IP Library Granted Patent US 12,475,234
Granted Patent B2
US 12,475,234 · App. 18/748,307 · Granted Nov 18, 2025

Profiling of spawned processes in container images and enforcing security policies respective thereof

Inventors: Dima Stopel (Herzliya, IL); Liron Levin (Kefar Sava, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/577G06F21/53G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,234
App. No.
18/748,307
Granted
Nov 18, 2025
Kind
B2
Abstract

Execution of software containers is secured using security profiles. A security profile is generated for a container image, wherein the container image includes resources utilized to execute a corresponding application container, wherein the generated security profile includes at least a spawned processes profile, wherein the spawned processes profile includes, for each spawned process executed at runtime by the application container, a signature of an executable file of the spawned process. The operation of a runtime execution of the application container is monitored. A violation of the spawned processes profile is detected based on the monitored operation.

Claims (34)

1 . A method comprising:

based on scanning a container image, generating a security profile for the container image; and

enforcing the security profile for containers corresponding to runtime instances of the container image based on monitoring operation of the containers,

wherein enforcing the security profile comprises,

based on detecting a violation of the security profile for a first of the containers during operation of the first container, performing an enforcement action for the first container.

2 . The method of claim 1 , wherein performing the enforcement action for the first container comprises at least one of generating an alert, halting operation of the first container, halting or disabling execution of a process spawned by the first container, and quarantining the first container.

3 . The method of claim 1 , wherein monitoring operation of the containers comprises, for each of the containers, intercepting at least one of communications to the container and communications from the container.

4 . The method of claim 3 , further comprising analyzing intercepted communications based on the security profile to determine if the intercepted communications violate the security profile, wherein detecting the violation of the security profile the first container comprises determining that a first of the intercepted communications corresponding to the first container violates the security profile.

5 . The method of claim 1 , wherein the security profile comprises indications of safe or authorized actions to be performed by the runtime instances of the container image.

6 . The method of claim 1 , wherein scanning the container image comprises scanning the container image to determine at least one of callable units indicated in the container image and indications of processes to be spawned by the runtime instances of the container image.

7 . The method of claim 6 , wherein generating the security profile comprises adding to the security profile at least one of indications of system calls to which the callable units map and signatures of the processes to be spawned.

8 . The method of claim 1 further comprising analyzing a network configuration file of the container image to determine permissible network actions for network resources, wherein generating the security profile comprises adding indications of the permissible network actions to the security profile.

9 . One or more non-transitory machine-readable media having program code stored thereon, the program code comprising instructions to:

scan a container image to generate a security profile for the container image; and

enforce the security profile for containers corresponding to runtime instances of the container image based on monitoring operation of the containers,

wherein the instructions to enforce the security profile comprise instructions to,

based on detection of a violation of the security profile for a first of the containers, perform an enforcement action for the first container.

10 . The non-transitory machine-readable media of claim 9 , wherein the instructions to perform the enforcement action for the first container comprise at least one of instructions to generate an alert, instructions to halt operation of the first container, instructions to halt or disable execution of a process spawned by the first container, and instructions to quarantine the first container.

11 . The non-transitory machine-readable media of claim 9 , wherein the instructions to monitor operation of the containers comprise instructions to, for each of the containers, intercept at least one of communications to the container and communications from the container.

12 . The non-transitory machine-readable media of claim 11 , wherein the program code further comprises instructions to analyze the intercepted communications based on the security profile to determine if the intercepted communications violate the security profile, wherein the instructions to detect the violation of the security profile the first container comprise instructions to determine that a first of the intercepted communications corresponding to the first container violates the security profile.

13 . The non-transitory machine-readable media of claim 9 , wherein the instructions to scan the container image comprise instructions to scan the container image to determine at least one of callable units indicated in the container image and indications of processes to be spawned by the runtime instances of the container image.

