The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 24, 2026

Filed:

Jul. 31, 2021
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Frederico Araujo, White Plains, NY (US);

William Blair, Boston, MA (US);

Teryl Paul Taylor, Danbury, CT (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 9/48 (2006.01); G06F 9/38 (2018.01); G06F 9/50 (2006.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01); G06F 9/455 (2018.01);
U.S. Cl.
CPC ...
G06F 9/4881 (2013.01); G06F 9/3836 (2013.01); G06F 9/5044 (2013.01); G06F 21/53 (2013.01); G06F 21/566 (2013.01); G06F 9/45558 (2013.01); G06F 2009/45587 (2013.01);
Abstract

A method, apparatus and computer program product for automated security policy synthesis and use in a container environment. In this approach, a binary analysis of a program associated with a container image is carried out within a binary analysis platform. During the binary analysis, the program is micro-executed directly inside the analysis platform to generate a graph that summarizes the program's expected interactions within the run-time container environment. The expected interactions are identified by analysis of one or more system calls and their arguments found during micro-executing the program. Once the graph is created, a security policy is then automatically synthesized from the graph and instantiated into the container environment. The policy embeds at least one system call argument. During run-time monitoring of an event sequence associated with the program executing in the container environment, an action is taken when the event sequence is determined to violate the security policy.


Find Patent Forward Citations

Loading…