AU2015244114B2

Method and system for providing security aware applications

Abstract

Instructions for monitoring and detecting one or more trigger events in assets used to implement an application are generated. Instructions for implementing at least one responsive action associated with each of the one or more trigger events is generated. At least part of instructions for monitoring and detecting the one or more trigger events is provided to an asset used to implement the application. The at least part of the instructions for monitoring and detecting the one or more trigger events are used by the asset to detect a trigger event. The instructions for implementing the at least one responsive action associated with each of the one or more trigger events is then used to automatically implement the at least one responsive action associated with the detected trigger event.

AU2015244114B2, drawing sheet 1
Sheet 1 of 4

Term

8.5 yearsleft in the term

Expires 6 April 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

10 claims: 2 independent, 8 dependent

  1. 1
    THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A system for providing security aware applications that can self-monitor and selfalarm, or respond, to various security vulnerabilities and breach events, the system comprising: an application;a production environment for implementing the application;one or more assets used to implement the application in the production environment, wherein the production environment comprises a first trusted computing environment including the application and a second untrusted computing environment including the one or more assets;data for monitoring and detecting one or more trigger events in one of more of the assets used to implement the application in the production environment;data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events upon detection of the one or more trigger events in one of more of the assets used to implement the application in the production environment;at least one processor;and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for providing security aware applications, the process for providing security aware applications including: providing at least part of the data for monitoring and detecting the one or more trigger events to at least one asset used to implement the application in the production environment;using the at least part of the data for monitoring and detecting the one or more trigger events to detect a trigger event involving the at least one asset;and using the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events to automatically implement the at least one responsive action associated with the detected trigger event.
  2. 2
    The system for providing security aware applications of Claim 1 wherein the data for monitoring and detecting the one or more trigger events and the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events is provided by providing a security policy library to the application, and/or one or more assets used to implement the application. -702015244114 29 Oct 2019
  3. 3
    The system for providing security aware applications of Claim 2 wherein the data for monitoring and detecting the one or more trigger events and the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events is provided through a virtual asset creation template used to instantiate the at least one virtual asset used to implement the application in the production environment.
  4. 4
    The system for providing security aware applications of Claim 1 wherein at least one of the defined trigger events is selected from the group of trigger events consisting of:a change in software associated with the application, and/or an asset used to implement the application;a change in a software stack associated with the application, and/or an asset used to implement the application;the receipt of one or more defined commands by the application, and/or an asset used to implement the application;a change in a deployment pattern associated with the application, and/or an asset used to implement the application;a change in a communications channel associated with the application, and/or an asset used to implement the application;a change in a communications channel configuration associated with the application, and/or an asset used to implement the application;a deviation from an expected communications traffic pattern associated with the application, and/or an asset used to implement the application;a geo-location of the recipient of communications traffic associated with the application, and/or an asset used to implement the application;a geo-location of the originator of communications traffic associated with the application, and/or an asset used to implement the application;a change in a pattern of wireless communications associated with the application, and/or an asset used to implement the application;a change in a phone number associated with communications associated with the application, and/or an asset used to implement the application;a change in a user ID associated with a user of the application, and/or an asset used to implement the application;a change in the profile of a user associated with the application, and/or an asset used to implement the application;a change in a periodic event associated with the application, and/or an asset used to implement the application;and -71 2015244114 29 Oct 2019 a deviation from any defined expected normal operations parameter associated with the application, and/or an asset used to implement the application.
  5. 5
    The system for providing security aware applications of Claim 1 wherein at least one of the defined responsive actions is selected from the group of responsive actions consisting of:notifying a party or entity of the detected trigger event;disabling one or more operations performed by the application, and/or an asset used to implement the application, until one or more required actions have taken place;permanently disabling one or more operations performed by the application, and/or an asset used to implement the application;disabling one or more communications channels associated with the application, and/or an asset used to implement the application, until one or more required actions have taken place;permanently disabling one or more communications channels associated with the application, and/or an asset used to implement the application;blocking a portion of communications traffic associated with the application, and/or an asset used to implement the application, until one or more required actions have taken place;permanently blocking a portion of communications traffic associated with the application, and/or an asset used to implement the application;disabling the application, and/or an asset used to implement the application, until one or more required actions have taken place;permanently disabling the application, and/or an asset used to implement the application, until one or more required actions have taken place;obtaining data from the application, and/or an asset used to implement the application, before disabling the application, and/or an asset used to implement the application;and directing a transfer of data from the application, and/or an asset used to implement the application, to a location outside the application, and/or an asset used to implement the application, before disabling the application, and/or an asset used to implement the application.
  6. 6
    The system for providing security aware applications of Claim 1 wherein the at least one asset used to implement the application is a virtual asset selected from the group of the virtual assets consisting of:a virtual machine;a virtual server;-722015244114 29 Oct 2019 a database or data store;an instance in a cloud environment;a cloud environment access system;part of a mobile device;part of a remote sensor;part of a server computing system;and part of a desktop computing system.
  7. 7
    The system for providing security aware applications of Claim 1 wherein the data representing instructions for monitoring and detecting the one or more trigger events in an asset and the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events is provided by the owner of the application.
  8. 8
    The system for providing security aware applications of Claim 1 wherein the data representing instructions for monitoring and detecting the one or more trigger events in an asset and the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events is provided by a provider of at least part of a production environment in which the application is implemented.
  9. 9
    The system for providing security aware applications of Claim 1 wherein the data representing instructions for monitoring and detecting the one or more trigger events in an asset and the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events is provided by a third party service provider.
  10. 10
    A method for providing security aware applications in a system comprising:an application;a production environment for implementing the application;one or more assets used to implement the application in the production environment, the production environment comprising a first trusted computing environment including the application and a second untrusted computing environment including the one or more assets;data for monitoring and detecting one or more trigger events in one of more of the assets used to implement the application in the production environment;and data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events upon detection of the one or more trigger events in one of more of the assets used to implement the application in the production environment;the method comprising: -73 2015244114 29 Oct 2019 providing at least part of the data for monitoring and detecting the one or more trigger events to at least one asset used to implement the application in the production environment;using the at least part of the data for monitoring and detecting the one or more trigger events to detect a trigger event involving the at least one asset;and using the data representing instructions for implementing the at least one responsive action associated with each of the one or more trigger events to automatically implement the at least one responsive action associated with the detected trigger event.