Attack virus detection method and device, electronic equipment and medium
By collecting and analyzing multi-dimensional behavioral data of containers and combining it with anomaly detection methods that use sliding windows and multi-feature fusion, we have solved the problem of insufficient recognition accuracy in traditional technologies, achieved high-precision detection and positioning of unknown variant viruses, and improved the security of containerized environments.
Patent Information
- Application Number
- CN202511220580.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-10-14
AI Technical Summary
Traditional container attack virus detection technology has difficulty identifying variant attack viruses that evade detection through code obfuscation, encrypted communication, or dynamic mutation, and its recognition accuracy is insufficient.
The multi-dimensional behavioral data of the container is collected. Through sliding window analysis, multi-feature fusion and two-level anomaly detection mechanism, feature conversion and anomaly detection are performed using Z-score standardization, Boolean logic feature encoding, isolation forest model and autoencoder to generate a fused feature vector. The presence of an attack virus is determined based on the preset scoring threshold.
It achieves high-precision, low-false-alarm detection of unknown threats, can accurately locate abnormal containers, and improves the security protection level of containerized environments.
Smart Images

Figure CN120785646A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to an attack virus detection method and device, electronic equipment and medium. BACKGROUND
[0002] With the deep application of container technology in cloud computing and micro-service architecture, attack viruses based on containers present new characteristics such as strong concealment, fast propagation speed and severe resource consumption. Taking attacks for malicious resource occupation as an example, attackers implant attack programs for malicious resource occupation in container environments such as Docker and Kubernetes through means such as vulnerability exploitation and image injection, and long-term steal CPU computing power by taking advantage of the limitations of the container resource isolation mechanism, resulting in decreased business performance, increased energy costs, and even triggering cluster-level resource exhaustion attacks.
[0003] However, traditional container attack virus detection technology usually relies on known static characteristics of attack viruses for detection, and is difficult to identify variants of attack viruses that evade detection through code obfuscation, encrypted communication or dynamic variation, and has the problem of insufficient recognition accuracy. SUMMARY
[0004] The embodiments of the present application provide an attack virus detection method, device, electronic equipment and medium to solve the problem of insufficient recognition accuracy of attack viruses based on containers in the prior art.
[0005] In a first aspect, the embodiments of the present application provide an attack virus detection method, which comprises: For each node of a target cluster, collect multi-dimensional behavior data of each container running on the node, wherein the behavior data includes resource utilization data for representing the running of each container, and operation behavior data of each container interaction or each container control plane; Slide a target window on the behavior data according to a preset step size, and perform the following process every time the target window is slid; According to the data feature type of the target behavior data in the target window, perform feature value conversion on the target behavior data, and combine the converted feature values of the target behavior data to obtain a fusion feature vector; Perform abnormal feature analysis on the fusion feature vector to determine a first detection result of the target behavior data; If it is determined that the target behavior data is abnormal based on the first detection result, perform feature reconstruction analysis on the fusion feature vector to determine a second detection result of the target behavior data; Based on the first detection result and the second detection result, determine a final result of the target behavior data; Determine whether the node in the target cluster has a container of an attack virus based on a final result of target behavior data corresponding to each target window.
[0006] In some embodiments, the data feature type of the target behavior data includes continuous numerical features and Boolean logic features. The feature value conversion of the target behavior data according to the data feature type of the target behavior data in the target window, and the combination of the converted feature values of the target behavior data to obtain the fusion feature vector, includes: The first feature value conversion of the behavior data corresponding to the continuous numerical features in the target behavior data by using the Z-score standardization method to generate the first feature value; The second feature value conversion of the behavior data corresponding to the Boolean logic features in the target behavior data by using the Boolean feature binary encoding to generate the second feature value; Combining each first feature value and each second feature value to generate the fusion feature vector.
[0007] In some embodiments, the abnormal feature analysis of the fusion feature vector to determine the first detection result of the target behavior data includes: Input the fusion feature vector into a pre-trained isolation forest model, and determine the path length of the fusion feature vector from the root node to the leaf node in each decision tree based on the number of decision trees of the isolation forest model; Determine the first detection score of the fusion feature vector based on the average value of the path length of the fusion feature vector in each decision tree; wherein the first detection score is used to represent the deviation degree of the target behavior data corresponding to the fusion feature vector relative to the normal behavior data; Determine the first detection result based on the first detection score and a preset first score threshold.
[0008] In some embodiments, the determination of the final result of the target behavior data based on the first detection result and the second detection result includes: Multiply the first detection score in the first detection result by the first weight corresponding to the first detection result to determine the first weighted score; Multiply the ratio between the reconstruction error in the second detection result and the preset reconstruction error by the second weight corresponding to the second detection result to determine the second weighted score; Determine the second detection score of the target behavior data by summing the first weighted score and the second weighted score; Determine the final result of the target behavior data based on the second detection score and a preset second score threshold.
[0009] In some embodiments, the determining the final result of the target behavior data based on the second detection score and a preset second score threshold comprises: if the second detection score is higher than the preset second score threshold, determining that the target behavior data is abnormal; if the second detection score is not higher than the preset second score threshold, determining that the target behavior data is normal.
[0010] In some embodiments, after the collecting the multi-dimensional behavior data of each container running on the node, before the sliding the target window on the behavior data according to the preset step size, the method further comprises: grouping the behavior data according to the container identifier carried by the behavior data; the sliding the target window on the behavior data according to the preset step size comprises: sliding the target window on the behavior data corresponding to any one container according to the preset step size; the determining whether the node in the target cluster has the container with the attack virus based on the final result of the target behavior data corresponding to each target window comprises: if the final result of the target behavior data corresponding to any target window is abnormal, determining that the any one container is the container with the attack virus in the node.
[0011] In some embodiments, after the determining that the any one container is the container with the attack virus in the node, the method further comprises: determining a target score level according to the second detection score corresponding to the abnormal target behavior data and the score interval corresponding to the score level; performing corresponding isolation treatment on the any one container according to the response strategy corresponding to the target score level.
[0012] In a second aspect, the embodiments of the present application provide an attack virus detection device, the device comprises: a collection module, configured to collect multi-dimensional behavior data of each container running on each node of a target cluster, wherein the behavior data comprises resource utilization data for representing the running of each container, and operation behavior data of interaction between each container or each container control plane; a detection module, configured to slide a target window on the behavior data according to a preset step size, and perform the following process each time the target window is slid; performing feature value conversion on the target behavior data according to the data feature type of the target behavior data in the target window, and combining the converted feature values corresponding to the target behavior data to obtain a fusion feature vector; performing an abnormal feature analysis on the fusion feature vector to determine a first detection result of the target behavior data; if it is determined that the target behavior data is abnormal based on the first detection result, performing a feature reconstruction analysis on the fusion feature vector to determine a second detection result of the target behavior data; determining a final result of the target behavior data based on the first detection result and the second detection result; a determination module configured to determine whether a container of an attack virus exists in the node in the target cluster based on the final result of the target behavior data corresponding to each target window.
[0013] In a third aspect, an electronic device is provided, which includes at least one processor and a memory connected with the at least one processor in communication, and wherein: The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the attack virus detection method.
