Recovering cloud vulnerabilities with dynamic packaging
The computer tool enables network operators to remove unused, vulnerable software components from software applications based on CVE information, addressing the inadequacies of existing methods by allowing for timely cybersecurity threat mitigation without third-party updates.
Patent Information
- Application Number
- PCT/IB2023/061806
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-22
- Publication Date
- 2025-05-30
AI Technical Summary
Existing methods for managing software applications are inadequate in addressing cybersecurity threats posed by unused, vulnerable software components identified by Common Vulnerabilities and Exposures (CVE) information, as they require waiting for third-party software updates.
A computer tool that allows network operators to identify and remove unused, vulnerable software components from software applications, generating a new software image that excludes these components, thereby enabling timely elimination of cybersecurity threats without relying on third-party updates.
This solution allows network operators to autonomously eliminate vulnerable software components, reducing cybersecurity risks and enabling quicker response to CVE-related issues, while also reducing dependence on third-party updates.
Smart Images

Figure IB2023061806_30052025_PF_FP_ABST
Abstract
Description
[0001] RECOVERING CLOUD VULNERABILITIES WITH DYNAMIC PACKAGING
[0002] TECHNICAL FIELD
[0003] This application relates generally to managing application services, and more particularly to modifying the software applications that provide such services according to Common Vulnerabilities and Exposure (CVE) information.
[0004] BACKGROUND
[0005] Different industries provide services that are controlled by software applications. Examples of such industries include, but are in no way limited to, manufacturing, commercial, communication (e.g., mobility, etc.), and health care. Regardless of the particular industry, though, the software applications that control the services are becoming increasingly complex. For example, it is quite common for these software applications to include one or more software modules that interact with each other over distributed platforms. As useful as they are, however, these software applications are vulnerable to cyberattacks. Therefore, understanding the security vulnerabilities of the software applications, as well as the ways in which they might be exploited by a malicious third party, is a key factor for monitoring, troubleshooting, and logging purposes.
[0006] SUMMARY
[0007] Embodiments of the present disclosure provide a computer tool that allows network operators in an Operations Support System (OSS), for example, to remove one or more software components or modules (e.g., libraries and / or classes) from a software application where those components or modules are unused and vulnerable to cybersecurity threats, as indicated by relevant CVE information. In particular, the present embodiments allow a network operator to identify unused, vulnerable software components or modules in one or more containers associated with a given software application for removal from the containers. Once the unused, vulnerable modules have been removed, the present embodiments generate a new software image version of the application based on the remaining software components or modules that are not affected by a CVE. This allows the network providers to autonomously eliminate vulnerable software components from a software application without having to wait for a software update from a third party provider.
[0008] In the context of the present disclosure, a “software image” is a collection of files that comprise a complete software package. Typically, a software image includes the executable files, the libraries, modules, (arranged as “containers,” for example), and any documentation needed to run and / or manage the software application. Often times, the files are compressed into a single file or archive (e.g., a .tar or .gzip file) that can be easily downloaded and installed on a computing device.
[0009] Accordingly, a first aspect of the present disclosure provides a method for managing services in a communications network. In this aspect, the method is implemented by a network node in a network management system and comprises the network node obtaining an image of an application service from an image repository. In this aspect, the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE). The method further includes the network node generating an archive of the application service based on the image. The archive comprises the plurality of software components. The method further includes the network node generating a modified archive of the application service by removing the at least one software component affected by the CVE from the archive, generating a modified image of the application service from the modified archive, and then uploading the modified image of the application service to the image repository.
[0010] In a second aspect, the present disclosure provides a network node, in a network management system, for managing services in a communications network. In this aspect, the network node comprises processing circuitry and memory comprising instructions that, when executed by the processing circuitry, causes the network node to obtain an image of an application service from an image repository, wherein the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE), generate an archive of the application service based on the image, wherein the archive comprises the plurality of software components, generate a modified archive of the application service by removing the at least one software component affected by the CVE from the archive, generate a modified image of the application service from the modified archive, and upload the modified image of the application service to the image repository.
[0011] In a third aspect, the present disclosure provides a network node, in a network management system, for managing services in a communications network. In this aspect, the network node is configured to obtain an image of an application service from an image repository, wherein the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE), generate an archive of the application service based on the image, wherein the archive comprises the plurality of software components, generate a modified archive of the application service by removing the at least one software component affected by the CVE from the archive, generate a modified image of the application service from the modified archive, and upload the modified image of the application service to the image repository.
[0012] In a fourth aspect, the present disclosure provides a computer program comprising instructions that, when executed on processing circuitry of a network node in a network management system configured to manage services in a communications network, causes the network node to perform the method according to the first aspect.
[0013] In a fifth aspect, the present disclosure provides a non-transitory computer-readable storage medium comprising a computer program stored thereon. In this aspect, the computer program comprises executable instructions that, when executed by processing circuitry in a network management system configured to manage services in a communications network, causes the network node to perform the method according to the first aspect.
[0014] BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a block diagram illustrating a communications network configured according to one aspect of the present disclosure.
[0016] Figure 2 is a call sequence diagram illustrating some exemplary messaging for modifying a software application associated with a service based on Common Vulnerabilities and Exposure (CVE) information according to one aspect of the present disclosure.
[0017] Figure 3 is a flow diagram illustrating a method for managing services based on CVE information according to one aspect of the present disclosure.
