Invention Grant
- Patent Title: Profiling of spawned processes in container images and enforcing security policies respective thereof
-
Application No.: US17195069Application Date: 2021-03-08
-
Publication No.: US11640472B2Publication Date: 2023-05-02
- Inventor: Dima Stopel , Liron Levin
- Applicant: Twistlock, Ltd.
- Applicant Address: IL Herzliya
- Assignee: Twistlock, Ltd.
- Current Assignee: Twistlock, Ltd.
- Current Assignee Address: IL Herzliya
- Agency: Gilliam IP PLLC
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/53

Abstract:
Execution of software containers is secured using security profiles. A security profile is generated for a container image, wherein the container image includes resources utilized to execute a corresponding application container, wherein the generated security profile includes at least a spawned processes profile, wherein the spawned processes profile includes, for each spawned process executed at runtime by the application container, a signature of an executable file of the spawned process. The operation of a runtime execution of the application container is monitored. A violation of the spawned processes profile is detected based on the monitored operation.
Public/Granted literature
- US20210192058A1 PROFILING OF SPAWNED PROCESSES IN CONTAINER IMAGES AND ENFORCING SECURITY POLICIES RESPECTIVE THEREOF Public/Granted day:2021-06-24
Information query