IP Library Granted Patent US 12,204,637
Granted Patent B2
US 12,204,637 · App. 17/209,603 · Granted Jan 21, 2025

Compliance profiling

Inventors: Shripad Nadgowda (Elmsford, NY); Fabio Abreu Oliveira (White Plains, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/52G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,637
App. No.
17/209,603
Granted
Jan 21, 2025
Kind
B2
Abstract

A computer implemented method for compliance profiling, the method comprising creating an application security profile indicating a set of permissions enabled for a corresponding application, associating one or more source files corresponding to the application to a running workload, executing the running workload, capturing a workload security profile with respect to one or more operations executed by the running workload, wherein the workload security profile indicates a set of permissions utilized by the running workload, comparing the workload security profile and the application security profile to identify one or more differences, and recommending a change to the application security profile according to the identified one or more differences.

Claims (39)

1. A computer implemented method for continuous compliance profiling, the method comprising:

creating an application security profile indicating a set of permissions enabled for an application, comprising identifying and analyzing source artifacts corresponding to the application within repositories;

associating an already running workload with one or more source files of the application;

executing the already running workload;

capturing a workload security profile with respect to one or more operations executed by the already running workload, wherein the workload security profile indicates a set of permissions utilized by the running workload;

continuously comparing the workload security profile of the already running workload and the application security profile to identify one or more differences; and

recommending a change to the application security profile according to the identified one or more differences.

2. The computer implemented method of claim 1 , further comprising altering the application security profile according to the recommended change.

3. The computer implemented method of claim 1 , further comprising mapping the application security profile to one or more security standards.

4. The computer implemented method of claim 1 , further comprising monitoring the running workload to identify one or more executed operations with respect to the running workload.

5. The computer implemented method of claim 4 , wherein capturing a workload security profile includes identifying one or more privileges required for the one or more executed operations to properly execute.

6. The computer implemented method of claim 2 , further comprising adjusting one or more security standard compliances according to the altered application security profile.

7. A computer program product for, the computer program product comprising:

one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising instructions to:

create an application security profile indicating a set of permissions enabled for an application, comprising identifying and analyzing source artifacts corresponding to the application within repositories;

associate an already running workload with one or more source files of the application;

execute the already running workload;

capture a workload security profile with respect to one or more operations executed by the already running workload, wherein the workload security profile indicates a set of permissions utilized by the already running workload;

continuously compare the workload security profile of the already running workload and the application security profile to identify one or more differences; and

recommend a change to the application security profile according to the identified one or more differences.

8. The computer program product of claim 6 , further comprising instructions to alter the application security profile according to the recommended change.

9. The computer program product of claim 6 , further comprising instructions to map the application security profile to one or more security standards.

10. The computer program product of claim 6 , further comprising instructions to monitor the running workload to identify one or more executed operations with respect to the running workload.

11. The computer program product of claim 10 , wherein instructions to capture a workload security profile include instructions to identify one or more privileges required for the one or more executed operations to properly execute.

12. The computer program product of claim 7 , further comprising instructions to adjust one or more security standard compliances according to the altered application security profile.

13. A computer system for, the computer system comprising:

one or more computer processors;

one or more computer-readable storage media;

program instructions stored on the computer-readable storage media for execution by at least one of the one or more processors, the program instructions comprising instructions to:

create an application security profile indicating a set of permissions enabled for an application, comprising identifying and analyzing source artifacts corresponding to the application within repositories;

associate an already running workload with one or more source files of the application;

execute the already running workload;

capture a workload security profile with respect to one or more operations executed by the already running workload, wherein the workload security profile indicates a set of permissions utilized by the already running workload;

continuously compare the workload security profile of the already running workload and the application security profile to identify one or more differences; and

recommend a change to the application security profile according to the identified one or more differences.

14. The computer system of claim 13 , further comprising instructions to alter the application security profile according to the recommended change.

15. The computer system of claim 13 , further comprising instructions to map the application security profile to one or more security standards.

16. The computer system of claim 13 , further comprising instructions to monitor the running workload to identify one or more executed operations with respect to the running workload.

17. The computer system of claim 16 , wherein instructions to capture a workload security profile include instructions to identify one or more privileges required for the one or more executed operations to properly execute.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: NADGOWDA, SHRIPAD; OLIVEIRA, FABIO ABREU
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055685/0402 →
Continuity (1)
Related Publication 20220309149A1 · Sep 29, 2022
References Cited (20)
US 9665465B1 · Jain · 2017 [cited by applicant]
US 10200358B2 · Lander · 2019 [cited by applicant]
US 10454934B2 · Parimi · 2019 [cited by applicant]
US 10574513B2 · Nagarajan · 2020 [cited by applicant]
US 10586042B2 · Stopel · 2020 [cited by applicant]
US 10803166B1 · Terkowitz · 2020 [cited by applicant]
US 20130263206A1 · Nefedov · 2013 [cited by examiner]
US 20180004936A1 · Bender · 2018 [cited by examiner]
US 20190318100A1 · Bhatia · 2019 [cited by examiner]
US 20200326931A1 · Nadgowda · 2020 [cited by applicant]
US 20210211445A1 · Albero · 2021 [cited by examiner]
Dai et al., “Data Profiling Technology of Data Governance Regarding Big Data: Review and Rethinking”, printed on Feb. 18, 2021, 13 pages. [cited by applicant]
Disclosed Anonymously, “Context-aware VM and application adaptation”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000239592D, IP.com Electronic Publication Date: Nov. 18, 2014, 6 pages. [cited by applicant]
Disclosed Anonymously, “Method and system for policy based security and compliance management for cloud environments”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000220537D, IP.com Electronic Pub… [cited by applicant]
Disclosed Anonymously, “Workload Discovery and Recommendations for Cloud Migration with AI”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000263649D, IP.com Electronic Publication Date: Sep. 23, 20… [cited by applicant]
Hassan et al., “Microservice transition and its granularity problem: A systematic mapping study”, Survey Paper, Wiley, Accepted: May 17, 2020, 31 pages. [cited by applicant]
Hwang et al., “Shift-Left Security Risk Analysis”, U.S. Appl. No. 17,249,997, Filed on Mar. 22, 2021, 33 pages. [cited by applicant]
Raesene, “Docker Capabilities and no new-privileges”, Jun. 1, 2019, 3 pages, <https://raesene.github.io/blog/2019/06/01/docker-capabilities-and-no-new-privileges>. [cited by applicant]
International Searching Authority, Patent Cooperation Treaty, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration, Date of … [cited by applicant]
“Compliance Profiling”, European Application No. EP2022/056729, IBM Docket No. P202009704PCT01, filed on Mar. 15, 2022, 17 pages. [cited by applicant]