IP Library Granted Patent US 12,301,433
Granted Patent B2
US 12,301,433 · App. 18/420,610 · Granted May 13, 2025

Automated service-oriented performance management

Inventor: Loris Degioanni (Davis, CA)
Assignee: Sysdig, Inc.
H04L41/5058H04L41/5041H04L43/045H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,433
App. No.
18/420,610
Granted
May 13, 2025
Kind
B2
Abstract

A monitoring system is configured to receive information regarding a microservice run in one or more containers at a computing cluster; submit a request to a cluster manager of the computing cluster via an application programming interface (API) for adding one or more configurations for monitoring the microservice to a configuration dataset managed by the cluster manager; receive monitoring data related to the microservice in accordance with the one or more configurations; and transmit the monitoring data to a user device associated with the microservice.

Claims (35)

1. A method comprising:

transmitting a request for information relating to new services at a cluster of computing nodes, wherein at a time of the transmitting the cluster of computing nodes is running one or more services in one or more containers that containerize the one or more services;

receiving an indication that a new service has been created at the cluster of computing nodes, wherein at a time of the receiving the indication the new service is running in one or more computing nodes in one or more containers that containerize the new service;

in response to receiving the indication, customizing a security service subsystem for performing a security function for the containerized new service;

assigning the security service subsystem to the containerized new service; and

performing, by the security service subsystem, the security function for the containerized new service as the new service is running in the one or more computing nodes.

2. The method of claim 1 , wherein the security function performed is deep packet inspection on packets forwarded toward the new service.

3. The method of claim 1 , wherein the security function performed is specifying a mode of authentication for user accounts attempting to log into the new service.

4. The method of claim 1 , wherein the request is an application programming interface (API) call.

5. The method of claim 4 , wherein the new service is described in a YAML configuration file.

6. The method of claim 5 , wherein the cluster is a Kubernetes cluster and the containers run in one or more Kubernetes pods.

7. A computer system comprising:

a cluster of computing nodes that are running one or more services in one or more containers that containerize the one or more services; and

a processor executing a security service to perform the steps of:

transmitting a request for information relating to new services at the cluster of computing nodes;

receiving an indication that a new service has been created at the cluster of computing nodes, wherein at a time of the receiving the indication the new service is running in one or more computing nodes in one or more containers that containerize the new service;

in response to receiving the indication, customizing a security service subsystem for performing a security function for the containerized new service; and

assigning the security service subsystem to the containerized new service,

wherein the security service subsystem performs the security function for the containerized new service as the new service is running in the one or more computing nodes.

8. The computer system of claim 7 , wherein the security function performed is deep packet inspection on packets forwarded toward the new service.

9. The computer system of claim 7 , wherein the security function performed is specifying a mode of authentication for user accounts attempting to log into the new service.

10. The computer system of claim 7 , wherein the request is an application programming interface (API) call.

11. The computer system of claim 10 , wherein the new service is described in a YAML configuration file.

12. The computer system of claim 11 , wherein the cluster is a Kubernetes cluster and the containers run in one or more Kubernetes pods.

13. A non-transitory computer readable medium comprising instructions to be executed in a processor to perform the steps of:

transmitting a request for information relating to new services at a cluster of computing nodes, wherein at a time of the transmitting the cluster of computing nodes is running one or more services in one or more containers that containerize the one or more services;

receiving an indication that a new service has been created at the cluster of computing nodes, wherein at a time of the receiving the indication the new service is running in one or more computing nodes in one or more containers that containerize the new service;

in response to receiving the indication, customizing a security service subsystem for performing a security function for the containerized new service; and

assigning the security service subsystem to the containerized new service,

wherein the security service subsystem performs the security function for the containerized new service as the new service is running in the one or more computing nodes.

14. The non-transitory computer readable medium of claim 13 , wherein the security function performed is deep packet inspection on packets forwarded toward the new service.

15. The non-transitory computer readable medium of claim 13 , wherein the security function performed is specifying a mode of authentication for user accounts attempting to log into the new service.

16. The non-transitory computer readable medium of claim 13 , wherein the request is an application programming interface (API) call.

17. The non-transitory computer readable medium of claim 16 , wherein the new service is described in a YAML configuration file.

18. The non-transitory computer readable medium of claim 17 , wherein the cluster is a Kubernetes cluster and the containers run in one or more Kubernetes pods.