[0018] Figure 4 is a flow diagram illustrating a method for removing a software component from a software application based on CVE information according to one aspect of the present disclosure.
[0019] Figure 5 is a flow diagram illustrating a method for inserting a software component into a software application according to one aspect of the present disclosure.
[0020] Figure 6 is a functional block diagram of a network node configured to manage services based on CVE information according to one aspect of the present disclosure.
[0021] DETAILED DESCRIPTION
[0022] As stated above, many different industries provide software applications that control services associated with that industry. These software applications typically contain “containers” (e.g., files comprising software classes and / or other software modules) that define the functionality and data of the application. Often times, one or more of the containers go unused by an implementation of the application despite being part of the application. Such unused classes and / or modules, however, can also be vulnerable to security threats. Therefore, the present disclosure provides a tool that allows a network operator, for example, to remove these containers from a software application where the container includes code and / or data that is both unused and vulnerable to cybersecurity issues.
[0023] In more detail, current industry and social trends are beginning to impose new, more stringent requirements on software applications and services in terms of vulnerability aware cases. For example, consider virtualization services, which may be related to Augmented Reality (AR), Virtual Reality (VR), and / or Mixed Reality (XR) services. In such cases, requirements are being imposed that affect how the different layers of an image are stacked (e.g., for visualization), how cloud computing devices process data, and how the various network resources are allocated. In another example, requirements are being imposed on network monitoring services and on services facilitating machine-to-machine (M2M) operations and communications in a 5G network. Additionally, stringent requirements are imposed on applications and services associated with “autonomously controlled” vehicles (e.g., cars, ships, trains, etc.) to affect the safety of the vehicle and its occupants, as well as on applications and services associated with e-Commerce and the Internet of Things (loT). In these latter cases, the requirements are intended to protect, inter alia, a user’s sensitive, private data. However, in many countries, such data is generally subject to a broad, dissimilar, and quickly evolving set of national regulations.
[0024] Some business-related information, such industrial and commercial information (e.g., device configurations, volumes, deployment details, etc.) may not be subject to the same privacy regulations as that applied to personal data. Nevertheless, this type of information is still deemed sensitive and must not be exposed to a company’s competitors unless that exposure is permitted by the company. In some cases, the business-related data and information may even be vulnerable to hackers, regardless of whether the hacker is an individual and / or is supported by a hostile nation. The damages related to cyberattacks are well known to individuals and companies alike, and therefore, security is at or near the top of practically every company’s agenda. Regardless of the particular industry or application, however, this “evolution” in protecting applications and services is growing rapidly with particular attention being focused on the security and / or privacy aspects of a software container.
[0025] PCT / IB2021 / 060941 , filed 24 November 2021 and entitled “Use Cases Tracking in a Distributed Environment,” which is incorporated herein by reference in its entirety, relates to a mechanism for tracing and troubleshooting use cases executing in a distributed network flow. More specifically, use-cases affected by known vulnerabilities can be identified in a real-time environment (i.e., at runtime) and eventually mitigated by a Third-Party Product (3PP) entity using code fixes. This is at least partially due to the fact that data produced by a tracing mechanism plays a key role in understanding system behavior. That is, just like the so-called “black boxes” in avionics are essential for recreating the actions of the pilots and the vehicle in cases of disasters, the analysis of vulnerability information is basic ground for both development and production phases.
[0026] In computer programming, a 3PP software component (e.g., a software container or module) is a reusable software component that is developed and freely distributed to the public or sold by an entity other than the original vendor of the development platform. Most, if not all, categories of applications tend to use 3PP libraries to accelerate the software development process. Thus, the use cases and the vulnerabilities associated with a given 3PP library are typically present throughout the entire lifetime of the product. In the development phase, for example, the use case and the vulnerability information can be used to help identify the correct needs for a customer, as well as the requirements for the planned application features. In the testing phase, the use case and the vulnerability information are necessary to find and solve different malfunctions or bugs, and / or to validate application features. In a live network, the use case and the vulnerabilities described in such information can affect the functionality of one or more software components of an application or service, and thus, can potentially impact a user's normal, daily work routine.
[0027] Information about the known vulnerabilities of software applications is already available and disseminated to interested parties. To assist with the dissemination of such cybersecurity vulnerability information, many companies use the Common Vulnerabilities and Exposures (CVE) system. As is known in the art, CVE is a list of entries describing a particular vulnerability. Each CVE entry in the list comprises an identification number, a description of the particular vulnerability, and at least one public reference to the particular vulnerability. The information contained in the CVE entries are used in numerous cybersecurity products and services from around the world, including the U.S. National Vulnerability Database.
[0028] Conventionally, whenever a CVE is found and identified, software companies having applications that are affected by the vulnerability release a “patch.” End users can usually download and install the patch to repair the vulnerability, although in some cases, the software companies may provide and install a patch via an Over-The-Air (OTA) update process (e.g., such as that used for updating firmware in vehicles, for example). Many companies have a patch-management solution to address patching systems in their network; however, even with their conventional processes, some companies still lack the ability to validate the functionality of an “patched” software application after a patch has been applied. Additionally, in at least some cases, they also lack knowledge about the completeness of the patching event. Additionally, end user customers typically demand a quick solution / mitigation for a newly-discovered use case that is affected by a given 3PP vulnerability.
