- Patent Title: Identifying container file events for providing container security
-
Application No.: US15647269Application Date: 2017-07-12
-
Publication No.: US10678935B2Publication Date: 2020-06-09
- Inventor: Laxmikant Gunda , Nilesh Awate , Priyal Rathi
- Applicant: NICIRA, INC.
- Applicant Address: US CA Palo Alto
- Assignee: Nicira, Inc.
- Current Assignee: Nicira, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Fish & Richardson P.C.
- Priority: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@6912a307
- Main IPC: G06F21/62
- IPC: G06F21/62 ; G06F9/455 ; G06F21/53

Abstract:
A method of providing security for containers executing on a physical host machine is provided. The method receives a notification of a file access request. The notification includes a path in a file system of the host machine being accessed by a process. From the path, the method determines whether the file access event is for accessing a location in the file system to which container file systems are mapped. The method identifies a namespace of the process using the identification of the process included in the file path. The method determines the process is a container when the namespace belongs to a service that is used to implement containers on the host machine. The method sends the identifier of the container, the identification of a VM executing the container, and the file path to a set of security applications to determine whether the file access request to be allowed.
Public/Granted literature
- US20180293394A1 IDENTIFYING CONTAINER FILE EVENTS FOR PROVIDING CONTAINER SECURITY Public/Granted day:2018-10-11
Information query