- 专利标题: Identifying container file events for providing container security
-
申请号: US15647269申请日: 2017-07-12
-
公开(公告)号: US10678935B2公开(公告)日: 2020-06-09
- 发明人: Laxmikant Gunda , Nilesh Awate , Priyal Rathi
- 申请人: NICIRA, INC.
- 申请人地址: US CA Palo Alto
- 专利权人: Nicira, Inc.
- 当前专利权人: Nicira, Inc.
- 当前专利权人地址: US CA Palo Alto
- 代理机构: Fish & Richardson P.C.
- 优先权: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@6912a307
- 主分类号: G06F21/62
- IPC分类号: G06F21/62 ; G06F9/455 ; G06F21/53
摘要:
A method of providing security for containers executing on a physical host machine is provided. The method receives a notification of a file access request. The notification includes a path in a file system of the host machine being accessed by a process. From the path, the method determines whether the file access event is for accessing a location in the file system to which container file systems are mapped. The method identifies a namespace of the process using the identification of the process included in the file path. The method determines the process is a container when the namespace belongs to a service that is used to implement containers on the host machine. The method sends the identifier of the container, the identification of a VM executing the container, and the file path to a set of security applications to determine whether the file access request to be allowed.
公开/授权文献
信息查询