IP Library Granted Patent US 11,277,436
Granted Patent B1
US 11,277,436 · App. 16/450,652 · Granted Mar 15, 2022

Identifying and mitigating harm from malicious network connections by a container

Inventors: Spencer Dale Smith (El Segundo, CA); Frank X. Barajas (Redondo Beach, CA); Paul D. Hernandez (Redondo Beach, CA)
Assignee: CA, INC.
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,436
App. No.
16/450,652
Granted
Mar 15, 2022
Kind
B1
Abstract

Identifying and mitigating harm from malicious network connections by a container. In some embodiments, a method may include receiving, from a shim, notifications of all network connections that a container has sought to establish through the shim. The method may also include monitoring all actual network connections established by the container. The method may further include comparing the notifications to the actual network connections to determine whether any actual network connection established by the container bypassed the shim. The method may also include, in response to determining that any actual network connection established by the container bypassed the shim, identifying the network connection established by the container that bypassed the shim as a malicious network connection, and performing a security action to mitigate harm from the malicious network connection.

Claims (44)

1. A computer-implemented method for identifying and mitigating harm from malicious network connections by a container, at least a portion of the method being performed by one or more computing devices comprising one or more processors, the method comprising:

receiving, from a shim, notifications of all network connections that the container has sought to establish through the shim, wherein the notifications are received from a shim library due to a function from the shim library being called from within the container;

monitoring all the network connections established by the container;

comparing the notifications to the network connections established by the container to determine whether a network connection established by the container bypassed the shim by using an illegitimate API call to the shim library of the shim, wherein a notification of the network connection that bypassed the shim does not have an identifier associated with the container and the shim library; and

in response to determining that the network connection established by the container bypassed the shim:

identifying the network connection established by the container that bypassed the shim as a malicious network connection; and

performing a security action to mitigate harm from the malicious network connection.

2. The method of claim 1 , wherein the performing of the security action to mitigate harm from the malicious network connection comprises one or more of:

blocking the malicious network connection, rerouting the malicious network connection, or throttling the malicious network connection.

3. The method of claim 1 , wherein the performing of the security action to mitigate harm from the malicious network connection comprises one or more of:

blocking the container, quarantining the container, or terminating execution of the container.

4. The method of claim 1 , wherein the monitoring of all the network connections established by the container comprises monitoring net flow logs of all the network connections established by the container.

5. The method of claim 1 , wherein the malicious network connection originated from a malicious third-party library that was injected into the container.

6. The method of claim 1 , wherein each notification of each network connection includes an IP address of another device with which the container seeks to communicate over a corresponding network connection.

7. A computer-implemented method for identifying and mitigating harm from malicious network connections by a container, at least a portion of the method being performed by one or more computing devices comprising one or more processors, the method comprising:

determining a unique identifier that is associated with the container;

receiving, from a shim, notifications of all network connections that the container has sought to establish through the shim, each notification either including the unique identifier or not including the unique identifier;

monitoring all the network connections established by the container;

comparing the notifications to the network connections established by the container to determine whether a network connection established by the container bypassed the shim by using an illegitimate API call from within the container, wherein a notification of the network connection that bypassed the shim does not have the unique identifier associated with the container; and

in response to determining that the network connection established by the container bypassed the shim:

identifying the network connection established by the container that bypassed the shim as a malicious network connection, wherein the malicious network connection originated from a malicious third-party library that was injected into the container; and

performing a security action to mitigate harm from the malicious network connection.

8. The method of claim 7 , wherein the performing of the security action to mitigate harm from the malicious network connection comprises one or more of:

blocking the malicious network connection, rerouting the malicious network connection.

9. The method of claim 7 , wherein the performing of the security action to mitigate harm from the malicious network connection comprises one or more of:

blocking the container, quarantining the container, or terminating execution of the container.

10. The method of claim 7 , wherein:

the shim comprises a shim library; and

the receiving, from the shim library, of the notifications comprises receiving the notifications from the shim library due to a function from the shim library being called from within the container.

11. The method of claim 7 , wherein the monitoring of all the network connections established by the container comprises monitoring net flow logs of all the network connections established by the container.

12. The method of claim 7 , wherein each notification of each network connection includes an IP address of another device with which the container seeks to communicate over a corresponding network connection.

13. The method of claim 7 , wherein the determining of the unique identifier that is associated with the container comprises receiving the unique identifier over a secure channel prior to the container establishing any network connections.

14. One or more non-transitory computer-readable media comprising one or more computer-readable instructions that, when executed by one or more processors of one or more computing devices, cause the one or more computing devices to perform a method for identifying and mitigating harm from malicious network connections by a container, the method comprising:

receiving, from a shim, notifications of all network connections that the container has sought to establish through the shim;

monitoring all the network connections established by the container;

comparing the notifications to the network connections to determine whether a network connection established by the container bypassed the shim by using an illegitimate API call to a shim library of the shim, wherein a notification of the network connection that bypassed the shim does not have an identifier associated with the container and the shim library; and

in response to determining that the network connection established by the container bypassed the shim:

identifying the network connection established by the container that bypassed the shim as a malicious network connection, wherein the malicious network connection originated from a malicious third-party library that was injected into the container; and

performing a security action to mitigate harm from the malicious network connection.

15. The one or more non-transitory computer-readable media of claim 14 , wherein the performing of the security action to mitigate harm from the malicious network connection comprises one or more of:

blocking the malicious network connection, rerouting the malicious network connection, throttling the malicious network connection, blocking the container, quarantining the container, or terminating execution of the container.

16. The one or more non-transitory computer-readable media of claim 14 , wherein:

the receiving, from the shim, the notifications of all the network connections comprises receiving the notifications from the shim library due to a function from the shim library being called from within the container.

17. The one or more non-transitory computer-readable media of claim 14 , wherein the monitoring of all the network connections established by the container comprises monitoring net flow logs of all the network connections established by the container.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2019
From: HERNANDEZ, PAUL D.; BARAJAS, FRANK X.; SMITH, SPENCER DALE
To: SYMANTEC CORPORATION
Reel/Frame 049570/0837 →