Securing collection of information of tenant container
Embodiments of the present disclosure provide a method, a first computing device, a second computing device, and a computer program product for securing the information related to a tenant container. The method is performed by a first computing device. The method comprises receiving, from an endpoint agent resident on the first computing device, information collected from the tenant container during execution of the tenant container and encrypting at least some of the information related to the tenant container. Further, the method comprises transmitting the encrypted information to be decrypted at a second computing device in a secure environment for analysing the information at the second computing device. Corresponding first computing device, second computing device and computer program products are also disclosed.
1 . A method for securing information related to a tenant container, the method performed by a second computing device, the method comprising:
receiving encrypted information related to the tenant container from a first computing device;
decrypting the encrypted information in a secure environment hosted by the second computing device; and
controlling the information leaving the secure environment, wherein controlling the information leaving the secure environment comprises:
selectively encrypting the information by:
identifying the information leaving the secure environment; and
further identifying result of analysis of the identified information leaving the secure environment.
2 . The method according to claim 1 , wherein the step of controlling the information leaving the secure environment comprises:
identifying the information leaving the secure environment; and
selectively masking at least some of the identified information leaving the secure environment.
3 . The method according to claim 1 , wherein the step of controlling the information leaving the secure environment comprises: selectively encrypting the information by:
identifying the information leaving the secure environment; and
selectively replacing at least some of the identified information leaving the secure environment with a plurality of encrypted strings.
4 . The method according to claim 1 , wherein composition of the information leaving the secure environment is dependent on a receiver of the information, wherein the receiver is one or more of: a tenant associated with the tenant container and a cloud service provider, CSP, hosting the tenant container.
5 . The method according to claim 1 , wherein the step of decrypting the encrypted information in a secure environment comprises:
registering for an encryption service executing within the secure environment hosted by the second computing device;
obtaining a private key which is generated or inserted into the secure environment in the second computing device; and
decrypting the encrypted information related to the tenant container using the private key.
6 . The method according to claim 1 , wherein the step of registering for an encryption service executing within a secure environment comprises:
generating a request for the encryption service; and
transmitting the request for the encryption service to the secure environment.
7 . The method according to claim 1 , wherein the information from the tenant container comprises metadata, events, and alerts.
8 . The method according to claim 1 , wherein a summary of the information leaving the secure environment is generated in the secure environment.
9 . The method according to claim 8 , further comprising:
transmitting, to a tenant associated with the tenant container, the summary of the information leaving the secure environment.
10 . A second computing device for securing information related to a tenant container, comprising processing circuitry and memory, the second computing device being adapted for:
receiving encrypted information related to the tenant container from a first computing device;
decrypting the encrypted information in a secure environment hosted in the second computing device; and
controlling the information leaving the secure environment, wherein controlling the information leaving the secure environment comprises:
selectively encrypting the information by:
identifying the information leaving the secure environment; and
further identifying result of analysis of the identified information leaving the secure environment.