The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 18, 2023

Filed:

Apr. 22, 2021
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Yuji Watanabe, Chuouku, JP;

Ruriko Kudo, Saitama, JP;

Kugamoorthy Gajananan, Toshima-ku, JP;

Hirokuni Kitahara, Sumida-ku, JP;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/54 (2013.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01); G06F 21/57 (2013.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 21/577 (2013.01); G06F 21/54 (2013.01); G06F 21/56 (2013.01); G06F 21/62 (2013.01);
Abstract

A computer-implemented method for assessing latent security risks in Kubernetes clusters is provided including selecting a service account from a plurality of service accounts defined in namespaces of a cluster, binding a role to the selected service account based on predetermined role-binding data, and determining if the role meets at least one of a first, second, and third conditions based on predetermined role data defining permitted operations for roles, the first condition being that the role can receive secret tokens for pods within a namespace of the namespaces, the second condition being that the role can perform execution operation to other pods, and the third condition being that the role can create DaemonSet, Deployment, StatefulSet, and additional pods on the namespace.


Find Patent Forward Citations

Loading…