Network Vulnerability Map for Container Image Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems fail to effectively identify and manage software vulnerabilities across network elements, as these vulnerabilities may be hidden within software containers and are not readily apparent to network managers.
Innovation Solution
A method and system that obtain image data from software containers on network elements, determine software vulnerabilities, and assign them to filesystem keys, generating a vulnerability map to track and monitor vulnerabilities across the network, utilizing a network controller and components like data collectors and vulnerability detectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software containers are used to hide applications within virtual machines, then network management flexibility and application isolation are improved, but vulnerability detection capability deteriorates because vulnerabilities are not apparent to network managers
Solution Approach 1:
The patent introduces a vulnerability map as an intermediary data structure that bridges the gap between containerized applications and network management systems. This vulnerability map translates hidden container vulnerabilities into a format that network managers can detect and manage, effectively mediating between the isolated application layer and the network management layer without breaking the isolation benefits
Solution Approach 2:
The system performs preliminary vulnerability assessment by analyzing software images before they are deployed to create containers. By detecting vulnerabilities in advance during the image build phase and pre-populating the vulnerability map, the system enables proactive security management rather than reactive detection after deployment
2Reliability
If comprehensive vulnerability monitoring is implemented across all network elements, then network security is improved, but system complexity increases due to the need to collect and manage image data and vulnerability information from multiple sources
Solution Approach 1:
The patent merges multiple data collection functions into a unified vulnerability map that consolidates information from software images, container instances, and vulnerability databases. This single centralized structure replaces what would otherwise require multiple separate monitoring systems, reducing overall system complexity while maintaining comprehensive security coverage
Solution Approach 2:
The vulnerability map serves multiple functions simultaneously: it stores vulnerability information, tracks software image versions, identifies affected containers, and provides data for security analysis. This multi-functional design eliminates the need for separate systems for each function, thereby reducing system complexity while enhancing network security
Data Source
AI summary
A method for managing network vulnerabilities may include obtaining image data regarding a software container located on a network element. The image data may describe a software image used to generate the software container. The method may further include determining, using the image data, a software vulnerability of the software image. The method may further include assigning the software vulnerability to a filesystem key. The method may further include generating, using the software vulnerability and the filesystem key, a vulnerability map of a network. The vulnerability map may describe various software vulnerabilities arranged according to various filesystem keys used on the network. The filesystem key may identify data of the software container within a filesystem on the network element.


