Abstract: In an embodiment, one or more non-transitory computer-readable media storing sequences of instructions which, when executed using processors, cause the processors to execute, using a runtime security engine deployed within a computing environment: obtaining telemetry data comprising security-related data from microservices executing in the computing environment; accessing risk categories codifying insecure behavior across multiple layers in the computing environment; accessing toxic combination patterns across the layers, the toxic combination patterns being generated based on the risk categories, and each of the toxic combination pattern indicating a high-severity security impact in case of an attack in the computing environment; evaluating the telemetry data against the risk categories and toxic combination patterns, the evaluating producing a customized set of toxic combination patterns specific to the application within the computing environment; and displaying the customized set of toxic combination patt
Abstract: In an embodiment, a method manages application security in a microservices environment. A local control plane collects telemetry data from microservices via their APIs, aggregates the data into a payload, and transmits it to a central control plane through a message queue. The central control plane constructs a graph representing microservice interactions based on the telemetry data and compares the current graph to a previous version. The method further includes checking whether a destination service matches a malicious hostname or IP address and marking the connection as denied if malicious. The method further includes evaluating compliance with predefined policies and denying interactions that violate those policies for each interaction.
Abstract: In various embodiments, a computer-implemented method, distributed systems architecture, and computer program product are programmed to enforce and update security policies for cloud-native application stacks deployed across multiple providers using a distributed control plane architecture.
Abstract: A computer-implemented method generates and manages a dynamic security graph that visualizes runtime security and risk context across a cloud-native application. The graph displays real-time interactions among application components, such as API traffic flows across public-facing endpoints, internal microservices, third-party APIs, and data stores. It maps user and service identities, roles, and access patterns to API and data resources, and tracks data flows that egress to external destinations. The graph highlights security vulnerabilities at each layer. Graph analytics can identify potential attack vectors by correlating risks across identities, APIs, and data layers. Embodiments include a computer system, method, and program product as recited in the claims.