In-container process abnormal behavior detection method and system
An anomaly detection and container technology, applied in the field of virtualization security, can solve problems such as difficult to determine uniformly, false positives or missed negatives, etc., and achieve the effect of improving detection rate, reducing false positive rate, and speeding up training speed
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0043] The present invention will be described in further detail below in conjunction with the accompanying drawings and specific embodiments.
[0044] attached figure 1 An overall architecture diagram of the abnormal behavior detection system of the process in the container based on the system call sequence and LSTM (Long Short-Term Memory, Long Short-Term Memory) in the present invention is given. Such as figure 1 As shown, the detection system can be used to detect the abnormal process system call behavior existing in the container, including the data acquisition module, data modeling module and abnormal detection module.
[0045] The data acquisition module is located at the host user layer outside the container. According to the ID of the specified container, it uses an agentless method to obtain information about all the processes running in the container, and monitors the runtime used to manage the life cycle of the container based on the ptrace system call. The carri...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com