[0014] In a fourth aspect, a storage medium is provided, and when a computer program in the storage medium is executed by a processor of an electronic device, the electronic device can perform the attack virus detection method.
[0015] In a fifth aspect, a computer program product is provided, and when the computer program product is executed by an electronic device, the electronic device performs the attack virus detection method.
[0016] In the embodiments of the present application, for each node of the target cluster, multi-dimensional behavior data of each container running on the node is collected, the behavior data including resource utilization data for representing the running time of each container, and operation behavior data of each container control plane or interaction between containers; a target window is slid on the behavior data according to a preset step, and the following process is performed each time the target window is slid; the target behavior data is converted according to the data feature type of the target behavior data in the target window, and a fusion feature vector is obtained by combining the converted feature values of the target behavior data; the fusion feature vector is analyzed for abnormal features to determine a first detection result of the target behavior data; if the target behavior data is determined to be abnormal based on the first detection result, the fusion feature vector is analyzed for feature reconstruction to determine a second detection result of the target behavior data; the final result of the target behavior data is determined based on the first detection result and the second detection result; and whether there is a container with an attack virus in the node of the target cluster is determined based on the final result of the target behavior data corresponding to each target window. In this way, by collecting multi-dimensional runtime behavior data, combining sliding window time series analysis, multi-feature fusion, and a two-level abnormality detection mechanism, the problem of insufficient recognition accuracy of unknown virus variants caused by the traditional technology relying only on static features is overcome, high-precision and low-false alarm detection of unknown threats is realized, and specific abnormal containers can be accurately located, thereby improving the security protection level of the containerized environment.
[0017] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS
[0018] The drawings described herein are intended to provide further understanding of the present application, and form a part of the present application. The illustrative embodiments of the present application and their description serve to explain the present application. They do not constitute an inappropriate limitation on the present application. In the drawings: Figure 1 A flowchart of an attack virus detection method provided by the embodiments of the present application; Figure 2 A system architecture schematic diagram of a malicious resource occupation attack program detection system provided by the embodiments of the present application; Figure 3 A flowchart of a malicious resource occupation attack program detection method implemented in a cluster provided by the embodiments of the present application; Figure 4 A flowchart of a malicious resource occupation attack program detection method for any container in a target window provided by the embodiments of the present application; Figure 5A structural schematic diagram of an attack virus detection device provided in an embodiment of the present application is provided. Figure 6 A hardware structural schematic diagram of an electronic device for implementing the method provided in an embodiment of the present application is provided. DETAILED DESCRIPTION
[0019] For the purpose and implementation of the present application to be more clear, the following will combine the drawings in the exemplary embodiments of the present application to clearly and completely describe the exemplary embodiments of the present application. Obviously, the described exemplary embodiments are only a part of the embodiments of the present application, but not all the embodiments.
[0020] It should be noted that the terms "first", "second" and the like in the description of the embodiments of the present application are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological order. It should be understood that the data used in this way can be exchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein.
[0021] In the description of the embodiments of the present application, "a plurality of" means two or more, unless otherwise specified. The association relationship of the associated objects is described, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. The character " / " generally represents that the associated objects before and after are a "or" relationship.
[0022] The terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device containing a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0023] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or a combination of hardware or / and software code capable of performing functions associated with the element.
[0024] Exemplary embodiments of the present application are described herein with reference to the accompanying drawings, which are cited as illustrative examples. Specific details of the present embodiments are set forth for the purpose of providing a thorough understanding of the present application. It will be readily apparent to one of ordinary skill in the art, however, that the embodiments described herein can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring the present application. It is to be understood that the phraseology and terminology employed herein are for the purpose of description and should not be regarded as limiting. It is to be understood that the use of the terms "including", "comprising", or "having" and variations thereof herein is intended to cover the various embodiments of the present application. It is to be understood that the use of the term "or" in the detailed description and claims is used to mean "and / or" unless otherwise stated. It is to be understood that the use of the term "about" in the detailed description and claims is used to mean "approximately", "substantially", "essentially", "close to", "around", "nearly", "nearly" or "in the vicinity of", unless otherwise stated.
[0025] In the technical solutions of the present application, the acquisition, transmission, storage, and use of data comply with relevant national laws and regulations.
[0026] Before introducing the method provided by the embodiments of the present application, in order to facilitate understanding, first, the technical background of the embodiments of the present application is introduced in detail.
[0027] With the deep application of container technology in cloud computing and micro-service architecture, container-based attack viruses present new characteristics such as strong concealment, fast propagation speed, and severe resource consumption. Taking the attack of malicious resource occupation as an example, attackers implant attack programs that maliciously occupy resources in container environments such as Docker and Kubernetes through means such as vulnerability exploitation and image injection, and long-term steal CPU computing power by taking advantage of the limitations of the container resource isolation mechanism, resulting in decreased business performance, increased energy costs, and even cluster-level resource exhaustion attacks.
[0028] However, the traditional container attack virus detection technology usually relies on the static characteristics of known attack viruses for detection, and it is difficult to identify variant attack viruses that evade detection through code obfuscation, encrypted communication, or dynamic variation, and there is a problem of insufficient recognition accuracy.
[0029] In view of this, in order to solve the problems in the prior art, the embodiments of the present application provide an attack virus detection method, device, electronic equipment and medium. Some preferred embodiments of the present application are described below with reference to the accompanying drawings.
[0030] In order to facilitate understanding of the present application, among the technical terms involved in the present application: Container: refers to a lightweight virtualization technology used to package and isolate applications and their dependencies, and to achieve efficient deployment and resource management through platforms such as Docker and Kubernetes.
[0031] Kubernetes (K8s): An open-source container orchestration system that supports the automatic deployment, scaling, and management of containerized applications, providing core functions such as resource scheduling, service discovery, etc.
[0032] Malicious resource occupation attack: Malicious programs exploit weak passwords to invade containers, illegally occupy CPU, memory, and other resources, with characteristics of strong concealment and high resource consumption.
[0033] Isolation Forest: An unsupervised anomaly detection algorithm based on random trees, which judges the degree of anomaly by the path length of "isolated" abnormal points, suitable for high-dimensional sparse data scenarios, with linear time complexity advantage.
[0034] cAdvisor (Container Advisor): An open-source tool from Google, used to monitor and collect resource usage data (CPU, memory, disk, network) of containers.
[0035] Daemonset deployment: A Kubernetes-provided workload resource that ensures a specified Pod replica is running on every node (Node) in the cluster. It is commonly used to deploy system-level components such as log collectors, monitoring agents, network plugins, etc.
[0036] Extended Berkeley Packet Filter (eBPF): A sandbox technology that runs user-defined programs in the Linux kernel, allowing developers to safely and efficiently inject custom programs into the kernel without modifying kernel sources or loading kernel modules, to observe, modify, and control kernel behavior.
[0037] Figure 1 A flowchart of an attack virus detection method provided by an embodiment of the present application, and the method comprises the following steps.
[0038] In step 101, for each node of the target cluster, collect multi-dimensional behavior data of each container running on the node, including resource utilization data representing the running time of each container, and interaction between each container or operation behavior data of each container control plane.
