IP Library › Granted Patent US 12,743,523
Granted Patent B2
US 12,743,523 · App. 18/540,178 · Granted Sep 22, 2026

Enhancing container security by performing container vulnerability reduction based on static and dynamic analysis of dynamically loaded symbols and system call blocking

Inventor: Azzedine Benameur (Fairfax, VA)
Assignee: NetApp, Inc.
G06F21/577G06F8/75G06F21/51G06F21/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,523
App. No.
18/540,178
Granted
Sep 22, 2026
Kind
B2
Abstract

Systems and methods for enhancing container security are provided by reducing the attack surface. In one example, the exposure of containers to potential security vulnerabilities is reduced by identifying dynamically loaded symbols by an application via performance of static symbol analysis by examining a section of an executable to identify dynamically loaded symbols corresponding to functions contained within shared libraries. Based on a given shared library's usage of functions within standard libraries and a known mapping between functions of standard libraries and system calls, those system calls potentially accessed by the application may be identified and a security policy may be generated and configured for enforcement by a kernel security module to limit system call usage accordingly. Thereafter, the security policy enforced by the kernel security module may be refined based on performance of dynamic symbol analysis to identify system calls that are actually called by the application during runtime.

Claims (44)

1 . A method of reducing one or more security vulnerabilities to which an application associated with a container image is exposed, the method comprising:

receiving the container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application, identifying a first set of kernel system calls by performing a static analysis of an executable representing the application, wherein the static analysis discovers one or more dynamically loaded symbols corresponding to one or more functions of a shared library of the one or more libraries in which the one or more functions of the shared library depend on respective kernel system calls of the first set of kernel system calls;

creating or updating a security policy based on the first set of kernel system calls;

causing a kernel security module to block those kernel system calls that are not in the first set of kernel system calls during execution of the application by configuring the kernel security module based on the security policy;

during execution of the application, determining a second set of kernel system calls that are actually used by the application, wherein said determining involves observing actual use of one or more dynamically loaded symbols corresponding to the one or more functions of the shared library that ultimately lead to respective kernel system calls of the second set of kernel system calls, and wherein a decision regarding which of the one or more functions ultimately lead to respective kernel system calls of the second set of kernel system calls is arrived at by for each function of the one or more functions by determining a kernel system call of the second set of kernel system calls upon which the function is reliant based on usage by the function of a second set of one or more functions contained within a standard library of the one or more libraries and a known mapping between the second set of one or more functions and the respective kernel system calls;

refining the security policy based on the second set of kernel system calls; and

causing the kernel security module to block those kernel system calls that are not in the second set of kernel system calls during execution of the application by configuring the kernel security module based on the refined security policy.

2 . The method of claim 1 , wherein the one or more dynamically loaded symbols are discovered by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

3 . The method of claim 1 , wherein said determining is performed after a trigger event including one or more of execution of a different workload by the application or expiration of a predetermined or configurable period of time.

4 . The method of claim 1 , wherein the standard library comprises a standard C library.

5 . The method of claim 1 , wherein the kernel security module comprises Security-Enhanced Linux or Application Armor.

6 . The method of claim 1 , wherein the security policy and the refined security policy comprise a syscall policy.

7 . The method of claim 1 , wherein the shared library comprises a shared object file or a dynamic library.

8 . A non-transitory machine readable medium storing instructions, for reducing one or more security vulnerabilities to which an application associated with a container image is exposed, which when executed by one or more processing resources of a system, cause the system to:

receive the container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application, identify a first set of kernel system calls by performing a static analysis of an executable representing the application, wherein the static analysis discovers one or more dynamically loaded symbols corresponding to one or more functions of a shared library of the one or more libraries in which the one or more functions of the shared library depend on respective kernel system calls of the first set of kernel system calls;

create or update a security policy based on the first set of kernel system calls;

cause a kernel security module to block those kernel system calls that are not in the first set of kernel system calls during execution of the application by configuring the kernel security module based on the security policy;

during execution of the application, determine a second set of kernel system calls that are actually used by the application, wherein determination of the second set of kernel system calls involves observing actual use of one or more dynamically loaded symbols corresponding to the one or more functions of the shared library that ultimately lead to respective kernel system calls of the second set of kernel system calls, and wherein a decision regarding which of the one or more functions ultimately lead to respective kernel system calls of the second set of kernel system calls is arrived at by for each function of the one or more functions by determining a kernel system call of the second set of kernel system calls upon which the function is reliant based on usage by the function of a second set of one or more functions contained within a standard library of the one or more libraries and a known mapping between the second set of one or more functions and the respective kernel system calls;

refine the security policy based on the second set of kernel system calls; and

cause the kernel security module to block those kernel system calls that are not in the second set of kernel system calls during execution of the application by configuring the kernel security module based on the refined security policy.

