-
公开(公告)号:US11893106B2
公开(公告)日:2024-02-06
申请号:US16944480
申请日:2020-07-31
Inventor: Sung-Jin Kim , Hyunyi Yi , Chulwoo Lee , Woomin Hwang , Byungjoon Kim
IPC: G06F21/53
CPC classification number: G06F21/53 , G06F2221/034
Abstract: An apparatus and method for generating a system call whitelist for an application container. The method may include determining whether a container is based on machine code or non-machine code by analyzing the internal configuration of the running container, identifying system calls included in an application through binary static analysis or static analysis of source code selected depending on the determination of whether the container is based on machine code or non-machine code, and generating a whitelist based on the numbers of all of the identified system calls.
-
公开(公告)号:US11159577B2
公开(公告)日:2021-10-26
申请号:US16555026
申请日:2019-08-29
Inventor: Hyunyi Yi , Sung-Jin Kim , Chulwoo Lee , Woomin Hwang , Byungjoon Kim
IPC: H04L29/06
Abstract: A method for interworking of a security tool and a cloud platform includes checking whether there is a record of confirming or applying security related to a target identifier when a cloud platform client calls a platform interface module, determining whether to interwork with the security tool when the record of confirming or applying security related to the target identifier is not present, requesting a resource required for running the security tool to the cloud platform when the security tool is invoked, and obtaining the resource from the cloud platform and storing the same.
-
公开(公告)号:US11669622B2
公开(公告)日:2023-06-06
申请号:US16991362
申请日:2020-08-12
Inventor: Hyunyi Yi , Sung-Jin Kim , Chulwoo Lee , Woomin Hwang , Byungjoon Kim
IPC: G06F21/57
CPC classification number: G06F21/577 , G06F2221/033
Abstract: A method and apparatus for providing security visibility into a container image. The method includes generating a software list by analyzing layers forming a container image, generating a vulnerability check result based on the software list, and generating a container image content report based on the software list and the vulnerability check result.
-
-