[0029] Conventional methods and systems for updating 3PP software components are useful but are not without problems. For example, PCT / IB2022 / 058263 filed September 2, 2022, and entitled “Dynamic Application Vulnerable Use Cases Identification in a Cloud Native Environment,” which is incorporated herein by reference in its entirety, discloses a mechanism for monitoring, in real-time, use case vulnerabilities. Based on the monitoring, the mechanism described in PCT / IB2022 / 058263 can identify particular 3PP components that are affected by an identified vulnerability, and links to the CVE descriptions about the identified vulnerabilities.
[0030] However, even if most (or all) critical vulnerabilities in third-party libraries (e.g., 3PP) are disclosed or identified as CVEs, the conventional mechanisms provided by a vendor or other third party do not timely update the libraries. Thus, it is not currently possible to immediately react to alter or update the software to eliminate the issue(s) caused by a CVE whenever a customer (e.g., a network operator) becomes aware that a particular 3PP library function in an identified use case is affected by the CVE. Nevertheless, customers always request a quick solution to obviate the problem.
[0031] Currently, conventional mechanisms and processes look to the effective vulnerabilities (i.e., CVEs) in a runtime environment. However, these conventional processes are also complicated and cumbersome. This is typically due to the fact that tens of applications may compose a feature affected by a CVE with hundreds of users using that feature. Further complicating matters is that conventional processes are applied to thousands of different use cases. Therefore, the outcome of a conventional CVE analysis always identifies the following remedial processes.
[0032] 1) Upgrade the application in a future release. More specifically: a) The affected 3PP software component will need to be upgraded to remove the vulnerability. However, this option is a tentative plan for a future release; or b) The affected 3PP software component is not directly used in the application or service but is still included as part of the distributed 3PP package. In these cases, the affected 3PP software component will still be modified to remove / mitigate the CVE and distributed in a new package in a future release; OR
[0033] 2) The application is not vulnerable to the identified CVE because the particular 3PP component that is affected by the identified CVE is not used by the application. In these cases, the affected 3PP component will still be modified to remove / mitigate the CVE and distributed to users in a new package in a future release.
[0034] Cases such as 1b and 2 above always involve discussions with the customers. Particularly, customers are informed of the existence of the CVE in their service and are provided with an explanation as to why the CVE does not affect their application or service (i.e., the customer’s application does not utilize the affected 3PP component). Nevertheless, customers are still unhappy knowing that their application has a component that is vulnerable to a given CVE. This is because hackers and other malicious third-party actors can still exploit a vulnerability in an unused 3PP software component to gain access to the customer’s network or environment.
[0035] Moreover, providers of a 3PP software component do not discriminate between customers that use applications that are affected by a given CVE and those that do not. Thus, rather than address a request to correct a CVE as a customization on a customer-by-customer basis, the 3PP software component providers address the requests in a general sense for all customers. For example, consider a customer with an application that includes a 3PP software component affected by a given CVE. With conventional mechanisms and methods, customers that are directly affected by the CVE (i.e., where the application uses the functionality of the 3PP software component) will get an upgraded 3PP software component removing the CVE in some future release. However, customers having an application that does not use the affected 3PP software component, but still has the affected 3PP software component as part of its package, must still wait for the future release to have the 3PP component corrected. This means that such customers must continue to execute the application while the unused 3PP software component affected by the CVE remains in their system as part of that application.
[0036] As stated above, this situation is problematic because, even though the particularly affected 3PP software component is not used by the application, an unscrupulous third-party actor can still exploit the CVE to gain unauthorized access to the customer’s network and / or environment. Consequently, conventional solutions are typically incompatible with customer requests to correct an issue related to an affected 3PP software component in a timely manner.
[0037] The embodiments in this disclosure, however, provide a mechanism and method that solves / mitigates the “vulnerable” operation of an application or service in a timelier manner. Specifically, the present embodiments provide a mechanism and method for removing unused 3PP software components that are affected by a CVE from a 3PP software package at runt- time. That is, customers with applications that have an affected 3PP software component, but whose applications and services do not use the functionality of the affected 3PP software component, can address their cybersecurity concerns by quickly and easily removing the 3PP software component from the application without having to wait for an upgraded 3PP software component in a future release of the 3PP software package. Not only does this expedite the handling of a specific customer’s request in a live environment, but it is also useful throughout the life-cycle of the 3PP software component - i.e. , from the early development stage to the customer support phase.
[0038] Accordingly, the present disclosure provides a tool that allows network operators, for example, to remove containers from a software application (e.g., a 3PP software package) where the container includes code and / or data that is both unused by the software application and vulnerable to cybersecurity issues. More specifically, the computer tool described herein allows network operators in an Operations Support System (OSS), for example, to remove one or more software components (e.g., 3PP software components such as libraries, classes, software modules, etc.) from a 3PP software package where those modules are unused by the application and are vulnerable to cybersecurity threats as indicated by relevant CVE information. In one embodiment, for example, a network operator identifies unused, vulnerable software components (e.g., containers) for removal from a given software application. Once the unused, vulnerable software components have been removed, the present embodiments generate a new image version of the modified software application for execution. This allows the network operators to autonomously eliminate vulnerable software components from a software application without having to depend on a future release of updated software components by the third-party entity that provided the vulnerable software components.