9 . The non-transitory machine readable medium of claim 8 , wherein the one or more dynamically loaded symbols are discovered by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

10 . The non-transitory machine readable medium of claim 8 , wherein determination of the second set of kernel system calls is performed after a trigger event including one or more of execution of a different workload by the application or expiration of a predetermined or configurable period of time.

11 . The non-transitory machine readable medium of claim 8 , wherein the standard library comprises a standard C library.

12 . The non-transitory machine readable medium of claim 8 , wherein the kernel security module comprises Security-Enhanced Linux or Application Armor.

13 . The non-transitory machine readable medium of claim 8 , wherein the security policy and the refined security policy comprise a syscall policy.

14 . The non-transitory machine readable medium of claim 11 , wherein the shared library comprises a shared object file or a dynamic library.

15 . A system comprising:

one or more hardware processing resources; and

instructions for reducing one or more security vulnerabilities to which an application associated with a container image is exposed that when executed by the one or more hardware processing resources cause the system to:

receive the container image in which the application and its dependencies, including one or more libraries, are packaged;

prior to execution of the application, identify a first set of kernel system calls by performing a static analysis of an executable representing the application, wherein the static analysis discovers one or more dynamically loaded symbols corresponding to one or more functions of a shared library of the one or more libraries in which the one or more functions of the shared library depend on respective kernel system calls of the first set of kernel system calls;

create or update a security policy based on the first set of kernel system calls;

cause a kernel security module to block those kernel system calls that are not in the first set of kernel system calls during execution of the application by configuring the kernel security module based on the security policy;

during execution of the application, determine a second set of kernel system calls that are actually used by the application, wherein determination of the second set of kernel system calls involves observing actual use of one or more dynamically loaded symbols corresponding to the one or more functions of the shared library that ultimately lead to respective kernel system calls of the second set of kernel system calls, and wherein a decision regarding which of the one or more functions ultimately lead to respective kernel system calls of the second set of kernel system calls is arrived at by for each function of the one or more functions by determining a kernel system call of the second set of kernel system calls upon which the function is reliant based on usage by the function of a second set of one or more functions contained within a standard library of the one or more libraries and a known mapping between the second set of one or more functions and the respective kernel system calls;

refine the security policy based on the second set of kernel system calls; and

cause the kernel security module to block those kernel system calls that are not in the second set of kernel system calls during execution of the application by configuring the kernel security module based on the refined security policy.

16 . The system of claim 15 , wherein the one or more dynamically loaded symbols are discovered by parsing and analyzing one or more portions of the executable that contain dynamic linking information.

17 . The system of claim 15 , wherein determination of the second set of kernel system calls is performed after a trigger event including one or more of execution of a different workload by the application or expiration of a predetermined or configurable period of time.

18 . The system of claim 15 , wherein the standard library comprises a standard C library.

19 . The system of claim 15 , wherein the kernel security module comprises Security-Enhanced Linux or Application Armor.

20 . The system of claim 15 , wherein the security policy and the refined security policy comprise a syscall policy.

