主权项 |
1. A method for security in a container-based virtualization environment comprising:
receiving metadata about a deployed container from a container orchestration layer, the metadata including an image type of the deployed container, the deployed container being deployed in a hardware server; determining an application or service performed by the deployed container from the received metadata; retrieving at least one model using the determined application or service, the at least one model identifying expected network communications behavior of the deployed container; generating a high-level declarative security policy associated with the deployed container using the at least one model, the high-level declarative security policy indicating at least an application or service with which the deployed container communicates; and launching a compiler, the compiler producing a low-level firewall rule set using the high-level declarative security policy, the low-level firewall rule set being provided to an enforcement point, the enforcement point applying the low-level firewall rule set to data network traffic. |