IP Library › Granted Patent US 12,348,646
Granted Patent B2
US 12,348,646 · App. 18/333,109 · Granted Jul 1, 2025

Techniques for validating a virtual workload signature from a software repository

Inventors: Amir Lande Blau (Tel Aviv, IL); Roy Reznik (Tel Aviv, IL); Bar Magnezi (Tel Aviv, IL)
Assignee: Wiz, Inc.
H04L9/3247G06F8/63G06F8/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,646
App. No.
18/333,109
Filed
Jun 12, 2023
Granted
Jul 1, 2025
Kind
B2
Art Unit
2443
USPC
713/189
Abstract

In some implementations, the device may include detecting a virtual instance deployed in a computing environment, the virtual instance deployed based on a software image. In addition, the device may include detecting an image name of the software image. The device may include accessing an image software repository to retrieve the software image based on the detected image name. Moreover, the device may include initiating validation of the retrieved software image. Also, the device may include initiating a mitigation action on the virtual instance in response to detecting that the retrieved software image is an invalid software image.

Claims (61)

1. A method for validating a software image of a virtual instance deployed in a computing environment, comprising:

detecting a virtual instance deployed in a computing environment, the virtual instance deployed based on a software image;

detecting an image name of the software image;

accessing an image software repository to retrieve the software image based on the detected image name;

initiating validation of the retrieved software image and;

initiating a mitigation action on the virtual instance in response to detecting that the retrieved software image is an invalid software image.

2. The method of claim 1 , further comprising:

configuring an admission controller of a software container cluster deployed in the computing environment to detect the virtual instance, wherein the virtual instance is a software container deployed in the software container cluster.

3. The method of claim 1 , further comprising:

accessing a public key of the software image, wherein the software image is a signed software image; and

performing validation by decrypting the signed software image using the public key.

4. The method of claim 1 , further comprising:

revoking the virtual instance in response to detecting that the validation of the software image is unsuccessful.

5. The method of claim 1 , wherein the mitigation action includes any one of:

sandboxing the virtual instance, revoking access to the virtual instance, revoking access from the virtual instance, deprovisioning the virtual instance, and any combination thereof.

6. The method of claim 1 , further comprising:

detecting an earlier version of the software image;

deprovisioning the virtual instance in response to detecting that the retrieved software image is an invalid software image; and

deploying the earlier version of the software image, in response to determining that the earlier version is a validated version.

7. The method of claim 6 , further comprising:

validating the earlier version of the software image.

8. The method of claim 1 , wherein the mitigation action includes any one of:

generating an alert, generating a notification, generating a ticket, and any combination thereof.

9. The method of claim 1 , further comprising:

parsing a name of the virtual instance to detect a repository identifier; and

accessing an image software repository corresponding to the repository identifier.

10. A non-transitory computer-readable medium storing a set of instructions for validating a software image of a virtual instance deployed in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect a virtual instance deployed in a computing environment, the virtual instance deployed based on a software image;

detect an image name of the software image;

access an image software repository to retrieve the software image based on the detected image name;

initiate validation of the retrieved software image; and

initiate a mitigation action on the virtual instance in response to detecting that the retrieved software image is an invalid software image.

11. A system for validating a software image of a virtual instance deployed in a computing environment comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a virtual instance deployed in a computing environment, the virtual instance deployed based on a software image;

detect an image name of the software image;

access an image software repository to retrieve the software image based on the detected image name;

initiate validation of the retrieved software image; and

initiate a mitigation action on the virtual instance in response to detecting that the retrieved software image is an invalid software image.

12. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure an admission controller of a software container cluster deployed in the computing environment to detect the virtual instance, wherein the virtual instance is a software container deployed in the software container cluster.

13. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

access a public key of the software image, wherein the software image is a signed software image; and

perform validation by decrypting the signed software image using the public key.

14. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

revoke the virtual instance in response to detecting that the validation of the software image is unsuccessful.

15. The system of claim 11 , wherein the mitigation action includes any one of:

sandboxing the virtual instance, revoking access to the virtual instance, revoking access from the virtual instance, deprovisioning the virtual instance, and any combination thereof.

16. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect an earlier version of the software image;

deprovision the virtual instance in response to detecting that the retrieved software image is an invalid software image; and

deploy the earlier version of the software image, in response to determining that the earlier version is a validated version.

17. The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

validate the earlier version of the software image.

18. The system of claim 11 , wherein the mitigation action includes any one of:

generating an alert, generating a notification, generating a ticket, and any combination thereof.

19. The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

parse a name of the virtual instance to detect a repository identifier; and

access an image software repository corresponding to the repository identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2023
From: BLAU, AMIR LANDE; REZNIK, ROY; MAGNEZI, BAR
To: WIZ, INC.
Reel/Frame 064197/0614 →
Continuity (1)
Related Publication 20240414006A1 · Dec 12, 2024
References Cited (8)
US 8291468B1 · Chickering · 2012 [cited by applicant]
US 10116670B2 · Muddu et al. · 2018 [cited by applicant]
US 11411958B2 · Pularikkal et al. · 2022 [cited by applicant]
US 11601512B2 · Xiao et al. · 2023 [cited by applicant]
US 20150254451A1 · Doane · 2015 [cited by examiner]
US 20160350535A1 · Garcia · 2016 [cited by examiner]
US 20210124593A1 · Tseng · 2021 [cited by examiner]
US 20220166626A1 · Madisetti · 2022 [cited by examiner]
Cited By (1)
US 12,488,078