Method to intelligently manage the end to end container compliance in cloud environments

US11989308B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11989308-B2
Application numberUS-202117383252-A
CountryUS
Kind codeB2
Filing dateJul 22, 2021
Priority dateMay 27, 2021
Publication dateMay 21, 2024
Grant dateMay 21, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One example method includes collecting container information concerning a container, analyzing the container information to identify a security tool needed to perform a vulnerability scan of the container, accessing the security tool from a knowledge lake, running the security tool on the container information to identify a security vulnerability of the container, based on the running of the security tool, generating an alert indicating that the container has the security vulnerability, capturing the security vulnerability and, based on the captured security vulnerability, updating a container image that was used to spawn the container.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising the operations: collecting container information concerning a container with port information of communication undertaken by the container; analyzing the container information and the port information to identify a security tool needed to perform a vulnerability scan of the container; accessing the security tool from a knowledge lake; running the security tool on the container information to identify a security vulnerability of the container; based on the running of the security tool, generating an alert indicating that the container has the security vulnerability; capturing the security vulnerability; and based on the captured security vulnerability, updating a container image that was used to spawn the container. 2. The method as recited in claim 1 , wherein capturing the security vulnerability comprises updating a fixed profile associated with the container to indicate that the container has the security vulnerability and to indicate a resolution to the security vulnerability. 3. The method as recited in claim 1 , wherein updating the container image comprises modifying the container image to eliminate the security vulnerability. 4. The method as recited in claim 1 , wherein the alert further indicates a security fix to the security vulnerability. 5. The method as recited in claim 1 , wherein the security vulnerability is captured in a fixed profile associated with the container, and the fixed profile includes all security fixes that have been previously implemented with respect to the container. 6. The method as recited in claim 1 , wherein a new container created with the updated container image includes a security fix identified by the alert. 7. The method as recited in claim 1 , wherein the container information is collected and presented to a device management console by way of a pass-through channel between the device management console and a host that includes the container. 8. The method as recited in claim 1 , wherein a number of security tools employed by an elastic container security hub scales up and/or down in accordance with a number of containers that are running. 9. The method as recited in claim 1 , wherein the container image is updated automatically when a human user does not respond to the alert within a specified time interval. 10. The method as recited in claim 1 , wherein the operations further comprise receiving a new container request, and generating a new container using the updated container image. 11. A computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising: collecting container information concerning a container with port information of communication undertaken by the container; analyzing the container information and the port information to identify a security tool needed to perform a vulnerability scan of the container; accessing the security tool from a knowledge lake; running the security tool on the container information to identify a security vulnerability of the container; based on the running of the security tool, generating an alert indicating that the container has the security vulnerability; capturing the security vulnerability; and based on the captured security vulnerability, updating a container image that was used to spawn the container. 12. The computer readable storage medium as recited in claim 11 , wherein capturing the security vulnerability comprises updating a fixed profile associated with the container to indicate that the container has the security vulnerability and to indicate a resolution to the security vulnerability. 13. The computer readable storage medium as recited in claim 11 , wherein updating the container image comprises modifying the container image to eliminate the security vulnerability. 14. The computer readable storage medium as recited in claim 11 , wherein the alert further indicates a security fix to the security vulnerability. 15. The computer readable storage medium as recited in claim 11 , wherein the security vulnerability is captured in a fixed profile associated with the container, and the fixed profile includes all security fixes that have been previously implemented with respect to the container. 16. The computer readable storage medium as recited in claim 11 , wherein a new container created with the updated container image includes a security fix identified by the alert. 17. The computer readable storage medium as recited in claim 11 , wherein the container information is collected and presented to a device management console by way of a pass-through channel between the device management console and a host that includes the container. 18. The computer readable storage medium as recited in claim 11 , wherein a number of security tools employed by an elastic container security hub scales up and/or down in accordance with a number of containers that are running. 19. The computer readable storage medium as recited in claim 11 , wherein the container image is updated automatically when a human user does not respond to the alert within a specified time interval. 20. The computer readable storage medium as recited in claim 11 , wherein the operations further comprise receiving a new container request, and generating a new container using the updated container image.

Assignees

Inventors

Classifications

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

  • Knowledge representation; Symbolic representation · CPC title

  • Test or assess a computer or a system · CPC title

  • G06F21/53Primary

    by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11989308B2 cover?
One example method includes collecting container information concerning a container, analyzing the container information to identify a security tool needed to perform a vulnerability scan of the container, accessing the security tool from a knowledge lake, running the security tool on the container information to identify a security vulnerability of the container, based on the running of the se…
Who is the assignee on this patent?
Emc Ip Holding Co Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 21 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).