[0039] As stated previously, control over this process may be implemented by an OSS-provided service / tool that allows network operators to update image versions of a software application by removing unused vulnerable classes from software containers (e.g., open source 3PP software components such as libraries and / or modules) provided by a third-party. This capability provides benefits and advantages that conventional mechanisms and methods of managing software applications do not or cannot provide. For example, as stated above, customers need not depend on 3PP providers of open-source software products (e.g., the software libraries and / or modules) to remove unused vulnerable components, such as classes, from their applications. Further, a computer implementing the present embodiments decreases the amount of time needed to resolve an identified CVE-related issue with an unused software component, thereby making the modification of a software product that includes the unused software component more compatible with customer requests to quickly eliminate the vulnerability associated with the unused software component.
[0040] The present embodiments provide benefits and advantages over conventional methods and mechanisms for both customers and the providers of the open source software packages. From a customer perspective, network operators can autonomously generate a new image of the service to exclude unused, vulnerable software components when a new version of a service (e.g., a software application) is released. This allows for the customization of a piece of software to specifically fit the needs and use cases of individual customers. The same goes for existing services. That is, in cases where the vulnerabilities of a service or application change and an unused vulnerable software component is impacted, a new image can be generated by the network operator using the tool described herein to adapt to the changes without waiting for the 3PP providers to release a new service version.
[0041] The present embodiments also provide benefits and advantages to the providers of 3PP software components affected by a given CVE. Particularly, with a computer configured according to the present embodiments, the cost of upgrading an affected 3PP software component and distributing the upgraded software component can be delayed or postponed until a customer urgently requests a fix to the vulnerability. Additionally, use cases can be different from customer to customer. Therefore, the provider of the 3PP software component can quickly and easily generate customer-specific versions of the 3PP software components for multiple different customers.
[0042] Referring now to the drawings, Figure 1 is a functional block diagram illustrating the architecture of an exemplary communications network 10 configured according to the present embodiments. As seen in Figure 1 , network 10 comprises one or more IP networks 12 communicatively interconnecting an OSS 14 with an image repository 16, one or more application servers (ASs) 18, and a Network Management System (NMS) 20. The NMS 20 further comprises a activator 22 and an executable software module 24. In this embodiment, the OSS 14 and the NMS 20 are illustrated as being separate entities. While this is possible, such separation is not required. In other embodiments, for example, the OSS 14 comprises the NMS 20.
[0043] The IP network(s) 12 is / are communication network(s) that comprise multiple computers and other devices (e.g., routers, gateway nodes, and the like). The computers and devices in the IP network(s) 12 are configured to use the Internet Protocol (IP) to send and receive data packets between endpoints such as the OSS 14, image repository 16, the ASs 18, and the NMS 20. Generally, IP networks and their operations are well-known to those of ordinary skill in the art; however, it should be appreciated that the IP network(s) 12 seen in Figure 1 may comprise one or more public networks (e.g., the Internet) and / or private networks.
[0044] The OSS 14 comprises various computer devices, equipment, and software applications that enable network operators to monitor, control, analyze, and manage a computer network. In this embodiment, the OSS 14 comprises a user terminal 14a (e.g., a computing device) configured to display a Graphical User Interface (GUI). Using the GUI, a network operator can modify the image of a software application (e.g., a service) executing on one or more of the ASs 18. To facilitate this function, the GUI displayed on terminal 14a is configured to display a variety of information and data from which the network operator can select to control the modification of a software image. For example, in one embodiment, the network operator uses the GUI to select an image of the software application that will be modified, the particular executable software module 24 that will be controlled to modify the image, one or more configuration parameters (e.g., a particular software component to remove from the image, such as the name or identifier of a class, file, method, module, etc.) that the selected executable software module 24 will use to modify the image, the location in the image repository where the image is stored, and the location in the image repository where the modified image of the software application will be stored.
[0045] Activator 22 is an executable program that comprises the logic and data needed to activate the selected executable software module 24 to modify the specified software image. As described in more detail below, activator 22 initiates the execution of the selected executable software module 24 based on the configuration parameters provided by the network operator via the GUI at terminal 14a. The result of the activation is the generation of a new software image that does not include the specified software component. As previously explained, the present disclosure removes software components that are affected by a known CVE but are unused by the software application. Therefore, the removal of the specified software component from the software image does not negatively affect the operation of the software application. After removal of the specified software component, activator 22 causes the modified software image to be stored in the image repository 16 at the location specified in the configuration parameters.
[0046] The executable software module 24 comprises the program code and instructions for modifying the image specified by the network operator responsive to receiving one or more control signals or messages from activator 22. In one embodiment, there are a plurality of different executable software modules 24. Each comprises an adaptation plug-in containing the business logic and / or data for removing a specified software component from the software image based on the syntax of specific programming / scripting language of the specified software component. That is, each executable software module 24 is specifically configured to modify an image of the software application according to the particular programming and / or scripting language of the specified software component that is to be removed from the image. In the context of the present disclosure, a network operator, using the GUI displayed on a computer terminal (e.g., terminal 14a), signals activator 22 with information that configures the NMS 20 to modify a current image of a software application in a specific manner. As described in more detail below, the network operator configures the executable software module 24 via activator 22 to remove certain software components from an application or service that may be executing on one or more of the ASs 18, for example. The software components to be removed may be, for example, one or more software containers associated with an open-source 3PP library and / or module. As previously described, the software component comprises code that, although included in the software applications executing on ASs 18, is unused by the software applications and vulnerable to at least one CVE. Therefore, removing such a software component would allow the network operator to eliminate a potential cybersecurity issue or threat while at the same time maintaining the functionality of the service. Regardless, once the modified image is available in the image repository 16, network operators can perform any necessary testing on the modified software image and upgrade the impacted application(s) and / or service(s).