Continuity (6)
Continuation 17678999 · Feb 23, 2022
Continuation 17236880 · Apr 21, 2021
Continuation 16585591 · Sep 27, 2019
Continuation 15297070 · Oct 18, 2016
Provisional Application 62243602 · Oct 19, 2015
Related Publication 20240163182A1 · May 16, 2024
References Cited (53)
US 7941762B1 · Tovino et al. · 2011 [cited by applicant]
US 8625757B1 · Karpov · 2014 [cited by examiner]
US 9210056B1 · Choudhary et al. · 2015 [cited by applicant]
US 9396456B1 · Wang et al. · 2016 [cited by applicant]
US 9467476B1 · Shieh · 2016 [cited by examiner]
US 9893968B1 · Nagargadde · 2018 [cited by examiner]
US 10069782B2 · Jayam et al. · 2018 [cited by applicant]
US 10084784B1 · Brandwine · 2018 [cited by examiner]
US 10205701B1 · Voss · 2019 [cited by examiner]
US 10992520B2 · Lee · 2021 [cited by examiner]
US 20040064411A1 · Tsui · 2004 [cited by examiner]
US 20070283002A1 · Bornhoevd et al. · 2007 [cited by applicant]
US 20080104032A1 · Sarkar · 2008 [cited by applicant]
US 20080239979A1 · Chou · 2008 [cited by examiner]
US 20090049177A1 · Iszlai et al. · 2009 [cited by applicant]
US 20110052155A1 · Desmarais et al. · 2011 [cited by applicant]
US 20110225463A1 · Davis et al. · 2011 [cited by applicant]
US 20110314326A1 · Mahajan et al. · 2011 [cited by applicant]
US 20120058742A1 · Razoumov et al. · 2012 [cited by applicant]
US 20130290188A1 · Olliphant · 2013 [cited by applicant]
US 20130339123A1 · Ennis et al. · 2013 [cited by applicant]
US 20140068549A1 · Friedman · 2014 [cited by examiner]
US 20140173398A1 · Beust et al. · 2014 [cited by applicant]
US 20140278624A1 · Steiner · 2014 [cited by applicant]
US 20140304399A1 · Chaudhary · 2014 [cited by examiner]
US 20150067147A1 · Carmel et al. · 2015 [cited by applicant]
US 20150117234A1 · Raman · 2015 [cited by examiner]
US 20150170045A1 · Kirkham et al. · 2015 [cited by applicant]
US 20150350349A1 · Kao et al. · 2015 [cited by applicant]
US 20160028855A1 · Goyal · 2016 [cited by examiner]
US 20160094483A1 · Johnston · 2016 [cited by examiner]
US 20160142262A1 · Werner et al. · 2016 [cited by applicant]
US 20160142475A1 · Kathuria · 2016 [cited by examiner]
US 20160241448A1 · Uriel · 2016 [cited by examiner]
US 20160269425A1 · Shieh · 2016 [cited by examiner]
US 20160380832A1 · Purushotham · 2016 [cited by examiner]
US 20170063645A1 · Testa · 2017 [cited by examiner]
US 20170085459A1 · Xia · 2017 [cited by examiner]
US 20170111241A1 · Degioanni · 2017 [cited by applicant]
US 20170249059A1 · Houseworth · 2017 [cited by applicant]
US 20180026856A1 · Yang · 2018 [cited by examiner]
US 20180109429A1 · Gupta · 2018 [cited by examiner]
US 20180123928A1 · Moradi · 2018 [cited by examiner]
US 20190286462A1 · Bodnick et al. · 2019 [cited by applicant]
US 20200252743A1 · Bellhy · 2020 [cited by applicant]
US 20200412732A1 · Muthukrishnan et al. · 2020 [cited by applicant]
US 20210243089A1 · Degioanni · 2021 [cited by applicant]
US 20230132740A1 · Navasivasakthivelsamy · 2023 [cited by examiner]
Ellingwood, J. “An Introduction to Kubernetes,” Oct. 1, 2014, URL: https://web.archive.org/web/20150421212948/https://www.digitalocean.com/community/tutorials/an-introduction-to-kubernetes (Year: 2014). [cited by applicant]
Notice of Allowance mailed Jun. 5, 2019 in U.S. Appl. No. 15/297,070. [cited by applicant]
Office Action mailed Oct. 16, 2020 in U.S. Appl. No. 16/585,591. [cited by applicant]
Final Office Action mailed Nov. 29, 2018 in U.S. Appl. No. 15/297,070. [cited by applicant]
Notice of Allowance mailed Jan. 12, 2022 in U.S. Appl. No. 17/236,880. [cited by applicant]