Intrusion detection in micro-services through container telemetry and behavior modeling
US11748473B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Oct 15, 2020 |
| Grant date | Sep 5, 2023 |
| Priority date | — |
| Expiry date | Jan 30, 2041 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F2221/034
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
An intrusion detection system (IDS) for a micro-services environment identifies attacks in substantially real-time and at a container-level. In this approach, behavior models are generated from container images using a binary analysis. A behavior model is a graph data structure having nodes and edges, wherein an edge represents a system call made by at least one process represented as a node in the graph data structure. The model is co-located with a running container, thereby enabling detection of anomalies as the container executes in a container environment on a hardware node. A per-container IDS function is instantiated by checking whether system call telemetry generated by an image's running container satisfies the associated behavior model that has been generated for the container image. If the telemetry indicates activity that deviates from the behavior model, an automated action is then initiated to attempt to address the attack, preferably while it is in progress.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.