IP Library Granted Patent US 10,333,951
Granted Patent B1
US 10,333,951 · App. 15/664,719 · Granted Jun 25, 2019

Method and system for implementing golden container storage

Inventors: Assaf Natanzon (Tel Aviv, IL); Amit Lieberman (Kefar Sava, IL); Oron Golan (Meitar, IL); Yuri Manusov (Beer Sheba, IL); Raul Shnier (Kibbutz Ruhama, IL)
Assignee: EMC IP Holding Company LLC
H04L63/1416H04L63/1425H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,951
App. No.
15/664,719
Granted
Jun 25, 2019
Kind
B1
Abstract

A method and a system for implementing golden container storage. Specifically, the disclosed method and system entail the creation of a container registry to securely store golden containers (or templates) for containers of specific application types that execute within a service platform. Given short retention spans, the containers are constantly being cycled out. Each recreated container is modeled after one of the golden containers, and assigned new Internet Protocol (IP) and/or media access control (MAC) addresses rather than assuming the existing addresses of the containers the recreated containers replace. Substantively, embodiments of the invention employ these tactics towards implementing a moving target defense (MTD) strategy.

Claims (88)

1. A method for managing containers, comprising:

selecting a first container executing on a service platform;

scanning the first container for malicious activity;

based on the scanning, determining that the first container is contaminated;

in response to the determining, obtaining a golden container from a container registry;

generating a second container based on the golden container;

connecting the second container into the service platform to replace the first container;

disconnecting the first container from the service platform;

after disconnecting the first container from the service platform:

feeding emulated network traffic to the first container; and

maintaining the first container as a honeypot.

2. The method of claim 1 , wherein the first container is associated with a first Internet Protocol (IP) address and a first media access control (MAC) address, wherein the second container is associated with a second IP address and a second MAC address.

3. The method of claim 1 , further comprising:

determining that a retention time for a third container has elapsed;

in response to the determining, obtaining the golden container from the container registry;

generating a fourth container based on the golden container;

connecting the fourth container into the service platform to replace the third container; and

disconnecting the third container from the service platform.

4. The method of claim 3 , further comprising:

selecting a third container executing on the service platform;

scanning third container for the malicious activity;

based on the scanning, determining that the third container is clean;

in response to the determining, generating the golden container based on the third container; and

storing the golden container in the container registry.

5. The method of claim 3 , wherein the first container, the golden container, the second container, the third container, and the fourth container are all associated with a same application type.

6. The method of claim 1 , wherein the malicious activity comprises at least one in a group consisting of a known attack signature and anomalous behavior.

7. A system, comprising:

a service platform; and

a container management system (CMS) kernel operatively connected to the service platform, and programmed to:

select a first container executing on a service platform;

scan the first container for malicious activity;

based on the scanning, determine that the first container is contaminated;

in response to the determining, obtain a golden container from a container registry;

generate a second container based on the golden container;

connect the second container into the service platform to replace the first container;

disconnect the first container from the service platform;

after disconnecting the first container from the service platform:

feed emulated network traffic to the first container; and

maintain the first container as a honeypot.

8. The system of claim 7 , further comprising a set of servers whereon a set of containers is executing, wherein the service platform comprises the set of servers, wherein the set of containers comprises the first container and the second container.

9. The system of claim 7 , further comprising a CMS comprising the CMS kernel and the container registry.

10. The system of claim 7 , further comprising a container scanner operatively connected to the CMS kernel, and programmed to:

scan a third container executing on the service platform for malicious activity, wherein the CMS kernel is further programmed to:

select the third container;

generate a scan request comprising a container ID associated with the third container;

submit the scan request to the container scanner;

after scanning of the third container, receive a scan response from the container scanner;

based on the scan response, determine that the third container is clean;

in response to the determining, generate the golden container based on the third container; and

store the golden container in the container registry.

11. The system of claim 7 , wherein the container management system (CMS) is further programmed to:

determine that a retention time for a third container has elapsed;

in response to the determining, obtain a golden container from the container registry;

generate a fourth container based on the golden container;

connect the fourth container into the service platform to replace the third container; and

disconnect the third container from the service platform.

12. The system of claim 11 , further comprising a retention tracker operatively connected to the CMS kernel, and programmed to:

track the retention time for the third container;

based on an elapsing of the retention time, notify the CMS kernel of the elapsing;

based on a connecting of the fourth container, initialize a second retention time for the fourth container; and

track the second retention time.

13. The system of claim 11 , wherein the first container, the golden container, the second container, and the third container, and the fourth container are all associated with a same application type.

14. A non-transitory computer readable medium (CRM) comprising computer readable program code, which when executed by a computer processor, enables the computer processor to:

select a first container executing on a service platform;

scan the first container for malicious activity;

based on the scanning, determine that the first container is contaminated;

in response to the determining, obtain a golden container from a container registry;

generate a second container based on the golden container;

connect the second container into the service platform to replace the first container;

disconnect the first container from the service platform;

after disconnecting the first container from the service platform:

feed emulated network traffic to the first container; and

maintain the first container as a honeypot.

15. The non-transitory CRM of claim 14 , wherein the first container is associated with a first Internet Protocol (IP) address and a first media access control (MAC) address, wherein the second container is associated with a second IP address and a second MAC address.

16. The non-transitory CRM of claim 14 , further comprising additional computer readable program code, which when executed by the computer processor, enables the computer processor to:

select a third container executing on the service platform;

scan the third container for malicious activity;

based on the scanning, determine that the third container is clean;

in response to the determining, generate the golden container based on the third container; and

store the golden container in the container registry.

17. The non-transitory CRM of claim 14 , wherein malicious activity comprises at least one in a group consisting of a known attack signature and anomalous behavior.

18. The non-transitory CRM of claim 14 , further comprising additional computer readable program code, which when executed by the computer processor, enables the computer processor to:

determine that a retention time for a third container has elapsed;

in response to the determining, obtain a golden container from a container registry;

generate a fourth container based on the golden container;

connect the fourth container into a service platform to replace the first container; and

disconnect the third container from the service platform.

19. The non-transitory CRM of claim 18 , wherein the first container, the golden container, the second container, the third container, and the fourth container are all associated with a same application type.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2017
From: NATANZON, ASSAF; LIEBERMAN, AMIT; GOLAN, ORON; MANUSOV, YURI; SHNIER, RAUL
To: EMC IP HOLDING COMPANY
Reel/Frame 044340/0961 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Cited By (2)
US 12,335,294 US 12,585,760