IP Library Granted Patent US 12,425,441
Granted Patent B2
US 12,425,441 · App. 18/349,348 · Granted Sep 23, 2025

Systems and methods for protecting pod deployment

Inventors: Alexei Kravtsov (Petah Tikva, IL); Idan Frimark (Tzora, IL); Erez Fishhimer (Tel-Aviv, IL)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1433H04L63/0263H04L63/105H04L63/1408H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,441
App. No.
18/349,348
Granted
Sep 23, 2025
Kind
B2
Abstract

In one embodiment, a method includes generating, by a pod deployment tool, a security context profile, associating, by the pod deployment tool, the security context profile with a deployment rule, and associating, by the pod deployment tool, a vulnerability level with the deployment rule. The method also includes identifying, by the pod deployment tool, pod policies associated with a pod located within a cluster of a network and analyzing, by the pod deployment tool, conditions of the deployment rule using the pod policies. The conditions may be associated with the security context profile and the vulnerability level. The method further includes determining, by the pod deployment tool, whether to allow deployment of the pod within the network in response to analyzing the conditions of the deployment rule.

Claims (82)

1. An apparatus, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the apparatus to perform operations comprising:

generating, prior to a deployment of a pod, a profile;

associating the profile with a deployment rule;

analyzing conditions of the deployment rule using a plurality of pod policies, wherein the plurality of pod policies is associated with the pod; and

determining whether to allow the deployment of the pod in response to analyzing the conditions of the deployment rule.

2. The apparatus of claim 1 , the operations further comprising:

monitoring the pod;

receiving, in response to monitoring the pod, a first pod policy of the plurality of pod policies; and

generating, using the first pod policy, a second pod policy of the plurality of pod policies.

3. The apparatus of claim 2 , wherein:

the first pod policy allows privilege escalation; and

the second pod policy is a vulnerability level associated with the pod.

4. The apparatus of claim 1 , wherein the profile is one of the following profiles:

a strict security context profile;

a flexible security context profile,

a recommended security profile,

a non-root read-only profile, or

anew security profile.

5. The apparatus of claim 1 , wherein:

the conditions of the deployment rule are associated with a vulnerability level; and

the vulnerability level is one of the following:

critical;

high;

medium; or

low.

6. The apparatus of claim 1 , the operations further comprising determining to allow the deployment of the pod when the plurality of pod policies satisfy the conditions of the deployment rule.

7. The apparatus of claim 1 , the operations further comprising determining to block the deployment of the pod when one or more of the plurality of pod policies fail to satisfy one or more of the conditions of the deployment rule.

8. A method, comprising:

generating, by a computing device and prior to a deployment of a pod, a profile;

associating the profile with a deployment rule;

analyzing conditions of the deployment rule using a plurality of pod policies, wherein the plurality of pod policies is associated with the pod; and

determining whether to allow the deployment of the pod in response to analyzing the conditions of the deployment rule.

9. The method of claim 8 , further comprising:

monitoring the pod;

receiving, in response to monitoring the pod, a first pod policy of the plurality of pod policies; and

generating, using the first pod policy, a second pod policy of the plurality of pod policies.

10. The method of claim 9 , wherein:

the first pod policy allows privilege escalation; and

the second pod policy is a vulnerability level associated with the pod.

11. The method of claim 8 , wherein the profile is one of the following profiles:

a strict security context profile;

a flexible security context profile,

a recommended security profile,

a non-root read-only profile, or

anew security profile.

12. The method of claim 8 , wherein:

the conditions of the deployment rule are associated with a vulnerability level; and

the vulnerability level is one of the following:

critical;

high;

medium; or

low.

13. The method of claim 8 , further comprising determining to allow the deployment of the pod when the plurality of pod policies satisfy the conditions of the deployment rule.

14. The method of claim 8 , further comprising determining to block the deployment of the pod when one or more of the plurality of pod policies fail to satisfy one or more of the conditions of the deployment rule.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

generating, prior to a deployment of a pod, a profile;

associating the profile with a deployment rule;

analyzing conditions of the deployment rule using a plurality of pod policies, wherein the plurality of pod policies is associated with the pod; and

determining whether to allow the deployment of the pod in response to analyzing the conditions of the deployment rule.

16. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

monitoring the pod;

receiving, in response to monitoring the pod, a first pod policy of the plurality of pod policies; and

generating, using the first pod policy, a second pod policy of the plurality of pod policies.

17. The one or more computer-readable non-transitory storage media of claim 16 , wherein:

the first pod policy allows privilege escalation; and

the second pod policy is a vulnerability level associated with the pod.

18. The one or more computer-readable non-transitory storage media of claim 15 , wherein the profile is one of the following profiles:

a strict security context profile;

a flexible security context profile,

a recommended security profile,

a non-root read-only profile, or

anew security profile.

19. The one or more computer-readable non-transitory storage media of claim 15 , wherein:

the conditions of the deployment rule are associated with a vulnerability level; and

the vulnerability level is one of the following:

critical;

high;

medium; or

low.

20. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising determining to allow the deployment of the pod when the plurality of pod policies satisfy the conditions of the deployment rule.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2023
From: KRAVTSOV, ALEXEI; FRIMARK, IDAN; FISHHIMER, EREZ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064198/0029 →
Continuity (3)
Continuation 17335848 · Jun 1, 2021
Provisional Application 63145579 · Feb 4, 2021
Related Publication 20230353593A1 · Nov 2, 2023
References Cited (44)
US 9313211B1 · Lototskiy · 2016 [cited by examiner]
US 9811667B2 · Hugard, IV · 2017 [cited by examiner]
US 10719369B1 · Aithal · 2020 [cited by examiner]
US 10754701B1 · Wagner · 2020 [cited by applicant]
US 10824726B1 · Herman Saffar · 2020 [cited by examiner]
US 10911404B1 · Argenti · 2021 [cited by applicant]
US 10938743B1 · Andrews · 2021 [cited by applicant]
US 10979446B1 · Stevens · 2021 [cited by examiner]
US 11050787B1 · Sharifi Mehr · 2021 [cited by examiner]
US 11134098B1 · Lieberman · 2021 [cited by examiner]
US 11516222B1 · Srinivasan · 2022 [cited by examiner]
US 12052285B1 · Anjaneyapura Range · 2024 [cited by examiner]
US 20050268336A1 · Finnegan · 2005 [cited by applicant]
US 20080134177A1 · Fitzgerald · 2008 [cited by applicant]
US 20100175108A1 · Protas · 2010 [cited by applicant]
US 20110145916A1 · McKenzie · 2011 [cited by applicant]
US 20110214176A1 · Burch · 2011 [cited by applicant]
US 20140053226A1 · Fadida · 2014 [cited by examiner]
US 20140115578A1 · Cooper · 2014 [cited by applicant]
US 20140317677A1 · Vaidya · 2014 [cited by applicant]
US 20150254451A1 · Doane · 2015 [cited by applicant]
US 20150312274A1 · Bishop · 2015 [cited by examiner]
US 20170054685A1 · Malkov · 2017 [cited by applicant]
US 20170214767A1 · Johnsen · 2017 [cited by applicant]
US 20170270313A1 · Achutha · 2017 [cited by applicant]
US 20170279770A1 · Woolward · 2017 [cited by applicant]
US 20180198824A1 · Pulapaka · 2018 [cited by applicant]
US 20180232517A1 · Roth · 2018 [cited by applicant]
US 20180287902A1 · Chitalia et al. · 2018 [cited by applicant]
US 20180300499A1 · Agarwal · 2018 [cited by examiner]
US 20180316725A1 · Mani · 2018 [cited by applicant]
US 20180324203A1 · Estes · 2018 [cited by examiner]
US 20180365435A1 · Anandam · 2018 [cited by examiner]
US 20190005246A1 · Cherny · 2019 [cited by applicant]
US 20200099721A1 · Golan · 2020 [cited by examiner]
US 20200184089A1 · Ponsini · 2020 [cited by examiner]
US 20200218798A1 · Kosaka et al. · 2020 [cited by applicant]
US 20210133329A1 · Andrews · 2021 [cited by applicant]
US 20210168093A1 · Andrews · 2021 [cited by examiner]
US 20210374014A1 · Appireddygari Venkataramana · 2021 [cited by examiner]
US 20220131888A1 · Kanso · 2022 [cited by examiner]
US 20230112579A1 · Parenti · 2023 [cited by examiner]
CN 109413065A · 2019 [cited by applicant]
CN 111694633A · 2020 [cited by applicant]