IP Library Granted Patent US 12,417,293
Granted Patent B2
US 12,417,293 · App. 18/622,522 · Granted Sep 16, 2025

Method to intelligently manage the end to end container compliance in cloud environments

Inventors: Suren Kumar (Bangalore, IN); Vinod Durairaj (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F21/577G06N5/02G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,293
App. No.
18/622,522
Granted
Sep 16, 2025
Kind
B2
Abstract

One example method includes receiving data from a container data collector (CDC), and the data concerns a container, analyzing the data and, based on the analyzing, identifying a security tool needed to scan the container, drawing the security tool from a knowledge lake, executing the security tool to perform a vulnerability scan of the container, based on the executing of the security tool, generating and analyzing a report concerning the vulnerability scan, and transmitting the report, and results of the analyzing, to an alert and action stage.

Claims (32)

1. A method, comprising:

receiving data from a container data collector (CDC), and the data concerns a container;

analyzing the data and, based on the analyzing, identifying a security tool needed to scan the container;

drawing the security tool from a knowledge lake;

executing the security tool to perform a vulnerability scan of the container;

based on the executing of the security tool, generating and analyzing a report concerning the vulnerability scan;

transmitting the report, and results of the analyzing, to an alert and action stage; and

the receiving, the analyzing of the data, the identifying, the drawing, the executing, the generating and the analyzing of the report, and the transmitting, are all performed by a device management console that comprises the CDC, an elastic container security hub (ECSH) module, the knowledge lake, the alert and action stage, and a fixed profile (FP) module.

2. The method as recited in claim 1 , wherein the vulnerability scan identifies a vulnerability in the container, and also identifies a potential resolution to the vulnerability.

3. The method as recited in claim 1 , wherein the report and/or results of the analyzing enable the alert and action stage to generate an alert which includes information that may be used by a fixed profile (FP) module to update a container image on which the container is based.

4. The method as recited in claim 1 , wherein a container image, on which the container is based, is updated based on the report and/or the results of the analyzing.

5. The method as recited in claim 1 , wherein the container is based on a container image, and a container image update is performed that results in an updated container image that lacks a vulnerability that was identified in the vulnerability scan.

6. The method as recited in claim 5 , wherein a container creation request is generated that triggers creation of a new container based on the updated container image, and the new container lacks the vulnerability.

7. The method as recited in claim 5 , wherein the updated container image is transmitted to a container image repository.

8. The method as recited in claim 1 , wherein the security tool is returned to the knowledge lake after the security tool is no longer needed.

9. The method as recited in claim 1 , wherein the CDC obtains the data concerning the container after the CDC determines that a host includes a container environment that includes the container.

10. A computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving data from a container data collector (CDC), and the data concerns a container;

analyzing the data and, based on the analyzing, identifying a security tool needed to scan the container;

drawing the security tool from a knowledge lake;

executing the security tool to perform a vulnerability scan of the container;

based on the executing of the security tool, generating and analyzing a report concerning the vulnerability scan;

transmitting the report, and results of the analyzing, to an alert and action stage; and

the report and/or the results of the analyzing enable the alert and action stage to generate an alert which includes information that may be used by a fixed profile (FP) module to update a container image on which the container is based.

11. The computer readable storage medium as recited in claim 10 , wherein the vulnerability scan identifies a vulnerability in the container, and also identifies a potential resolution to the vulnerability.

12. The computer readable storage medium as recited in claim 10 , wherein a container image, on which the container is based, is updated based on the report and/or the results of the analyzing.

13. The computer readable storage medium as recited in claim 10 , wherein the container is based on a container image, and a container image update is performed that results in an updated container image that lacks a vulnerability that was identified in the vulnerability scan.

14. The computer readable storage medium as recited in claim 13 , wherein a container creation request is generated that triggers creation of a new container based on the updated container image, and the new container lacks the vulnerability.

15. The computer readable storage medium as recited in claim 13 , wherein the updated container image is transmitted to a container image repository.

16. The computer readable storage medium as recited in claim 10 , wherein the security tool is returned to the knowledge lake after the security tool is no longer needed.

17. The computer readable storage medium as recited in claim 10 , wherein the receiving, the analyzing of the data, the identifying, the drawing, the executing, the generating and the analyzing of the report, and the transmitting, are all performed by a device management console that comprises the CDC, an elastic container security hub (ECSH) module, the knowledge lake, the alert and action stage, and a fixed profile (FP) module.

18. The computer readable storage medium as recited in claim 10 , wherein the CDC obtains the data concerning the container after the CDC determines that a host includes a container environment that includes the container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2024
From: KUMAR, SUREN; DURAIRAJ, VINOD
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 067327/0198 →
Continuity (2)
Continuation 17383252 · Jul 22, 2021
Related Publication 20240241967A1 · Jul 18, 2024
References Cited (16)
US 10154065B1 · Buchler et al. · 2018 [cited by applicant]
US 11989308B2 · Kumar · 2024 [cited by examiner]
US 20120174228A1 · Giakouminakis · 2012 [cited by examiner]
US 20170353496A1 · Pai · 2017 [cited by examiner]
US 20180114025A1 · Cui · 2018 [cited by examiner]
US 20180309747A1 · Sweet · 2018 [cited by examiner]
US 20180336351A1 · Jeffries · 2018 [cited by examiner]
US 20190114435A1 · Bhalla · 2019 [cited by examiner]
US 20200082094A1 · Mcallister · 2020 [cited by examiner]
US 20200082095A1 · Mcallister · 2020 [cited by examiner]
US 20200097662A1 · Hufsmith · 2020 [cited by examiner]
US 20200167477A1 · Ionescu · 2020 [cited by examiner]
US 20210352159A1 · Sethi · 2021 [cited by examiner]
US 20220171856A1 · Bhatt et al. · 2022 [cited by applicant]
US 20220374218A1 · Monteiro Vieira · 2022 [cited by examiner]
US 20230130746A1 · Binder · 2023 [cited by examiner]