IP Library › Granted Patent US 12,321,464
Granted Patent B2
US 12,321,464 · App. 18/917,410 · Granted Jun 3, 2025

Cyber attribution of software containers

Inventors: Eshel Yaron (Amsterdam, NL); Tomer Schwartz (Tel Aviv, IL); Pavel Resnianski (Tel Aviv, IL)
Assignee: Dazz, Inc.
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,464
App. No.
18/917,410
Granted
Jun 3, 2025
Kind
B2
Abstract

A system and method for software containers attribution are provided. The method includes de-compiling a configuration file of a container image of a software container; identifying at least one candidate build file in the de-compiled configuration file, wherein the at least one candidate build potentially formed the container image; determining if at least one matching condition is satisfied between each of the at least one candidate build file and the de-compiled configuration file; associating the configuration file with each candidate build file satisfying the matching condition; and updating an inventory with the associated configuration file and the respective candidate build, wherein such association provides a direct mapping between the container image and the build files formed the container image.

Claims (62)

1. A method for software containers attribution, comprising:

de-compiling a configuration file of a first container image of a software container, wherein the first container image is among a plurality of container images, wherein the de-compiled configuration file includes a plurality of commands;

identifying at least one candidate build file in the de-compiled configuration file, wherein each candidate build file contains a plurality of commands executed to create a respective container image among the plurality of container images;

determining if at least one matching condition is satisfied between each of the at least one candidate build file and the de-compiled configuration file based on the plurality of commands of the de-compiled configuration file and the plurality of commands of each of the at least one candidate build file;

associating the configuration file with each candidate build file satisfying the at least one matching condition; and

updating an inventory with the associated configuration file and the respective candidate build file, wherein such association provides a direct mapping between the container image and each build file that formed the container image.

2. The method of claim 1 , further comprising:

retrieving, from a software container repository, any of the configuration file and the container image; and

retrieving build files from a code repository.

3. The method of claim 2 , further comprising:

determining attribution for each container image stored in the software container repository.

4. The method of claim 1 , wherein identifying the at least one candidate build file further comprises:

searching for matching commands in both the de-compiled configuration and build files, wherein a build file with at least one matching command is a candidate build file.

5. The method of claim 1 , wherein determining if the at least one matching condition is satisfied, further comprises:

determining if there is only one candidate build file; and

associating the only one candidate build file with the de-compiled configuration file.

6. The method of claim 1 , wherein determining if the at least one matching condition is satisfied further comprises:

matching each of the candidate build files to the de-compiled configuration file based on a matching condition, wherein the matching condition includes any one of: similarity; a creation time; a number of commands; and a hierarchical matching.

7. The method of claim 6 , wherein the similarity matching condition is satisfied when all candidate build files are the same file and match the de-compiled configuration file.

8. The method of claim 6 , wherein the creation time matching condition is satisfied when the creation time of a candidate build time is earlier than a creation time of a container image corresponding to the de-compiled configuration file.

9. The method of claim 6 , wherein the number of commands matching condition is satisfied when the number of commands, excluding FROM commands, in the de-compiled configuration file is the same as the number of commands in a candidate build file.

10. The method of claim 6 , further comprising:

performing the hierarchical matching when the container image is formed from multiple build files.

11. The method of claim 10 , wherein the hierarchical matching is satisfied when a dependency tree representing a relationship between the candidate build files and the container image matches commands, excluding FROM commands, listed in the de-compiled configuration file.

12. The method of claim 1 , wherein updating the inventory further comprises:

associating each container layer in the container image with a respective code line in the build file; and

listing any vulnerability reported on at least one of: the container image and its image layers.

13. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for software containers attribution, the process comprising:

de-compiling a configuration file of a first container image of a software container, wherein the first container image is among a plurality of container images, wherein the de-compiled configuration file includes a plurality of commands;

identifying at least one candidate build file in the de-compiled configuration file, wherein each candidate build file contains a plurality of commands executed to create a respective container image among the plurality of container images;

determining if at least one matching condition is satisfied between each of the at least one candidate build file and the de-compiled configuration file based on the plurality of commands of the de-compiled configuration file and the plurality of commands of each of the at least one candidate build file;

associating the configuration file with each candidate build file satisfying the at least one matching condition; and

updating an inventory with the associated configuration file and the respective candidate build file, wherein such association provides a direct mapping between the container image and each build file that formed the container image.

14. A system for remediating software containers attribution, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

de-compile a configuration file of a first container image of a software container, wherein the first container image is among a plurality of container images, wherein the de-compiled configuration file includes a plurality of commands;

identify at least one candidate build file in the de-compiled configuration file, wherein each candidate build file contains a plurality of commands executed to create a respective container image among the plurality of container images;

determine if at least one matching condition is satisfied between each of the at least one candidate build file and the de-compiled configuration file based on the plurality of commands of the de-compiled configuration file and the plurality of commands of each of the at least one candidate build file;

associate the configuration file with each candidate build file satisfying the at least one matching condition; and

update an inventory with the associated configuration file and the respective candidate build file, wherein such association provides a direct mapping between the container image and each build file that formed the container image.

15. The system of claim 14 , wherein the system is further configured to:

retrieve, from a software container repository, any of the configuration file and the container image; and

retrieve build files from a code repository.

