US2023325493A1PendingUtilityA1
Stateful microservice-aware intrusion detection
Est. expiryMar 29, 2041(~14.7 yrs left)· nominal 20-yr term from priority
G06F 21/54G06F 21/554G06F 21/566G06F 2221/033G06F 21/53G06F 21/577
67
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method, system, and computer program product for performing microservice-aware reference policy checking that accept stateful security policies. The method may include receiving a stateful security policy, where the stateful security policy has connection to previous data. The method may also include determining that the stateful security policy applies to a corresponding container. The method may also include enforcing the stateful security policy against the container. The system and computer program product may include similar steps.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method comprising:
receiving a stateful security policy, wherein the stateful security policy has connection to previous data; determining that the stateful security policy applies to a corresponding container; and enforcing the stateful security policy against the container.
2 . The method of claim 1 , further comprising:
obtaining a security model for the container; and generating a behavioral model for the container.
3 . The method of claim 2 , further comprising:
comparing the behavioral model to the security model; and determining whether the container has deviated from the stateful security policy based on the comparing.
4 . The method of claim 3 , further comprising:
determining that the container has deviated from the stateful security policy; and determining that the container has potentially malicious behavior.
5 . The method of claim 4 , wherein enforcing the stateful security policy comprises:
flagging the container as having potentially malicious behavior; determining which behaviors from the behavior model are different from the stateful security policy; and pausing execution of the container.
6 . The method of claim 3 , wherein, in response to determining that the container has not deviated from the stateful security policy, enforcing the stateful security policy comprises:
marking the container as conforming with the stateful security policy.
7 . The method of claim 2 , wherein obtaining the security model comprises:
transforming the stateful security policy into the security model in a form of a first effect graph.
8 . The method of claim 2 , wherein generating the behavioral model for the container comprises:
generating a second effect graph of execution behavior of the container.
9 . The method of claim 8 , wherein generating the second effect graph of execution behavior of the container comprises summarizing operations and interactions between entities in the execution behavior.
10 . The method of claim 9 , wherein summarizing the operations and interactions between the entities in the execution behavior comprises:
receiving a telemetry stream of the execution behavior of the container, wherein the telemetry stream records behavior of entities, events, and flows of the container; synthesizing the telemetry stream into one or more flows between the entities; and generating a succinct structure of the one or more flows, resulting in the second effect graph.
11 . The method of claim 1 , further comprising:
continuously monitoring the container and the stateful security policy.
12 . A system having one or more computer processors, the system configured to:
receive a stateful security policy, wherein the stateful security policy has connection to previous data; determine that the stateful security policy applies to a corresponding container; and enforce the stateful security policy against the container.
13 . The system of claim 12 , further configured to:
obtain a security model for the container; and generate a behavioral model for the container.
14 . The system of claim 13 , further configured to:
compare the behavioral model to the security model; and determine whether the container has deviated from the stateful security policy based on the comparing.
15 . The system of claim 13 , wherein obtaining the security model comprises:
transforming the stateful security policy into the security model in a form of a first effect graph.
16 . The system of claim 13 , wherein generating the behavioral model for the container comprises:
generating a second effect graph of execution behavior of the container.
17 . A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a server to cause the server to perform a method, the method comprising:
receiving a stateful security policy, wherein the stateful security policy has connection to previous data; determining that the stateful security policy applies to a corresponding container; and enforcing the stateful security policy against the container.
18 . The computer program product of claim 17 , further comprising:
obtaining a security model for the container; and generating a behavioral model for the container.
19 . The computer program product of claim 18 , wherein obtaining the security model comprises:
transforming the stateful security policy into the security model in a form of a first effect graph.
20 . The computer program product of claim 18 , wherein generating the behavioral model for the container comprises:
generating a second effect graph of execution behavior of the container.Join the waitlist — get patent alerts
Track US2023325493A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.