[0047] There are a variety of scenarios under which the present embodiments can invoke activator 22 to remove a specified software component. For example, activator 22 may be invoked according to the present disclosure whenever the vulnerabilities declared by a given software application (e.g., a service) changes. In these cases, methods or functions that are unused by the software application and affected by the changed vulnerabilities can be removed.
[0048] Those of ordinary skill in the art should appreciate that the embodiments of the present disclosure are not merely used to remove affected software components from a software image. In other embodiments, the present embodiments may also be implemented to insert / re-insert specified software components into a software image. By way of example only, consider a situation where a software application includes a container that is affected by a given CVE. As stated above, that container can be removed from the image if the functions of the software application do not use the functions of the affected container. If the software application subsequently activates functionality that utilizes the container functions, however, that container will need to be available to the software application. In these cases, the present embodiments can be implemented to insert / re-insert the affected container into the software application image.
[0049] Figure 2 is a call sequence diagram illustrating some exemplary control signaling / messaging 30 for modifying a software application based on CVE information according to one aspect of the present disclosure. In at least one embodiment, the software application is a service that affects the operation of one or more user devices, such as User Equipment (UE).
[0050] As seen in Figure 2, a network operator at OSS 14 provides the configuration parameters for removing or inserting a specified software component (e.g., a container) from / into a software image (box 32). As previously described, this entails the network operator utilizing the GUI to select and provide the various parameters needed by activator 22 and executable software module 24 to modify the software image. Once the configuration parameters have been provided, the network operator, via the GUI, sends an activation command to the activator 22 to initiate modification of the software image (line 34).
[0051] Upon receiving the activation command, activator 22 generates and sends a message to the image repository 16 requesting to retrieve the image specified by the network operator (line 36). In one embodiment, the message includes one or more of the configuration parameters provided by the network operator. The activator 22 then receives the requested software image from the image repository 16 (line 38) and generates an activation signal that activates the executable software module 24 (e.g., a plug-in) to remove (or insert) the specified software component from (or into) the retrieved software image (line 40). The activation signal may be, for example, a message or command that causes the executable software module 24 to initiate processing of the software image. The executable software module 24 then indicates, to the activator 22, that it has started processing the software image (e.g., by returning an ACK to activator 22) and implements its logic to generate a modified image by removing / inserting the software components specified in the configuration parameters from / into the image (box 42). The executable software module 24 then provides the modified software image to the activator 22 (line 44), which in turn, stores the modified software image in the image repository 16 (line 46). Activator 22 will also, in at least some embodiments, provide an indication that the software image has been modified and stored to the network operator at the OSS 14 (line 48).
[0052] The following is an example of the present disclosure in which a software component is removed from an image of a Java application. As is known in the art, Java applications provide their functionality in a plurality of software containers known as .class files. According to the present disclosure, any .class file(s) that include or are otherwise related to a method or function that is negatively affected by a CVE can be removed from the Java application. Once removed, the Java application need not be re-compiled.
[0053] For example, consider the 3PP Application Programming Interface (API) “Jackson- Databind.” As is known in the art, the Jackson-Databind API is a data binding API that converts JavaScript Object Notation (JSON) to and from Plain Old Java Object (POJO) using a JSON property accessor or annotations. Further consider that the vulnerability CVE-2022-42003 negatively affects the code of the NodeSerialization.java class, which is part of the Jackson- Databind API but not used by the Jackson-Databind API. In this scenario, the network operator can remove the NodeSerialization.java class from the Jackson-Databind API.
[0054] To accomplish such removal, the activator 22 clones an image of the Jackson-Databind API retrieved from the image repository 16. Activator 22 then controls the executable software module 24 to create an archive file, such as a .tgz file, for example. Once the .tgz file has been generated, activator 22 controls the executable software module 24 selected for the Jackson- Databind API to remove the affected class (i.e., the NodeSerialization.java class) from the .tgz file. Activator 22 then uploads the modified .tgz file to the image repository 16 (i.e., a database from which the product / service resolves its dependencies). So removed, the network operator is able to declare that the software application using the Jackson-Databind API is unaffected by the CVE-2022-42003 vulnerability.
[0055] As another example, consider an application created using a scripting language such as Python. As is known by those of ordinary skill in the art, Python source files generate .exe files. Each .exe file may contain or be associated with a related set of functions. Using the techniques disclosed in the present embodiments, a network operator can remove an .exe from the Python application if that .exe contains code that is both unused by the Python application and affected or impacted by a CVE.
[0056] In more detail, activator 22 would first clone an image of the .exe file from the image repository 16 and control the executable software module 24 to create an archive file. Once generated, activator 22 would control the executable software module 24 selected for the .exe file to remove the affected code (e.g., a class) from the .exe file. The modified .exe file would then be uploaded to the image repository 16, and the network operator would be able to declare that the modified .exe file is unaffected by the particular identified vulnerability.