16. The system of claim 15 , wherein the system is further configured to:

determine attribution for each container image stored in the software container repository.

17. The system of claim 14 , wherein the system is further configured to:

search for matching commands in both the de-compiled configuration and build files, wherein a build file with at least one matching command is a candidate build file.

18. The system of claim 14 , wherein the system is further configured to:

determine if there is only one candidate build file; and

associate the only one candidate build file with the de-compiled configuration file.

19. The system of claim 14 , wherein the system is further configured to:

match each of the candidate build files to the de-compiled configuration file based on a matching condition, wherein the matching condition includes any one of: similarity; a creation time; a number of commands; and a hierarchical matching.

20. The system of claim 19 , wherein the similarity matching condition is satisfied when all candidate build files are the same file and match the de-compiled configuration file.

21. The system of claim 19 , wherein the creation time matching condition is satisfied when the creation time of a candidate build time is earlier than a creation time of a container image corresponding to the de-compiled configuration file.

22. The system of claim 19 , wherein the number of commands matching condition is satisfied when the number of commands, excluding FROM commands, in the de-compiled configuration file is the same as the number of commands in a candidate build file.

23. The system of claim 19 , wherein the system is further configured to:

perform the hierarchical matching when the container image is formed from multiple build files.

24. The system of claim 23 , wherein the hierarchical matching is satisfied when a dependency tree representing a relationship between the candidate build files and the container image matches commands, excluding FROM commands, listed in the de-compiled configuration file.

25. The system of claim 14 , wherein the system is further configured to:

associate each container layer in the container image with a respective code line in the build file; and

list any vulnerability reported on at least one of: the container image and its image layers.

Continuity (2)
Continuation 17656914 · Mar 29, 2022
Related Publication 20250036779A1 · Jan 30, 2025
References Cited (48)
US 8806425B1 · Willis et al. · 2014 [cited by applicant]
US 9052961B2 · Mangtani et al. · 2015 [cited by applicant]
US 10108803B2 · Chari et al. · 2018 [cited by applicant]
US 11429353B1 · Liguori et al. · 2022 [cited by applicant]
US 11893106B2 · Kim · 2024 [cited by examiner]
US 20030131284A1 · Flanagan et al. · 2003 [cited by applicant]
US 20090222479A1 · Burukhin et al. · 2009 [cited by applicant]
US 20100070448A1 · Omoigui · 2010 [cited by applicant]
US 20130167241A1 · Siman · 2013 [cited by applicant]
US 20150341214A1 · Croy et al. · 2015 [cited by applicant]
US 20150347759A1 · Cabrera et al. · 2015 [cited by applicant]
US 20160379480A1 · OlmstedThompson et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170185785A1 · Vorona et al. · 2017 [cited by applicant]
US 20170249128A1 · Fojtik et al. · 2017 [cited by applicant]
US 20170286692A1 · Nakajima et al. · 2017 [cited by applicant]
US 20180025160A1 · Hwang et al. · 2018 [cited by applicant]
US 20180129479A1 · McPherson · 2018 [cited by examiner]
US 20180285199A1 · Mitkar et al. · 2018 [cited by applicant]
US 20180321918A1 · Mcclory et al. · 2018 [cited by applicant]
US 20190007290A1 · He et al. · 2019 [cited by applicant]
US 20190068622A1 · Lin et al. · 2019 [cited by applicant]
US 20190294477A1 · Koppes et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190354389A1 · Du · 2019 [cited by examiner]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200183766A1 · Kumar-Mayernik · 2020 [cited by examiner]
US 20200296117A1 · Karpovsky et al. · 2020 [cited by applicant]
US 20210042096A1 · White, III et al. · 2021 [cited by applicant]
US 20210168165A1 · Alsaeed et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210311855A1 · Khan · 2021 [cited by examiner]
US 20210382997A1 · Yi · 2021 [cited by examiner]
US 20220114023A1 · Choksi et al. · 2022 [cited by applicant]
US 20220129539A1 · Walsh · 2022 [cited by examiner]
US 20220353341A1 · Östrand et al. · 2022 [cited by applicant]
US 20230036739A1 · Deppisch et al. · 2023 [cited by applicant]
EP 3208996A1 · 2017 [cited by applicant]
EP 3494506A1 · 2019 [cited by applicant]
Doan TP, Jung S. Davs: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC-Computers Materials & Continua. Jan. 1, 2022;72(1):1699-711. Jan. 1, 2022 (Jan. 1, 2022). [cited by applicant]
International Search Report for PCT Application No. PCT/IB2022/059483. The International Bureau of WIPO, Dated Jan. 5, 2023. [cited by applicant]
International Search Report for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
International Search Report for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]
International Search Report, PCT/IB2023/052415; Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the International Searching Authority for PCT Application No. PCT/IB2022/059483 dated Jan. 8, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the International Searching Authority, PCT/IB2023/052415. Israel Patent Office, Jerusalem. Dated Jun. 14, 2023. [cited by applicant]
Written Opinion of the Searching Authority for PCT application PCT/IB2023/052413 dated Jun. 12, 2023. The International Bureau of WIPO. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2023/057511, dated Nov. 2, 2023. Searching Authority Israel Patent Office, Jerusalem, Israel. [cited by applicant]