IP Library Granted Patent US 11,394,750
Granted Patent B1
US 11,394,750 · App. 16/805,208 · Granted Jul 19, 2022

System and method for generating network security policies in a distributed computation system utilizing containers

Inventors: Malte Isberner (Mountain View, CA); Connor Gorman (Mountain View, CA); Wei Lien Dang (Mountain View, CA); Hillary Benson (Mountain View, CA); Connor Gilbert (Mountain View, CA)
Assignee: Red Hat, Inc.
H04L63/20H04L41/22H04L43/067H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,394,750
App. No.
16/805,208
Granted
Jul 19, 2022
Kind
B1
Abstract

A server has a processor and a memory connected to the processor. The memory stores instructions executed by the processor to collect operating signals from machines. The operating signals characterize establishing or closing a network connection associated with a designated application operating within a designated container. The designated container is an isolated process in user space designated by an operating system kernel. A network security policy that permits network connections based upon the operating signals collected is automatically generated.

Claims (22)

1. A server, comprising:

a processor; and

a memory connected to the processor, the memory storing instructions executable by the processor to:

collect operating signals from a machine, wherein the operating signals characterize establishing or closing a network connection by each of a plurality of containers running on the machine in a same namespace, each container being an isolated process in user space designated by an operating system kernel;

generate, based on the operating signals, data that identifies a state of outgoing connections of each container of the plurality of containers running on the machine; and

automatically generate, based on the data, a network security policy that permits certain network connections to at least one container of the plurality of containers and prohibits other network connections to the at least one container of the plurality of containers.

2. The server of claim 1 wherein the operating signals are collected during a configurable window of time.

3. The server of claim 1 wherein the operating signals include a container identification within a container orchestrator workload.

4. The server of claim 1 wherein the operating signals include a pod Internet Protocol address.

5. The server of claim 1 wherein the operating signals include a service Internet Protocol address.

6. The server of claim 1 wherein the operating signals include a node Internet Protocol address for a node port.

7. The server of claim 1 wherein the operating signals include a node Internet Protocol address for a host port.

8. The server of claim 1 further comprising instructions executable by the processor to display a network graph characterizing interactions between networked resources.

9. The server of claim 1 further comprising instructions executable by the processor to simulate the network security policy.

10. The server of claim 1 further comprising instructions executable by the processor to supply network security policy analytics.

11. The server of claim 10 wherein the network security policy analytics include an allowed network connections graph.

12. The server of claim 10 wherein the network security policy analytics include an active network connections graph.

13. The server of claim 1 wherein the network security policy is expressed in a YAML file format.

14. A method comprising:

collecting, by a server comprising a processor and a memory connected to the processor, operating signals from a machine, wherein the operating signals characterize establishing or closing a network connection by each of a plurality of containers running on the machine in a same namespace, each container being an isolated process in user space designated by an operating system kernel;

generating, based on the operating signals, data that identifies a state of outgoing connections of each container of the plurality of containers running on the machine; and

automatically generating, based on the data, a network security policy that permits certain network connections to at least one container of the plurality of containers and prohibits other network connections to the at least one container of the plurality of containers.

Assignments (4)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: STACKROX, INC.
To: RED HAT, INC.
Reel/Frame 055686/0345 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: ISBERNER, MALTE; GORMAN, CONNOR; DANG, WEI LIEN; BENSON, HILLARY; GILBERT, CONNOR
To: STACKROX, INC.
Reel/Frame 055687/0394 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2020
From: ISBERNER, MALTE; GORMAN, CONNOR; DANG, WEI LIEN; BENSON, HILLARY; GILBERT, CONNOR
To: STACKROX, INC.
Reel/Frame 051997/0603 →
Cited By (1)
US 12,267,208