IP Library Granted Patent US 9,497,209
Granted Patent B2
US 9,497,209 · App. 14/727,906 · Granted Nov 15, 2016

Image vulnerability repair in a networked computing environment

Inventors: Al Chakra (Apex, NC); Christopher J. Dawson (Arlington, VA); Yu Deng (Yorktown Heights, NY); Rick A. Hamilton, II (Charlottesville, VA); Jenny S. Li (Danbury, CT); Liangzhao Zeng (Mohegan Lake, NY)
Assignee: International Business Machines Corporation
H04L63/1433G06F21/55G06F21/577H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,497,209
App. No.
14/727,906
Granted
Nov 15, 2016
Kind
B2
Abstract

Embodiments of the present invention provide an approach to repair vulnerabilities (e.g., security vulnerabilities) in images (e.g., application images) in a networked computing environment (e.g., a cloud computing environment). Specifically, an image is checked for vulnerabilities using a database of known images and/or vulnerabilities. If a vulnerability is found, a flexible/elastic firewall is established around the image so as to isolate the vulnerability. Once the firewall has been put in place, the vulnerability can be repaired by a variety of means such as upgrading the image, quarantining the image, discarding the image, and/or generating a new image. Once the image has been repaired, the firewall can be removed.

Claims (37)

1. A method for repairing image vulnerability in a networked computing environment, comprising:

identifying a first image in the networked computing environment having a vulnerability, the first image being identified based on a database of known vulnerabilities;

establishing a firewall around the first image and a second image, having a similar vulnerability to the first image, to isolate the vulnerability of the first image and the second image;

repairing the first image to remove the vulnerability, the repairing comprising at least one of: (a) upgrading the image, (b) quarantining the image, or (c) discarding the image and generating a new image; and

releasing the first image and the second image from the firewall.

2. The method of claim 1 , the image being an application image.

3. The method of claim 1 , the vulnerability being a security vulnerability.

4. The method of claim 1 , the database being populated based on at least one of:

updates, and defects that are published by enterprises owning products used and stored in the networked computing environment.

5. The method of claim 1 , further comprising updating the database based on the repairing.

6. The method of claim 1 , wherein the networked computing environment comprises a cloud computing environment.

7. The method of claim 1 , wherein a service solution provider provides a computer infrastructure that performs the method for one or more consumers.

8. A system for repairing image vulnerability in a networked computing environment, comprising:

a bus;

a processor coupled to the bus; and

a memory medium coupled to the bus, the memory medium comprising instructions to:

identify a first image in the networked computing environment having a vulnerability, the first image being identified based on a database of known vulnerabilities;

establish a firewall around the first image and a second image, having a similar vulnerability to the first image, to isolate the vulnerability of the first image and the second image;

repair the first image to remove the vulnerability, the repairing comprising at least one of: (a) upgrading the image, (b) quarantining the image, or (c) discarding the image and generating a new image; and

release the first image and the second image from the firewall.

9. The system of claim 8 , the image being an application image.

10. The system of claim 8 , the vulnerability being a security vulnerability.

11. The system of claim 8 , the database being populated based on at least one of:

updates, and defects that are published by enterprises owning products used and stored in the networked computing environment.

12. The system of claim 8 , the memory medium further comprising instructions to update the database based on the repair.

13. The system of claim 8 , wherein the networked computing environment comprises a cloud computing environment.

14. A computer program product for repairing image vulnerability in a networked computing environment, the computer program product comprising a computer readable storage media, and program instructions stored on the computer readable storage media, to:

identify a first image in the networked computing environment having a vulnerability, the first image being identified based on a database of known vulnerabilities;

establish a firewall around the first image and a second image, having a similar vulnerability to the first image, to isolate the vulnerability of the first image and the second image;

repair the first image to remove the vulnerability, the repairing comprising at least one of: (a) upgrading the image, (b) quarantining the image, or (c) discarding the image and generating a new image; and

release the first image and the second image from the firewall.

15. The computer program product of claim 14 , the image being an application image.

16. The computer program product of claim 15 , further comprising program instructions stored on the computer readable storage media to update the database based on the repair.

17. The computer program product of claim 16 , wherein the networked computing environment comprises a cloud computing environment.

18. The computer program product of claim 14 , the vulnerability being a security vulnerability.

19. The computer program product of claim 14 , the database being populated based on updates.

20. The computer program product of claim 14 , the database being populated based on defects that are published by enterprises owning products used and stored in the networked computing environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: FINJAN BLUE, INC.
Reel/Frame 046037/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2015
From: CHAKRA, AL; DAWSON, CHRISTOPHER J.; DENG, YU; HAMILTON, RICK A., II; LI, JENNY S.; ZENG, LIANGZHAO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 035760/0510 →
Continuity (3)
Continuation 14156665 · Jan 16, 2014
Continuation 12951373 · Nov 22, 2010
Related Publication 20150264076A1 · Sep 17, 2015