US2023325493A1PendingUtilityA1

Stateful microservice-aware intrusion detection

Assignee: IBMPriority: Mar 29, 2021Filed: Jun 14, 2023Published: Oct 12, 2023
Est. expiryMar 29, 2041(~14.7 yrs left)· nominal 20-yr term from priority
G06F 21/54G06F 21/554G06F 21/566G06F 2221/033G06F 21/53G06F 21/577
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system, and computer program product for performing microservice-aware reference policy checking that accept stateful security policies. The method may include receiving a stateful security policy, where the stateful security policy has connection to previous data. The method may also include determining that the stateful security policy applies to a corresponding container. The method may also include enforcing the stateful security policy against the container. The system and computer program product may include similar steps.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method comprising:
 receiving a stateful security policy, wherein the stateful security policy has connection to previous data;   determining that the stateful security policy applies to a corresponding container; and   enforcing the stateful security policy against the container.   
     
     
         2 . The method of  claim 1 , further comprising:
 obtaining a security model for the container; and   generating a behavioral model for the container.   
     
     
         3 . The method of  claim 2 , further comprising:
 comparing the behavioral model to the security model; and   determining whether the container has deviated from the stateful security policy based on the comparing.   
     
     
         4 . The method of  claim 3 , further comprising:
 determining that the container has deviated from the stateful security policy; and   determining that the container has potentially malicious behavior.   
     
     
         5 . The method of  claim 4 , wherein enforcing the stateful security policy comprises:
 flagging the container as having potentially malicious behavior;   determining which behaviors from the behavior model are different from the stateful security policy; and   pausing execution of the container.   
     
     
         6 . The method of  claim 3 , wherein, in response to determining that the container has not deviated from the stateful security policy, enforcing the stateful security policy comprises:
 marking the container as conforming with the stateful security policy.   
     
     
         7 . The method of  claim 2 , wherein obtaining the security model comprises:
 transforming the stateful security policy into the security model in a form of a first effect graph.   
     
     
         8 . The method of  claim 2 , wherein generating the behavioral model for the container comprises:
 generating a second effect graph of execution behavior of the container.   
     
     
         9 . The method of  claim 8 , wherein generating the second effect graph of execution behavior of the container comprises summarizing operations and interactions between entities in the execution behavior. 
     
     
         10 . The method of  claim 9 , wherein summarizing the operations and interactions between the entities in the execution behavior comprises:
 receiving a telemetry stream of the execution behavior of the container, wherein the telemetry stream records behavior of entities, events, and flows of the container;   synthesizing the telemetry stream into one or more flows between the entities; and   generating a succinct structure of the one or more flows, resulting in the second effect graph.   
     
     
         11 . The method of  claim 1 , further comprising:
 continuously monitoring the container and the stateful security policy.   
     
     
         12 . A system having one or more computer processors, the system configured to:
 receive a stateful security policy, wherein the stateful security policy has connection to previous data;   determine that the stateful security policy applies to a corresponding container; and   enforce the stateful security policy against the container.   
     
     
         13 . The system of  claim 12 , further configured to:
 obtain a security model for the container; and   generate a behavioral model for the container.   
     
     
         14 . The system of  claim 13 , further configured to:
 compare the behavioral model to the security model; and   determine whether the container has deviated from the stateful security policy based on the comparing.   
     
     
         15 . The system of  claim 13 , wherein obtaining the security model comprises:
 transforming the stateful security policy into the security model in a form of a first effect graph.   
     
     
         16 . The system of  claim 13 , wherein generating the behavioral model for the container comprises:
 generating a second effect graph of execution behavior of the container.   
     
     
         17 . A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a server to cause the server to perform a method, the method comprising:
 receiving a stateful security policy, wherein the stateful security policy has connection to previous data;   determining that the stateful security policy applies to a corresponding container; and   enforcing the stateful security policy against the container.   
     
     
         18 . The computer program product of  claim 17 , further comprising:
 obtaining a security model for the container; and   generating a behavioral model for the container.   
     
     
         19 . The computer program product of  claim 18 , wherein obtaining the security model comprises:
 transforming the stateful security policy into the security model in a form of a first effect graph.   
     
     
         20 . The computer program product of  claim 18 , wherein generating the behavioral model for the container comprises:
 generating a second effect graph of execution behavior of the container.

Join the waitlist — get patent alerts

Track US2023325493A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.