Malicious code avoidance using transparent containers
Abstract
A method, computer program product, and system for managing container security, the method including consuming a recipe queue on a first checker container, wherein the first checker container is on a first host of a computer system, and the recipe queue comprises a predefined set of rules, storing the first checker container recipe queue result in the first checker container, comparing the first checker container recipe queue result with an expected result of the recipe queue, wherein the expected result is stored in the first checker container, and following a first fail procedure from a plurality of fail procedures, based on the first checker container recipe queue result not matching the expected result.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for managing container security by a computer, the method comprising:
consuming a recipe queue on a first checker container, wherein the first checker container is on a first host of a computer system, and the recipe queue comprises a predefined set of rules; storing the first checker container recipe queue result in the first checker container; comparing the first checker container recipe queue result with an expected result of the recipe queue, wherein the expected result is stored in the first checker container; following a first fail procedure from a plurality of fail procedures, based on the first checker container recipe queue result not matching the expected result; consuming the recipe queue on a second checker container, based on the first checker container recipe queue result not matching the expected result, wherein the second checker container is on a second host of the computer system; storing the second checker container recipe queue result on the second checker container; comparing the second checker container recipe queue result with the expected result of the recipe queue, wherein the expected result is stored on the second checker container; following a second fail procedure from the plurality of fail procedures, based on the second checker container recipe queue result not matching the expected result; consuming the recipe queue on one or more additional checker containers, based on the first checker container recipe queue result not matching the expected result, wherein the one or more additional checker containers are on one or more corresponding additional hosts of the computer system; storing the one or more checker container recipe queue results each on the corresponding one or more checker containers; following a third fail procedure from the plurality of fail procedures, based on the second checker container recipe queue results not matching the expected result, wherein the third fail procedure comprises rebooting the first host; comparing the one or more checker container recipe queue results with the expected result of the recipe queue, wherein the expected result is stored on the one or more checker containers; following one or more corresponding fail procedures from the plurality of fail procedures, based on the one or more checker container recipe queue results not matching the expected result;\ rebooting one or more additional hosts, based on the one or more corresponding checker container recipe queue results not matching the expected result; reconfirming the expected result, based on three or more checker container recipe queue results matching each other; and shutting the computer server down, based on more than a threshold number of the one or more corresponding checker container recipe queue results not matching the expected result.Join the waitlist — get patent alerts
Track US2018096141A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.