CA3070593A1 - Remediation automatique de cybersecurite au niveau d'une entreprise - Google Patents

Remediation automatique de cybersecurite au niveau d'une entreprise

Info

Publication number
CA3070593A1
CA3070593A1 CA3070593A CA3070593A CA3070593A1 CA 3070593 A1 CA3070593 A1 CA 3070593A1 CA 3070593 A CA3070593 A CA 3070593A CA 3070593 A CA3070593 A CA 3070593A CA 3070593 A1 CA3070593 A1 CA 3070593A1
Authority
CA
Canada
Prior art keywords
remediation
generated
orchestration
response
enterprise
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
CA3070593A
Other languages
English (en)
Inventor
Ernesto Digiambattista
Andrei Bezdedeanu
Michael D. KAIL
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Harness Inc
Original Assignee
ZeroNorth Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US15/658,022 external-priority patent/US10277622B2/en
Application filed by ZeroNorth Inc filed Critical ZeroNorth Inc
Publication of CA3070593A1 publication Critical patent/CA3070593A1/fr
Abandoned legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
    • G06F21/12Protecting executable software
    • G06F21/121Restricting unauthorised execution of programs
    • G06F21/125Restricting unauthorised execution of programs by manipulating the program code, e.g. source code, compiled code, interpreted code, machine code
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Technology Law (AREA)
  • Multimedia (AREA)
  • Computing Systems (AREA)
  • Stored Programmes (AREA)
  • Storage Device Security (AREA)

Abstract

La présente invention concerne la détection et la remédiation automatiques de menaces de cybersécurité dans une installation de technologie de l'information. Une installation de technologie de l'information reçoit, au niveau d'un système d'orchestration, une mise à jour demandée qui peut comprendre un changement de configuration, un changement de code, un changement en binaire ou un autre changement dans l'installation. Une instance en miroir de l'installation est instanciée sur une infrastructure en nuage où la mise à jour demandée est appliquée et parcourue pour détecter des menaces de cybersécurité. Lorsque des menaces de cybersécurité sont détectées, une réponse de remédiation est identifiée. La mise à jour et la réponse de remédiation peuvent être envoyées à un administrateur pour acceptation avant le déploiement en production, ou peuvent être déployées automatiquement, avec des informations de retour en arrière générées au cas où l'administrateur souhaiterait annuler le déploiement. Des informations sur l'acceptation ou le rejet, par un administrateur, d'une mise à jour et/ou d'une remédiation sont stockées dans une base de données de communauté pour aider d'autres personnes à évaluer la mise à jour et/ou la remédiation pour leur utilisation.
CA3070593A 2017-07-21 2018-07-16 Remediation automatique de cybersecurite au niveau d'une entreprise Abandoned CA3070593A1 (fr)

Applications Claiming Priority (5)

Application Number Priority Date Filing Date Title
US201762535780P 2017-07-21 2017-07-21
US62/535,780 2017-07-21
US15/658,022 2017-07-24
US15/658,022 US10277622B2 (en) 2015-07-13 2017-07-24 Enterprise level cybersecurity automatic remediation
PCT/US2018/042357 WO2019018316A1 (fr) 2017-07-21 2018-07-16 Remédiation automatique de cybersécurité au niveau d'une entreprise

Publications (1)

Publication Number Publication Date
CA3070593A1 true CA3070593A1 (fr) 2019-01-24

Family

ID=65015699

Family Applications (1)

Application Number Title Priority Date Filing Date
CA3070593A Abandoned CA3070593A1 (fr) 2017-07-21 2018-07-16 Remediation automatique de cybersecurite au niveau d'une entreprise

Country Status (3)

Country Link
EP (1) EP3639130A1 (fr)
CA (1) CA3070593A1 (fr)
WO (1) WO2019018316A1 (fr)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11588847B2 (en) 2020-12-15 2023-02-21 International Business Machines Corporation Automated seamless recovery
CN112699041B (zh) * 2021-01-04 2024-03-26 中车青岛四方车辆研究所有限公司 一种嵌入式软件自动部署方法、系统及设备

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110126197A1 (en) * 2009-11-25 2011-05-26 Novell, Inc. System and method for controlling cloud and virtualized data centers in an intelligent workload management system
WO2016049376A1 (fr) * 2014-09-24 2016-03-31 Oracle International Corporation Système et procédé de prise en charge de corrections dans un environnement de serveur d'applications partagées

Also Published As

Publication number Publication date
EP3639130A1 (fr) 2020-04-22
WO2019018316A1 (fr) 2019-01-24

Similar Documents

Publication Publication Date Title
US10277622B2 (en) Enterprise level cybersecurity automatic remediation
US11121872B2 (en) Trusted verification of cybersecurity remediation
US11539748B2 (en) Monitoring and reporting enterprise level cybersecurity remediation
US11063983B2 (en) Componentized security policy generation
US10148752B2 (en) Enterprise level security orchestration
US10817410B2 (en) Application programming interface for providing access to computing platform definitions
US9354865B2 (en) System and method for controlling the development of a software application
US10469315B2 (en) Using computing platform definitions to provide segmented computing platforms in a computing system
US10284634B2 (en) Closed-loop infrastructure orchestration templates
US11748487B2 (en) Detecting a potential security leak by a microservice
US12032461B2 (en) Software upgrade stability recommendations
US11150895B1 (en) Automatically deploying artifacts
US10936468B1 (en) System and method of automatic software release termination based on customized reporting static code analysis
US20200073763A1 (en) Auto point in time data restore for instance copy
US11151025B1 (en) Generating software test plans based at least in part on monitored traffic of a production application
US20120130702A1 (en) Verification of a computer program in respect to an unexpected response to an access request
US10394793B1 (en) Method and system for governed replay for compliance applications
AU2017276243B2 (en) System And Method For Generating Service Operation Implementation
CA3070593A1 (fr) Remediation automatique de cybersecurite au niveau d'une entreprise
US20220147657A1 (en) Data inspection system and method
US20240289745A1 (en) Systems, methods, and computer readable media for operationalizing sbom content and providing sbom analysis
Day Cloud-Based Software
Day Cloud-Based Software: Virtualization and containers
Selvaraj Advanced DevOps and Infrastructure Automation
Meyler et al. System Center 2012 Operations Manager Unleashed

Legal Events

Date Code Title Description
EEER Examination request

Effective date: 20200120

FZDE Discontinued

Effective date: 20220301