Proactively determining security risks and deployment impacts across cloud computing environments
This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and/or automatically modify the candidate changes to eliminate security vulnerabilities.
1 . A computer-implemented method for preventing resource breaches in a cloud computing system, comprising:
receiving a cloud resource deployment request to deploy a candidate code-based infrastructure change in a cloud infrastructure environment;
generating a security map of a target portion of the cloud infrastructure environment that indicates security information of nodes and edges within the target portion;
based on determining that the cloud resource deployment request corresponds to the target portion, generating a candidate security map by merging security information from the candidate code-based infrastructure change into the security map;
determining a security risk based on performing a security pattern analysis on one or more pattern-based data structures generated from the candidate security map; and
based on determining the security risk:
deploying changes from the candidate code-based infrastructure change to the cloud infrastructure environment; or
preventing the cloud resource deployment request from deploying in the cloud infrastructure environment.
2 . The computer-implemented method of claim 1 , wherein performing the security pattern analysis includes performing a what-if analysis on the candidate security map that provides expected impacts of implementing the candidate code-based infrastructure change.
3 . The computer-implemented method of claim 1 , further comprising:
determining a target resource within the cloud resource deployment request;
identifying the target resource within the target portion of the cloud infrastructure environment, wherein the target portion corresponds to a target tenant of the cloud infrastructure environment; and
obtaining the security map for the target portion, wherein the security map is a subset of a target tenant security map.
4 . The computer-implemented method of claim 3 , wherein the security map is stored as a table in a security database.
5 . The computer-implemented method of claim 1 , wherein merging the security information from the candidate code-based infrastructure change into the security map includes:
identifying target cloud resources and surrounding target cloud resources affected by a change within the candidate code-based infrastructure change;
identifying the changes from the candidate code-based infrastructure change to the target cloud resources and the surrounding target cloud resources; and
generating the candidate security map to indicate updated security information to the nodes and the edges within the target portion based on the changes.
6 . The computer-implemented method of claim 1 , wherein determining the security risk includes comparing pattern-based data structures from the security map to the one or more pattern-based data structures generated from the candidate security map to determine changes in the security information.
7 . The computer-implemented method of claim 1 , wherein performing the security pattern analysis includes:
comparing a set of known resource vulnerability patterns to the one or more pattern-based data structures; and
identifying a match between a resource vulnerability pattern of the set of known resource vulnerability patterns and the one or more pattern-based data structures.
8 . The computer-implemented method of claim 1 , further comprising providing a security threat notification based on determining that the security risk meets a security threat threshold.
9 . The computer-implemented method of claim 8 , wherein:
the security threat threshold is based on a current threat level of a subscription identifier or a tenant identifier associated with the target portion of the cloud infrastructure environment; and
the security threat threshold is met based on the one or more pattern-based data structures generated from the candidate security map having a threat level above the current threat level.
10 . The computer-implemented method of claim 8 , wherein the security threat threshold is met based on the one or more pattern-based data structures generated from the candidate security map having a critical breach threat level.
11 . The computer-implemented method of claim 1 , wherein the cloud resource deployment request is received from an administrator device, a client device associated with a developer, or a recommendation system.
12 . The computer-implemented method of claim 1 , wherein the cloud resource deployment request is provided as a code-based infrastructure file with corresponding parameters.
13 . The computer-implemented method of claim 1 , wherein the security information of a node includes security contexts and security risks of the node.
14 . The computer-implemented method of claim 1 , further comprising:
receiving an additional cloud resource deployment request;
based on determining that the additional cloud resource deployment request corresponds to the target portion, generating an additional candidate security map from additional security information in the additional cloud resource deployment request;
determining that the additional cloud resource deployment request includes a low-security risk based on performing the security pattern analysis with the candidate security map; and
deploying the additional cloud resource deployment request in the cloud infrastructure environment based on the low-security risk.
15 . A system for preventing resource breaches in a cloud computing system comprising:
a processing system having a processor; and
a computer memory including instructions that, when executed by the processing system, cause the system to carry out operations comprising:
receiving a candidate code-based infrastructure change for changing resources in a cloud infrastructure environment;
generating a security map of a target portion of the cloud infrastructure environment;
generating a candidate security map by merging security information from the candidate code-based infrastructure change into the security map of the target portion;
determining a security risk based on performing a security pattern analysis on a pattern-based data structure generated from the candidate security map; and
based on determining the security risk;
deploying changes from the candidate code-based infrastructure change to the cloud infrastructure environment; or
providing a security notification indicating that deploying the candidate code-based infrastructure change will result in a negative change to a security risk profile.
16 . The system of claim 15 , wherein the security risk introduces a new vulnerability into the cloud infrastructure environment if the candidate code-based infrastructure change is implemented.
17 . The system of claim 15 , wherein the security risk violates a best practices policy of the cloud infrastructure environment if the candidate code-based infrastructure change is implemented.
18 . The system of claim 15 , further comprising generating the pattern-based data structure from the candidate security map into a pattern-based data structure by converting a portion of the candidate security map into a format that is compatible with performing the security pattern analysis.
19 . A non-transitory computer-readable storage medium comprising instructions that, when executed by a processor, cause a computer device to carry out operations comprising:
receiving a cloud resource deployment request with a candidate code-based infrastructure change for changing resources within a cloud infrastructure environment;
generating a security map of a target portion of the cloud infrastructure environment that indicates security information of nodes and edges within the target portion;
based on determining that the cloud resource deployment request corresponds to the target portion, generating a candidate security map by:
identifying target cloud resources and surrounding target cloud resources affected by a change within the candidate code-based infrastructure change;
identifying changes from the candidate code-based infrastructure change to the target cloud resources and the surrounding target cloud resources; and
generating the candidate security map to indicate updated security information to the nodes and the edges within the target portion based on the changes;
determining a security risk based on performing a security pattern analysis on one or more pattern-based data structures generated from the candidate security map; and
based on determining the security risk:
deploying the changes from the candidate code-based infrastructure change to the cloud infrastructure environment; or
preventing the cloud resource deployment request from deploying in the cloud infrastructure environment.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein performing the security pattern analysis includes:
comparing a set of known resource vulnerability patterns to the one or more pattern-based data structures; and
identifying a match between a resource vulnerability pattern of the set of known resource vulnerability patterns and the one or more pattern-based data structures.