Modeling application dependencies to identify operational risk

US11863580B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11863580-B2
Application numberUS-202017133466-A
CountryUS
Kind codeB2
Filing dateDec 23, 2020
Priority dateMay 31, 2019
Publication dateJan 2, 2024
Grant dateJan 2, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for managing security in a cloud computing environment are provided. Exemplary methods include: gathering data about workloads and applications in the cloud computing environment; updating a graph database using the data, the graph database representing the workloads of the cloud computing environment as nodes and relationships between the workloads as edges; receiving a security template, the security template logically describing targets in the cloud computing environment to be protected and how to protect the targets; creating a security policy using the security template and information in the graph database; and deploying the security policy in the cloud computing environment.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for modeling application dependencies to identify operational risk, the method comprising: gathering, by a processor, data about applications and computing systems in a cloud computing environment or in an enterprise datacenter; updating, by the processor, a graph database using the data including the graph database representing relationships as mapped between the applications in the cloud computing environment or in the enterprise datacenter; using logic to analyze, by the processor, the data in the graph database to identify, based on the relationships, operational mismatches as mapped between operational requirements set for at least one application of the applications and operational requirements set for at least one further application of the applications in the cloud computing environment or in the enterprise datacenter; deploying, by the processor, an alert for the identified operational mismatches; creating an operations policy based on a difference between a recovery time objective and the recovery time objective on a dependent system; and validating the operations policy by simulating the operations policy using the graph database, the validating the operations policy comprising: determining a level of entropy in the cloud computing environment; and determining a reliability score and at least one recommendation for the operations policy based on the level of entropy. 2. The computer-implemented method of claim 1 , wherein the data further comprises common metadata. 3. The computer-implemented method of claim 2 , wherein the common metadata further comprises compliance information. 4. The computer-implemented method of claim 3 , wherein the compliance information further comprises operational service level objectives. 5. The computer-implemented method of claim 4 , wherein the operational service level objectives comprise a recovery point objective. 6. The computer-implemented method of claim 5 , further comprising creating the operations policy based on a difference between the recovery point objective and the recovery point objective on a dependent system. 7. The computer-implemented method of claim 6 , wherein the operations policy is based on a predetermined amount of minimum operational risk. 8. The computer-implemented method of claim 7 , wherein the operations policy is based on a predetermined amount of maximum operational risk. 9. The computer-implemented method of claim 5 , wherein the creating the operations policy includes: identifying targets in the cloud computing environment or in the enterprise datacenter in the graph database using labels associated with an operations template. 10. The computer-implemented method of claim 1 , wherein the cloud computing environment is hosted by a plurality of different cloud services, the different cloud services being at least one of a public cloud, private cloud, and on-premise data center. 11. The computer-implemented method of claim 10 , further comprising determining operational risk throughout the plurality of the different cloud services. 12. A system for modeling application dependencies to identify operational risk, the system comprising: a processor; and a memory communicatively coupled to the processor, the memory storing instructions executable by the processor to perform a method comprising: gathering, by a processor, data about applications and computing systems in a cloud computing environment or in an enterprise datacenter; updating a graph database using the data, the graph database representing relationships as mapped between the applications in the cloud computing environment or in the enterprise datacenter; using logic to analyze the data in the graph database to identify, based on the relationships, operational mismatches as mapped between operational requirements set for at least one application of the applications and operational requirements set for at least one further application of the applications in the cloud computing environment or in the enterprise datacenter; deploying an alert for the identified operational mismatches; creating an operations policy based on a difference between a recovery time objective and the recovery time objective on a dependent system; and validating the operations policy by simulating the operations policy using the graph database, the validating the operations policy comprising: determining a level of entropy in the cloud computing environment; and determining a reliability score and at least one recommendation for the operations policy based on the level of entropy. 13. The system of claim 12 , wherein the data further comprises common metadata. 14. The system of claim 13 , wherein the common metadata further comprises compliance information. 15. The system of claim 14 , wherein the compliance information further comprises operational service level objectives. 16. The system of claim 12 , wherein the alert further comprises a human readable pdf file. 17. The system of claim 12 , wherein the alert further comprises a machine readable image. 18. The system of claim 12 , wherein the alert is deployed via an application programming interface.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Event management; Broadcasting; Multicasting; Notifications · CPC title

  • Updates performed during online database operations; commit processing · CPC title

  • Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11863580B2 cover?
Methods and systems for managing security in a cloud computing environment are provided. Exemplary methods include: gathering data about workloads and applications in the cloud computing environment; updating a graph database using the data, the graph database representing the workloads of the cloud computing environment as nodes and relationships between the workloads as edges; receiving a sec…
Who is the assignee on this patent?
Varmour Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 02 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).