Invention Grant
- Patent Title: Prevention of container escape-based attacks of a host system
-
Application No.: US18621511Application Date: 2024-03-29
-
Publication No.: US12248569B2Publication Date: 2025-03-11
- Inventor: Daniel Prizmant , Ariel M. Zelivansky , Liron Levin , Eran Yanay
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Gilliam IP PLLC
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/52

Abstract:
A service prevents attacks carried out through container escape for silo-based containers. A callback is registered for a function(s) that may be invoked from inside a container and returns an object handle(s). The callback, when triggered by invocation of the function(s), executes for determination of whether requests for access to objects via their handles are issued by suspicious processes. Access to CExecSvc.exe is restricted for processes that request a handle for CExecSvc.exe and are determined to be associated with a container themselves. Processes that escape their container through a technique that evades detection are also blocked from accessing the host system. When a process requests access to an object via invocation of a function that returns a handle, the callback executes for determination of whether the process but not the requested object is associated with a container, in which case the service restricts the process' access to the host system.
Public/Granted literature
- US20240241950A1 PREVENTION OF CONTAINER ESCAPE-BASED ATTACKS OF A HOST SYSTEM Public/Granted day:2024-07-18
Information query