14 . The non-transitory machine-readable media of claim 13 , wherein the instructions to generate the security profile comprise instructions to add to the security profile at least one of indications of system calls to which the callable units map and signatures of the processes to be spawned.

15 . An apparatus comprising:

a processor; and

a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,

scan a container image;

generate a security profile for the container image based on the scan of the container image; and

enforce the security profile for containers corresponding to runtime instances of the container image based on monitoring operation of the containers, wherein the instructions to enforce the security profile comprise instructions to,

based on detection of a violation of the security profile for a first of the containers during operation of the first container, perform an enforcement action for the first container.

16 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to perform the enforcement action for the first container comprise instructions executable by the processor to cause the apparatus to perform at least one of generating an alert, halting operation of the first container, halting or disabling execution of a process spawned by the first container, and quarantining the first container.

17 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to monitor operation of the containers comprise instructions executable by the processor to cause the apparatus to, for each of the containers, intercept at least one of communications to the container and communications from the container.

18 . The apparatus of claim 15 , further comprising instructions executable by the processor to cause the apparatus to analyze intercepted communications based on the security profile to determine if the intercepted communications violate the security profile, wherein the instructions executable by the processor to cause the apparatus to detect the violation of the security profile the first container comprise instructions executable by the processor to cause the apparatus to determine that a first of the intercepted communications corresponding to the first container violates the security profile.

19 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to scan the container image comprise instructions executable by the processor to cause the apparatus to scan the container image to determine at least one of callable units indicated in the container image and indications of processes to be spawned by the runtime instances of the container image, wherein the instructions executable by the processor to cause the apparatus to generate the security profile comprise instructions executable by the processor to cause the apparatus to add to the security profile at least one of indications of system calls to which the callable units map and signatures of the processes to be spawned.