[0057] It should be noted that Java and Python applications are only examples and are mentioned herein for illustrative purposes only. The present embodiments can be applied to applications / services written using any type of programming and / or scripting language.
[0058] Figure 3 is a flow diagram illustrating a method 50 for managing services in a communications network (12) based on CVE information according to one aspect of the present disclosure. Method 50 is performed, in at least one embodiment, by a network node 100 (see Figure 6) configured to implement the functions of activator 22 and / or the executable software module 24.
[0059] As seen in Figure 3, the network node implementing method 50 receives a request to remove at least one software component from an application service (box 52). The request may, for example, be an activation command (e.g., an activation message) originating from a terminal 14a in OSS 14 and includes the configuration parameters used by activator 22 and the executable software module 24 to remove or insert a specified software component (e.g., a container) from / into a software image, as previously described. The network node then obtains an image of the application service from the image repository 16 (box 54). In one embodiment, for example, the well-known “git” system is used to in the image repository. As known in the art, git is a distributed version control system configured to track changes in a set of computer files (e.g., those comprising the software image). Using git, the network node can obtain the image of the application service by issuing the following command: git clone <address> where <address> is a Uniform Resource Locator (URL) of the image to be retrieved and cloned. The image obtained by the network node comprises a plurality of software components, including the software component identified in the activation command, with at least one of the software components (e.g., the identified software component) being affected by a known CVE. Once the image has been obtained, the network node generates an archive of the application service based on the retrieved image (box 56). In one embodiment, for example, the network node issues the following Maven command to generate the archive: mvn clean install
[0060] As known in the art, Maven is a build automation tool that is used to build and manage software projects, and the “mvn clean install” command executes a clean build life cycle and installs a build phase in the default build cycle. The generated archive comprises the plurality of software components, including the software component identified in the received activation command.
[0061] The network node next generates a modified archive of the application service by removing the at least one software component affected by the CVE from the generated archive (box 58). For example, in one embodiment of the present disclosure, the network node issues a series of commands to perform this function. By way of example only, the network node may first issue the following “jar” command to unpack the archive “genericService.jar” generated by the mvn clean install command. jar xf genericService.jar
[0062] Once the genericService.jar file is unpacked, the network node issues a “rm” command to remove one or more components affected by the CVE. In this example, the ObjectBuffer. class component is affected by the CVE and is therefore removed from the unpacked genericService.jar archive. rm com / genericService / util / ObjectBuffer.class
[0063] So removed, the network node implementing method 50 can then issue the following command to remove the original jar file. rm genericService.jar
[0064] The network node implementing method 50 then generates a modified image of the application service from the modified archive (box 60) and uploads the modified image of the application service to the image repository (box 62). According to one embodiment, the network node implementing method 50 is configured to issue the following series of commands to perform these functions. Particularly, the network node may first issue the following command to generate the new jar file. This new jar file will not include the ObjectBuffer.class component removed above, and therefore, is unaffected by the CVE. jar cf genericService.jar * Once the new jar file is generated, the network node implementing method 50 can upload the newly generated jar file to the image registry using the following curl command. curl -X PUT -u <username>:<password> -T <genericService.jar> “http: / / localhost:8081 / artifactory / <repo_name> / <genericService.jar>” where <repo_name> is a part of the URL of the image that was retrieved and cloned, as previously described.
[0065] It should be noted here that the techniques for generating the archives and / or the software images, as described herein, are platform and / or environment dependent. For example, as those of ordinary skill in the art will readily appreciate, the commands and processes for generating an archive and / or a software image in a MICROSOFT WINDOWS environment may be different than those used in a UNIX or LINUX environment..
[0066] As stated above, the request received from the OSS 14 comprises data and information used by activator 22 and the executable software module 24 to remove or insert a specified software component (e.g., a container) from / into the retrieved software image. In one embodiment, for example, the received request comprises one or more of an image identifier that identifies the image of a software application to obtain from the image repository, a module identifier that identifies which executable software module 24 is configured to remove / insert the at least one software component from / into the archive of the software application, one or more configuration parameters for the executable software module 24 indicating the at least one software component to remove from the archive, and an upload location at the image repository to upload the modified image.
[0067] In one embodiment, seen in the method 70 of Figure 4, for example, the network node implementing method 70 obtains the image of the application service from the image repository 16 by retrieving the image of the application service from the image repository 16 via the communications network 12 (box 72). So retrieved, the network node clones the retrieved image to generate a cloned image (box 74) using, for example, the git clone <address> command, and then generates the archive from the cloned image (box 76) using the jar xf genericService.jar command, as previously described. The network node then removes the at least one software component affected by the CVE from the archive by activating the executable software module 24 to remove the at least one software component from the archive (box 78). As stated above, the network node configured to implement one embodiment of the present disclosure may issue the “rm” command, as previously described. Once removed, the network node implementing method 70 can then generate the modified image and upload the modified image to the image repository, as previously described in Figure 3.
[0068] Although the previous embodiments discuss the removal of a software component affected by a CVE from an image file, the present disclosure is not limited solely to removal processes. In other aspects, for example, the present embodiments may be utilized to insert a software component into an image.
[0069] For example, consider a situation where a given 3PP software component was removed from an image. At the time of removal, the 3PP software component was affected by a known CVE but unused by the application. Once the 3PP corrects the CVE issue, the network operator may want to reinsert the corrected software component back into the application. Alternatively, the network operator may simply want to include a new software component developed by the 3PP in the image. In either case, the present embodiments configure the network node to perform this insertion function.