[0039] In specific implementation, the target cluster can be a Kubernetes (K8s) cluster, and each node runs multiple pods, each pod can include containers.
[0040] Suppose there is a K8s cluster containing 3 worker nodes (Node-1, Node-2, Node-3), wherein Node-1 runs: Web application Pod-1 (1 container), Web application Pod-2 (1 container), database Pod (1 container), log collection Pod (1 container), a total of 4 containers; Node-2 runs: Web application Pod-3 (1 container), Web application Pod-4 (1 container), log collection Pod (1 container), a total of 3 containers; Node-2 runs: Web application Pod-5 (1 container), log collection Pod (1 container), a total of 2 containers.
[0041] The behavior data includes resource utilization data for characterizing the running of each container, such as CPU, memory, disk I / O, network traffic, and the like, and specifically can collect CPU usage, memory usage and peak, network traffic; operation behavior data of interaction between containers, such as system call behavior data, external IP, DNS query, abnormal port connection, and the like, and specifically can collect suspicious command invocation frequency, external IP quantity, DNS query frequency, out-direction traffic rate, and whether to connect an abnormal port; operation behavior data of the control plane of each container, such as container creation, privilege mode configuration, and the like, and specifically can collect whether to use a privileged container and container restart times.
[0042] In step 102, a target window is slid on the behavior data according to a preset step size, and the following process is performed each time the window is slid.
[0043] In specific implementation, after collecting multi-dimensional behavior data of each container running on a node, before sliding the target window on the behavior data according to the preset step size, the behavior data can be grouped according to the container identifier carried by the behavior data, and then the target window is slid on the behavior data corresponding to any one container according to the preset step size. In this way, all subsequent aggregation and calculation are performed independently for a single container, avoiding confusion of data of different containers.
[0044] In specific implementation, the preset step size can be 30 seconds, 1 minute, or 5 minutes, and the target window can be 5 minutes, 10 minutes, or the like. Taking the preset step size as 30 seconds and the target window as 5 minutes as an example, a complete detection process is independently performed for each container every 30 seconds, such as the first analysis is triggered at 10:05:00, the window covers the time [10:05:00-10:10:00], and the interval is 30 seconds. Therefore, the second analysis is triggered at 10:05:30, and the corresponding window covers the time [10:05:30-10:10:30].
[0045] In step 102a, the target behavior data in the target window is converted into feature values according to the data feature type of the target behavior data, and the converted feature values of the target behavior data are combined to obtain a fusion feature vector.
[0046] In specific implementation, before the target behavior data in the target window is converted into feature values, the target behavior data can also be preprocessed, and the data preprocessing process is as follows: 1. Average CPU usage (cpu_avg): calculate the 5-minute average value of CPU usage.
[0047] 2. CPU fluctuation standard deviation (cpu_std): calculate the 5-minute standard deviation of CPU usage.
[0048] 3. Memory usage peak (mem_peak): take the 5-minute maximum value of memory usage, and clip it to the upper limit of the host physical memory.
[0049] 4. Command call frequency (curl_freq): 5-minute cumulative statistics of curl command frequency, and set it to 200 if it exceeds 200.
[0050] 5. Number of remote IPs (remote_ip_count): total IP number statistics of remote IP number within 5 minutes, and set it to 100 if it exceeds 100.
[0051] 6. Whether to connect to abnormal port (port_used): binary flag for whether to connect to abnormal port (1 if connected), 0 / 1 encoding (Boolean to integer).
[0052] 7. Whether to use privileged container (privileged_flag): whether to use privileged container, use privileged container (1 if connected), 0 / 1 encoding (Boolean to integer).
[0053] 8. DNS query frequency (dns_qps): record the number of DNS queries per minute, with a maximum of 100 queries per minute.
[0054] 9. Outbound network traffic rate (tx_rate): Calculate the 5-minute average rate of outbound network traffic, and perform P99 clipping, i.e., the system automatically calculates the tx_rate (unit: KB / s) data of all containers in each 5-minute sliding window in the past 7 days every day. According to the statistical results, the 99th percentile (P99) is calculated, i.e., the maximum value of the top 99% data values, as the reasonable upper limit of the current network traffic. If the actual tx_rate exceeds this value, the P99 value is used for truncation clipping.
[0055] 10. Container restart count (restart_count): The maximum threshold of container restart count (hour level) is 10.
[0056] For example, focus on the 5-minute average CPU usage, collect data every 30 seconds in the target window of [00:00-05:00], and assume that the collected raw data is [(00:00, CPU=10%), (00:30, CPU=15%), (01:00, CPU=20%), (01:30, CPU=18%), (02:00, CPU=25%), (02:30, CPU=22%), (03:00, CPU=19%), (03:30, CPU=17%), (04:00, CPU=16%), (04:30, CPU=14%)], a total of 10 30-second data points, then the average CPU usage is (10+15+20+18+25+22+19+17+16+14) / 10=17.6%, which is the average CPU usage (cpu_avg) in this 5-minute target window.
[0057] In specific implementation, after the target behavior data in the target window is processed as described above, the target behavior data can be converted into feature values according to the data feature type of the target behavior data, wherein the data feature type of the target behavior data includes continuous numerical features and Boolean logical features.
[0058] In specific implementation, for the behavior data of continuous numerical features, such as average CPU usage, CPU fluctuation standard deviation, memory usage peak value, command invocation frequency, number of external IP, DNS query frequency, outbound network traffic rate, and container restart count.
[0059] The Z-score standardization method can be used to convert the behavior data corresponding to the continuous numerical features in the target behavior data into first feature values to generate the first feature values.
[0060] Formula 1; wherein, and respectively represent the characteristics Mean and standard deviation in the past 7 days of data, and dynamically updated daily through the sliding window mechanism to adapt to environmental changes.
[0061] In implementation, for the behavior data of Boolean logic features, such as whether to use a privileged container (privileged_flag) and whether to connect an abnormal port (port_used), a discrete variable is uniformly coded.
[0062] Equation 2; In implementation, the feature values corresponding to the converted target behavior data are combined to obtain the following fusion feature vector: ; wherein, represents resource consumption features: average cpu usage, cpu fluctuation standard deviation, memory usage peak; represents system call behavior data, command call frequency; represents network communication behavior data, number of external IP, abnormal port connection, DNS query frequency, and network traffic rate in the outgoing direction; represents control plane operation behavior data: whether the container is privileged, and container restart frequency.
[0063] In step 102b, the fusion feature vector is subjected to abnormal feature analysis to determine the first detection result of the target behavior data.
[0064] In implementation, the fusion feature vector can be input into a pre-trained isolation forest model. Based on the number of decision trees of the isolation forest model, the path length of the fusion feature vector from the root node to the leaf node in each decision tree is determined. Based on the average value of the path length of the fusion feature vector in each decision tree, the first detection score of the fusion feature vector is determined. The first detection score is used to represent the deviation degree of the target behavior data corresponding to the fusion feature vector relative to the normal behavior data. Based on the first detection score and a preset first score threshold, the first detection result is determined.
[0065] In implementation, the isolation forest model can be trained based on the following method: Input: multi-dimensional feature fusion processed feature vector x=[ ](d=10 dimensions).