20 . The apparatus of claim 15 , further comprising instructions executable by the processor to cause the apparatus to determine permissible network actions for network resources based on analysis of a network configuration file of the container image, wherein the instructions executable by the processor to cause the apparatus to generate the security profile comprise instructions executable by the processor to cause the apparatus to add indications of the permissible network actions to the security profile.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: TWISTLOCK LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068685/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2024
From: STOPEL, DIMA; LEVIN, LIRON
To: TWISTLOCK LTD.
Reel/Frame 067778/0827 →
Continuity (11)
Continuation 18296648 · Apr 6, 2023
Continuation 17195069 · Mar 8, 2021
Continuation 15397245 · Jan 3, 2017
Continuation In Part 15292915 · Oct 13, 2016
Continuation In Part 15278700 · Sep 28, 2016
Provisional Application 62274798 · Jan 5, 2016
Provisional Application 62274420 · Jan 4, 2016
Provisional Application 62241812 · Oct 15, 2015
Provisional Application 62235644 · Oct 1, 2015
Provisional Application 62235641 · Oct 1, 2015
Related Publication 20240338460A1 · Oct 10, 2024
References Cited (134)
US 6490620B1 · Ditmer et al. · 2002 [cited by applicant]
US 6502102B1 · Haswell et al. · 2002 [cited by applicant]
US 6523027B1 · Underwood · 2003 [cited by applicant]
US 6704873B1 · Underwood · 2004 [cited by applicant]
US 6732162B1 · Wood et al. · 2004 [cited by applicant]
US 7100195B1 · Underwood · 2006 [cited by applicant]
US 7103740B1 · Colgrove et al. · 2006 [cited by applicant]
US 7379978B2 · Anderson et al. · 2008 [cited by applicant]
US 7577848B2 · Schwartz et al. · 2009 [cited by applicant]
US 7596227B2 · Illowsky et al. · 2009 [cited by applicant]
US 7640235B2 · Shulman et al. · 2009 [cited by applicant]
US 7698741B2 · Marinescu et al. · 2010 [cited by applicant]
US 7743420B2 · Shulman et al. · 2010 [cited by applicant]
US 7752662B2 · Shulman et al. · 2010 [cited by applicant]
US 7752669B2 · Palliyil et al. · 2010 [cited by applicant]
US 7779468B1 · Magdych et al. · 2010 [cited by applicant]
US 7861303B2 · Kouznetsov et al. · 2010 [cited by applicant]
US 7882542B2 · Neystadt et al. · 2011 [cited by applicant]
US 8024804B2 · Shulman et al. · 2011 [cited by applicant]
US 8051484B2 · Shulman et al. · 2011 [cited by applicant]
US 8056141B2 · Shulman et al. · 2011 [cited by applicant]
US 8108933B2 · Mahaffey · 2012 [cited by applicant]
US 8135948B2 · Shulman et al. · 2012 [cited by applicant]
US 8181246B2 · Shulman et al. · 2012 [cited by applicant]
US 8302192B1 · Cnudde et al. · 2012 [cited by applicant]
US 8316237B1 · Felsher et al. · 2012 [cited by applicant]
US 8499150B1 · Nachenberg et al. · 2013 [cited by applicant]
US 8510571B1 · Chang et al. · 2013 [cited by applicant]
US 8621613B1 · Mcclintock et al. · 2013 [cited by applicant]
US 8639625B1 · Ginter et al. · 2014 [cited by applicant]
US 8677472B1 · Dotan et al. · 2014 [cited by applicant]
US 8756683B2 · Manion et al. · 2014 [cited by applicant]
US 8806625B1 · Berger et al. · 2014 [cited by applicant]
US 8966629B2 · Sallam · 2015 [cited by applicant]
US 9003141B2 · Nielson et al. · 2015 [cited by applicant]
US 9098333B1 · Obrecht et al. · 2015 [cited by applicant]
US 9203862B1 · Kashyap et al. · 2015 [cited by applicant]
US 9223966B1 · Satish et al. · 2015 [cited by applicant]
US 9256467B1 · Singh et al. · 2016 [cited by applicant]
US 9355248B1 · Wiest et al. · 2016 [cited by applicant]
US 9401922B1 · Walters · 2016 [cited by applicant]
US 9594590B2 · Hsu · 2017 [cited by applicant]
US 9904781B2 · Martini et al. · 2018 [cited by applicant]
US 9928379B1 · Hoffer · 2018 [cited by applicant]
US 10223534B2 · Stopel et al. · 2019 [cited by applicant]
US 10333967B2 · Litva et al. · 2019 [cited by applicant]
US 20010007131A1 · Galasso et al. · 2001 [cited by applicant]
