Method for detecting intrusion in a container environment, device for detecting intrusion in a container environment, electronic device, computer-readable storage medium, and computer program product

By employing an event identification model to filter normal events in container environments, the method improves intrusion detection efficiency and performance by reducing resource usage and accelerating detection, focusing on suspicious events with pre-configured rules.

JP2025530695AActive Publication Date: 2025-09-17BEIJING VOLCANO ENGINE TECH CO LTD
View PDF -1 Cites 0 Cited by

Patent Information

Application Number
JP2025510382
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-06-30
Filing Date
2024-06-24
Publication Date
2025-09-17
Estimated Expiration
2044-06-24

AI Technical Summary

Technical Problem

Traditional intrusion detection methods in container environments suffer from increased memory and CPU occupancy as the number of detection rule sets grow, leading to reduced performance and efficiency.

Method used

An intrusion detection method that utilizes an event identification model based on historical normal system events of a target container to filter out normal system events, followed by intrusion detection on suspicious events using pre-configured rules, thereby reducing resource occupation and improving efficiency.

Benefits of technology

This approach significantly reduces resource usage, enhances detection performance, and accelerates intrusion detection by filtering out 99.99% of normal events, ensuring timely and efficient detection of potential intrusions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025530695000001_ABST
    Figure 2025530695000001_ABST
Patent Text Reader

Abstract

An embodiment of the present disclosure provides a method, device, and storage medium for intrusion detection in a container environment, which invokes an event identification model corresponding to a target container to perform event identification on real-time system events, the event identification model being constructed based on the historical normal system events of the target container, and if it is determined that the real-time system events are not normal system events, invokes pre-configured intrusion detection rules to perform intrusion detection on the real-time system events and determine whether the real-time system events are intrusion events. Utilizing the unity and stability characteristics of the container, an event identification model corresponding to the target container is constructed based on the historical normal system events of the target container, and can accurately identify whether the real-time system events are normal system events based on the event identification model. Furthermore, real-time system events belonging to normal system events are filtered, and full intrusion detection is performed on the unfiltered real-time system events, thereby reducing the amount of intrusion detection data, reducing resource occupation, and improving intrusion detection performance and efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application claims priority from a Chinese patent application entitled "Method, Apparatus and Storage Medium for Detecting Intrusion in a Container Environment" filed on June 30, 2023, bearing application number 2023107988073, the entire contents of which are incorporated herein by reference.

[0002] TECHNICAL FIELD The present disclosure relates to the field of computer and network communication technology, and more particularly to a method, apparatus, and storage medium for detecting intrusions in a container environment. [Background technology]

[0003] Intrusion detection is an important core technology for terminal security products, and it is equally important for containerized environments to detect and block malicious network intrusions in a timely manner, ensuring the security of the containerized environment.

[0004] Traditional intrusion detection methods usually perform detection based on a detection rule set, and as the number of detection rule sets increases, the intrusion detection process linearly increases the memory and CPU occupancy, reducing the intrusion detection performance and efficiency. Summary of the Invention [Problem to be solved by the invention]

[0005] SUMMARY OF THE INVENTION Embodiments of the present disclosure provide a method, apparatus, and storage medium for intrusion detection in a container environment to improve the performance and efficiency of intrusion detection in a container environment. [Means for solving the problem]

[0006] According to a first aspect, an embodiment of the present disclosure provides an intrusion detection method for a container environment, the method including: for a real-time system event of a target container, invoking an event identification model corresponding to the target container to perform event identification on the real-time system event, the event identification model being a model constructed based on historical normal system events of the target container and being used to identify whether the real-time system event in the target container belongs to a normal system event; and if it is determined that the real-time system event is not a normal system event, invoking a pre-configured intrusion detection rule to perform intrusion detection on the real-time system event to determine whether the real-time system event is an intrusion event.

