The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 17, 2025

Filed:

Oct. 23, 2020
Applicant:

Red Hat, Inc., Raleigh, NC (US);

Inventors:

Giuseppe Scrivano, Milan, IT;

Daniel Walsh, Westford, MA (US);

Assignee:

Red Hat, Inc., Raleigh, NC (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 9/46 (2006.01); G06F 9/455 (2018.01); G06F 9/54 (2006.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 9/45558 (2013.01); G06F 9/545 (2013.01); G06F 21/562 (2013.01); G06F 21/566 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45591 (2013.01); G06F 2221/034 (2013.01);
Abstract

Embodiments of the present disclosure provide a substitute audit log for use by applications in the user-space of a host operating system to write audit information. When a container makes a system call attempting to write audit information to an audit log of the kernel, the kernel may utilize a predefined set of instructions indicating how to detect such system calls and how such system calls are to be modified so as to reroute the system call to an unprivileged socket. The kernel write the audit information of the system call to an unprivileged socket that is connected to a substitute audit log. A container management program monitoring the unprivileged socket may write the audit information to the substitute log which is defined in container specific directories of the container.


Find Patent Forward Citations

Loading…