[0066] Parameter configuration: Number of sub-samples = 256 (number of samples trained per tree) Number of trees = 100 (number of decision trees in ensemble learning) Maximum depth = 10 (limit the depth of trees to avoid overfitting) Training process: Random sampling: randomly select samples from the training data.
[0067] Random split: Randomly select a feature .
[0068] Randomly select a split value s (between the minimum and maximum values of the feature for the current sample).
[0069] Split the data by s, forming left and right subtrees.
[0070] Recursive construction: repeat the above process until the termination condition is met (such as reaching the maximum depth or the number of sub-samples ≤ 1).
[0071] Ensemble learning: build = 100 trees to form an isolated forest (iForest).
[0072] In implementation, input the fusion feature vector into the pre-trained isolated forest model, pass the fusion feature vector through all decision trees, record the path length passed through when isolated (i.e. reaching the leaf node), where the path length is the number of edges from the root node of the tree to the leaf node, then integrate the average of the path lengths in each decision tree h ( x ) , if the average of the path lengths E( h ( x ) ) is small, then x is an isolated point, if E( h ( x ) ) is large, then x is close to a normal point.
[0073] Since h ( x ) depends on the number of sub-samples , normalization correction is needed: Equation 3; is a normalization factor related to the depth of the sum, representing the average path length a normal point needs in a binary tree of n samples, is the k-th harmonic number. .
[0074] First detection score is: Formula 4; If →1, indicates x very easy to be isolated (abnormal); if →0.5, indicates x similar to normal points.
[0075] In specific implementation, the first score threshold can be preset as =0.65, and when the first detection score is higher than 0.65, it is determined as abnormal.
[0076] In step 102c, if it is determined that the target behavior data is abnormal based on the first detection result, the fusion feature vector is analyzed for feature reconstruction to determine a second detection result of the target behavior data.
[0077] In specific implementation, the abnormal fusion feature vector can be input into a pre-trained autoencoder model to calculate the reconstruction error, and if the error is small, it indicates that the fusion feature vector is normal, and if the error is large, it indicates that it can be an abnormal behavior.
[0078] In specific implementation, the autoencoder model can be trained based on the following manner: Construct the network structure: Encoder: compress the input feature vector to a low-dimensional latent space; Decoder: restore the latent space representation to the reconstruction of the original input feature.
[0079] Wherein, the encoding process is: Formula 5; Wherein, x is the input fusion feature vector, is the weight matrix of the encoder, is the bias term, is the activation function, h represents the low-dimensional vector after encoding.
[0080] The decoding process is: Formula 6; is the output restored by the model, , is the weight matrix and bias term of the decoder, is the activation function.
[0081] Reconstruction error: Formula 7; Through the above formula 7, the difference between the input data and the reconstructed data is measured, and the abnormal sample usually has a larger RE(x).
[0082] In the training stage, the loss function can be calculated to minimize the reconstruction error: Equation 8 N is the number of training samples, and the first detection score is used The normal sample is used to train the autoencoder model, and the minimum reconstruction error is obtained The optimal value is obtained, and the trained autoencoder model is obtained.
[0083] In step 102d, based on the first detection result and the second detection result, the final result of the target behavior data is determined.
[0084] In specific implementation, the first detection score in the first detection result can be multiplied by the first weight corresponding to the first detection result to determine the first weighted score; the ratio between the reconstruction error in the second detection result and the preset reconstruction error can be multiplied by the second weight corresponding to the second detection result to determine the second weighted score; the sum of the first weighted score and the second weighted score is determined as the second detection score of the target behavior data; based on the second detection score and the preset second score threshold, the final result of the target behavior data is determined.
[0085] In specific implementation, the results of Isolation Forest and Autoencoder are combined to generate the second detection score S(x).
[0086] Equation 9 wherein, is the first detection score, is the reconstruction error, is a weight coefficient, such as 0.6-0.7, is the maximum reconstruction error on the training set.
[0087] In specific implementation, if the second detection score is higher than the preset second score threshold, it is determined that the target behavior data is abnormal; if the second detection score is not higher than the preset second score threshold, it is determined that the target behavior data is normal, for example, the preset second score threshold can be =0.7, and when the second detection score is higher than 0.7, it is determined to be abnormal.
[0088] In step 103, based on the final result of the target behavior data corresponding to each target window, it is determined whether there is a container of attack virus in the node in the target cluster.
[0089] In specific implementation, if the final result of the target behavior data corresponding to any target window is abnormal, it is determined that any container is a container of attack virus in the node.
[0090] In this way, by collecting multi-dimensional runtime behavior data, combining sliding window time series analysis, multi-feature fusion, and a two-level anomaly detection mechanism, the problem of insufficient recognition accuracy of unknown variant viruses caused by the traditional technology relying only on static features is overcome, high-precision and low-false alarm detection of unknown threats is realized, and specific abnormal containers can be accurately located, thereby improving the security protection level of the containerized environment.
[0091] In specific implementation, after determining that any one container is an attacked container, the target score level can be determined according to the second detection score corresponding to the abnormal target behavior data and the score interval corresponding to the score level.
[0092] For example, three score levels, high, medium and low, are set, wherein the score interval corresponding to the high score level is (0.7, 1], the score interval corresponding to the medium score level is (0.5, 0.7], and the score interval corresponding to the low score level is (0, 0.5], each score level corresponds to a different isolation strategy, for example, the high level corresponds to emergency isolation, the medium level corresponds to monitoring upgrade, and the low level corresponds to normal monitoring, so that the hierarchical response strategy is executed based on the detection result, the automatic isolation and alarm of the abnormal container are realized, and a “detection-response” rapid closed loop is constructed.
[0093] The attack virus detection method provided in the present application will be described in detail below taking the attack virus as a malicious resource-occupying attack program and the target cluster as a K8s cluster as an example.
[0094] As shown in Figure 2 Fig. 1 is a system architecture schematic diagram of a detection system for a malicious resource-occupying attack program provided by an embodiment of the present application, and the system includes seven modules, namely a data acquisition module, a data preprocessing module, a multi-dimensional feature fusion module, an unsupervised anomaly detection module, a K8s ecological linkage response module, a model training module, and a database module, wherein: The data acquisition module is used to realize real-time capture of multi-dimensional behavior data of containers in runtime by using a K8s native controller (DaemonSet) and a lightweight Sidecar architecture.
[0095] In implementation, the CPU, memory, disk I / O, network traffic and other resource consumption data are collected through the integrated cAdvisor, the high-dimensional features such as system calls and process behaviors are captured by embedding the Sysdig tool, the network behaviors such as external IP, DNS query and abnormal port connection are monitored through the eBPF technology under the Cilium network framework, and the Kubernetes Audit Log is listened to to collect the control plane events such as container creation and privilege mode configuration.
