US2017078325A1PendingUtilityA1

Pre-processing system for minimizing application-level denial-of-service in a multi-tenant system

Assignee: IBMPriority: Jan 6, 2014Filed: Nov 22, 2016Published: Mar 16, 2017
Est. expiryJan 6, 2034(~7.4 yrs left)· nominal 20-yr term from priority
G06F 16/1744H04L 63/1416H04L 63/1425G06F 9/505H04L 2463/141H04L 63/1458
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Denial-of-service attacks are prevented or mitigated in a cloud compute environment, such as a multi-tenant, collaborative SaaS system. This is achieved by providing a mechanism by which characterization of “legitimate” behavior is defined for tenant applications or application classes, preferably along with actions to be taken in the event a request to execute an application is anticipated to exceed defined workflow limits. A set of application profiles are generated. Typically, a profile comprises information, such as a request defined by one or more request variables, one or more “constraints,” one or more “request mappings,” and one or more “actions.” A constraint is a maximum permitted workload for the application. A request mapping maps a request variable to the constraint, either directly or indirectly. The profile information defines how a request is mapped to a workload to determine whether the request is in policy or, if not, what action to take.

Claims

exact text as granted — not AI-modified
Having described our invention, what we claim is as follows: 
     
         1 . A method of minimizing application-level denial-of-service attacks with respect to compute resources in a multi-tenant shared infrastructure, the method comprising:
 profiling anticipated application behavior in response to one or more requests to generate an application profile having at least one workload constraint, the application profile including a mapping of a request type to a workload and a workload limit;   upon receipt of a request, and prior to execution, determining whether execution of the request satisfies the at least one workload constraint in the application profile by evaluating whether the request is predicted to result in a workload that exceeds the workload limit;   responsive to determining whether execution of the request satisfies the at least one workload constraint in the application profile, taking a given action;   wherein the steps are carried out in software executing in a hardware element.   
     
     
         2 . The method as described in  claim 1  wherein the given action is one of: throttling execution of the request, rejecting the request, and providing a given notification. 
     
     
         3 . The method as described in  claim 1  wherein determining whether execution of the request satisfies the at least one workload constraint allocates processing or storage in the multi-tenant shared infrastructure to simulate how execution of the request affects availability of the compute resources. 
     
     
         4 . The method as described in  claim 1  wherein the anticipated application behavior characterizes legitimate behavior for each of one or more tenant applications in the multi-tenant shared infrastructure. 
     
     
         5 . The method as described in  claim 4  wherein the anticipated application behavior is profiled as a machine-encoded data set. 
     
     
         6 . The method as described in  claim 1  wherein the determining step executes a number of application operations in a separate execution thread to determine if the number of application operations in the workload exceeds the workload limit. 
     
     
         7 . Apparatus, comprising:
 a processor;   computer memory holding computer program instructions that when executed by the processor minimize application-level denial-of-service with respect to compute resources in a multi-tenant shared infrastructure, the computer program instructions comprising:
 program code to profile anticipated application behavior in response to one or more requests to generate an application profile having at least one workload constraint, the application profile including a mapping of a request type to a workload and a workload limit; 
 program code operative upon receipt of a request, and prior to execution, to determine whether execution of the request satisfies the at least one workload constraint in the application profile by evaluating whether the request is predicted to result in a workload that exceeds the workload limit; and 
 program code, responsive to determining whether execution of the request satisfies the at least one workload constraint in the application profile, to take a given action. 
   
     
     
         8 . The apparatus as described in  claim 7  further including program to take that given action that is one of: throttling execution of the request, rejecting the request, and providing a given notification. 
     
     
         9 . The apparatus as described in  claim 7  wherein the program code to determine whether execution of the request satisfies the at least one workload constraint includes program code to allocate processing or storage in the multi-tenant shared infrastructure to simulate how execution of the request affects availability of the compute resources. 
     
     
         10 . The apparatus as described in  claim 7  wherein the anticipated application behavior characterizes legitimate behavior for each of one or more tenant applications in the multi-tenant shared infrastructure. 
     
     
         11 . The apparatus as described in  claim 10  wherein the anticipated application behavior is profiled as a machine-encoded data set. 
     
     
         12 . The apparatus as described in  claim 7  wherein the program code to evaluate executes a number of application operations in a separate execution thread to determine if the number of application operations in the workload exceeds the workload limit. 
     
     
         13 . A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, minimize application-level denial-of-service with respect to compute resources in a multi-tenant shared infrastructure, the computer program instructions comprising:
 program code to profile anticipated application behavior in response to one or more requests to generate an application profile having at least one workload constraint, the application profile including a mapping of a request type to a workload and a workload limit;   program code operative upon receipt of a request, and prior to execution, to determine whether execution of the request satisfies the at least one workload constraint in the application profile by evaluating whether the request is predicted to result in a workload that exceeds the workload limit; and   program code, responsive to determining whether execution of the request satisfies the at least one workload constraint in the application profile, to take a given action.   
     
     
         14 . The computer program product as described in  claim 13  further including program to take that given action that is one of: throttling execution of the request, rejecting the request, and providing a given notification. 
     
     
         15 . The computer program product as described in  claim 13  wherein the program code to determine whether execution of the request satisfies the at least one workload constraint includes program code to allocate processing or storage in the multi-tenant shared infrastructure to simulate how execution of the request affects availability of the compute resources. 
     
     
         16 . The computer program product as described in  claim 13  wherein the anticipated application behavior characterizes legitimate behavior for each of one or more tenant applications in the multi-tenant shared infrastructure. 
     
     
         17 . The computer program product as described in  claim 16  wherein the anticipated application behavior is profiled as a machine-encoded data set. 
     
     
         18 . The computer program product as described in  claim 13  wherein the program code to evaluate executes a number of application operations in a separate execution thread to determine if the number of application operations in the workload exceeds the workload limit.

Join the waitlist — get patent alerts

Track US2017078325A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.