Insider attack resistant system and method for cloud services integrity checking

US10079844B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10079844-B2
Application numberUS-201715683129-A
CountryUS
Kind codeB2
Filing dateAug 22, 2017
Priority dateAug 13, 2015
Publication dateSep 18, 2018
Grant dateSep 18, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An insider attack resistant system for providing cloud services integrity checking is disclosed. In particular, the system utilizes an automated integrity checking script and virtual machines to check the integrity of a service. The system may utilize the integrity checking script and virtual machines to execute a set of operations associated with the service so as to check the integrity of the service. When executing the set of operations, the system may only have access to the minimum level of access to peripherals that is required for each operation in the set of operations to be executed. After each operation is executed, the system may log each result for each operation, and analyze each result to determine if a failure exists for any of the operations. If a failure exists, the system may determine that a change in an expected system behavior associated with the service has occurred.

First claim

Opening claim text (preview).

We claim: 1. A system, comprising: a memory that stores instructions; and a processor that executes the instructions to perform operations, the operations comprising: executing, during an integrity checking mode and by utilizing a virtual machine, a set of operations associated with a service to check an integrity of the service, wherein the set of operations are executed based on a minimum level of access to a peripheral that is required for each operation in the set of operations to be executed, wherein the minimum level of access is established by suspending access to a network port; executing, when the system is in a normal operation mode, the set of operations associated with the service based on a full level of access to the peripheral and the network port; and determining, if a failure of an operation in the set of operations exists, that a change in a system behavior associated with the service has occurred. 2. The system of claim 1 , wherein the operations further comprise logging each result for each operation in the set of operations after each operation is executed. 3. The system of claim 1 , wherein the operations further comprise analyzing, by utilizing the virtual machine, each result of each operation in the set of operations to determine if the failure of the operation in the set of operations exists. 4. The system of claim 1 , wherein the operations further comprise activating an integrity checking script during the integrity checking mode. 5. The system of claim 4 , wherein the operations further comprise determining if the integrity checking script is contaminated. 6. The system of claim 1 , wherein the operations further comprise outputting an alert in response to determining that the change in the system behavior associated with the service has occurred. 7. The system of claim 1 , wherein the operations further comprise performing an action to correct the change in the system behavior. 8. The system of claim 1 , wherein the operations further comprise performing an action to correct the failure. 9. The system of claim 1 , wherein the operations further comprise executing, by utilizing the virtual machine, a copy of the service. 10. The system of claim 1 , wherein the operations further comprise synchronizing a software-defined network script with an integrity checking script to impose the minimum level of access. 11. The system of claim 1 , wherein the operations further comprise determining that the service is functioning properly if the failure of the operation in the set of operations does not exist. 12. The system of claim 1 , wherein the operations further comprise determining if malware is affecting the service. 13. The system of claim 12 , wherein the operations further comprise removing, if the malware is affecting the service, the malware. 14. A method, comprising processing, during an integrity checking mode, a set of operations associated with a service to check an integrity of the service, wherein the set of operations are executed based on a minimum level of access to a peripheral that is required for each operation in the set of operations to be executed, wherein the minimum level of access is established by suspending access to a network port; processing, when the system is in a normal operation mode, the set of operations associated with the service based on a full level of access to the peripheral and the network port; and determining, if a failure of an operation in the set of operations exists, that a change in a behavior associated with the service has occurred, wherein the determining is performed by utilizing instructions from a memory that are executed by a processor. 15. The method of claim 14 , further comprising determining that the service is functioning properly if the failure of the operation in the set of operations does not exist. 16. The method of claim 14 , further comprising performing an action to correct the change in the system behavior. 17. The method of claim 14 , further comprising synchronizing a software-defined network script with an integrity checking script to impose the minimum level of access. 18. The method of claim 14 , further comprising logging each result for each operation in the set of operations after each operation is executed. 19. The method of claim 14 , further comprising deactivating a virtual machine processing the set of operations. 20. A computer-readable device comprising instructions, which when executed by a processor, cause the processor to perform operations comprising: launching, at a virtual machine and during an integrity checking mode, an integrity checking script for checking an integrity of the service; executing, by utilizing the virtual machine, a set of operations associated with a service to check the integrity of the service, wherein the set of operations are executed based on a minimum level of access to a peripheral that is required for each operation in the set of operations to be executed, wherein the minimum level of access is established by suspending access to a network port; executing, when the system is in a normal operation mode, the set of operations associated with the service based on a full level of access to the peripheral and the network port; and determining, if a failure of an operation in the set of operations exists, that a change in a system behavior associated with the service has occurred.

Assignees

Inventors

Classifications

  • G06F11/079Primary

    Root cause analysis, i.e. error or fault diagnosis (in a hardware test environment G06F11/22; in a software test environment G06F11/36) · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • Hypervisor-specific management and integration aspects · CPC title

  • in a virtual computing platform, e.g. logically partitioned systems · CPC title

  • Isolation or security of virtual machine instances · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10079844B2 cover?
An insider attack resistant system for providing cloud services integrity checking is disclosed. In particular, the system utilizes an automated integrity checking script and virtual machines to check the integrity of a service. The system may utilize the integrity checking script and virtual machines to execute a set of operations associated with the service so as to check the integrity of the…
Who is the assignee on this patent?
At & T Ip I Lp
What technology area does this patent fall under?
Primary CPC classification G06F11/079. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 18 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).