IP Library Granted Patent US 12,488,146
Granted Patent B2
US 12,488,146 · App. 17/699,521 · Granted Dec 2, 2025

Filtering sensitive data in cloud native application logs

Inventors: Da Li Liu (Beijing, CN); Qi Feng Huo (Beijing, CN); Lei Li (Beijing, CN); Yuan Yuan Wang (Beijing, CN); Yan Song Liu (Beijing, CN)
Assignee: International Business Machines Corporation
G06F21/6254G06F21/31G06F21/6218H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,146
App. No.
17/699,521
Granted
Dec 2, 2025
Kind
B2
Abstract

A computer-implemented method to limit access to sensitive information by filtering log files. The method includes deploying a first pod on a node of a cloud computing system, where the first pod includes a first container configured to run an application. The method also includes generating a first log file for the first container, where the first log file includes a set of actions performed by the application for a period of time. The method further includes filtering, by a filter, the first log file wherein the filter is configured to remove a type of sensitive data from the first log file. The method includes exporting, in response to the filtering, the first log file to the node. Advantageously, this can prevent various parties from accessing sensitive data that is contained in log files.

Claims (41)

1 . A computer-implemented method comprising:

deploying a first pod on a node of a cloud computing system, wherein the first pod includes a first container configured to run an application and the node is contained within a computing device;

deploying a second pod on the node within the computing device;

generating a first log file for the first container, wherein the first log file includes a set of actions performed by the application for a period of time;

filtering, by a filter, the first log file wherein the filter is configured to remove a type of sensitive data from the first log file;

exporting, from the first pod and in response to the filtering, the first log file to a log storage on the node, wherein the log storage is outside of the first pod wherein a second container in the second pod can access the log storage on the node; and

rotating, in response to an event, the first log file from the log storage, wherein the event is closing the first pod and the rotating includes removing the first log file from the node.

2 . The computer-implemented method of claim 1 , wherein the exporting includes storing the first log file in the log storage.

3 . The computer-implemented method of claim 1 , wherein the first log file stored in the log storage is accessible to a user account for the node.

4 . The computer-implemented method of claim 1 , further comprising:

generating a second log file, wherein the first log file is a standard output log and the second log file is a standard error log.

5 . The computer-implemented method of claim 4 , wherein the filter includes one or more providers, and a first provider is configured to remove the type of sensitive data, and a second provider is configured to remove a second type of sensitive data.

6 . The computer-implemented method of claim 5 , wherein the first log file and the second log file are filtered by a common set of providers.

7 . The computer-implemented method of claim 5 , wherein the first log file is filtered by the first provider and the second log file is filtered by the second provider.

8 . The computer-implemented method of claim 1 , wherein the filter includes a user interface configured to receive, from a data owner, one or more filter scripts, wherein each filter script is configured to remove a different type of sensitive data from the first log file.

9 . The computer-implemented method of claim 8 , wherein the each filter script can identify the different type of sensitive data and replace the different type of sensitive data with a generic value.

10 . A system comprising:

a processor;

a node of a cloud computing system configured to operate a plurality of pods received from one or more hosts, wherein the node is contained within a computing device, and the node includes a log storage; and

a computer-readable storage medium communicatively coupled to the processor and storing program instructions which, when executed by the processor, are configured to cause the processor to:

receive a first pod of the plurality of pods to the node of a cloud computing system, wherein the first pod:

includes a first container configured to run an application;

generates a first log file for the first container, wherein the first log file includes a set of actions performed the application for a period of time;

filters, by a filter, the first log file wherein the filter is configured to remove a type of sensitive data from the first log file; and

export, from the first pod and in response to the filtering of the first log file, the first log file to the log storage, wherein the log storage is outside of the first pod;

receive a second pod of the plurality of pods to the node of the cloud computing system, wherein a second container in the second pod can access the log storage on the node; and

rotate, in response to an event, the first log file from the log storage, wherein the event is closing the first pod and the rotating includes removing the first log file from the node.

11 . The system of claim 10 , wherein the node is configured to store a set of log files generated on the node, include the first log file in response to the export of the first log file.

12 . The system of claim 11 , wherein the set of log files is accessible to an account authorized to access the node.

13 . The system of claim 10 , wherein the filter includes a series of two or more filter scripts, and each filter script is configured to remove a different type of data from the first log file.

14 . A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processing unit to cause the processing unit to:

deploy a first pod on a node of a cloud computing system, wherein the first pod includes a first container configured to run an application and the node is contained within a computing device;

deploy a second pod on the node within the computing device;

generate a first log file for the first container, wherein the first log file includes a set of actions performed the application for a period of time;

filter, by a filter, the first log file wherein the filter is configured to remove a type of sensitive data from the first log file;

export, from the first pod and in response to the filtering, the first log file to a log storage on the node, wherein the log storage is outside of the first pod wherein a second container in the second pod can access the log storage on the node; and

rotate, in response to an event, the first log file from the log storage, wherein the event is closing the first pod and the rotating includes removing the first log file from the node.