[0096] The data preprocessing module is used for implementing standardization, cleaning and dynamic adaptation processing on multi-source heterogeneous data. The real-time Z-score standardized value of continuous features (such as CPU usage rate and memory peak value) is calculated through a sliding time window (the window size is adaptively configured) to eliminate the dimensional difference; the binary and one-hot encoding conversion is implemented on discrete features (such as whether a privileged container is used); the P99 quantile dynamic clipping mechanism is adopted for abnormal values (such as CPU ≥ 100%). The mean and standard deviation parameters are updated in real time through a rolling window to ensure the dynamic adaptation of the data distribution characteristics. This module purifies data noise from the source, standardizes feature expression, and provides high-quality standardized data flow for model training and real-time detection.
[0097] The multi-dimensional feature fusion module is used for integrating the resource monitoring data of cadvisor, the process behavior data of Sysdig, the network feature data of eBPF and the control plane events of Kubernetes Audit Log to form a ten-dimensional core feature set including CPU dynamic load features, suspicious process call patterns, abnormal external connection behavior labels and high-risk configuration parameters. The sliding window statistics are used to continuously optimize the feature combination, ensure the accurate description of abnormal behavior patterns in complex container environments, and effectively improve the difference representation ability of high and low frequency anomalies.
[0098] The database module is used for designing a multi-level distributed storage architecture. The Prometheus time series database is used to store container behavior feature data, the Push Gateway is used to support high-concurrency index writing, and Thanos is used to realize horizontal expansion and long-term storage. The EFK (Elasticsearch-Fluentd-Kibana) technology stack is used to aggregate alarm and audit logs. This module realizes flexible real-time query through PromQL, ensures the millisecond-level response of data retrieval performance, supports TB-level long-term reliable storage of monitoring data, and provides traceability and big data analysis basis for the system.
[0099] Model training module, for managing training data using time series partition storage strategy, implementing periodic incremental training based on KubernetesCronJob, resampling recent 7 days data daily to maintain model timeliness. Through dynamic expansion tree model (Extra Trees) and adaptive network pruning strategy, resource efficient training is realized, distributed computing framework (TensorFlow on K8s) is used to complete large-scale data parallel processing, and the model continuously maintains the generalization detection ability to new attack patterns.
[0100] Unsupervised anomaly detection module, for fusing Isolation Forest (Isolation Forest) and Autoencoder to build a hybrid detection engine, realizing high-precision unknown threat identification. The Isolation Forest algorithm of ensemble learning is used to perform fast branching operation on multi-dimensional feature space, and the sample path length is calculated to generate isolation score, and the sliding window is used to dynamically adjust the isolation judgment threshold; a deep compression type Autoencoder network architecture is designed, the reconstruction error (RE) is used to quantify the feature deviation degree, and a dynamic threshold adjustment mechanism is introduced to eliminate periodic fluctuation interference. Finally, nonlinear feature fusion is implemented, and the weighted score formula Comprehensive evaluation of abnormal level, breaking through known feature dependence and accurately detecting unknown anomalies.
[0101] K8s ecological linkage response module, for building a multi-level response mechanism based on unsupervised anomaly detection results, through deep connection with Kubernetes API and cloud native monitoring tool chain, realizing automatic isolation and alarm of abnormal containers, forming a complete "detection-response-audit" closed loop.
[0102] Figure 3 A flowchart of a method for detecting an attack program that maliciously occupies resources in a cluster is provided. The method comprises the following steps.
[0103] Step 1: data collection 1) Resource monitoring data Using the Kubernetes native DaemonSet controller, cAdvisor runs an instance on all nodes in the cluster, ensuring that data collection covers all containers on each node. Each worker node can report the resource usage data of its local container in real time, including CPU, memory, network traffic and other indicators. The specific collected data is as follows: ① CPU usage; ② Memory usage and peak value; ③ Network transmit and receive traffic; 2) Process behavior data In the Kubernetes cluster, the Sysdig tool is deployed in DaemonSet mode to all nodes to ensure that the kernel behavior of all containers on each host is observable and recordable. The collected data is as follows: ① Suspicious command invocation frequency; 3) Network connection data To enhance the visualization and anomaly detection capabilities of container network communication behavior, the system deploys a container network observability platform Cilium based on eBPF technology, and combines its subsystem Hubble to realize real-time monitoring of container traffic, external connection, DNS request and other key behaviors. Cilium is deployed in DaemonSet mode in the Kubernetes cluster, with one instance running on each node, acting on the network data path layer. The collected data is as follows: ① Number of external IP addresses; ② Whether to connect to the attack program port that occupies resources maliciously; ③ DNS query frequency and outbound traffic rate; 4) Kubernetes control plane events To collect and analyze high-risk operation behavior of the Kubernetes control plane, the system deploys and enables the Kubernetes native audit log mechanism (kube-audit) to capture API request events closely related to container security configuration, including privileged container creation, container startup and other operation behaviors. The collected data is as follows: ① Whether to use a privileged container; ② Number of container restarts.
[0104] Step 2, data preprocessing: The following data preprocessing is performed by the data processing node: 1) Group all raw data by container unique identifier (Container ID); 2) Roll up the 30-second granularity data in a 5-minute sliding window; The specific data processing process is as follows: 1. Average CPU usage (cpu_avg): Calculate the 5-minute average value of CPU usage.
[0105] 2. CPU fluctuation standard deviation (cpu_std): Calculate the 5-minute standard deviation of CPU usage.
[0106] 3. Memory usage peak (mem_peak): Take the 5-minute maximum value of memory usage and clip it to the upper limit of the host's physical memory.
[0107] 4. Command call frequency (curl_freq): 5-minute cumulative statistics of the number of curl commands, and more than 200 times is set to 200.
[0108] 5. Number of remote IPs (remote_ip_count): Total IP number statistics of the number of remote IPs within 5 minutes, and more than 100 is set to 100.
[0109] 6. Whether to connect to the attack program port that maliciously occupies resources (port_used): Binary flag for whether to connect to the attack program port that maliciously occupies resources (1 if yes), 0 / 1 encoding (Boolean to integer).
[0110] 7. Whether to use privileged containers (privileged_flag): Whether to use privileged containers, use privileged containers (1 if yes), 0 / 1 encoding (Boolean to integer).
[0111] 8. DNS query frequency (dns_qps): Record the number of DNS queries per minute, with a maximum of 100 queries per minute.
[0112] 9. Network traffic rate in the out direction (tx_rate): Calculate the 5-minute average rate of network traffic in the out direction, and perform P99 clipping, i.e., the system automatically calculates the tx_rate (unit: KB / s) data of all containers in each 5-minute sliding window within the past 7 days every day. According to the statistical results, calculate the 99th percentile (P99), i.e., the maximum value of the top 99% data, as the reasonable upper limit of the current network traffic. If the actual tx_rate exceeds this value, use the P99 value for truncation clipping.
[0113] 10. Container restart count (restart_count): Set the maximum threshold for container restart count (hour level) to 10.
[0114] Step 3: Multi-dimensional feature fusion: The pre-processed multi-source behavior indicators are mapped and logically combined to construct a unified feature vector. The fused multi-dimensional features include ten fields, covering both continuous numerical features and Boolean logical features, and the fusion method is as follows: Use Z-score standardization method to perform first feature value conversion on continuous features to generate first feature values: such as average cpu usage, cpu fluctuation standard deviation, memory usage peak value, command call frequency, number of remote IPs, DNS query frequency, network traffic rate in the out direction, and container restart count.
