Network Vulnerability Map for Container Image Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems fail to effectively identify and manage software vulnerabilities across network elements, as these vulnerabilities may be hidden within software containers and are not readily apparent to network managers.

Innovation Solution

A method and system that obtain image data from software containers on network elements, determine software vulnerabilities, and assign them to filesystem keys, generating a vulnerability map to track and monitor vulnerabilities across the network, utilizing a network controller and components like data collectors and vulnerability detectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software containers are used to hide applications within virtual machines, then network management flexibility and application isolation are improved, but vulnerability detection capability deteriorates because vulnerabilities are not apparent to network managers

Engineering Contradiction:
Improveapplication isolationVSAvoidvulnerability detection capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a vulnerability map as an intermediary data structure that bridges the gap between containerized applications and network management systems. This vulnerability map translates hidden container vulnerabilities into a format that network managers can detect and manage, effectively mediating between the isolated application layer and the network management layer without breaking the isolation benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary vulnerability assessment by analyzing software images before they are deployed to create containers. By detecting vulnerabilities in advance during the image build phase and pre-populating the vulnerability map, the system enables proactive security management rather than reactive detection after deployment

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive vulnerability monitoring is implemented across all network elements, then network security is improved, but system complexity increases due to the need to collect and manage image data and vulnerability information from multiple sources

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple data collection functions into a unified vulnerability map that consolidates information from software images, container instances, and vulnerability databases. This single centralized structure replaces what would otherwise require multiple separate monitoring systems, reducing overall system complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The vulnerability map serves multiple functions simultaneously: it stores vulnerability information, tracks software image versions, identifies affected containers, and provides data for security analysis. This multi-functional design eliminates the need for separate systems for each function, thereby reducing system complexity while enhancing network security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10050991B2System and method for monitoring network vulnerabilities
Publication Date: 2018.08.14 CIENA CORP
  • US10050991B2 patent drawing
  • US10050991B2 patent drawing
  • US10050991B2 patent drawing

AI summary

A method for managing network vulnerabilities may include obtaining image data regarding a software container located on a network element. The image data may describe a software image used to generate the software container. The method may further include determining, using the image data, a software vulnerability of the software image. The method may further include assigning the software vulnerability to a filesystem key. The method may further include generating, using the software vulnerability and the filesystem key, a vulnerability map of a network. The vulnerability map may describe various software vulnerabilities arranged according to various filesystem keys used on the network. The filesystem key may identify data of the software container within a filesystem on the network element.