15 . The computer program product of claim 14 , wherein the program instructions are further configured to cause the processing unit to:

generate a second log file, wherein the first log file is a standard output log and the second log file is a standard error log.

16 . The computer program product of claim 15 , wherein the filter includes one or more providers, and a first provider is configured to remove the type of sensitive data, and a second provider is configured to remove a second type of sensitive data.

17 . The computer program product of claim 16 , wherein the first log file and the second log file are filtered by a common set of providers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2022
From: LIU, DA LI; HUO, QI FENG; LI, LEI; WANG, YUAN YUAN; LIU, YAN SONG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 059324/0429 →
Continuity (1)
Related Publication 20230297719A1 · Sep 21, 2023
References Cited (32)
US 9454671B2 · Engberg · 2016 [cited by examiner]
US 10762049B1 · Liang · 2020 [cited by examiner]
US 10929415B1 · Shcherbakov · 2021 [cited by examiner]
US 11113301B1 · Modestino · 2021 [cited by examiner]
US 20120072992A1 · Arasaratnam · 2012 [cited by examiner]
US 20170004185A1 · Zhu · 2017 [cited by examiner]
US 20190034652A1 · Kludy · 2019 [cited by examiner]
US 20190243687A1 · Chen · 2019 [cited by examiner]
US 20200137097A1 · Zimmermann · 2020 [cited by applicant]
US 20200159421A1 · Karumbunathan · 2020 [cited by examiner]
US 20200285772A1 · Malecki · 2020 [cited by applicant]
US 20210026611A1 · Bequet · 2021 [cited by examiner]
US 20210056225A1 · Sislow · 2021 [cited by examiner]
US 20210224259A1 · Shcherbakov · 2021 [cited by examiner]
US 20210297487A1 · Hegde · 2021 [cited by examiner]
US 20220156247A1 · Gururaj · 2022 [cited by examiner]
US 20220342997A1 · Watanabe · 2022 [cited by examiner]
CN 116800465A · 2023 [cited by applicant]
DE 102012220716A1 · 2013 [cited by applicant]
JP 2023138909A · 2023 [cited by applicant]
Fu, Yuqi, et al. “Progress-based container scheduling for short-lived applications in a kubernetes cluster.” 2019 IEEE International Conference on Big Data (Big Data). IEEE, 2019. (Year: 2019). [cited by examiner]
Tak, Byungchul, et al. “Understanding security implications of using containers in the cloud.” 2017 USENIX Annual Technical Conference (USENIX ATC 17). 2017. (Year: 2017). [cited by examiner]
“De-identifying sensitive data”, Google Cloud, Last updated Nov. 19, 2021, 26 pages, <https://cloud.google.com/dlp/docs/deidentify-sensitive-data>. [cited by applicant]
“Filter secrets from Kubernetes logs”, radu's blog, Aug. 20, 2018, 7 pages, <https://radu-matei.com/blog/filter-k8s-ogs/>. [cited by applicant]
“kubernetes / enhancements”, GitHub, KEP-1753: Kubernetes system components logs sanitization, downloaded from the Internet on Nov. 30, 2021, 12 pages. [cited by applicant]
“Logging Architecture”, Kubernetes, downloaded from the Internet on Feb. 14, 2022, 9 pages, <https://kubernetes.io/docs/concepts/cluster-administration/logging/>. [cited by applicant]
“Manage sensitive data with Docker secrets”, Docker Documentation, downloaded from the Internet on Nov. 30, 2021, 21 pages, <https://docs.docker.com/engine/swarm/secrets/>. [cited by applicant]
Authors et. al.: Disclosed Anonymously, “Processing Logs in Real Time to Create Kubernetes Events Upon Filtered Logs”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000266246D, IP.com Electronic Pub… [cited by applicant]
Baer et al., “Using logging for your apps running on Kubernetes Engine”, Google Cloud, May 11, 2020, 11 pages, <https://cloud.google.com/blog/products/management-tools/using-logging-your-apps-running-kubernetes-engine>. [cited by applicant]
Crosbymichael, “Shim pluggable logging #3085”, GitHub, containerd / containerd, Mar. 8, 2019, 8 pages, <https://github.com/containerd/containerd/pull/3085>. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, Recommendations of the National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Wang, Rosemary, “Application Logging in Kubernetes with fluentd”, Feb. 14, 2018, 10 pages, <https://medium.com/@joatmon08/application-logging-in-kubernetes-with-fluentd-4556f1573672>. [cited by applicant]