[0115] For the behavioral data of Boolean features, such as whether to use privileged containers (privileged_flag) and whether to connect abnormal ports (port_used), they are uniformly coded as discrete variables.
[0116] Finally, all the processed feature values are combined into a unified input vector: ; where, represents resource consumption features: average cpu usage, cpu fluctuation standard deviation, memory usage peak; represents system call behavior data, command call frequency; represents network communication behavior data, number of external IP connections, abnormal port connections, DNS query frequency, and outgoing network traffic rate; represents the operation behavior data of the control plane: whether the container is privileged, and the container restart frequency.
[0117] The final vector has a fixed dimension and a unified structure, which is suitable for the input format of the Isolation Forest model, supports batch detection of multiple container samples, and improves the separability of malicious resource occupation attack programs in high-dimensional space.
[0118] Step 4, unsupervised anomaly detection
[0119] In the model processing node, first perform unsupervised detection using Isolation Forest.
[0120] In implementation, the Isolation Forest model can be trained based on the following methods: Input: multi-dimensional feature fusion processed feature vector x=[ ] (d=10 dimensions).
[0121] Parameter configuration: Number of sub-samples =256 (number of samples trained for each tree) Number of trees =100 (number of decision trees in ensemble learning) Maximum depth =10 (limit the depth of the tree to avoid overfitting) Training process: Random sampling: randomly select samples from the training data.
[0122] Randomly divide: Randomly select a feature .
[0123] Randomly choose a split value s (between the minimum and maximum of the feature in the current sample).
[0124] Split the data by s, forming left and right sub-trees.
[0125] Recursive construction: repeat the above process until termination conditions are met (e.g. maximum depth reached or number of sub-samples ≤ 1).
[0126] Ensemble learning: build =100 trees, forming an Isolation Forest (iForest).
[0127] In implementation, input the fusion feature vector into the pre-trained Isolation Forest model, pass the fusion feature vector through all decision trees, record the path length passed through when isolated (i.e. reaching the leaf node), where the path length is the number of edges passed from the root node to the leaf node, then integrate the average of the path lengths in each decision tree h ( x ) , if the average of the path lengths E( h ( x ) ) is small, then x is an isolated point, if E( h ( x ) ) is large, then x is close to a normal point.
[0128] Since h ( x ) depends on the number of sub-samples , normalization correction is needed: ; is a normalization factor related to the depth of the sum, representing the average path length a normal point needs in a binary tree of n samples, is the k-th harmonic number. .
[0129] The first detection score is: ; If →1, it means x is easily isolated (abnormal); if →0.5, it means x is similar to a normal point.
[0130] In implementation, the first score threshold can be preset as =0.65, when the first detection score is higher than 0.65, it is determined as abnormal.
[0131] After determining the anomaly, fine detection is performed by the Autoencoder.
[0132] In implementation, the Autoencoder model can be trained based on the following manner: Construct the network structure: Encoder: compress the input feature vector to a low-dimensional latent space; Decoder: restore the latent space representation to the reconstruction of the original input feature.
[0133] wherein the encoding process is: ; wherein x is the input fusion feature vector, is the weight matrix of the encoder, is the bias term, is the activation function, h represents the low-dimensional vector after encoding.
[0134] The decoding process is: ; is the output restored by the model, , is the weight matrix and bias term of the decoder, is the activation function.
[0135] Reconstruction error: ; Through the above formula 7, the difference between the input data and the reconstructed data is measured, and the abnormal sample usually has a larger RE(x).
[0136] In the training phase, the loss function can be calculated to minimize the reconstruction error: ; = , N is the number of training samples, and the first detection score ≤ of the normal sample is used to train the Autoencoder model to obtain the minimum reconstruction error, and the optimal value of is obtained, and the trained Autoencoder model is obtained.
[0137] The abnormal fusion feature vector is input into the pre-trained Autoencoder model (Autoencoder), and the reconstruction error is calculated. If the error is small, it means that the fusion feature vector is normal, and if the error is large, it means that it may be an abnormal behavior.
[0138] Step 5: Perform abnormal detection fusion judgment.
[0139] Combine the results of Isolation Forest and Autoencoder to generate a second detection score S(x).
[0140] ; wherein, is the first detection score, is the reconstruction error, is a weight coefficient, such as 0.6-0.7, is the maximum reconstruction error on the training set.
[0141] If the second detection score is higher than a preset second score threshold , it is determined that the target behavior data is abnormal; if the second detection score is not higher than the preset second score threshold , it is determined that the target behavior data is normal.
[0142] Step 6: K8s ecological linkage response
[0143] Emergency isolation ( ): Create NetworkPolicy in real time through K8s API to block network traffic in and out of abnormal containers, and mark as non-schedulable (nodeSelector isolation), and contain attack spread within 10 seconds.
[0144] Monitoring upgrade ( ): Increase data collection frequency to 15 seconds / second, trigger Prometheus Alertmanager alarm, and attach container ID, abnormal characteristics and score details for security personnel to review.
[0145] Normal monitoring ( ): Maintain the default collection frequency, and store the data in the ELK platform for behavior baseline backtracking analysis.
[0146] Ecological integration: seamlessly integrate with Prometheus and ELK tools, support real-time visualization and historical log auditing of attack behavior, and compatible with cloud-native security system.
[0147] Step 7: Dynamic model update
[0148] Through periodic incremental training, the model adapts to the dynamic changes of the container environment, continuously optimizes the detection accuracy and generalization ability.
[0149] Data-driven: Trigger model update at 0 am every day, recalculate the standardization parameters (μ / σ) based on the latest 7 days of normal behavior data (default ≥ 100k samples), and incrementally train the Isolation Forest, retaining 70% of the old trees to avoid overfitting; retrain the Autoencoder with new data to dynamically update the reconstruction error threshold; adjust the anomaly threshold of the Isolation Forest to adapt to behavior drift.
[0150] Adaptive optimization: dynamically adjust the volatility weight in the anomaly score formula (e.g., 0.15 can be adjusted to the interval of 0.1-0.2) by counting false positives / false negatives cases, to improve the model's adaptability to specific business scenarios.
[0151] Figure 4 A flowchart of a detection method for an attack program that maliciously occupies resources of any container in a target window is provided for the embodiments of the present application, including the following steps.
[0152] In step 401, multi-dimensional behavior data of any container in the target window is collected.
[0153] In step 402, the target behavior data is converted into feature values according to the data feature types of the target behavior data, and the fusion feature vector is obtained by combining the converted feature values corresponding to the target behavior data.
[0154] In step 403, the fusion feature vector is input into the pre-trained Isolation Forest model to generate a first detection score.
[0155] In step 404, it is determined whether the first detection score exceeds a preset first score threshold, if yes, the fusion feature vector is determined to be abnormal and proceeds to step 405, otherwise, proceeds to step 409.
[0156] In step 405, the abnormal fusion feature vector is input into the Autoencoder model to calculate the reconstruction error.
[0157] In step 406, a second detection score is calculated based on the first detection score and the reconstruction error.
[0158] In step 407, it is determined whether the second detection score is greater than a preset second score threshold, if yes, proceeds to step 408, otherwise, proceeds to step 409.
