IP Library Granted Patent US 11,483,329
Granted Patent B1
US 11,483,329 · App. 17/067,593 · Granted Oct 25, 2022

Using a logical graph of a containerized network environment

Inventors: Harish Kumar Bharat Singh (Mountain View, CA); Vikram Kapoor (Cupertino, CA)
Assignee: Lacework Inc.
H04L63/1425G06F9/45558G06N3/006H04L63/1416G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,329
App. No.
17/067,593
Granted
Oct 25, 2022
Kind
B1
Abstract

Log data associated with an environment that includes containers is received. An example of such an environment is one managed by Kubernetes. A logical graph is generated using at least a portion of the received log data. The logical graph is used to detect an anomaly. In response to the anomaly being detected, the anomaly is recorded.

Claims (31)

1. A system, comprising:

a memory storing instructions; and

a processor coupled to the memory and configured to execute the instructions to:

receive log data associated with a containerized network environment;

generate a logical graph using at least a portion of the received log data, at least in part by clustering multiple items into a node of the logical graph based at least in part on launching behaviors of components in the containerized network environment; and

use the logical graph to respond to a query received from a computer, at least in part by providing, in response to the query, data representing a portion of the logical graph to the computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

2. The system of claim 1 wherein the containerized network environment is a hybridized environment and wherein the logical graph includes nodes corresponding to non-containerized processes.

3. The system of claim 2 wherein operating system information associated with the non-containerized processes is used to define an artificial containerization overlay for the non-containerized processes.

4. The system of claim 1 wherein generating the logical graph includes clustering a plurality of Kubernetes namespaces based on launching behaviors of the Kubernetes namespaces.

5. The system of claim 1 wherein generating the logical graph includes clustering a plurality of pods based at least in part on launching behaviors of the pods.

6. The system of claim 1 wherein generating the logical graph includes clustering a plurality of pods based at least in part on which namespaces launch the pods.

7. The system of claim 1 wherein the log data comprises one or more tags associated with the containerized network environment.

8. The system of claim 1 wherein the processor is configured to detect an anomaly at least in part by generating a baseline for a Kubernetes cluster.

9. The system of claim 1 wherein the processor is further configured to determine a pod type for a pod.

10. The system of claim 1 wherein the processor is further configured to use the query response to detect an anomaly.

11. The system of claim 1 wherein responding to the query includes identifying a particular set of one or more clusters that are executing a queried-for application.

12. The system of claim 1 wherein the node represents the multiple items in the logical graph.

13. The system of claim 1 wherein the generated logical graph comprises a plurality of vertical tiers of clusters.

14. The system of claim 1 wherein the generated logical graph comprises a plurality of horizontal tiers.

15. A method, comprising:

receiving log data associated with a containerized network environment;

generating a logical graph using at least a portion of the received log data, at least in part by clustering multiple nodes into a single node of the logical graph based at least in part on launching behaviors of components in the containerized network environment; and

using the logical graph to respond to a query received from a computer, at least in part by providing, in response to the query, data representing a portion of the logical graph to the computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

16. The method of claim 15 wherein the data representing the portion of the logical graph comprises data representing the node into which the multiple items are clustered.

17. The method of claim 15 wherein generating the logical graph includes clustering multiple nodes representing a plurality of namespaces into a single node based on launching behaviors of the namespaces.

18. The method of claim 15 wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on launching behaviors of the pods.

19. The method of claim 15 wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on which namespaces launch the pods.

20. A computer program product embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

receiving log data associated with a containerized network environment;

generating a logical graph using at least a portion of the received log data, at least in part by clustering multiple nodes into a single node of the logical graph based at least in part on launching behaviors of components in the containerized network environment; and

using the logical graph to respond to a query received from a computer, at least in part by providing, in response to the query, data representing a portion of the logical graph to the computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: SINGH, HARISH KUMAR BHARAT; KAPOOR, VIKRAM
To: LACEWORK, INC.
Reel/Frame 060225/0104 →