IP Library › Granted Patent US 12,608,485
Granted Patent B2
US 12,608,485 · App. 18/540,192 · Granted Apr 21, 2026

Enhancing container security by performing container vulnerability reduction based on library and/or function removal and system call blocking

Inventor: Azzedine Benameur (Fairfax, VA)
Assignee: NetApp, Inc.
G06F21/577G06F8/75G06F21/51G06F21/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,485
App. No.
18/540,192
Granted
Apr 21, 2026
Kind
B2
Abstract

Systems and methods for enhancing container security are provided. In one example, exposure of a containerize application to potential security vulnerabilities is reduced by identifying dynamically loaded symbols by the application via performance of static and/or dynamic symbol analysis to identify dynamically loaded symbols that are potentially and/or actually used, respectively, and that correspond to functions contained within shared libraries. Based on a shared library's usage of functions within a standard library and a known mapping between functions of the standard library and system calls, those system calls potentially and actually accessed by the application may be identified and a security policy may be generated and configured for enforcement by a kernel security module to limit system call usage accordingly. Additionally, removal of files or functions of libraries that are deemed unnecessary for proper execution of the applications may be performed to reduce the footprint of the application.

Claims (65)

1 . A method of reducing one or more security vulnerabilities to which an application associated with a first container image is exposed, the method comprising:

receiving the first container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application in a production environment, identifying a first set of libraries or functions of the one or more libraries that are not used by the application by performing one or more of:

static analysis of an executable representing the application; and

dynamic monitoring of the application as the application is run in a build environment;

generating a second container image in which the application and its dependencies are packaged that excludes the identified first set of libraries or functions;

deploying a container based on the second container image within the production environment; and

causing a kernel security module to block one or more kernel system calls during execution of the application in the production environment based on identification of one or more dynamically loaded symbols corresponding to one or more functions of the one or more libraries.

2 . The method of claim 1 , wherein at least a first kernel system call of the one or more kernel system calls represents a kernel system call that might or might not be used by the application, wherein the method further comprises identifying a first subset of the one or more dynamically loaded symbols during the static analysis, wherein the first subset of the one or more dynamically loaded symbols correspond to one or more functions of a first set of functions contained within a first shared library of the one or more libraries.

3 . The method of claim 2 , wherein the one or more functions ultimately lead to respective kernel system calls of the one or more kernel system calls.

4 . The method of claim 2 , wherein the one or more dynamically loaded symbols are identified by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

5 . The method of claim 2 , further comprising:

creating or updating a security policy based at least on the first kernel system call; and

wherein said causing a kernel security module to block one or more kernel system calls comprises configuring the kernel security module based on the security policy.

6 . The method of claim 5 , wherein at least a second kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the method further comprises identifying a second subset of the one or more dynamically loaded symbols during a dynamic analysis, and wherein the second subset of the one or more dynamically loaded symbols correspond to one or more functions of a second set of functions contained within the first shared library or a second shared library of the one or more libraries.

7 . The method of claim 6 , further comprising:

refining the security policy based at least on the second kernel system call; and

wherein said causing a kernel security module to block one or more kernel system calls further comprises configuring the kernel security module based on the refined security policy.

8 . The method of claim 7 , wherein the security policy and the refined security policy comprise a syscall policy.

9 . The method of claim 6 , wherein the first shared library and the second shared library comprise one or more of a shared object file and a dynamic library.

10 . The method of claim 1 , wherein at least one kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the method further comprises identifying the one or more dynamically loaded symbols by performing a dynamic analysis including monitoring events that occur during the execution of the application in the production environment, and wherein the one or more dynamically loaded symbols correspond to one or more functions of a set of functions contained within a shared library of the one or more libraries.

11 . A non-transitory machine readable medium storing instructions for reducing one or more security vulnerabilities to which an application associated with a first container image is exposed, which when executed by one or more processing resources of a system, cause the system to:

receive the first container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application in a production environment, identify a first set of libraries or functions of the one or more libraries that are not used by the application by performing one or more of:

static analysis of an executable representing the application; and

dynamic monitoring of the application as the application is run in a build environment;

generate a second container image in which the application and its dependencies are packaged that excludes the identified first set of libraries or functions;

deploy a container based on the second container image within the production environment; and

cause a kernel security module to block one or more kernel system calls during execution of the application in the production environment based on identification of one or more dynamically loaded symbols corresponding to one or more functions of the one or more libraries.