[0007] According to a second aspect, an embodiment of the present disclosure provides an intrusion detection device for a container environment, the device including: an identification unit for, for a real-time system event of a target container, calling an event identification model corresponding to the target container to perform event identification on the real-time system event, the event identification model being a model constructed based on historical normal system events of the target container and being used to identify whether the real-time system event in the target container belongs to a normal system event; and an intrusion detection unit for, if it is determined that the real-time system event is not a normal system event, calling a preset intrusion detection rule to perform intrusion detection on the real-time system event, and determining whether the real-time system event is an intrusion event.

[0008] According to a third aspect, an embodiment of the present disclosure provides an electronic device, comprising at least one processor and a memory, wherein the memory stores computer-executable instructions, and the at least one processor executes the computer-executable instructions stored in the memory, thereby causing the at least one processor to perform the intrusion detection method for a container environment described in the first aspect and various possible designs of the first aspect.

[0009] According to a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having stored thereon computer-executable instructions, which, when executed by a processor, implements the intrusion detection method for a container environment as set forth in the first aspect above and various possible designs of the first aspect.

[0010] According to a fifth aspect, an embodiment of the present disclosure provides a computer program product including computer-executable instructions that, when executed by a processor, implements the intrusion detection method for a container environment as set forth in the first aspect above and various possible designs of the first aspect. [Brief explanation of the drawings]

[0011] In order to more clearly describe the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings that need to be used in the description of the embodiments or the prior art. It is obvious that the drawings in the following description are some embodiments of the present disclosure, and those skilled in the art can also obtain other drawings based on these drawings without any creative labor.

[0012] [Figure 1] 1 is a flowchart of an intrusion detection method for a container environment according to an embodiment of the present disclosure. [Figure 2] 10 is a flowchart of an intrusion detection method for a container environment according to another embodiment of the present disclosure. [Figure 3] 10 is a flowchart of an intrusion detection method for a container environment according to another embodiment of the present disclosure. [Figure 4]10 is a flowchart of a feature extraction process according to another embodiment of the present disclosure. [Figure 5] 10 is a flowchart of an intrusion detection method for a container environment according to another embodiment of the present disclosure. [Figure 6] 10 is a flowchart of a training process according to another embodiment of the present disclosure. [Figure 7] FIG. 1 is a structural block diagram of an intrusion detection device for a container environment according to an embodiment of the present disclosure. [Figure 8] FIG. 1 is a schematic diagram illustrating a hardware structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0013] In order to clarify the objectives, technical solutions and advantages of the embodiments of the present disclosure, the technical solutions of the embodiments of the present disclosure will be described below clearly and completely with reference to the drawings in the embodiments of the present disclosure, and it is obvious that the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments that can be obtained by a person skilled in the art without creative labor also fall within the scope of protection of the present disclosure.

[0014] First, technical terms related to the present disclosure will be explained.

[0015] Container: A container is an operating system layer virtualization technology with a lightweight kernel that can form an isolated operating system space and run specific services.

[0016] System behavior events: In terminal security products, system behavior events collected by security probe technology, such as process execution events, file read / write events, and network connection events.

[0017] Intrusion detection: Detects whether hackers are attempting to hack into the application service while it is running.

[0018] ML algorithm: An abbreviation for Machine Learning, a machine learning algorithm.

[0019] Isolation Forest Algorithm: Isolation Forest is a fast out-point detection method with linear time complexity and high accuracy, and is used in network security attack detection, financial transaction fraud detection, disease detection, and noise data filtering.

[0020] Conventional intrusion detection methods typically perform detection based on a detection rule set. As the number of detection rule sets increases, the intrusion detection process linearly increases memory and CPU usage, reducing intrusion detection performance and efficiency. Therefore, as long as the intrusion detection effectiveness (false alarm rate and missed alarm rate) is not lost, how to improve intrusion detection performance and efficiency and reduce system resource usage dependency is a very important indicator of intrusion detection engine performance.

