发明名称 Security policy generation using container metadata
摘要 Methods, systems, and media for producing a firewall rule set are provided herein. Exemplary methods may include: receiving metadata about a deployed container from a container orchestration layer; determining an application or service associated with the container from the received metadata; retrieving at least one model using the determined application or service, the at least one model identifying expected network communications behavior of the container; and generating a high-level declarative security policy associated with the container using the at least one model, the high-level declarative security policy indicating at least an application or service with which the container can communicate.
申请公布号 US9521115(B1) 申请公布日期 2016.12.13
申请号 US201615080519 申请日期 2016.03.24
申请人 vArmour Networks, Inc. 发明人 Woolward Marc
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Carr & Ferrell LLP 代理人 Carr & Ferrell LLP
主权项 1. A method for security in a container-based virtualization environment comprising: receiving metadata about a deployed container from a container orchestration layer, the metadata including an image type of the deployed container, the deployed container being deployed in a hardware server; determining an application or service performed by the deployed container from the received metadata; retrieving at least one model using the determined application or service, the at least one model identifying expected network communications behavior of the deployed container; generating a high-level declarative security policy associated with the deployed container using the at least one model, the high-level declarative security policy indicating at least an application or service with which the deployed container communicates; and launching a compiler, the compiler producing a low-level firewall rule set using the high-level declarative security policy, the low-level firewall rule set being provided to an enforcement point, the enforcement point applying the low-level firewall rule set to data network traffic.
地址 Mountain View CA US