IP Library Granted Patent US 10,534,915
Granted Patent B2
US 10,534,915 · App. 15/636,694 · Granted Jan 14, 2020

System for virtual patching security vulnerabilities in software containers

Inventors: Michael Cherny (Ramat Gan, IL); Sagie Dulce (Tel Aviv, IL)
Assignee: AQUA SECURITY SOFTWARE, LTD.
G06F21/577G06F21/50G06F21/57G06F11/3612G06F21/554G06F2221/033H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,534,915
App. No.
15/636,694
Granted
Jan 14, 2020
Kind
B2
Abstract

An example computer-implemented method of preventing exploitation of software vulnerabilities includes determining that a software container is susceptible to a vulnerability, determining one or more soft spots required to exploit the vulnerability, and analyzing runtime behavior of the software container to determine if the software container uses the one or more soft spots. The method includes automatically applying a security policy that prevents the software container from using the one or more soft spots based on the analyzing indicating that the software container does not use the one or more soft spots at runtime.

Claims (43)

1. A computer-implemented method of preventing exploitation of software vulnerabilities, comprising:

determining that a software container is susceptible to a vulnerability;

determining one or more soft spots required to exploit the vulnerability;

analyzing runtime behavior of the software container to determine whether the software container uses the one or more soft spots;

based on the analyzing indicating that the software container does not use the one or more soft spots at runtime: automatically applying a security policy that prevents the software container from using the one or more soft spots, and providing a notification that a patch to protect the software container against the vulnerability can be applied with a low priority; and

based on the analyzing indicating that the software container does use any of the one or more soft spots at runtime: controlling whether use of the software container is allowed or prevented based on a predefined use policy, and providing a notification that a patch to protect the software container against the vulnerability should be applied with a high priority.

2. The computer-implemented method of claim 1 , wherein said controlling comprising performing one of:

preventing the software container from running;

allowing the software container to run but preventing the software container from using the one or more soft spots; and

allowing the software container to run and use the one or more soft spots.

3. The computer-implemented method of claim 1 , wherein the one or more soft spots comprise access to one or more particular files.

4. The computer-implemented method of claim 1 , wherein the one or more soft spots comprise one or more particular system calls.

5. The computer-implemented method of claim 1 , wherein the one or more soft spots comprise access to a specific network resource.

6. The computer-implemented method of claim 1 , wherein said automatically applying a security policy that prevents the software container from using the one or more soft spots comprises creating or updating a whitelist for the software container that excludes use of the one or more soft spots by the software container.

7. The computer-implemented method of claim 1 , wherein said determining that the software container is susceptible to the vulnerability comprises scanning the software container, or its corresponding container image, against a list of known vulnerabilities.

8. The computer-implemented method of claim 1 , wherein said analyzing and said automatically applying are performed by an additional, second software container.

9. A computing device comprising:

memory configured to store an image for a software container; and

processing circuitry operatively connected to the memory and configured to:

determine that the software container is susceptible to a vulnerability;

determine one or more soft spots required to exploit the vulnerability;

analyze runtime behavior of the software container to determine whether the software container uses the one or more soft spots;

based on the analysis indicating that the software container does not use the one or more soft spots at runtime: automatically apply a security policy that prevents the software container from using the one or more soft spots, and provide a notification that a patch to protect the software container against the vulnerability can be applied with a low priority; and

based on the analysis indicating that the software container does use any of the one or more soft spots at runtime: control whether use of the software container is allowed or prevented based on a predefined use policy, and provide a notification that a patch to protect the software container against the vulnerability should be applied with a high priority.

10. The computing device of claim 9 , wherein to control whether use of the software container is allowed or prevented based on the predefined use policy, the processing circuitry is configured to perform one of:

prevent the software container from running;

allow the software container to run but preventing the software container from using the one or more soft spots; and

allow the software container to run and use the one or more soft spots.

11. The computing device of claim 9 , wherein the one or more soft spots comprise access to one or more particular files.

12. The computing device of claim 9 , wherein the one or more soft spots comprise one or more particular system calls.

13. The computing device of claim 9 , wherein the one or more soft spots comprise access to a specific network resource.

14. The computing device of claim 9 , wherein to automatically apply a security policy that prevents the software container from using the one or more soft spots, the processing circuitry is configured to create or update a whitelist for the software container that excludes use of the one or more soft spots by the software container.

15. The computing device of claim 9 , wherein to determine that the software container is susceptible to the vulnerability, the processing circuitry is configured to scan the software container, or its corresponding container image, against a list of known vulnerabilities.

16. A computer program product stored in a non-transitory computer-readable medium, said computer program product comprising program instructions which, when run on a computing device, configures the computing device to:

determine that a software container is susceptible to a vulnerability;

determine one or more soft spots required to exploit the vulnerability;

analyze runtime behavior of the software container to determine whether the software container uses the one or more soft spots;

based on the analysis indicating that the software container does not use the one or more soft spots at runtime: automatically apply a security policy that prevents the software container from using the one or more soft spots, and provide a notification that a patch to protect the software container against the vulnerability can be applied with a low priority; and

based on the analysis indicating that the software container does use any of the one or more soft spots at runtime: control whether use of the software container is allowed or prevented based on a predefined use policy, and provide a notification that a patch to protect the software container against the vulnerability should be applied with a high priority.

17. The computer program product of claim 16 , wherein to control whether use of the software container is allowed or prevented based on the predefined use policy, the program instructions configure the computing device to perform one of:

prevent the software container from running;

allow the software container to run but preventing the software container from using the one or more soft spots; and

allow the software container to run and use the one or more soft spots.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Aug 3, 2026
From: BANK LEUMI LE-ISRAEL B.M.
To: AQUA SECURITY SOFTWARE LTD.
Reel/Frame 075495/0666 →
SECURITY INTEREST Recorded Jul 29, 2026
From: AQUA SECURITY SOFTWARE LTD
To: HSBC BANK PLC
Reel/Frame 075441/0921 →
SECURITY INTEREST Recorded Jul 30, 2023
From: AQUA SECURITY SOFTWARE LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 064429/0026 →
SECURITY INTEREST Recorded Nov 7, 2022
From: AQUA SECURITY SOFTWARE LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 061668/0709 →
RELEASE OF SECURITY INTEREST Recorded Oct 27, 2022
From: SILICON VALLEY BANK
To: AQUA SECURITY SOFTWARE LTD
Reel/Frame 061567/0852 →
SECURITY INTEREST Recorded Oct 21, 2020
From: AQUA SECURITY SOFTWARE LTD.
To: SILICON VALLEY BANK
Reel/Frame 054130/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2017
From: CHERNY, MICHAEL; DULCE, SAGIE
To: AQUA SECURITY SOFTWARE, LTD.
Reel/Frame 042859/0007 →
Continuity (1)
Related Publication 20190005246A1 · Jan 3, 2019
Cited By (20)
US 12,204,930 US 12,355,787 US 12,363,148 US 12,368,746 US 12,375,573 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,500,911 US 12,513,221 US 12,537,837 US 12,537,839 US 12,556,548 US 12,587,553 US 12,608,475 US 12,659,326 US 12,689,638 US 12,706,932