US 12,137,105 B2
Security management method and security management apparatus
Zechao Meng, Shenzhen (CN)
Assigned to Huawei Cloud Computing Technologies Co., Ltd., Gui'an New District (CN)
Filed by HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD., Gui'an New District (CN)
Filed on Nov. 6, 2020, as Appl. No. 17/091,877.
Application 17/091,877 is a continuation of application No. PCT/CN2019/087127, filed on May 16, 2019.
Claims priority of application No. 201811101197.2 (CN), filed on Sep. 20, 2018.
Prior Publication US 2021/0058414 A1, Feb. 25, 2021
Int. Cl. H04L 9/40 (2022.01); G06F 21/52 (2013.01)
CPC H04L 63/1416 (2013.01) [G06F 21/52 (2013.01); G06F 2221/034 (2013.01)] 12 Claims
OG exemplary drawing
 
1. A security management method carried out on behalf of an application deployable in a multi-machine operating environment, the method comprising:
receiving a suspected attack alarm from a centralized security monitoring apparatus;
extracting, from the suspected attack alarm, an identifier used to associate the application;
determining, in accordance with the identifier, the application associated with the suspected attack alarm;
issuing, in accordance with the receiving a suspected attack alarm and the determining the application associated with the suspected attack alarm, a request for a monitoring program to be deployed to an operating environment of the application, wherein the monitoring program is executed in the operating environment to generate a monitoring information during operation of the application;
obtaining, in accordance with the issuing the request and by executing the monitoring program deployed to and executed in the operating environment, the monitoring information of the application;
determining, in accordance with the obtaining and based on the monitoring information of the application, the application has been attacked;
stopping or isolating, in accordance with the determining the application has been attacked, the application; and
deleting, after the determining the application has been attacked, the monitoring program from the operating environment of the application.