IP Library Granted Patent US 10,116,625
Granted Patent B2
US 10,116,625 · App. 14/991,628 · Granted Oct 30, 2018

Systems and methods for secure containerization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,625
App. No.
14/991,628
Granted
Oct 30, 2018
Kind
B2
Abstract

A method for provisioning a secure container for running an application includes routing traffic between the application and a secure container service over a virtual private network, and restricting the flow of traffic to or from the application other than traffic to or from the secure container service. The method further includes providing limited name resolution for the secure container with a customized domain name system server, establishing network proxy services to filter and route approved inbound traffic to the application, and establishing outbound network proxy services to filter and route approved outbound traffic from the application.

Claims (35)

1. A method for provisioning a secure container for running an application, comprising:

routing traffic between the application and a secure container service over a virtual private network;

using network filter rules to restrict network traffic to or from the application other than traffic to or from the secure container service;

using a customized domain name system service to provide name resolution to domain name system requests from the application within the secure container, the name resolution limited to server names allowed by a security policy;

examining the secure container for known vulnerabilities and preventing the secure container from launching when a known vulnerability is detected, the examining including at least one of checking configuration settings to identify combinations of settings that create known vulnerabilities, checking versions of libraries or applications within the secure container to identify unpatched known vulnerabilities, performing a port scan to identify known vulnerabilities, and any combination thereof;

establishing an inbound network proxy to filter and route approved inbound traffic to the application; and

establishing an outbound network proxy to filter and route approved outbound traffic from the application.

2. The method of claim 1 , further comprising receiving a request to create the secure container for the application.

3. The method of claim 1 , further comprising examining a container image or startup options to determine the security policy for the secure container.

4. The method of claim 1 , further comprising capturing data streams from the application and forwarding the data streams to a logging function.

5. The method of claim 1 , wherein the inbound network proxy and the outbound network proxy are components of the secure container service.

6. The method of claim 1 , wherein the customized domain name system server is provided by the secure container service.

7. A method for providing name resolution for an application within a secure container, the method comprising:

receiving a request for name resolution from the application;

forwarding the request for name resolution to an upstream domain name server if a requested name is allowed by a security policy;

receiving a response from the upstream domain name server, the response including a network address and a time-to-live;

modifying a network filter to allow traffic to the network address;

forwarding the response to the application; and

modifying the network filter to disallow traffic to the network address after the time-to-live has expired.

8. The method of claim 7 , wherein the security policy is determined by examining a container image or startup options.

9. The method of claim 7 , wherein the application resides within a virtual container.

10. The method of claim 7 , wherein the network filter is provided by a secure container service.

11. An information handling system comprising:

a processor configured to:

route traffic between an application and a secure container service over a virtual private network;

use network filter rules to restrict network traffic to or from the application other than traffic to or from the secure container service;

provide name resolution to domain name system requests from the application within the secure container using a customized domain name system server, the name resolution limited to server names allowed by a security policy;

examine the secure container for known vulnerabilities, including at least one of check configuration settings to identify combinations of settings that create known vulnerabilities, check versions of libraries or applications within the secure container to identify unpatched known vulnerabilities, perform a port scan to identify known vulnerabilities, and any combination thereof,

prevent the secure container from launching when a known vulnerability is detected;

establish an inbound network proxy to filter and route approved inbound traffic to the application; and

establish an outbound network proxy to filter and route approved outbound traffic from the application.

12. The information handling system of claim 11 , further comprising receiving a request to create the secure container for the application.

13. The information handling system of claim 11 , further comprising examining a container image or startup options to determine the security policy for the secure container.

14. The information handling system of claim 11 , further comprising capturing data streams from the application and forwarding the data streams to a logging function.

15. The information handling system of claim 11 , wherein the inbound network proxy and the outbound network proxy are components of the secure container service.

Assignments (6)
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
ENTITY CONVERSION WITH NAME CHANGE Recorded May 4, 2016
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 038608/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2016
From: KINDER, ROSS R.; RAMSEY, JON R.; VIDAS, TIMOTHY M.; DANFORD, ROBERT
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 038389/0814 →