发明名称 REMEDIATION OF KNOWN DEFECTS AND VULNERABILITIES IN CLOUD APPLICATION PACKAGES
摘要 A method for applying remediation policy to a cloud application package having a set of components is described. The method is initiated in response to discovery of a new vulnerability. It begins by comparing information from a deployment description against a data set of known problems associated with the one or more of the components. The deployment description represents the set of components and their interrelationships. For each of the one or more components, one or more known problems that satisfy a given severity and/or complexity criteria are identified. Thereafter, and with respect to at least one of the components for which one known problem satisfying the given criteria has been identified, the remediation policy (e.g., an update, a replacement, a patch, an additional installable) is applied to attempt to rectify the known problem. After applying the policy, the old version of the package is replaced with the new version.
申请公布号 US2015356000(A1) 申请公布日期 2015.12.10
申请号 US201414300364 申请日期 2014.06.10
申请人 International Business Machines Corporation 发明人 Giammaria Alberto;Peters Christopher Andrew;Spatzier Thomas
分类号 G06F11/36;G06F9/44;H04L29/08 主分类号 G06F11/36
代理机构 代理人
主权项
地址 Armonk NY US