Patent · US Active

Intrusion detection in micro-services through container telemetry and behavior modeling

US11748473B2 · kind B2 · utility

47Cited by
4References
24Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 15, 2020
Grant dateSep 5, 2023
Priority date
Expiry dateJan 30, 2041

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An intrusion detection system (IDS) for a micro-services environment identifies attacks in substantially real-time and at a container-level. In this approach, behavior models are generated from container images using a binary analysis. A behavior model is a graph data structure having nodes and edges, wherein an edge represents a system call made by at least one process represented as a node in the graph data structure. The model is co-located with a running container, thereby enabling detection of anomalies as the container executes in a container environment on a hardware node. A per-container IDS function is instantiated by checking whether system call telemetry generated by an image's running container satisfies the associated behavior model that has been generated for the container image. If the telemetry indicates activity that deviates from the behavior model, an automated action is then initiated to attempt to address the attack, preferably while it is in progress.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.