[0070] Figure 5 is a flow diagram illustrating a method 80 for introducing / reintroducing a software component into the image of a software application according to one aspect of the present disclosure. As seen in Figure 5, the network node obtains the modified image of the application service from the image repository 16 (box 82). This step may be initiated by activator 22 responsive to receiving an activation command from a network operator using the GUI displayed on terminal 14a. For example, in one embodiment, the activation command identifies an image identifier that identifies the modified image to obtain from the image repository 16, a module identifier that identifies which executable software module 24 is configured to insert the at least one software component into the archive of the application, one or more configuration parameters for the executable software module 24 indicating the at least one software component to insert into the archive, and an upload location at the image repository 16 to upload the image once the software component has been inserted into the image.
[0071] Based on the information provided in the activation command, the network node regenerates the modified archive from the modified image (box 84). So generated, the network node regenerates the archive of the application service by inserting the at least one software module into the modified archive of the application service (box 86). The network node then regenerates the image of the application service from the regenerated archive (box 88) and uploads the regenerated image of the application service to the image repository 16 (box 90).
[0072] In one embodiment, the executable software module 24 configured to remove the at least one software module is a plug-in selected from among one or more different plug-ins. Each of the plurality of plug-ins is configured to remove and / or insert an identified software component from / to a given archive based on the particular language used by the at least one software module.
[0073] In one embodiment, the at least one software module affected by the CVE comprises compiled application code.
[0074] In one embodiment, the at least one software module affected by the CVE is a .exe file.
[0075] In one embodiment, the at least one software module affected by the CVE is a .class file. In one embodiment, one or both of the archive and the modified archive is a compressed file.
[0076] An apparatus can perform any of the methods herein described by implementing any functional means, modules, units, or circuitry. In one embodiment, for example, the apparatuses comprise respective circuits or circuitry configured to perform the steps shown in the method figures. The circuits or circuitry in this regard may comprise circuits dedicated to performing certain functional processing and / or one or more microprocessors in conjunction with memory. For instance, the circuitry may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein, in several embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the one or more processors, carries out the techniques described herein.
[0077] Figure 6 is a functional block diagram illustrating some of the main functional components of a network node 100 configured to manage services based on CVE information according to one aspect of the present disclosure. As previously described, network node 100 may be a physical computing device in a NMS 20 that implements the functionality of both the activator 22 and the executable software module 24. However, those of ordinary skill in the art will readily appreciate that the present disclosure is not so limited. In other embodiments, for example, the network node 100 comprises a plurality of physical computing devices in the NMS 20. In these latter cases, the functions of activator 22 and the executable software module 24 are distributed across these physical computing devices. Thus, the particular identification of the network node 100 as being a single computing device in the NMS 20 is merely illustrative.
[0078] Regardless of its particular implementation, however, network node 100 in this embodiment comprises communication circuitry 102, processing circuitry 104, and memory 106 configured to store a computer program 108 thereon. The communication circuitry 102 comprises the hardware required for communicating with one or more other network nodes, such as one or more core network nodes, OSS 14, and image repository 16, for example. In this regard, the communication circuitry 102 may comprise a Network Interface Circuit (NIC) (e.g., an ETHERNET or similar interface). In some embodiments, the network node 100 may be configured for wireless communications. In these situations, communication circuitry 102 would comprise the radio frequency (RF) circuitry needed for transmitting and receiving signals over a wireless communication channel. Accordingly, network node 100 may also be coupled to one or more antenna (not shown). In other embodiments, however, network node 100 is configured to communicate via a wire interface.
[0079] The processing circuitry 104 comprises one or more microprocessors, hardware, firmware, or a combination thereof that controls the overall operation of network node 100. In accordance with the present disclosure, the processing circuitry 104 can be configured by software to perform one or more of the methods herein described including any of methods 30, 50, 70, and 80 seen in Figures 2-5, respectively.
[0080] Memory 106 comprises both volatile and non-volatile memory for storing computer program code and data needed by the processing circuitry 104 for operation. Memory 106 may comprise any tangible, non-transitory computer-readable storage medium for storing data including electronic, magnetic, optical, electromagnetic, or semiconductor data storage. Memory 106 stores a computer program 108 comprising executable instructions that configure the processing circuit 104 in network node 100 to perform one or more of the methods herein described including any of methods 30, 50, 70, and 80 seen in Figures 2-5, respectively. A computer program 108 in this regard may comprise one or more code modules corresponding to the means or units described above. Additionally, according to the present disclosure, the computer program 108 may comprise the instructions and data for one or both of the activator 22 and the executable software module 24.
[0081] Regardless, computer program instructions and configuration information are stored in a non-volatile memory, such as a ROM, erasable programmable read only memory (EPROM) or flash memory. Temporary data generated during operation may be stored in a volatile memory, such as a random-access memory (RAM). In some embodiments, computer program 108 for configuring the processing circuitry 104 as herein described may be stored in a removable memory, such as a portable compact disc, portable digital video disc, or other removable media. The computer program 108 may also be embodied in a carrier such as an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0082] Those skilled in the art will also appreciate that embodiments herein further include corresponding computer programs. A computer program comprises instructions which, when executed on at least one processor of an apparatus, cause the apparatus to carry out any of the respective processing described above. A computer program in this regard may comprise one or more code modules corresponding to the means or units described above.
