IP Library Granted Patent US 11,989,308
Granted Patent B2
US 11,989,308 · App. 17/383,252 · Granted May 21, 2024

Method to intelligently manage the end to end container compliance in cloud environments

Inventors: Suren Kumar (Bangalore, IN); Vinod Durairaj (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F21/577G06N5/02G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,989,308
App. No.
17/383,252
Granted
May 21, 2024
Kind
B2
Abstract

One example method includes collecting container information concerning a container, analyzing the container information to identify a security tool needed to perform a vulnerability scan of the container, accessing the security tool from a knowledge lake, running the security tool on the container information to identify a security vulnerability of the container, based on the running of the security tool, generating an alert indicating that the container has the security vulnerability, capturing the security vulnerability and, based on the captured security vulnerability, updating a container image that was used to spawn the container.

Claims (34)

1. A method, comprising the operations:

collecting container information concerning a container with port information of communication undertaken by the container;

analyzing the container information and the port information to identify a security tool needed to perform a vulnerability scan of the container;

accessing the security tool from a knowledge lake;

running the security tool on the container information to identify a security vulnerability of the container;

based on the running of the security tool, generating an alert indicating that the container has the security vulnerability;

capturing the security vulnerability; and

based on the captured security vulnerability, updating a container image that was used to spawn the container.

2. The method as recited in claim 1 , wherein capturing the security vulnerability comprises updating a fixed profile associated with the container to indicate that the container has the security vulnerability and to indicate a resolution to the security vulnerability.

3. The method as recited in claim 1 , wherein updating the container image comprises modifying the container image to eliminate the security vulnerability.

4. The method as recited in claim 1 , wherein the alert further indicates a security fix to the security vulnerability.

5. The method as recited in claim 1 , wherein the security vulnerability is captured in a fixed profile associated with the container, and the fixed profile includes all security fixes that have been previously implemented with respect to the container.

6. The method as recited in claim 1 , wherein a new container created with the updated container image includes a security fix identified by the alert.

7. The method as recited in claim 1 , wherein the container information is collected and presented to a device management console by way of a pass-through channel between the device management console and a host that includes the container.

8. The method as recited in claim 1 , wherein a number of security tools employed by an elastic container security hub scales up and/or down in accordance with a number of containers that are running.

9. The method as recited in claim 1 , wherein the container image is updated automatically when a human user does not respond to the alert within a specified time interval.

10. The method as recited in claim 1 , wherein the operations further comprise receiving a new container request, and generating a new container using the updated container image.

11. A computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

collecting container information concerning a container with port information of communication undertaken by the container;

analyzing the container information and the port information to identify a security tool needed to perform a vulnerability scan of the container;

accessing the security tool from a knowledge lake;

running the security tool on the container information to identify a security vulnerability of the container;

based on the running of the security tool, generating an alert indicating that the container has the security vulnerability;

capturing the security vulnerability; and

based on the captured security vulnerability, updating a container image that was used to spawn the container.

12. The computer readable storage medium as recited in claim 11 , wherein capturing the security vulnerability comprises updating a fixed profile associated with the container to indicate that the container has the security vulnerability and to indicate a resolution to the security vulnerability.

13. The computer readable storage medium as recited in claim 11 , wherein updating the container image comprises modifying the container image to eliminate the security vulnerability.

14. The computer readable storage medium as recited in claim 11 , wherein the alert further indicates a security fix to the security vulnerability.

15. The computer readable storage medium as recited in claim 11 , wherein the security vulnerability is captured in a fixed profile associated with the container, and the fixed profile includes all security fixes that have been previously implemented with respect to the container.

16. The computer readable storage medium as recited in claim 11 , wherein a new container created with the updated container image includes a security fix identified by the alert.

17. The computer readable storage medium as recited in claim 11 , wherein the container information is collected and presented to a device management console by way of a pass-through channel between the device management console and a host that includes the container.

18. The computer readable storage medium as recited in claim 11 , wherein a number of security tools employed by an elastic container security hub scales up and/or down in accordance with a number of containers that are running.

19. The computer readable storage medium as recited in claim 11 , wherein the container image is updated automatically when a human user does not respond to the alert within a specified time interval.

20. The computer readable storage medium as recited in claim 11 , wherein the operations further comprise receiving a new container request, and generating a new container using the updated container image.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2022
From: KUMAR, SUREN; DURAIRAJ, VINOD
To: EMC IP HOLDING COMPANY
Reel/Frame 059309/0948 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
Priority Claims (1)
IN 202111023665 · May 27, 2021 · national
Continuity (1)
Related Publication 20220382879A1 · Dec 1, 2022
Cited By (1)
US 12,417,293