US 11,677,762 B2
Apparatus and method for evaluating multiple aspects of the security for virtualized infrastructure in a cloud environment
Taous Madi, Montreal (CA); Mengyuan Zhang, Montreal (CA); Yosr Jarraya, Montreal (CA); Lingyu Wang, Montreal (CA); Makan Pourzandi, Montreal (CA); and Mourad Debbabi, Dollard des Ormeaux (CA)
Assigned to TELEFONAKTIEBOLAGET LM ERICSSON (PUBL), Stockholm (SE)
Appl. No. 17/46,458
Filed by Telefonaktiebolaget LM Ericsson (publ), Stockholm (SE)
PCT Filed Apr. 23, 2019, PCT No. PCT/IB2019/053352
§ 371(c)(1), (2) Date Oct. 9, 2020,
PCT Pub. No. WO2019/207486, PCT Pub. Date Oct. 31, 2019.
Claims priority of provisional application 62/661,410, filed on Apr. 23, 2018.
Prior Publication US 2021/0152572 A1, May 20, 2021
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 63/1433 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computing device for evaluating security for virtualized infrastructures of tenants in a cloud environment, the computing device comprising processing circuitry including instructions executable by the processing circuitry to configure the computing device to:
calculate at least one security metric for a first tenant based at least in part on information associated with at least one virtual resource of the first tenant and at least one interaction of the at least one virtual resource of the first tenant with at least one virtual resource of at least one other tenant in a multi-tenant virtualized infrastructure;
evaluate at least one security parameter for the first tenant based at least in part on at least one of the at least one calculated security metric for monitoring a security level of the first tenant relative to the at least one other tenant in the multi-tenant virtualized infrastructure;
determine a multi-tenancy attack surface value for the first tenant for each host in the multi-tenant virtualized infrastructure; and
calculate a total multi-tenancy attack surface value for the first tenant as a sum of the multi-tenancy attack surface values for the first tenant for each host multiplied by a severity weight.