21 . The system of claim 15 , wherein the shared library comprises a shared object file or a dynamic library.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: BENAMEUR, AZZEDINE
To: NETAPP, INC.
Reel/Frame 066391/0974 →
Continuity (3)
Provisional Application 63517693 · Aug 4, 2023
Provisional Application 63477598 · Dec 29, 2022
Related Publication 20240220633A1 · Jul 4, 2024
References Cited (33)
US 8656497B2 · Amarasinghe et al. · 2014 [cited by applicant]
US 11175902B2 · McLaren · 2021 [cited by applicant]
US 11748473B2 · Araujo · 2023 [cited by examiner]
US 20200125731A1 · Benameur et al. · 2020 [cited by applicant]
US 20200285733A1 · Kim · 2020 [cited by examiner]
US 20200293354A1 · Song · 2020 [cited by examiner]
US 20210026947A1 · Korotaev · 2021 [cited by applicant]
US 20240004993A1 · Rozenberg · 2024 [cited by examiner]
US 20240220616A1 · Benameur · 2024 [cited by applicant]
US 20240220632A1 · Benameur · 2024 [cited by applicant]
US 20240220634A1 · Benameur · 2024 [cited by applicant]
EP 3640831B1 · 2022 [cited by applicant]
Automated Policy Synthesis for System Call Sandboxing (Year: 2020). [cited by examiner]
Automating Seccomp Filter Generation for Linux Applications (Year: 2021). [cited by examiner]
Canella C., et al., “Automating Seccomp Filter Generation for Linux Applications,” Proceedings of the 14th Acm Workshop on Artificial Intelligence and Security, Acmpub27, Nov. 15, 2021, 13 pages. [cited by applicant]
Hasan M.M., et al., “Decap: Deprivileging Programs by Reducing Their Capabilities,” Proceedings of the 1st Acm Sigspatial International Workshop on Geospatial Knowledge Graphs, Acmpub2 7, New York, Ny, USA, Oct. 26, 202… [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/086071, mailed on Apr. 15, 2024, 17 pages. [cited by applicant]
Liguni T., et al., “Sprofiler: Automatic Generating System of Container-Native System Call Filtering Rules for Attack Surface Reduction,” 2021 International Conference on Computational Science and Computational Intellig… [cited by applicant]
Pailoor S., et al., “Automated Policy Synthesis for System Call Sandboxing,” Proceedings of the ACM on Programming Languages 4(OOPSLA), 2020, pp. 1-26. [cited by applicant]
Wan Z., et al., “Practical and Effective Sandboxing for Linux Containers,” Empirical Software Engineering, 2019, 38 pages. [cited by applicant]
Zhang H., et al., “One Size Does not Fit All: Security Hardening of MIPS Embedded Systems via Static Binary Debloating for Shared Libraries,” The Sixth International Conference on Information Management and Technology, … [cited by applicant]
AppArmor., “Linux Kernel Security Module,” AppArmor, 2023, pp. 1-4 pages. URL: https://apparmor.net/. [cited by applicant]
Beattie S., “Getting Started,” AppArmor, 2023, 1 page. URL: https://gitlab.com/apparmor/apparmor/-/wikis/GettingStarted. [cited by applicant]
Benameur A., et al., “Container Attack Surface Reduction Beyond Name Space Isolation,” Accenture Labs, Security R&D, 2018, pp. 1-40. [cited by applicant]
Johansen J., “Documentation: AppArmor Documentation,” GitLab, 2023, 3 pages. URL: https://gitlab.com/apparmor/apparmor/-/wikis/Documentation. [cited by applicant]
Linux Tutorials., “SELinux Explained with Examples in Easy Language,” Computer Networking Notes, 2023, pp. 1-12. URL: https://www.computernetworkingnotes.com/linux-tutorials/selinux-explained-with-examples-in-easy-langu… [cited by applicant]
Wiki., “Elf—OSDev Wiki,” Unix System Laboratories, 2023, 9 pages. URL: https://wiki.osdev.org/ELF. [cited by applicant]
Non-Final Office Action mailed on Aug. 19, 2025 for U.S. Appl. No. 18/540,165, filed Dec. 14, 2023, 11 pages. [cited by applicant]
Non-Final Office Action mailed on Jul. 15, 2025 for U.S. Appl. No. 18/540,192, filed Dec. 14, 2024, 13 pages. [cited by applicant]
Non-Final Office Action mailed on Sep. 11, 2025 for U.S. Appl. No. 18/540,211, filed Dec. 14, 2023, 23 pages. [cited by applicant]
Final Office Action mailed on Jan. 12, 2026 for U.S. Appl. No. 18/540,165, filed Dec. 14, 2023, 15 pages. [cited by applicant]
Final Office Action mailed on Jan. 13, 2026 for U.S. Appl. No. 18/540,211, filed Dec. 14, 2023, 23 pages. [cited by applicant]
Notice of Allowance mailed on Dec. 3, 2025 for U.S. Appl. No. 18/540,192, filed Dec. 14, 2023, 08 pages. [cited by applicant]