IP Library Granted Patent US 11,036,534
Granted Patent B2
US 11,036,534 · App. 16/144,347 · Granted Jun 15, 2021

Techniques for serverless runtime application self-protection

Inventors: Liron Levin (Herzliya, IL); Dima Stopel (Herzliya, IL); Michael Velbaum (Herzliya, IL); Alon Adler (Bat-Yam, IL); Michael Kletselman (Tel Aviv, IL); John Morello (Baton Rouge, LA)
Assignee: TWISTLOCK, Ltd.
G06F9/45558G06F9/44505G06F16/2379G06F21/51G06F21/53G06F21/54G06K9/6256G06N20/00H04L63/20G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,036,534
App. No.
16/144,347
Granted
Jun 15, 2021
Kind
B2
Abstract

A system and method for serverless runtime application self-protection. The method includes embedding a serverless defender function into a function serverless bundle containing an application deployment bundle of a serverless application, wherein the embedding further comprises modifying the function serverless bundle to include a serverless defender shared library and a security policy, wherein the serverless defender shared library is configured to install at least one hook into at least one system call of the serverless application when the serverless application is executed, wherein each hook only allows running of system calls and library functions that satisfy the security policy during execution of the serverless application, wherein the serverless defender function is loaded at a system when the serverless application is initiated by the system, wherein the serverless defender function is configured to perform at least one mitigation action when the security policy is violated during execution of the serverless application.

Claims (34)

1. A method for serverless runtime application self-protection, comprising:

embedding a serverless defender function into a function serverless bundle containing an application deployment bundle of a serverless application, wherein the embedding further comprises modifying the function serverless bundle to include a serverless defender shared library and a security policy, wherein the serverless defender shared library is configured to install at least one hook into at least one system call of the serverless application when the serverless application is executed, wherein each hook only allows running of system calls and library functions that satisfy the security policy during execution of the serverless application, wherein the serverless defender function is loaded at a system when the serverless application is initiated by the system, wherein the serverless defender function is configured to perform at least one mitigation action when the security policy is violated during execution of the serverless application.

2. The method of claim 1 , wherein the embedding further comprises:

injecting loader code into the function serverless bundle, wherein the loader code, when executed by a system, configures the system to load the serverless defender upon startup of the serverless application.

3. The method of claim 2 , further comprising:

hiding at least one environmental variable used to inject the loader code.

4. The method of claim 1 , wherein the at least one mitigation action includes generating an audit, wherein the audit is a report indicating a violation of the security policy.

5. The method of claim 1 , wherein the serverless defender is invoked when a system call occurs.

6. The method of claim 1 , wherein the serverless defender is configured to generate a protected task based on each of at least one task definition of the serverless application.

7. The method of claim 1 , further comprising:

modifying a sidecar container to use an image of the serverless defender and to share a volume with the serverless defender, wherein the modified sidecar container is configured to copy an executable file of the serverless defender and the serverless application shared library to the shared volume.

8. The method of claim 1 , further comprising:

uploading the function serverless bundle to a cloud computing platform for execution of the serverless application and the serverless defender by the cloud computing platform.

9. The method of claim 1 , wherein the serverless defender is run as a first entry point of each of at least one container of the system, wherein the serverless defender is configured to execute a second entry point of each of the at least one container, and to attach the serverless application shared library to each process of each of the at least one container, wherein the second entry point is an original entry point of the container.

10. The method of claim 1 , wherein the serverless application shared library is configured to hijack all functions including interaction with a kernel by the serverless application, wherein the kernel is a kernel of a system executing the serverless application.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

embedding a serverless defender function into a function serverless bundle containing an application deployment bundle of a serverless application, wherein the embedding further comprises modifying the function serverless bundle to include a serverless defender shared library and a security policy, wherein the serverless defender shared library is configured to install at least one hook into at least one system call of the serverless application when the serverless application is executed, wherein each hook only allows running of system calls and library functions that satisfy the security policy during execution of the serverless application, wherein the serverless defender function is loaded at a system when the serverless application is initiated by the system, wherein the serverless defender function is configured to perform at least one mitigation action when the security policy is violated during execution of the serverless application.

12. A system for serverless runtime application self-protection, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

embed a serverless defender function into a function serverless bundle containing an application deployment bundle of a serverless application, wherein the embedding further comprises modifying the function serverless bundle to include a serverless defender shared library and a security policy, wherein the serverless defender shared library is configured to install at least one hook into at least one system call of the serverless application when the serverless application is executed, wherein each hook only allows running of system calls and library functions that satisfy the security policy during execution of the serverless application, wherein the serverless defender function is loaded at a system when the serverless application is initiated by the system, wherein the serverless defender function is configured to perform at least one mitigation action when the security policy is violated during execution of the serverless application.

13. The system of claim 12 , wherein the system is further configured to:

inject loader code into the function serverless bundle, wherein the loader code, when executed by a system, configures the system to load the serverless defender upon startup of the serverless application.

14. The system of claim 13 , wherein the system is further configured to:

hide at least one environmental variable used to inject the loader code.

15. The system of claim 12 , wherein the at least one mitigation action includes generating an audit, wherein the audit is a report indicating a violation of the security policy.

16. The system of claim 12 , wherein the serverless defender is invoked when a system call occurs.

17. The system of claim 12 , wherein the serverless defender is configured to generate a protected task based on each of at least one task definition of the serverless application.

18. The system of claim 12 , wherein the system is further configured to:

modify a sidecar container to use an image of the serverless defender and to share a volume with the serverless defender, wherein the modified sidecar container is configured to copy an executable file of the serverless defender and the serverless application shared library to the shared volume.

19. The system of claim 12 , wherein the system is further configured to:

upload the function serverless bundle to a cloud computing platform for execution of the serverless application and the serverless defender by the cloud computing platform.

20. The system of claim 12 , wherein the serverless defender is run as a first entry point of each of at least one container of the system, wherein the serverless defender is configured to execute a second entry point of each of the at least one container, and to attach the serverless application shared library to each process of each of the at least one container, wherein the second entry point is an original entry point of the container.

21. The system of claim 12 , wherein the serverless application shared library is configured to hijack all functions including interaction with a kernel by the serverless application, wherein the kernel is a kernel of a system executing the serverless application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: TWISTLOCK LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068685/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2018
From: LEVIN, LIRON; STOPEL, DIMA; VELBAUM, MICHAEL; ADLER, ALON; KLETSELMAN, MICHAEL; MORELLO, JOHN
To: TWISTLOCK, LTD.
Reel/Frame 046996/0813 →