IP Library Granted Patent US 12,554,856
Granted Patent B2
US 12,554,856 · App. 18/115,101 · Granted Feb 17, 2026

Detecting security vulnerabilities associated with software artifacts hosted by pods

Inventors: Shachee Mishra Gupta (Gurgaon, IN); Ashok Pon Kumar Sree Prakash (Bangalore, IN); Abhishek Jain (Pune, IN)
Assignee: International Business Machines Corporation
G06F21/577G06F8/61G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,856
App. No.
18/115,101
Granted
Feb 17, 2026
Kind
B2
Abstract

An example operation may include one or more of determining that a software artifact hosted by a pod within a cluster of a host platform contains code that is a security vulnerability, identifying a function within the software artifact that requests the code, activating a filter within the pod of the host platform which prevents execution of the function within the software artifact, and installing a fix for the security vulnerability within the software artifact.

Claims (60)

1 . An apparatus, comprising:

a memory configured to store computer-executable instructions; and

a processor configured to execute the computer-executable instructions to:

perform a static analysis of a code associated with a software artifact, wherein the software artifact is hosted by a first pod within a cluster of a host platform;

determine, based on the static analysis, that the code comprises a security vulnerability;

identify, based on the determination, a specific function among a plurality of functions within the software artifact, wherein the specific function requests the code;

activate, within the first pod, a filter on the specific function to restrict execution of the specific function while allowing the plurality of functions other than different from the specific function within the software artifact to continue with operations uninterrupted;

identify, based on the activation of the filter, a second pod, different from the first pod, within the cluster, wherein

the second pod is capable of execution of the specific function, and

the second pod does not contain the security vulnerability;

detect a request for the specific function;

offload, based on the detection of the request, the request to the second pod within the cluster for the execution of the specific function;

install, based on the offload of the request, a fix for the security vulnerability within the software artifact; and

deactivate, based on the installation of the fix within the software artifact, the filter within the first pod.

2 . The apparatus of claim 1 , wherein;

the filter comprises a secure computing mode (SECCOMP) filter, and

the processor is further configured to:

apply the SECCOMP filter to a kernel of an operating system of the first pod.

3 . The apparatus of claim 1 , wherein the processor is further configured to:

scan log data of the first pod; and

identify, based on the scanned log data, a version of the software artifact and a name of the software artifact.

4 . The apparatus of claim 3 , wherein the processor is further configured to:

query, based on the identified version and the identified name, a database to identify the security vulnerability.

5 . The apparatus of claim 1 , wherein the processor is further configured to:

download the fix from a software repository, wherein the software repository is associated with an operating system of the first pod.

6 . A computer-implemented method, comprising:

performing a static analysis of a code associated with a software artifact, wherein the software artifact is hosted by a first pod within a cluster of a host platform;

determining, based on the static analysis, that the code comprises a security vulnerability;

identifying, based on the determination, a specific function among a plurality of functions within the software artifact, wherein the specific function requests the code;

activating, within the first pod, a filter on the specific function to restrict execution of the specific function while allowing the plurality of functions different from the specific function within the software artifact to continue operating uninterrupted;

identifying, based on the activating of the filter, a second pod, different from the first pod, within the cluster, wherein

the second pod is capable of execution of the specific function, and

the second pod does not contain the security vulnerability;

detecting a request for the specific function;

offloading, based on the detecting of the request, the request to the second pod within the cluster for the execution of the specific function;

installing, based on the offloading of the request, a fix for the security vulnerability within the software artifact; and

deactivating, based on the installing of the fix within the software artifact, the filter within the first pod.

7 . The computer-implemented method of claim 6 , wherein:

the filter further comprises a secure computing mode (SECCOMP) filter, and

the computer-implemented method further comprises:

applying the SECCOMP filter to a kernel of an operating system of the first pod.

8 . The computer-implemented method of claim 6 , wherein the determining further comprises:

scanning log data of the first pod; and

identifying, based on the scanning of the log data, a version of the software artifact and a name of the software artifact.

9 . The computer-implemented method of claim 8 , wherein the determining further comprises:

querying, based on the identified version and the identified name, a database to identify the security vulnerability.

10 . The computer-implemented method of claim 6 , wherein the computer-implemented method further comprises:

downloading the fix from a software repository, wherein the software repository is associated with an operating system of the first pod.

11 . A computer-readable storage medium comprising instructions that, when executed by a processor, cause the processor to perform operations comprising:

performing a static analysis of a code associated with a software artifact, wherein the software artifact is hosted by a first pod within a cluster of a host platform;

determining, based on the static analysis, that the code comprises a security vulnerability;

identifying, based on the determination, a specific function among a plurality of functions within the software artifact, wherein the specific function requests the code;

activating, within the first pod, a filter on the specific function to restrict execution of the specific function while allowing the plurality of functions other than different from the specific function within the software artifact to continue operating uninterrupted;

identifying, based on the activating of the filter, a second pod, different from the first pod, within the cluster, wherein

the second pod is capable of execution of the specific function, and

the second pod does not contain the security vulnerability;

detecting a request for the specific function;

offloading, based on the detecting of the request, the request to the second pod within the cluster for the execution of the specific function;

installing, based on the offloading of the request, a fix for the security vulnerability within the software artifact; and

deactivating, based on the installing of the fix within the software artifact, the filter within the first pod.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2023
From: MISHRA GUPTA, SHACHEE; SREE PRAKASH, ASHOK PON KUMAR; JAIN, ABHISHEK
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062823/0086 →
Continuity (1)
Related Publication 20240289463A1 · Aug 29, 2024
References Cited (25)
US 11151024B2 · Hwang · 2021 [cited by examiner]
US 11188450B2 · Khan · 2021 [cited by examiner]
US 11288178B2 · Benes · 2022 [cited by examiner]
US 11463478B2 · Nadgowda · 2022 [cited by examiner]
US 11556315B2 · Fontecilla · 2023 [cited by examiner]
US 20180300220A1 · Agarwal · 2018 [cited by examiner]
US 20180300499A1 · Agarwal · 2018 [cited by examiner]
US 20190260716A1 · Lerner · 2019 [cited by applicant]
US 20220129539A1 · Walsh et al. · 2022 [cited by applicant]
US 20220156380A1 · Pradzynski et al. · 2022 [cited by applicant]
US 20220269790A1 · Rajana et al. · 2022 [cited by applicant]
US 20220337618A1 · Shemer et al. · 2022 [cited by applicant]
US 20240289463A1 · Mishra Gupta · 2024 [cited by examiner]
CN 106716432A · 2017 [cited by applicant]
CN 106746432A · 2017 [cited by applicant]
CN 109313687A · 2019 [cited by applicant]
CN 110795128A · 2020 [cited by applicant]
CN 114968470 · 2022 [cited by examiner]
CN 114968470A · 2022 [cited by applicant]
WO 2024180382A1 · 2024 [cited by applicant]
PACED: Provenance-based Automated Container Escape Detection. Abbas. IEEE. (Year: 2022). [cited by examiner]
XI Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices. Shamin. IEEE. (Year: 2020). [cited by examiner]
An Empirical Analysis of Practitioners' Perspectives on Security Tool Integration into DevOps. Rajapakse. ACM. (Year: 2021). [cited by examiner]
Qiao et al., Intelligent Container Reallocation at Microsoft 365, Jul. 2021, Conference: The ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE)At: Athe… [cited by applicant]
International Search Report issued in the International Application No. PCT/IB2023/0615, mailed on Jul. 8, 2024. [cited by applicant]