IP Library › Granted Patent US 12,452,281
Granted Patent B2
US 12,452,281 · App. 18/055,900 · Granted Oct 21, 2025

Automated container security

Inventors: Thiagarajan Ramakrishnan (Round Rock, TX); Shamik Kacker (Austin, TX); Leandro Lopes (Austin, TX)
Assignee: DELL PRODUCTS, L.P.
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,281
App. No.
18/055,900
Granted
Oct 21, 2025
Kind
B2
Abstract

Architectures and techniques are described that can automate container security elements in the context of applications being deployed on a container orchestration platform. Techniques detailed herein can serve to increase awareness of container product security in an automated manner, can automate processes on detecting security vulnerabilities and bringing down insecure workspaces, can automate processes for mitigating the security vulnerabilities, notifying, verifying, and bringing the associated containers back online.

Claims (37)

1. A device, comprising:

a processor; and

a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:

scanning containerized applications deployed on a container orchestration platform and identifying a vulnerability of a containerized application of the containerized applications;

performing a vulnerability mitigation procedure that identifies solution data based on a source of the vulnerability, where in the source represents a portion of the containerized application that exhibits the vulnerability, and wherein the solution data is indicated to mitigate the vulnerability of the containerized application and is determined in response to building a docker file that is constructed as a function of the source of the vulnerability;

determining a confidence score indicative of a likelihood that the containerized application to function nominally after application of the solution data that is selected as a function of the source of the vulnerability; and

in response to the confidence score being above a defined threshold, applying the solution data to the containerized application.

2. The device of claim 1 , wherein the solution data is at least one of:

update data that, when applied, updates the containerized application, patch data that, when applied, patches the containerized application, or vulnerability removal data that, when applied removes a dependency of the containerized application.

3. The device of claim 1 , wherein the solution data is identified in response to comparing the vulnerability to a common vulnerabilities and exposures database.

4. The device of claim 1 , wherein the confidence score is determined as a function of a history of success resulting from previously applying the solution data to other containerized applications.

5. The device of claim 1 , wherein the vulnerability mitigation procedure further comprises determining, from among multiple sections of the containerized application, the source of the vulnerability.

6. The device of claim 1 , wherein the source of the vulnerability is one of:

a first source indicative of the vulnerability being in a base image, a second source indicative of the vulnerability being in an operating system dependency, a third source indicative of the vulnerability being in a driver, or a fourth source indicative of the vulnerability being in a Python dependency.

7. The device of claim 1 , wherein the vulnerability mitigation procedure identifies multiple instances of solution data and selects from among the multiple instances of solution data the solution data that is determined to have a highest respective confidence score.

8. The device of claim 1 , wherein the multiple instances of solution data are determined as a function of the source of the vulnerability.

9. The device of claim 1 , wherein the operations further comprise generating report data that describes the vulnerability.

10. The device of claim 9 , wherein the report data comprises a first reference to the vulnerability and a second reference to the solution data.

11. The device of claim 9 , wherein the operations further comprise transmitting the report data to a customer device of an entity that manages the containerized application.

12. The device of claim 1 , wherein identifying the vulnerability of the containerized application comprises determining that a vulnerability severity score indicative of a severity of the vulnerability is above a severity threshold.

13. A non-transitory computer-readable medium comprising instructions that, in response to execution, cause a system comprising a processor to perform operations, comprising:

in response to parsing containerized applications deployed on a container orchestration platform, identify a vulnerability of a containerized application of the containerized applications and a source of the vulnerability, wherein the source represents a portion of the containerized application that exhibits the vulnerability;

perform a vulnerability mitigation procedure that identifies solution data as a function of the source of the vulnerability, wherein the solution data mitigates the vulnerability and is generated in response to building a docker file constructed as a function of the source of the vulnerability;

determine a confidence score indicative of a likelihood that the containerized application functions nominally after application of the solution data, wherein the solution data is determined based on the source of the vulnerability; and

in response to the confidence score being above a defined threshold, apply the solution data to the containerized application.

14. The non-transitory computer-readable medium of claim 13 , wherein

the solution data is identified in response to comparing the vulnerability to a common vulnerabilities and exposures database.

15. The non-transitory computer-readable medium of claim 13 , wherein the confidence score is determined as a function of a history of success resulting from previously applying the solution data to other containerized applications.

16. The non-transitory computer-readable medium of claim 13 , wherein the vulnerability mitigation procedure further comprises determining, from among multiple sections of the containerized application, the source of the vulnerability.

