IP Library Granted Patent US 12,001,543
Granted Patent B2
US 12,001,543 · App. 17/477,691 · Granted Jun 4, 2024

System and method for container assessment using sandboxing

Inventors: Idan Revivo (Tel Aviv, IL); Yaniv Agman (Hod Hasharon, IL); Roi Kol (Jerusalem, IL); Ziv Karliner (Givatayim, IL)
Assignee: Aqua Security Software, Ltd.
G06F21/53G06F21/564G06F21/566G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,543
App. No.
17/477,691
Granted
Jun 4, 2024
Kind
B2
Abstract

An example method for a software container includes instantiating the following in a sandbox of a computing device: an operating system, a Berkeley Packet Filter (BPF) virtual machine within a kernel of the operating system, and a software container. The kernel monitors runtime behavior events of the software container, with the monitoring at least partially performed by the BPF virtual machine. Based on the monitoring, a respective risk score is assigned to each of the runtime behavior events that is potentially malicious, with each risk score indicating a likelihood that a corresponding behavior event is malicious. An overall risk score is assigned to the software container that indicates a likelihood that the software container is malicious based on the respective risk scores.

Claims (42)

1. A method for a software container, comprising:

instantiating the following in a sandbox of a computing device: an operating system, a Berkeley Packet Filter (BPF) virtual machine within a kernel of the operating system, and a software container;

monitoring runtime behavior events of the software container, wherein the monitoring comprises:

monitoring at least one first type of behavior of the software container by the BPF virtual machine; and

monitoring, by the kernel but outside of the BPF virtual machine, a second type of behavior of the container that is different from the at least one first type of behavior;

assigning, based on the monitoring of the at least one first type of behavior and the second type of behavior of the software container, a respective risk score to each of the runtime behavior events that is potentially malicious, each risk score indicating a likelihood that a corresponding behavior event is malicious; and

assigning an overall risk score to the software container that indicates a likelihood that the software container is malicious based on a highest severity risk score of the respective risk scores.

2. The method of claim 1 , wherein the software container is instantiated from a container image, the method comprising:

assigning, based on static image scanning of the container image, a respective container image risk score to each static scanning event of the container image that is potentially malicious, each container image risk score indicating a likelihood that a corresponding static scanning event is malicious; and

further basing said assigning the overall risk score on the container image risk scores.

3. The method of claim 2 , wherein the software container is instantiated by a container engine, the method comprising:

further monitoring runtime behavior events of the software container from outside the sandbox by reviewing a runtime behavior log file from the container engine;

wherein said assigning the overall risk score is further based on said reviewing the runtime behavior log file.

4. The method of claim 1 , wherein the kernel is a LINUX kernel and the at least one first type of behavior includes one or more of:

system calls to the LINUX kernel;

requests to utilize LINUX security hooks; and

file system requests to the LINUX kernel.

5. The method of claim 4 , wherein the second type of behavior includes network traffic behavior associated with the software container.

6. The method of claim 1 , wherein said assigning an overall risk score to the software container comprises assigning a highest severity risk score of the respective risk scores as the overall risk score.

7. The method of claim 1 , wherein the assigning of the respective risk scores and the overall risk score are performed outside of the sandbox.

8. A computing device comprising:

memory; and

a processor operatively connected to the memory, the processor configured to:

instantiate the following in a sandbox of a computing device: an operating system, a Berkeley Packet Filter (BPF) virtual machine within a kernel of the operating system, and a software container, the sandbox corresponding to a virtual machine that is different from the BPF virtual machine;

monitor runtime behavior events of the software container, wherein to monitor the runtime behavior events, the processor is configured to:

monitor at least one first type of behavior of the software container by the BPF virtual machine; and

monitor, by the kernel but outside of the BPF virtual machine, a second type of behavior of the software container that is different from the at least one first type of behavior;

assign, based on the monitoring of the at least one first type of behavior and the second type of behavior of the software container, a respective risk score to each of the runtime behavior events that is potentially malicious, each risk score indicating a likelihood that a corresponding behavior event is malicious; and

assign an overall risk score to the software container that indicates a likelihood that the software container is malicious based on a highest severity risk score of the respective risk scores.

9. The computing device of claim 8 , wherein the software container is instantiated from a container image, and the processor is configured to:

assign, based on static image scanning of the container image, a respective container image risk score to each static scanning event of the container image that is potentially malicious, each container image risk score indicating a likelihood that a corresponding static scanning event is malicious; and

further base the assignment of the overall risk score on the container image risk scores.

10. The computing device of claim 9 , wherein the software container is instantiated by a container engine and the processor is configured to:

further monitor runtime behavior events of the software container from outside the sandbox by reviewing a runtime behavior log file from the container engine; and

further base the assignment of the overall risk score on the reviewing of the log file.

11. The computing device of claim 8 , wherein the kernel is a LINUX kernel and the at least one first type of behavior includes one or more of:

system calls to the LINUX kernel;

requests to utilize LINUX security hooks; and

file system requests to the LINUX kernel.

12. The computing device of claim 11 , wherein the second type of behavior includes network traffic behavior associated with the software container.

13. The computing device of claim 8 , wherein the processor is configured to assign a highest severity risk score of the respective risk scores as the overall risk score.

14. The computing device of claim 8 , wherein the processor is configured to assign the respective risk scores and the overall risk score outside of the sandbox.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 3, 2026
From: BANK LEUMI LE-ISRAEL B.M.
To: AQUA SECURITY SOFTWARE LTD.
Reel/Frame 075495/0666 →
SECURITY INTEREST Recorded Jul 29, 2026
From: AQUA SECURITY SOFTWARE LTD
To: HSBC BANK PLC
Reel/Frame 075441/0921 →
SECURITY INTEREST Recorded Jul 30, 2023
From: AQUA SECURITY SOFTWARE LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 064429/0026 →
SECURITY INTEREST Recorded Nov 7, 2022
From: AQUA SECURITY SOFTWARE LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 061668/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: ROBERTSON, DOUGLAS LAWRENCE; PIZER, ADAM
To: IKEYLESS, LLC
Reel/Frame 057802/0793 →
Continuity (2)
Continuation 16838903 · Apr 2, 2020
Related Publication 20220004624A1 · Jan 6, 2022
Cited By (1)
US 12,455,965