[0159] In step 408, the target score level is determined according to the score interval corresponding to the second detection score and the score level, and the corresponding isolation treatment is performed on the container according to the response strategy corresponding to the target score level.
[0160] In step 409, continue monitoring.
[0161] The embodiment of the application constructs an anomaly detection framework through unsupervised learning (Isolation Forest) and deep feature analysis (Autoencoder), and can automatically discover abnormal activities deviating from the normal container behavior pattern without relying on a prior feature library. Precise identification: multi-dimensional analysis of composite abnormal behaviors such as resource abuse, abnormal processes, suspicious network connections, and high-risk configurations, precise detection of unknown or variant malicious resource occupation attack programs. Anti-variant attack: through dynamic baseline adjustment, adapt to new attack patterns and behavior characteristics, effectively cope with the threat of malicious resource occupation attack programs and their variants. Integrate the rapid screening ability of Isolation Forest and the deep reconstruction error analysis of Autoencoder, combined with a dynamic weight adjustment strategy, greatly improve the detection accuracy and anti-interference ability. Low false alarm guarantee: through sliding window dynamic standardization and multi-dimensional behavior analysis, avoid false alarms caused by periodic fluctuations in business, ensure that normal business is not affected. High recall ability: the integrated model integrates multi-source features in the anomaly scoring stage to ensure that even malicious resource occupation attack programs can be accurately identified using evasion methods such as camouflage and confusion. Through feature fusion (resources, processes, networks, K8s control surface) and adaptive threshold mechanism, build comprehensive abnormal behavior pattern recognition capability. Behavior depth analysis: fusion of multi-dimensional features and dynamic weight adjustment, accurate identification of hidden propagation paths of malicious resource occupation attack programs (such as malicious resource occupation attack processes disguised as). Continuous protection: adaptive model optimization mechanism continuously learns new attack methods, dynamically updates anomaly baseline, prevents defense failure caused by attack method upgrade. Based on the hierarchical response strategy, quickly contain malicious behavior and prevent illegal occupation of computing resources. Zero delay blocking: after high-risk anomalies are triggered, the abnormal container is automatically isolated (network blocking + node isolation) through the K8s API within 10 seconds, blocking the continuous running of malicious resource occupation attack processes and the stealing of computing power. Through continuous collection of behavior data and dynamic model optimization, ensure that the defense system evolves synchronously with the attack method. Confront new attacks: regularly train the fusion model, automatically optimize the Isolation Forest score threshold and the Autoencoder reconstruction error standard, adapt to the behavior characteristics of new malicious resource occupation attack programs.
[0162] Based on the same technical concept, the embodiment of the application also provides an attack virus detection device. The principle of the attack virus detection device for solving the problem is similar to the attack virus detection method described above, and therefore the implementation of the attack virus detection device can be referred to the implementation of the attack virus detection method, and the repeated parts will not be described again.
[0163] Figure 5A structural schematic diagram of an attack virus detection device provided by an embodiment of the present application includes a collection module 501, a detection module 502, and a determination module 503.
[0164] The collection module 501 is configured to collect multi-dimensional behavior data of each container running on each node of a target cluster, wherein the behavior data includes resource utilization data for representing the running of each container and operation behavior data of each container control plane or interaction between containers. The detection module 502 is configured to slide a target window on the behavior data according to a preset step size, and perform the following processes each time the target window is slid. According to a data feature type of the target behavior data in the target window, the target behavior data is subjected to feature value conversion, and a fusion feature vector is obtained by combining the converted feature values of the target behavior data. The fusion feature vector is subjected to abnormal feature analysis to determine a first detection result of the target behavior data. If the target behavior data is determined to be abnormal based on the first detection result, the fusion feature vector is subjected to feature reconstruction analysis to determine a second detection result of the target behavior data. Based on the first detection result and the second detection result, a final result of the target behavior data is determined. The determination module 503 is configured to determine whether there is a container of an attack virus in the node in the target cluster based on the final result of the target behavior data corresponding to each target window.
[0165] In some embodiments, the data feature type of the target behavior data includes continuous numerical features and Boolean logic features. The detection module 502 is specifically configured to perform first feature value conversion on behavior data corresponding to the continuous numerical features in the target behavior data by using a Z-score standardization method to generate first feature values. Second feature values are generated by performing second feature value conversion on behavior data corresponding to the Boolean logic features in the target behavior data by using Boolean feature binary coding. The first feature values and the second feature values are combined to generate the fusion feature vector.
[0166] In some embodiments, the detection module 502 is specifically configured to: The fusion feature vector is input into a pre-trained isolation forest model, and the path length of the fusion feature vector from a root node to a leaf node in each decision tree of the isolation forest model is determined based on the number of decision trees of the isolation forest model. determine a first detection score of the fusion feature vector based on an average value of path lengths of the fusion feature vector in each decision tree, wherein the first detection score is used to represent a deviation degree of target behavior data corresponding to the fusion feature vector relative to normal behavior data; determine the first detection result based on the first detection score and a preset first score threshold.
[0167] In some embodiments, the detection module 502 is specifically configured to: multiply the first detection score in the first detection result by a first weight corresponding to the first detection result to determine a first weighted score; multiply a ratio between the reconstruction error in the second detection result and a preset reconstruction error by a second weight corresponding to the second detection result to determine a second weighted score; determine a second detection score of the target behavior data based on a sum of the first weighted score and the second weighted score; determine a final result of the target behavior data based on the second detection score and a preset second score threshold.
[0168] In some embodiments, the detection module 502 is specifically configured to: if the second detection score is higher than the preset second score threshold, determine that the target behavior data is abnormal; if the second detection score is not higher than the preset second score threshold, determine that the target behavior data is normal.
[0169] In some embodiments, after the collection module 501 collects the multi-dimensional behavior data of each container running on the node, before the detection module 502 slides a target window on the behavior data according to a preset step size, the detection module 502 is further configured to: group the behavior data according to container identifiers carried by the behavior data; the detection module 502 is specifically configured to slide the target window on behavior data corresponding to any one container according to a preset step size; the determination module 503 is specifically configured to, if a final result of target behavior data corresponding to any one target window is abnormal, determine that the any one container is a container in which an attack virus exists in the node.
[0170] In some embodiments, after the determination module 503 determines that the any one container is a container in which an attack virus exists in the node, the determination module 503 is further configured to: determine a target score level according to a score interval corresponding to the score level of the second detection score of the abnormal target behavior data; According to the response strategy corresponding to the target score level, the corresponding isolation treatment is performed on the arbitrary one container.
[0171] Having described the method and apparatus of the exemplary embodiments of the present application, next, an electronic device according to another exemplary embodiment of the present application is described.
[0172] The electronic device 130 implemented according to this embodiment of the present application is described below with reference to Figure 6 Figure 6 The displayed electronic device 130 is merely an example and should not impose any limitation on the function and scope of use of the embodiments of the present application.
[0173] As shown in Figure 6 The electronic device 130 is shown in the form of a general electronic device. The components of the electronic device 130 can include, but are not limited to, the at least one processor 131 described above, the at least one memory 132 described above, and a bus 133 connecting different system components, including the memory 132 and the processor 131.
