IP Library › Granted Patent US 11,924,165
Granted Patent B2
US 11,924,165 · App. 17/900,721 · Granted Mar 5, 2024

Securing containerized applications

Inventors: John Edward McDowall (Redwood City, CA); Sharad Saha (Santa Clara, CA); Nilesh Bansal (Santa Clara, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0245G06F9/45558H04L63/02H04L63/14H04L63/1408H04L63/1441H04L63/20H04W12/08H04W12/088H04W12/30G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,165
App. No.
17/900,721
Granted
Mar 5, 2024
Kind
B2
Abstract

Techniques for securing containerized applications are disclosed. In some embodiments, a system, process, and/or computer program product for securing containerized applications includes detecting a new application container (e.g., an application pod); deploying a security entity (e.g., a firewall) to the application container; and monitoring all traffic to and from the application container (e.g., all layer-7 ingress, egress, and east-west traffic associated with the application container) using the security entity to enforce a policy.

Claims (39)

1. A system comprising:

a processor configured to:

deploy a security entity to a new application container into a path of application layer network traffic in a container environment for securing all network traffic types, wherein the security entity is transparently inserted into the path of all application layer network traffic for ingress, egress, and east-west flows without modification of the flows and without using a sidecar container or IP tables by performing the following:

generate a new network namespace associated with the security entity on a node in the container environment; and

move a side interface of the node to the new network namespace associated with the security entity and create a new pair of interfaces between the new network namespace and a network namespace associated with the application container, wherein the new pair of interfaces between the new network namespace associated with the security entity and the network namespace associated with the application container facilitate performing inline security in the container environment to detect and prevent threats traveling between namespace boundaries; and

monitor all traffic to and from the application container using the security entity to enforce a security policy; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security entity is a firewall.

3. The system recited in claim 1 , wherein the security entity is a firewall, and the security policy is a firewall policy.

4. The system recited in claim 1 , wherein the security entity is deployed to the application container dynamically with no user intervention with the application container as the application container is created and destroyed.

5. The system recited in claim 1 , wherein monitoring all traffic to and from the application container includes an application identification associated with a flow determined using deep packet inspection.

6. The system recited in claim 1 , wherein the application container is executed in a cloud-based container service.

7. The system recited in claim 1 , wherein the application container is executed in a cloud-based container service that is provided using a public cloud service provider.

8. The system recited in claim 1 , wherein the application container is executed in a cloud-based container service that is provided using a plurality of public cloud service providers.

9. The system recited in claim 1 , wherein the security policy is a firewall policy, wherein the processor is further configured to:

inspect a packet using the security entity, and

send the packet without any modifications if it is determined to not violate a security policy, and drop the packet if it is determined to violate the firewall policy.

10. The system recited in claim 1 , wherein the processor is further configured to:

send traffic log data from the security entity to a security management entity, wherein the is traffic log data is sent to the security management entity periodically and prior to the application container being destroyed.

11. A method, comprising:

deploying a security entity to a new application container into a path of application layer network traffic in a container environment for securing all network traffic types, wherein the security entity is transparently inserted into the path of all application layer network traffic for ingress, egress, and east-west flows without modification of the flows and without using a sidecar container or IP tables by performing the following:

generating a new network namespace associated with the security entity on a node in the container environment; and

moving a side interface of the node to the new network namespace associated with the security entity and create a new pair of interfaces between the new network namespace and a network namespace associated with the application container, wherein the new pair of interfaces between the new network namespace associated with the security entity and the network namespace associated with the application container facilitate performing inline security in the container environment to detect and prevent threats traveling between namespace boundaries; and

monitoring all traffic to and from the application container using the security entity to enforce a security policy.

12. The method of claim 11 , wherein the security entity is a firewall, and the security policy is a firewall policy.

13. The method of claim 11 , wherein the security entity is deployed to the application container dynamically with no user intervention with the application container as the application container is created and destroyed.

14. The method of claim 11 , wherein the application container is executed in a cloud-based container service.

15. The method of claim 11 , wherein the application container is executed in a cloud-based container service that is provided using a public cloud service provider.

16. The method of claim 11 , wherein the application container is executed in a cloud-based is container service that is provided using a plurality of public cloud service providers.

17. The method of claim 11 , wherein the security policy is a firewall policy, further comprising:

inspecting a packet using the security entity, and

sending the packet without any modifications if it is determined to not violate a security policy, and dropping the packet if it is determined to violate the firewall policy.

18. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

deploying a security entity to a new application container into a path of application layer network traffic in a container environment for securing all network traffic types, wherein the security entity is transparently inserted into the path of all application layer network traffic for ingress, egress, and east-west flows without modification of the flows and without using a sidecar container or IP tables by performing the following:

generating a new network namespace associated with the security entity on a node in the container environment; and

moving a side interface of the node to the new network namespace associated with the security entity and create a new pair of interfaces between the new network namespace and a network namespace associated with the application container, wherein the new pair of interfaces between the new network namespace associated with the security entity and the network namespace associated with the application container facilitate performing inline security in the container environment to detect and prevent threats traveling between namespace boundaries; and

monitoring all traffic to and from the application container using the security entity to enforce a security policy.

19. The computer program product recited in claim 18 , wherein the security entity is a firewall, and the security policy is a firewall policy.

20. The computer program product recited in claim 18 , wherein the security entity is deployed to the application container dynamically with no user intervention with the application container as the application container is created and destroyed.

Continuity (2)
Continuation 17334485 · May 28, 2021
Related Publication 20230008901A1 · Jan 12, 2023
Cited By (1)
US 12,411,973