12 . The non-transitory machine readable medium of claim 11 , wherein at least a first kernel system call of the one or more kernel system calls represents a kernel system call that might or might not be used by the application, wherein the instructions further cause the system to identify a first subset of the one or more dynamically loaded symbols during the static analysis, wherein the first subset of the one or more dynamically loaded symbols correspond to one or more functions of a first set of functions contained within a first shared library of the one or more libraries.

13 . The non-transitory machine readable medium of claim 12 , wherein the one or more functions ultimately lead to respective kernel system calls of the one or more kernel system calls.

14 . The non-transitory machine readable medium of claim 12 , wherein the one or more dynamically loaded symbols are identified by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

15 . The non-transitory machine readable medium of claim 12 , wherein the instructions further cause the system to:

create or update a security policy based at least on the first kernel system call; and

wherein the kernel security module is caused to block the one or more kernel system calls by configuring the kernel security module based on the security policy.

16 . The non-transitory machine readable medium of claim 15 , wherein at least a second kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the instructions further cause the system to identify a second subset of the one or more dynamically loaded symbols during a dynamic analysis, and wherein the second subset of the one or more dynamically loaded symbols correspond to one or more functions of a second set of functions contained within the first shared library or a second shared library of the one or more libraries.

17 . The non-transitory machine readable medium of claim 16 , wherein the instructions further cause the system to:

refine the security policy based at least on the second kernel system call; and

wherein the kernel security module is caused to block the one or more kernel system calls by configuring the kernel security module based on the refined security policy.

18 . The non-transitory machine readable medium of claim 17 , wherein the security policy and the refined security policy comprise a syscall policy.

19 . The non-transitory machine readable medium of claim 16 , wherein the first shared library and the second shared library comprise one or more of a shared object file and a dynamic library.

20 . The non-transitory machine readable medium of claim 11 , wherein at least one kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the instructions further cause the system to identify the one or more dynamically loaded symbols by performing a dynamic analysis including monitoring events that occur during the execution of the application in the production environment, and wherein the one or more dynamically loaded symbols correspond to one or more functions of a set of functions contained within a shared library of the one or more libraries.

21 . A system comprising:

one or more hardware processing resources; and

instructions for reducing one or more security vulnerabilities to which an application associated with a first container image is exposed that when executed by the one or more hardware processing resources cause the system to:

receive the first container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application in a production environment, identify a first set of libraries or functions of the one or more libraries that are not used by the application by performing one or more of:

static analysis of an executable representing the application; and

dynamic monitoring of the application as the application is run in a build environment;

generate a second container image in which the application and its dependencies are packaged that excludes the identified first set of libraries or functions;

deploy a container based on the second container image within the production environment; and

cause a kernel security module to block one or more kernel system calls during execution of the application in the production environment based on identification of one or more dynamically loaded symbols corresponding to one or more functions of the one or more libraries.

22 . The system of claim 21 , wherein at least a first kernel system call of the one or more kernel system calls represents a kernel system call that might or might not be used by the application, wherein the instructions further cause the system to identify a first subset of the one or more dynamically loaded symbols during the static analysis, wherein the first subset of the one or more dynamically loaded symbols correspond to one or more functions of a first set of functions contained within a first shared library of the one or more libraries.

23 . The system of claim 22 , wherein the one or more functions ultimately lead to respective kernel system calls of the one or more kernel system calls.

24 . The system of claim 22 , wherein the one or more dynamically loaded symbols are identified by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

25 . The system of claim 22 , wherein the instructions further cause the system to:

create or update a security policy based at least on the first kernel system call; and

wherein the kernel security module is caused to block the one or more kernel system calls by configuring the kernel security module based on the security policy.

26 . The system of claim 25 , wherein at least a second kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the instructions further cause the system to identify a second subset of the one or more dynamically loaded symbols during a dynamic analysis, and wherein the second subset of the one or more dynamically loaded symbols correspond to one or more functions of a second set of functions contained within the first shared library or a second shared library of the one or more libraries.

27 . The system of claim 26 , wherein the instructions further cause the system to:

refine the security policy based at least on the second kernel system call; and

wherein the kernel security module is caused to block the one or more kernel system calls by configuring the kernel security module based on the refined security policy.

28 . The system of claim 27 , wherein the security policy and the refined security policy comprise a syscall policy.

29 . The system of claim 26 , wherein the first shared library and the second shared library comprise one or more of a shared object file and a dynamic library.