[0083] Embodiments of the present disclosure further include a carrier containing such a computer program 108. This carrier may comprise one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0084] In this regard, embodiments herein also include a computer program product stored on a non-transitory computer readable (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to perform as described above.
[0085] Embodiments further include a computer program product comprising program code portions for performing the steps of any of the embodiments herein when the computer program product is executed by network node 100. This computer program product may be stored on a computer readable recording medium.
[0086] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
[0087] The present embodiments may, of course, be carried out in other ways than those specifically set forth herein without departing from characteristics described herein. The present embodiments are therefore to be considered in all respects as illustrative and not restrictive, and all changes coming within the meaning and equivalency range of the appended claims are intended to be embraced therein.
Claims
CLAIMSWhat is claimed is:1 . A method (50) for managing services in a communications network (12), the method implemented by a network node (100) in a network management system (20) and comprising: obtaining (54) an image of an application service from an image repository (16), wherein the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE); generating (56) an archive of the application service based on the image, wherein the archive comprises the plurality of software components; generating (58) a modified archive of the application service by removing the at least one software component affected by the CVE from the archive; generating (60) a modified image of the application service from the modified archive; and uploading (62) the modified image of the application service to the image repository.
2. The method of claim 1 , further comprising receiving (52) a request to remove the at least one software component from the application service.
3. The method of any of claims 1-2, wherein the request comprises one or more of: an image identifier that identifies the image to obtain from the image repository; a module identifier that identifies an executable software module configured to remove the at least one software component from the archive of the application service; one or more configuration parameters for the executable software module, wherein the one or more configuration parameters indicate the at least one software component to remove from the archive; and an upload location at the image repository to upload the modified image.
4. The method of any of claims 1-3, wherein obtaining the image of the application service from the image repository comprises: retrieving (72) the image of the application service from the image repository via the communications network; and cloning (74) the retrieved image to generate a cloned image.
5. The method of claim 4, wherein generating the archive of the application service comprises generating (76) the archive from the cloned image.
6. The method of any of claims 1-5, wherein removing the at least one software component affected by the CVE comprises activating (78) the executable software module to remove the at least one software component from the archive.
7. The method of any of claims 1-6, further comprising reintroducing (80) the at least one software module affected by the CVE into the application service.
8. The method of any of claims 1-7, wherein reintroducing the at least one software module affected by the CVE into the application service comprises: obtaining (82) the modified image of the application service from the image repository; regenerating (84) the modified archive from the modified image; regenerating (86) the archive of the application service by inserting the at least one software module affected by the CVE into the modified archive of the application service; regenerating (88) the image of the application service from the regenerated archive; and uploading (90) the regenerated image of the application service to the image repository.
9. The method of any of the preceding claims, wherein the executable software module configured to remove the at least one software module is a plug-in.
10. The method of any of the preceding claims, wherein the at least one software module affected by the CVE comprises compiled application code.11 . The method of any of the preceding claims, wherein the at least one software module affected by the CVE is a .exe file.
12. The method of any of the preceding claims, wherein the at least one software module affected by the CVE is a .class file.
13. The method of any of the preceding claims, wherein one or both of the archive and the modified archive is a compressed file.
14. A network node (100), in a network management system (20), for managing services in a communications network (12), the network node comprising: processing circuitry (104); and memory (106) comprising instructions (108) that, when executed by the processing circuitry, causes the network node to: obtain (54) an image of an application service from an image repository (16), wherein the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE); generate (56) an archive of the application service based on the image, wherein the archive comprises the plurality of software components;generate (58) a modified archive of the application service by removing the at least one software component affected by the CVE from the archive; generate (60) a modified image of the application service from the modified archive; and upload (62) the modified image of the application service to the image repository..
15. The network node of claim 14, wherein the network node is further configured to perform the method according to any one of claims 2-13.
16. A network node (100), in a network management system (20), for managing services in a communications network (12), the network node configured to: obtain (54) an image of an application service from an image repository (16), wherein the image comprises a plurality of software components with at least one software component being affected by a Common Vulnerability and Exposure (CVE); generate (56) an archive of the application service based on the image, wherein the archive comprises the plurality of software components; generate (58) a modified archive of the application service by removing the at least one software component affected by the CVE from the archive; generate (60) a modified image of the application service from the modified archive; and upload (62) the modified image of the application service to the image repository.
17. The network node of claim 16, wherein the network node is further configured to perform the method according to any one of claims 2-13.
18. A computer program (108) comprising instructions that, when executed on processing circuitry (104) of a network node (100) in a network management system (20) configured to manage services in a communications network (12), causes the network node to perform the method according to any of claims 1-13.
19. A carrier containing the computer program of claim 18, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
20. A non-transitory computer-readable storage medium (106) comprising a computer program (108) stored thereon, the computer program comprising executable instructions that, when executed by processing circuitry (104) in a network management system (20) configured to manage services in a communications network (12), causes the network node to perform the method of any one of claims 1-13.
Citation Information
Patent Citations
Method and apparatus for handover
WO2021060941A1
Steering column with tolerance compensation element
WO2022058263A1
Method and system for automatically identifying and correcting security vulnerabilities in containers
EP3835987B1
Software container registry container image deployment
US20170177860A1