Enhancing container security by performing container vulnerability reduction based on static analysis of dynamically loaded symbols and system call blocking
US-2024220632-A1 · Jul 4, 2024 · US
US9531758B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9531758-B2 |
| Application number | US-201514712154-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 14, 2015 |
| Priority date | Mar 18, 2011 |
| Publication date | Dec 27, 2016 |
| Grant date | Dec 27, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebetween. There are two basic requirements for the cloud-based SWG: (i) Having some means of forwarding traffic from the organization or its users to the SWG nodes, and (ii) Being able to authenticate the organization and users for policy enforcement and access logging. The SWG systems and methods dynamically associate traffic to users regardless of the source (device, location, encryption, application type, etc.), and once traffic is tagged to a user/organization, various polices can be enforced and audit logs of user access can be maintained.
Opening claim text (preview).
What is claimed is: 1. A cloud-based gateway, comprising: a network interface communicatively coupled to a network; a processor; and memory storing instructions that, when executed, cause the processor to: dynamically associate traffic received on the network interface with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintain the dynamic association over time, wherein the dynamic association is maintained over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; and apply policies to the traffic based on the dynamic association. 2. The cloud-based gateway of claim 1 , wherein an association is pre-configured between an organization and a destination port to identify traffic originating from the organization. 3. The cloud-based gateway of claim 2 , wherein the instructions, when executed, further cause the processor to: perform authentication challenges for known traffic to identify the destination port periodically and to detect fraudulent use. 4. The cloud-based gateway of claim 1 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 5. The cloud-based gateway of claim 1 , wherein the unknown traffic is associated to the associated user based on determining the associated user through authenticated HTTP traffic from a same destination IP address. 6. The cloud-based gateway of claim 1 , wherein the instructions, when executed, further cause the processor to: map the unknown traffic to an organization depending on whether the destination IP address is private or specific to the organization when multiple users are determined on the destination IP address based on seeing multiple users through authenticated HTTP traffic thereon. 7. The cloud-based gateway of claim 1 , wherein the traffic is received via generic routing encapsulation (GRE). 8. The cloud-based gateway of claim 1 , wherein the traffic is received via a virtual private network (VPN). 9. The cloud-based gateway of claim 1 , wherein the traffic is received via an explicit Proxy mode. 10. The cloud-based gateway of claim 1 , wherein the cloud-based gateway is a node in a distributed security system, and wherein the node is configured to receive dynamic associations from other nodes in the distributed security system. 11. A cloud-based gateway method, implemented by a gateway server, comprising: dynamically associating traffic received on a network with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintaining the dynamic association over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; applying policies to the traffic based on the dynamic association. 12. The cloud-based gateway method of claim 11 , further comprising: pre-configuring an association between an organization and a destination port to identify traffic originating from the organization. 13. The cloud-based gateway method of claim 12 , further comprising: performing authentication challenges for known traffic to identify the destination port periodically and to detect fraudulent use. 14. The cloud-based gateway method of claim 11 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 15. The cloud-based gateway method of claim 11 , wherein the unknown traffic is associated to the associated user based on determining the user through authenticated HTTP traffic from a same destination IP address. 16. The cloud-based gateway method of claim 11 , further comprising: mapping the unknown traffic to an organization depending on whether the destination IP address is private or specific to the organization when multiple users are determined on the destination IP address based on seeing multiple users through authenticated HTTP traffic thereon. 17. The cloud-based gateway method of claim 11 , wherein the traffic is received via one of generic routing encapsulation (GRE), a virtual private network (VPN), and an explicit Proxy mode. 18. A network, comprising: a distributed cloud-based security system coupled to the Internet; a plurality of cloud-based gateways within the distributed cloud-based security system; and a plurality of users accessing the Internet through the distributed cloud-based security system; wherein each of the plurality of cloud-based gateways is configured to: dynamically associate traffic received on the network interface with users to form a dynamic association, wherein the traffic comprises a combination of authenticated traffic and unknown traffic, wherein the authenticated traffic is associated to an authenticated user and the unknown traffic is associated to an associated user of a destination Internet Protocol (IP) address from the unknown traffic; maintain the dynamic association over time, wherein the dynamic association is maintained over time by updating the dynamic association based on newly received authenticated HTTP traffic, on pre-defined time thresholds for expiring associations, and on detecting collisions of multiple users on the destination IP address; and apply policies to the traffic based on the dynamic association. 19. The network of claim 18 , wherein the authenticated traffic is authenticated Hypertext Transfer Protocol (HTTP) traffic. 20. The network of claim 18 , wherein the unknown traffic is associated to the associated user based on determining the user through authenticated HTTP traffic from a same destination IP address.
at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title
Electricity · mapped topic
Physics · mapped topic
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.