IP Library Granted Patent US 12,676,890
Granted Patent B2
US 12,676,890 · App. 18/333,052 · Granted Jul 7, 2026

Techniques for contextually applying a security policy on a software container

Inventors: Amir Lande Blau (Tel Aviv, IL); Roy Reznik (Tel Aviv, IL); Bar Magnezi (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L63/20G06F9/45558H04L63/0272G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,890
App. No.
18/333,052
Granted
Jul 7, 2026
Kind
B2
Abstract

A system and method for applying a cybersecurity contextual policy in a computing environment are disclosed. In an embodiment, the method includes: detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment; detecting a policy of the computing environment, the policy including a conditional rule; generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.

Claims (53)

1 . A method for applying a cybersecurity contextual policy in a computing environment, comprising:

detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;

detecting a policy of the computing environment, the policy including a conditional rule;

generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and

configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.

2 . The method of claim 1 , further comprising:

configuring the admission controller to apply the contextual policy on a plurality of software containers deployed in the software container cluster.

3 . The method of claim 1 , further comprising:

applying the policy to a code object, wherein the code object is utilized to deploy the virtualization.

4 . The method of claim 1 , wherein the conditional rule is any one of: an exclusionary rule, or an inclusionary rule.

5 . The method of claim 1 , further comprising:

detecting a virtualization deployed in the computing environment which is an exception to the conditional rule; and

generating the exception based on a parameter of the detected virtualization.

6 . The method of claim 1 , further comprising:

intercepting a request from a software container to an application programming interface (API); and

applying the contextual policy to the request.

7 . The method of claim 6 , further comprising:

configuring a webhook in the software container cluster to intercept requests from a container of a first node; and

configuring the webhook to send the intercepted requests to the admission controller.

8 . The method of claim 1 , further comprising:

configuring a second admission controller of a second software container cluster deployed in a second computing environment to apply the contextual policy, wherein the second computing environment is deployed on a cloud computing infrastructure which is different than a cloud computing infrastructure on which the cloud computing environment is deployed.

9 . The method of claim 1 , wherein the admission controller is any one of: a validating admission controller, a mutating admission controller, and a combination thereof.

10 . A non-transitory computer-readable medium storing a set of instructions for applying a cybersecurity contextual policy in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;

detect a policy of the computing environment, the policy including a conditional rule;

generate a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and

configure an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.

11 . A system for applying a cybersecurity contextual policy in a computing environment, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;

detect a policy of the computing environment, the policy including a conditional rule;

generate a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and

configure an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the admission controller to apply the contextual policy on a plurality of software containers deployed in the software container cluster.

13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

apply the policy to a code object, wherein the code object is utilized to deploy the virtualization.

14 . The system of claim 11 , wherein the conditional rule is any one of: an exclusionary rule, or an inclusionary rule.

15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a virtualization deployed in the computing environment which is an exception to the conditional rule; and

generate the exception based on a parameter of the detected virtualization.

16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

intercept a request from a software container to an application programming interface (API); and

apply the contextual policy to the request.

17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure a webhook in the software container cluster to intercept requests from a container of a first node; and

configure the webhook to send the intercepted requests to the admission controller.

18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure a second admission controller of a second software container cluster deployed in a second computing environment to apply the contextual policy, wherein the second computing environment is deployed on a cloud computing infrastructure which is different than a cloud computing infrastructure on which the cloud computing environment is deployed.

19 . The system of claim 11 , wherein the admission controller is any one of:

a validating admission controller, a mutating admission controller, and a combination thereof.