17. A method, comprising:

in response to scanning containerized applications deployed on a container orchestration platform, identifying, by a device comprising a processor, a vulnerability of a containerized application of the containerized applications, and identifying a source of the vulnerability, wherein the source represents a portion of the containerized application that exhibits the vulnerability;

performing, by the device, a vulnerability mitigation procedure that identifies, based on the source of the vulnerability, solution data that is indicated to mitigate the vulnerability of the containerized application, wherein the solution data is determined in response to building a docker file constructed as a function of the source of the vulnerability;

determining, by the device, a confidence score that is indicative of a probability that the containerized application functions nominally after application of the solution data that is selected as a function of the source of the vulnerability; and

in response to the confidence score being above a defined threshold, applying, by the device, the solution data to the containerized application.

18. The method of claim 17 , further comprising generating, by the device, report data that describes the vulnerability comprising a first reference to the vulnerability and a second reference to the solution data.

19. The method of claim 17 , further comprising transmitting, by the device, the report data to a customer device of an entity that manages the containerized application.

20. The method of claim 17 , further comprising identifying, by the device, the vulnerability of the containerized application comprises determining that a vulnerability severity score indicative of a severity of the vulnerability is above a severity threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2022
From: RAMAKRISHNAN, THIAGARAJAN; KACKER, SHAMIK; LOPES, LEANDRO
To: DELL PRODUCTS, L.P.
Reel/Frame 061789/0712 →
Continuity (1)
Related Publication 20240163306A1 · May 16, 2024
References Cited (26)
US 11070582B1 · Berger · 2021 [cited by examiner]
US 11122073B1 · Cai · 2021 [cited by examiner]
US 11895101B2 · Montemayor et al. · 2024 [cited by applicant]
US 20180109387A1 · Vyas · 2018 [cited by examiner]
US 20190354690A1 · Brigandi · 2019 [cited by examiner]
US 20200252423A1 · Hogg · 2020 [cited by examiner]
US 20200265134A1 · Cristina · 2020 [cited by examiner]
US 20210099478A1 · Seetharamaiah · 2021 [cited by examiner]
US 20210329022A1 · Chhetri · 2021 [cited by examiner]
US 20210352104A1 · Sampat · 2021 [cited by examiner]
US 20210367966A1 · Yanay · 2021 [cited by examiner]
US 20220200869A1 · Erlingsson · 2022 [cited by examiner]
US 20220329616A1 · O'Hearn · 2022 [cited by examiner]
US 20240168855A1 · Lopes et al. · 2024 [cited by applicant]
National Research Council, et al. “Frontiers in Massive Data Analysis” [https://nap.nationalacademies.org/catalog/18374/frontiers-in-massive-data-analysis], 2013, 191 pages. [cited by applicant]
“What Is Kubernetes Container Security?” TrendMicro. [https://www.trendmicro.com/en_us/what-is/container-security/kubernetes.html], retrieved Aug. 28, 2025, 5 pages. [cited by applicant]
Lakshminarayan et al., “Enterprise-wide Machine Learning using Teradata Vantage: An Integrated Analytics Platform” 2019 IEEE International Conference on Big Data (Big Data), Dec. 2019, 4 pages. [cited by applicant]
Moradi, et al. “Reproducible Model Sharing for AI Practitioners” [https://dl.acm.org/doi/pdf/10.1145/3493652.3505630], DIDL '21, Dec. 6, 2021, Virtual Event, Canada, 6 pages. [cited by applicant]
“DevOps Terminology: A Glossary” Plutora. [https://www.plutora.com/devops-at-scale/terminology-glossary], retrieved Sep. 26, 2022, 12 pages. [cited by applicant]
Mehrotra, et al. “Supporting “Big Data” Analysis and Analytics at the NASA Advanced Supercomputing (NAS) Facility” NAS Technical Report: NAS-2014-02, Jan. 29, 2014, 19 pages. [cited by applicant]
Sculley, et al. “Hidden Technical Debt in Machine Learning Systems” Advances in Neural Information Processing Systems 28, 2015, 9 pages. [cited by applicant]
“secureIT-project / CVEfixes” GitHub. [https://github.com/secureIT-project/CVEfixes], retrieved Aug. 28, 2025, 4 pages. [cited by applicant]
Osnat, Rani. “Kubernetes Security Basics and 10 Essential Best Practices” AquaSec. [https://www.aquasec.com/cloud-native-academy/kubernetes-in-production/kubernetes-security-best-practices-10-steps-to-securing-k8s/], De… [cited by applicant]
“Our Partners for your ICT-Security, Network & Cloud environments” Infoguard. [https://www.infoguard.ch/en/partners/twistlock-container-security] retrieved Aug. 28, 2025, 47 pages. [cited by applicant]
“Twistlock: Prisma Cloud Container Security Overview and Analysis” eSecurityPlanet. [https://www.esecurityplanet.com/products/twistlock/] retrieved Aug. 28, 2025, 10 pages. [cited by applicant]
“CVE-2020-27153” debian. [https://security-tracker.debian.org/tracker/CVE-2020-27153] retrieved Aug. 28, 2025, 1 page. [cited by applicant]