US 20030014629A1 · Zuccherato · 2003 [cited by applicant]
US 20030079145A1 · Kouznetsov et al. · 2003 [cited by applicant]
US 20030120593A1 · Bansal et al. · 2003 [cited by applicant]
US 20030229801A1 · Kouznetsov et al. · 2003 [cited by applicant]
US 20030233566A1 · Kouznetsov et al. · 2003 [cited by applicant]
US 20030233574A1 · Kouznetsov et al. · 2003 [cited by applicant]
US 20040133793A1 · Ginter et al. · 2004 [cited by applicant]
US 20050120054A1 · Shulman · 2005 [cited by examiner]
US 20050177715A1 · Somin et al. · 2005 [cited by applicant]
US 20060075494A1 · Bertman et al. · 2006 [cited by applicant]
US 20060230451A1 · Kramer et al. · 2006 [cited by applicant]
US 20060277606A1 · Yunus · 2006 [cited by examiner]
US 20060282664A1 · Zhao · 2006 [cited by applicant]
US 20060288420A1 · Mantripragada et al. · 2006 [cited by applicant]
US 20070112714A1 · Fairweather · 2007 [cited by applicant]
US 20070130621A1 · Marinescu et al. · 2007 [cited by applicant]
US 20070136282A1 · Takashima · 2007 [cited by applicant]
US 20070174630A1 · Shannon et al. · 2007 [cited by applicant]
US 20070240218A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240220A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240221A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240222A1 · Tuvell et al. · 2007 [cited by applicant]
US 20080086773A1 · Tuvell et al. · 2008 [cited by applicant]
US 20080134177A1 · Fitzgerald · 2008 [cited by examiner]
US 20080168135A1 · Redlich et al. · 2008 [cited by applicant]
US 20080177994A1 · Mayer et al. · 2008 [cited by applicant]
US 20080196104A1 · Tuvell et al. · 2008 [cited by applicant]
US 20080256636A1 · Gassoway · 2008 [cited by applicant]
US 20090144823A1 · Lamastra et al. · 2009 [cited by applicant]
US 20090158432A1 · Zheng · 2009 [cited by examiner]
US 20090217260A1 · Gebhart et al. · 2009 [cited by applicant]
US 20090319796A1 · Kim et al. · 2009 [cited by applicant]
US 20100011029A1 · Niemela · 2010 [cited by applicant]
US 20110116637A1 · Schiefelbein · 2011 [cited by applicant]
US 20110125894A1 · Anderson et al. · 2011 [cited by applicant]
US 20110179484A1 · Tuvell et al. · 2011 [cited by applicant]
US 20110258701A1 · Cruz et al. · 2011 [cited by applicant]
US 20110314542A1 · Viswanathan et al. · 2011 [cited by applicant]
US 20110314548A1 · Yoo · 2011 [cited by applicant]
US 20110321139A1 · Jayaraman et al. · 2011 [cited by applicant]
US 20120008529A1 · Averbuch et al. · 2012 [cited by applicant]
US 20120023584A1 · Yoo · 2012 [cited by applicant]
US 20120036572A1 · Yoo · 2012 [cited by applicant]
US 20120042375A1 · Yoo · 2012 [cited by applicant]
US 20120117203A1 · Taylor et al. · 2012 [cited by applicant]
US 20120222123A1 · Williams et al. · 2012 [cited by applicant]
US 20130073388A1 · Heath · 2013 [cited by applicant]
US 20140059226A1 · Messerli et al. · 2014 [cited by applicant]
US 20140173761A1 · Hong · 2014 [cited by examiner]
US 20140181894A1 · Von Bokern et al. · 2014 [cited by applicant]
US 20140237550A1 · Anderson et al. · 2014 [cited by applicant]
US 20140283071A1 · Spikes · 2014 [cited by examiner]
US 20140337234A1 · Tang et al. · 2014 [cited by applicant]
US 20150156183A1 · Beyer et al. · 2015 [cited by applicant]
US 20150178497A1 · Lukacs · 2015 [cited by examiner]
US 20150220735A1 · Paithane et al. · 2015 [cited by applicant]
US 20150271139A1 · Lukacs et al. · 2015 [cited by applicant]
US 20150332043A1 · Russello · 2015 [cited by examiner]
US 20150372980A1 · Eyada · 2015 [cited by examiner]
US 20150379287A1 · Mathur · 2015 [cited by applicant]
US 20160323315A1 · Hathaway · 2016 [cited by examiner]
US 20170004302A1 · Derbeko · 2017 [cited by examiner]
US 20170063557A1 · Chalmandrier-Perna · 2017 [cited by applicant]
US 20170068676A1 · Jayachandran · 2017 [cited by examiner]
US 20170177877A1 · Suarez · 2017 [cited by examiner]
US 20170244748A1 · Krause et al. · 2017 [cited by applicant]
