Invention Grant
- Patent Title: Automatic deployment of application security policy using application manifest and dynamic process analysis in a containerization environment
-
Application No.: US17576432Application Date: 2022-01-14
-
Publication No.: US11966463B2Publication Date: 2024-04-23
- Inventor: Glen K. Kosaka , Gang Duan , Fei Huang
- Applicant: SUSE LLC
- Applicant Address: US UT Pleasant Grove
- Assignee: SUSE LLC
- Current Assignee: SUSE LLC
- Current Assignee Address: US UT Pleasant Grove
- Main IPC: G06F21/50
- IPC: G06F21/50 ; G06F9/451 ; G06F9/455 ; G06F21/53

Abstract:
A policy interpreter detects that an application container has been added in a container system, and opens a stored manifest for the application container. The policy interpreter retrieves running services information regarding the application container, and generates a security policy for the application container. The security policy defines a set of actions for which the application container can perform, and the set of actions are determined using the manifest and the running service information associated with the application container. The policy interpreter loads the security policy at a security container. The security container blocks an action performed by the application container in response to determining that the action performed by the application container does not match any action in the set of actions defined in the security policy. The policy interpreter transmits the security policy to a graphical user interface container for presentation to a user via a display device.
Public/Granted literature
Information query