Invention Grant
- Patent Title: Security for container networks
-
Application No.: US17125551Application Date: 2020-12-17
-
Publication No.: US11314614B2Publication Date: 2022-04-26
- Inventor: Phillip A. Porras , Vinod Yegneswaran , Jaehyun Nam , Seungwon Shin
- Applicant: SRI International
- Applicant Address: US CA Menlo Park
- Assignee: SRI International
- Current Assignee: SRI International
- Current Assignee Address: US CA Menlo Park
- Agency: Moser Taboada
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F11/34 ; G06N10/00 ; G06N3/08 ; G06F11/36 ; H04L61/103

Abstract:
A method, apparatus and system for providing security for a container network having a plurality of containers includes establishing a network stack for each of the plurality of containers of the container network, determining network and policy information from active containers, based on a set of pre-determined inter-container dependencies for the plurality of containers learned from the determined network and policy information, configuring container access in the container network to be limited to only containers of the plurality of containers that are relevant to a respective communication, and configuring inter-container traffic in the container network to be directed only from a source container into a destination container in a point-to-point manner such that exposure of the inter-container traffic to peer containers is prevented.
Public/Granted literature
- US20210211408A1 SECURITY FOR CONTAINER NETWORKS Public/Granted day:2021-07-08
Information query