The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 26, 2022

Filed:

Dec. 17, 2020
Applicant:

Sri International, Menlo Park, CA (US);

Inventors:

Phillip A. Porras, Cupertino, CA (US);

Vinod Yegneswaran, Foster City, CA (US);

Jaehyun Nam, Daejeon, KR;

Seungwon Shin, Daejeon, KR;

Assignee:

SRI International, Menlo Park, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 11/34 (2006.01); G06N 10/00 (2022.01); G06N 3/08 (2006.01); G06F 11/36 (2006.01); H04L 61/103 (2022.01);
U.S. Cl.
CPC ...
G06F 11/3409 (2013.01); G06F 11/36 (2013.01); G06N 3/08 (2013.01); G06N 10/00 (2019.01); H04L 63/0236 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01); H04L 61/103 (2013.01); H04L 63/029 (2013.01);
Abstract

A method, apparatus and system for providing security for a container network having a plurality of containers includes establishing a network stack for each of the plurality of containers of the container network, determining network and policy information from active containers, based on a set of pre-determined inter-container dependencies for the plurality of containers learned from the determined network and policy information, configuring container access in the container network to be limited to only containers of the plurality of containers that are relevant to a respective communication, and configuring inter-container traffic in the container network to be directed only from a source container into a destination container in a point-to-point manner such that exposure of the inter-container traffic to peer containers is prevented.


Find Patent Forward Citations

Loading…