[0174] The bus 133 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a processor or local bus using any of a variety of bus structures.
[0175] The memory 132 can include a readable medium in the form of volatile memory, such as a random access memory (RAM) 1321 and / or a cache memory 1322, and can further include a read-only memory (ROM) 1323.
[0176] The memory 132 can further include a program / utility 1325 having a set of program modules 1324, including but not limited to an operating system, one or more application programs, other program modules, and program data, each of which or some combination thereof can include implementation of a network environment.
[0177] The electronic device 130 can also communicate with one or more external devices 134 such as a keyboard or pointing devices, etc.; other devices which enable a user to interact with the electronic device 130; and / or any devices (e.g., a router, a modem, a peer device etc.) that enable the electronic device 130 to communicate with one or more other electronic devices. Such communication can occur via an input / output (I / O) interface 135. Still yet, the electronic device 130 can communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or the Internet) through a network adapter 136. As depicted, the network adapter 136 communicates with the other components of the electronic device 130 via the bus 133. It should be appreciated that the network adapter 136 and / or the bus 133 can be implemented using one or more types of technology, including but not limited to, wired technology, wireless technology, and / or optical technology.
[0178] In an example embodiment, there is also provided a storage medium, when a computer program in the storage medium is executed by a processor of an electronic device, the electronic device can perform the attack virus detection method described above. Optionally, the storage medium can be a non-transitory computer readable storage medium, for example, the non-transitory computer readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0179] In an example embodiment, the electronic device of the present application can at least include at least one processor, and a memory connected to the at least one processor in communication, wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the steps of any attack virus detection method provided by the embodiments of the present application.
[0180] In an example embodiment, there is also provided a computer program product, when the computer program product is executed by an electronic device, the electronic device can implement any example method provided by the present application.
[0181] Those skilled in the art will appreciate that embodiments of the present application can be supplied as a method, a system, or a computer program product. Thus, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) embodying computer readable program code thereon.
[0182] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0183] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0184] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.
[0185] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A method for detecting an attack virus, characterized in that: The method comprises: For each node in the target cluster, collect multi-dimensional behavior data of each container running on the node. The behavior data includes resource utilization data used to characterize each container at runtime, as well as interaction data between containers or operational behavior data of each container's control plane. Slide the target window across the behavioral data at a preset step size, performing the following process each time it slides; According to the data feature type of the target behavior data in the target window, the target behavior data is subjected to feature value conversion, and the feature values corresponding to the converted target behavior data are combined to obtain a fused feature vector; Performing abnormal feature analysis on the fused feature vector to determine a first detection result of the target behavior data; If it is determined based on the first detection result that the target behavior data is abnormal, performing feature reconstruction analysis on the fused feature vector to determine a second detection result of the target behavior data; Determining a final result of the target behavior data based on the first detection result and the second detection result; Based on the final result of the target behavior data corresponding to each target window, it is determined whether the node in the target cluster has a container of the attack virus.
2. The method according to claim 1, wherein The data feature types of the target behavior data include continuous numerical features and Boolean logic features; The step of performing feature value conversion on the target behavior data according to the data feature type of the target behavior data in the target window, and combining the feature values corresponding to the converted target behavior data to obtain a fused feature vector includes: Performing a first eigenvalue conversion on the behavior data corresponding to the continuous numerical feature in the target behavior data using a Z-score normalization method to generate a first eigenvalue; Performing a second eigenvalue conversion on the behavior data corresponding to the Boolean logic feature in the target behavior data using Boolean feature binary coding to generate a second eigenvalue; Each first eigenvalue and each second eigenvalue are combined to generate the fused eigenvector.
3. The method according to claim 1, wherein The performing abnormal feature analysis on the fused feature vector to determine the first detection result of the target behavior data includes: Inputting the fused feature vector into a pre-trained isolation forest model, and determining the path length of the fused feature vector from the root node to the leaf node in each decision tree based on the number of decision trees in the isolation forest model; Determining a first detection score of the fused feature vector based on an average of the path lengths of the fused feature vector in each decision tree; wherein the first detection score is used to represent a degree of deviation of the target behavior data corresponding to the fused feature vector from the normal behavior data; The first detection result is determined based on the first detection score and a preset first score threshold.
4. The method according to claim 1, wherein The determining a final result of the target behavior data based on the first detection result and the second detection result includes: multiplying a first test score in the first test result by a first weight corresponding to the first test result to determine a first weighted score; multiplying a ratio between a reconstruction error in the second detection result and a preset reconstruction error by a second weight corresponding to the second detection result to determine a second weighted score; Determining a second detection score of the target behavior data by summing the first weighted score and the second weighted score; Based on the second detection score and a preset second score threshold, a final result of the target behavior data is determined.
5. The method according to claim 4, wherein The determining of the final result of the target behavior data based on the second detection score and a preset second score threshold includes: If the second detection score is higher than the preset second score threshold, determining that the target behavior data is abnormal; If the second detection score is not higher than the preset second score threshold, it is determined that the target behavior data is normal.
6. The method according to any one of claims 1 to 5, wherein: After collecting the multi-dimensional behavior data of each container running on the node, and before sliding the target window on the behavior data according to the preset step size, the method further includes: grouping the behavior data according to the container identifier carried by the behavior data; Sliding the target window on the behavior data according to the preset step size includes: Slide the target window on the behavior data corresponding to any container according to the preset step size; The determining, based on the final result of the target behavior data corresponding to each target window, whether the node in the target cluster has a container of the attack virus includes: If the final result of the target behavior data corresponding to any target window is abnormal, it is determined that the any one container is a container in which an attack virus exists in the node.
7. The method according to claim 6, wherein After determining that any one of the containers is a container containing an attack virus in the node, the method further includes: Determining a target scoring level based on the second detection score corresponding to the abnormal target behavior data and the scoring interval corresponding to the scoring level; According to the response strategy corresponding to the target scoring level, a corresponding isolation treatment is performed on the any one container.
8. An attack virus detection device, characterized in that: The device comprises: A collection module is used to collect multi-dimensional behavior data of each container running on each node of the target cluster. The behavior data includes resource utilization data used to characterize each container at runtime, as well as interaction data between containers or operational behavior data of each container control plane; The detection module is used to slide the target window on the behavior data according to a preset step size, and perform the following process each time it slides; According to the data feature type of the target behavior data in the target window, the target behavior data is subjected to feature value conversion, and the feature values corresponding to the converted target behavior data are combined to obtain a fused feature vector; Performing abnormal feature analysis on the fused feature vector to determine a first detection result of the target behavior data; If it is determined based on the first detection result that the target behavior data is abnormal, performing feature reconstruction analysis on the fused feature vector to determine a second detection result of the target behavior data; Determining a final result of the target behavior data based on the first detection result and the second detection result; The determination module is configured to determine whether a container of an attack virus exists on the node in the target cluster based on a final result of the target behavior data corresponding to each target window.
9. An electronic device, characterized in that: include: at least one processor, and a memory communicatively coupled to the at least one processor, wherein: The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: When the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can perform the method according to any one of claims 1 to 7.