- Patent Title: Filesystem action profiling of containers and security enforcement
-
Application No.: US15865763Application Date: 2018-01-09
-
Publication No.: US10664590B2Publication Date: 2020-05-26
- Inventor: Liron Levin , Dima Stopel , Eran Yanay
- Applicant: Twistlock, Ltd.
- Applicant Address: IL Herzliya
- Assignee: TWISTLOCK, LTD.
- Current Assignee: TWISTLOCK, LTD.
- Current Assignee Address: IL Herzliya
- Agency: M&B IP Analysts, LLC
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/52 ; G06F21/55 ; G06F21/54 ; G06N20/00

Abstract:
A system and method for securing execution of software containers using security profiles. The method includes receiving an event indicating that a container image requires profiling, wherein the container image includes resources utilized to execute a corresponding application container; generating a security profile for the container image when the event is received, wherein the generated security profile indicates at least a list of permissible filesystem actions, wherein each permissible filesystem action is an action performed with respect to at least one filesystem resource; monitoring an operation of a runtime execution of the application container; and detecting a violation of the security profile based on the monitored operation.
Public/Granted literature
- US20180129803A1 FILESYSTEM ACTION PROFILING OF CONTAINERS AND SECURITY ENFORCEMENT Public/Granted day:2018-05-10
Information query