Azkia, et al., “Reconciling IHE-ATNA Profile with a posteriori Contextual Access and Usage Control Policy in Healthcare Environment”, 2010 Sixth International Conference on Information Assurance and Security, 2010 IEEE,… [cited by applicant]
Balázsi, et al., “Software System for Broadcasting and Monitoring Traffic Information”, 2014 IEEE 12th International Symposium on Intelligent Systems and Informatics (SISY), 2014, pp. 39-42, Subotica, Serbia. [cited by applicant]
Canali, et al., “Distributed Architectures for High Performance and Privacy-Aware Content Generation and Delivery”, Second International Conference on Automated Production of Cross Media Content for Multi-Channel Distri… [cited by applicant]
Cooper, et al., “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”, May 2008, 151 pages. [cited by applicant]
Cziva, et al., “Container-based Network Function Virtualization for Software-Defined Networks”, 2015 IEEE Symposium on Computers and Communication (ISCC), pp. 415-420, Scotland. [cited by applicant]
Dhakchianandan, et al., “Memory Efficacious Pattern Matching Intrusion Detection System”, 2013 International Conference on Recent Trends in Information Technology (ICRTIT), pp. 652-656, Anna University, Chennai, India. [cited by applicant]
Guenane, et al., “Autonomous Architecture for Managing Firewalling Cloud-Based Service”, 2014 International Conference and Workshop on the Network of the Future (NOF), Paris, France, pp. 1-5. [cited by applicant]
Housley, et al., “Internet X 509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”, Apr. 2002, 259 pages. [cited by applicant]
Jing, et al., “A Context-aware Disaster Response System Using Mobile Software Technologies and Collaborative Filtering Approach”, 2014 IEEE 18th International Conference on Computer Supported Cooperative Work in Design,… [cited by applicant]
Kovatsch, et al., “Actinium: A RESTful Runtime Container for Scriptable Internet of Things Applications”, 3rd IEEE International Conference on the Internet of Things, Oct. 2012. [cited by applicant]
Linn, et al., “Protecting Against Unexpected System Calls”, 14th USENIX Security Symposium, 2005. [cited by applicant]
Mattetti, et al., “Securing the Infrastructure and the Workloads of Linux Containers”, IEEE Conference on Communications and Network Security (CNS), 2015. [cited by applicant]
Pan, et al., “Robust Container Code Recognition System”, Fifth World Congress on Intelligent Control and Automation, 2004. [cited by applicant]
Rehák, et al., “Adaptive Multiagent System for Network Traffic Monitoring”, IEEE Intelligent Systems, vol. 24, Issue: 3, 2009, Czechia, pp. 16-25. [cited by applicant]
Schneier, “Economics of Information Security and Privacy III”, Springer New York, 2013, pp. 73-109. [cited by applicant]
Shouman, et al., “Surviving Cyber Warfare With a Hybrid Multiagent-based Intrusion Prevention System”, IEEE Potentials, vol. 29, Issue: 1, 2010, pp. 32-40. [cited by applicant]
Skillen, et al., “Mobiflage: Deniable Storage Encryption for Mobile Devices”, IEEE Transaction on Dependable and Secure Computing, vol. 11, No. 3, May-Jun. 2014, 2013 IEEE, pp. 224-237, Canada. [cited by applicant]
Song, et al., “A Control Theoretical Approach for Flow Control to Mitigate Bandwidth Attacks”, 2006 IEEE Information Assurance Workshop, West Point, NY, pp. 348-360. [cited by applicant]
Van Niekerk, et al., “Cloud-Based Security Mechanisms for Critical Information Infrastructure Protection”, 2013 International Conference on Adaptive Science and Technology, South Africa, pp. 1-4. [cited by applicant]
Wang, et al., “Transport-Aware IP Routers: A Built-in Protection Mechanism to Counter DDOS Attacks”, IEEE Transactions on Parallel and Distributed Systems, vol. 14, Issue: 9, pp. 873-884, Sep. 2003. [cited by applicant]
Zhauniarovich, et al., “MOSES: Supporting and Enforcing Security Profiles on Smartphones”, IEEE Transactions on Dependable and Secure Computing, vol. 11, Issue: 3, pp. 211-223, 2014. [cited by applicant]