data protection in a networked computing environment, comprising:

detecting, by at least one computer device, a breach of a first system in the networked computing environment;

in response to the detecting of the breach of the first system, generating, by the at least one computer device, a second system in the networked computing environment, wherein the second system includes a database which includes a scrambled version of low value data and a patch which is a configuration update applied to the database of the second system that eliminates a vulnerability exposed by the breach; and

converting, by the at least one computer device, the first system to a decoy system.

2. The method of claim 1 , wherein the generating the second system comprises:

determining a vulnerability that permitted the breach;

creating the patch to eliminate the vulnerability;

provisioning a new production server and a new production database in the networked computing environment; and

applying the patch to at least one of the new production server and the new production database.

3. The method of claim 1 , further comprising:

routing a client request for a service to the first system prior to the generating the second system; and

routing a client request for the service to the second system after the generating the second system.

4. The method of claim 1 , wherein:

the first system and the second system are physically separate; and

the first system in the networked computer environment comprises a first server and a first database and the second system in the networked computer environment comprises a second server and a second database.

5. The method of claim 1 , wherein the converting the first system to the decoy system comprises generating and adding decoy high value data to the database of the first system.

6. The method of claim 1 , wherein a service provider at least one of creates, maintains, deploys and supports the at least one computer device.

7. The method of claim 1 , wherein the detecting the breach, the generating the second system, and the converting the first system are provided by a service provider on a subscription, advertising, and/or fee basis.

8. The method of claim 1 , wherein the detecting the breach, the generating the second system, and the converting the first system are provided by software as a service in a cloud environment.

9. The method of claim 1 , wherein the configuration update mitigates the breach.

10. A computer program product for providing data protection in a networked computing environment, the computer program product comprising a computer readable storage device having program instructions embodied therewith, the program instructions being executable by a computer device to cause the computer device to:

detect a breach of a first production system in the networked computing environment;

in response to the detecting the breach of the first production system, generate a second production system in the networked computing environment, wherein the second production system includes a database which includes a scrambled version of low value data and a patch which is a configuration update applied to the database of the second system that eliminates a vulnerability exposed by the breach; and

convert the first production system to a decoy system,

wherein the scrambled version of the low value data is encrypted.

11. The computer program product of claim 10 , wherein the generating the second production system comprises:

determining a vulnerability that permitted the breach;

creating the patch to eliminate the vulnerability;

provisioning a new production server and a new production database in the networked computing environment; and

applying the patch to at least one of the new production server and the new production database.

12. The computer program product of claim 10 , the program instructions further being executable by the computer device to cause the computer device to:

route a client request for a service to the first production system prior to the generating the second production system; and

route a client request for the service to the second production system after the generating the second production system.

13. The computer program product of claim 10 , wherein:

the first production system and the second production system are physically separate; and

the first production system in the networked computer environment comprises a first server and a first database and the second production system in the networked computer environment comprises a second server and a second database.

14. The computer program product of claim 10 , wherein the converting the first production system to the decoy system comprises generating decoy high value data based on low value data contained in a database in the first production system; and storing the decoy high value data in the database.

15. The computer program product of claim 10 , wherein a service provider at least one of creates, maintains, deploys and supports the at least one computer device.

16. The computer program product of claim 10 , wherein the detecting the breach, the generating the second production system, and the converting the first production system are provided by a service provider on a subscription, advertising, and/or fee basis.

17. The computer program product of claim 10 , wherein the detecting the breach, the generating the second production system, and the converting the first production system are provided by software as a service in a cloud environment.

18. The method of claim 1 , wherein the low value data comprises non-confidential data.

19. The method of claim 18 , wherein the converting the first system to the decoy system comprises deleting high value data from the decoy system.

20. The method of claim 19 , wherein the high value data comprises confidential data and a decoy high value data is generated based on the low value data contained in a first database in the first system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2019
From: BOSS, GREGORY J.; HAMILTON, RICK A., II; HOY, JEFFREY R.; MAGRO, AGUEDA M.H.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 049093/0395 →
Continuity (3)
Continuation 15842131 · Dec 14, 2017
Continuation 14699218 · Apr 29, 2015
Related Publication 20190260774A1 · Aug 22, 2019
Cited By (7)
US 12,204,652 US 12,229,276 US 12,346,451 US 12,373,566 US 12,406,068 US 12,495,074 US 12,717,931