30 . The system of claim 21 , wherein at least one kernel system call of the one or more kernel system calls represents a kernel system call that is actually used by the application, wherein the instructions further cause the system to identify the one or more dynamically loaded symbols by performing a dynamic analysis including monitoring events that occur during the execution of the application in the production environment, and wherein the one or more dynamically loaded symbols correspond to one or more functions of a set of functions contained within a shared library of the one or more libraries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: BENAMEUR, AZZEDINE
To: NETAPP, INC.
Reel/Frame 066391/0980 →
Continuity (3)
Provisional Application 63517693 · Aug 4, 2023
Provisional Application 63477598 · Dec 29, 2022
Related Publication 20240220616A1 · Jul 4, 2024
References Cited (28)
US 8656497B2 · Amarasinghe et al. · 2014 [cited by applicant]
US 11175902B2 · McLaren · 2021 [cited by applicant]
US 11748473B2 · Araujo et al. · 2023 [cited by applicant]
US 20200125731A1 · Benameur et al. · 2020 [cited by applicant]
US 20200285733A1 · Kim et al. · 2020 [cited by applicant]
US 20200293354A1 · Song · 2020 [cited by examiner]
US 20210026947A1 · Korotaev · 2021 [cited by applicant]
US 20240004993A1 · Rozenberg et al. · 2024 [cited by applicant]
US 20240220632A1 · Benameur · 2024 [cited by applicant]
US 20240220633A1 · Benameur · 2024 [cited by applicant]
US 20240220634A1 · Benameur · 2024 [cited by applicant]
EP 3640831B1 · 2022 [cited by examiner]
AppArmor., “Linux Kernel Security Module,” AppArmor, 2023, pp. 1-4 pages. URL: https://apparmor.net/. [cited by applicant]
Beattie S., “Getting Started,” AppArmor, 2023, 1 page. URL: https://gitlab.com/apparmor/apparmor/-/wikis/GettingStarted. [cited by applicant]
Benameur A., et al., “Container Attack Surface Reduction Beyond Name Space Isolation,” Accenture Labs, Security R&D, 2018, pp. 1-40. [cited by applicant]
Johansen J., “Documentation: AppArmor Documentation,” GitLab, 2023, 3 pages. URL: https://gitlab.com/apparmor/apparmor/-/wikis/Documentation. [cited by applicant]
Linux Tutorials., “SELinux Explained with Examples in Easy Language,” Computer Networking Notes, 2023, pp. 1-12. URL: https://www.computernetworkingnotes.com/linux-tutorials/selinux-explained-with-examples-in-easy-langu… [cited by applicant]
Wiki., “ELF—OSDev Wiki,” Unix System Laboratories, 2023, 9 pages. URL: https://wiki.osdev.org/ELF. [cited by applicant]
Canella C., et al., “Automating Seccomp Filter Generation for Linux Applications,” Proceedings of the 14th Acm Workshop on Artificial Intelligence and Security, Acmpub27, Nov. 15, 2021, 13 pages. [cited by applicant]
Hasan M.M., et al., “Decap: Deprivileging Programs by Reducing Their Capabilities,” Proceedings of the 1st Acm Sigspatial International Workshop on Geospatial Knowledge Graphs, Acmpub2 7, New York, NY, USA, Oct. 26, 202… [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/086071, mailed on Apr. 15, 2024, 17 pages. [cited by applicant]
Liguni T., et al., “Sprofiler: Automatic Generating System of Container-Native System Call Filtering Rules for Attack Surface Reduction,” 2021 International Conference on Computational Science and Computational Intellig… [cited by applicant]
Pailoor S., et al., “Automated Policy Synthesis for System Call Sandboxing,” Proceedings of the ACM on Programming Languages 4(OOPSLA), 2020, pp. 1-26. [cited by applicant]
Wan Z., et al., “Practical and Effective Sandboxing for Linux Containers,” Empirical Software Engineering, 2019, 38 pages. [cited by applicant]
Zhang H., et al., “One Size Does not Fit All: Security Hardening of MIPS Embedded Systems via Static Binary Debloating for Shared Libraries,” The Sixth International Conference on Information Management and Technology, … [cited by applicant]
Non-Final Office Action mailed on Aug. 19, 2025 for U.S. Appl. No. 18/540,165, filed Dec. 14, 2023, 11 pages. [cited by applicant]
Non-Final Office Action mailed on Sep. 11, 2025 for U.S. Appl. No. 18/540,211, filed Dec. 14, 2023, 23 pages. [cited by applicant]
Non-Final Office Action mailed Sep. 5, 2025 for U.S. Appl. No. 18/540,178, filed Dec. 14, 2023, 17 pages. [cited by applicant]