Invention Grant
- Patent Title: Securing privileged virtualized execution instances from penetrating a virtual host environment
-
Application No.: US16390542Application Date: 2019-04-22
-
Publication No.: US11222123B2Publication Date: 2022-01-11
- Inventor: Nimrod Stoler , Lavi Lazarovitz
- Applicant: CyberArk Software Ltd.
- Applicant Address: IL Petach-Tikva
- Assignee: CyberArk Software Ltd.
- Current Assignee: CyberArk Software Ltd.
- Current Assignee Address: IL Petach-Tikva
- Agency: Finnegan, Henderson, Farabow, Garrett & Dunner, LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F9/455

Abstract:
Disclosed embodiments relate to systems and methods for identifying vulnerabilities for virtualized execution instances to escape their operating environment and threaten a host environment. Techniques include identifying a virtualized execution instance configured for deployment on a host in a virtual computing environment; performing a privileged configuration inspection for the virtualized execution instance, the privileged configuration inspection analyzing whether the virtualized execution instance has been configured with one or more attributes that can permit operation of the virtualized execution instance to perform operations, beyond an environment of the virtualized execution instance, on an environment of the host; and implementing, based on the privileged configuration inspection, a control action for controlling the virtualized execution instance's ability to perform operations on the environment of the host.
Public/Granted literature
- US20200334362A1 SECURING PRIVILEGED VIRTUALIZED EXECUTION INSTANCES Public/Granted day:2020-10-22
Information query