[0021] To accelerate intrusion detection and improve detection efficiency, a method can be adopted in which: 1) a small number of strong rule sets are used in part, and intrusion detection is performed based on the strong rule sets. If there is no match, it is simply determined to be a normal event and not all rules are executed. This method has several disadvantages. (2) There is a possibility of increasing the calculation performance of the detection engine. This method is generally achieved by hard coding or by increasing the system resource allocation of the detection engine. The disadvantages are poor program scalability and high resource usage. (3) The number of collected events is reduced and processed using an event compression method. The disadvantage of this method is that data may be distorted, which may lead to missed or false alarms.

[0022] Therefore, the above method mainly improves and optimizes the problem itself, but at the same time introduces several new problems and does not solve the computational efficiency problem from the root source. In actual applications, the probability of intrusion events occurring is relatively low, and the flow rate of normal events in the system is generally above 99.99%. All of these normal events require a complete set of intrusion detection rules to detect, which is extremely performance-intensive and may result in false positives, putting pressure on safety operations. Therefore, to ensure safety, a lightweight approach is needed to solve the above problem, which is a highly efficient and safe solution concept.

[0023] In container workloads, a single container typically represents a single microservice and therefore has only one service capability. This allows containers to be unified, stable, and resistant to change. The process, file, and network behavior of a running container is relatively unified and consistent. For example, a MySQL container's normal system behavior typically involves reading and writing data files in a specific directory and accessing port 3306, which is opened by a specific application IP. An Nginx container's normal system behavior, i.e., accessing port 80 or 443 via an external IP and proxying network traffic, typically does not involve executing system commands or writing files. Authorization and authentication service containers typically do not have API interfaces to access databases or specific subsystem modules, and do not involve externally connected blacklisted IPs or executing system commands. Therefore, in container application scenarios, containerized services have better data purity of system events generated by containers than services deployed on virtual machines, a difference brought about by the unified and stable characteristics of containers. Based on the characteristics of container unity and stability, the present disclosure can know that the parameter length and feature information of the normal system events of the container have a certain regularity, so that an event identification model corresponding to the target container can be constructed based on the historical normal system events of the target container, and based on the event identification model, it can accurately identify whether a real-time system event is a normal system event, and further, by filtering the real-time system events that belong to the normal system events and performing complete intrusion detection on the unfiltered real-time system events, the amount of intrusion detection data can be reduced, resource occupation can be reduced, the performance and efficiency of intrusion detection can be improved, and intrusion detection can be accelerated.

[0024] Specifically, as shown in FIG. 1, in the present disclosure, feature extraction is performed on the real-time system event of the target container, target feature information is obtained, detection is performed based on an event identification model, and it is determined whether the parameter length and target feature information of the real-time system event deviate from those of a normal system event. Based on the determination result, it is determined whether the real-time system event is a suspicious event. If it is determined that the real-time system event is a normal system event, there is no need to perform subsequent intrusion detection. If it is determined that the real-time system event is a suspicious event, a preset intrusion detection rule is invoked to perform intrusion detection on the real-time system event, and it is determined whether the real-time system event is an intrusion event.

[0025] Optionally, the event identification model includes a first event identification model and a second event identification model, where the first event identification model is constructed based on the parameter length of the historical normal system event of the target container, and the second event identification model is constructed based on the feature information of the historical normal system event of the target container, so that the first event identification model and the second event identification model can be used to determine whether the parameter length and target feature information of the real-time system event deviate from the normal system event. Furthermore, the real-time system event belonging to the normal system event filtered by the model detection process and the real-time system event that is not an intrusion event by the intrusion detection process can be determined and added to the historical normal system event. By repeatedly training the first event identification model and the second event identification model, the model can achieve self-adaptation and improve the robustness of the system.

[0026] The intrusion detection method for a container environment of the present disclosure will be described in detail below with reference to specific embodiments.

[0027] 2, which is a flowchart of an intrusion detection method for a container environment according to an embodiment of the present disclosure. The method of this embodiment can be applied to a terminal device or a server, and the intrusion detection method for a container environment includes:

[0028] S201: For a real-time system event of a target container, an event identification model corresponding to the target container is called to perform event identification on the real-time system event, and the event identification model is a model constructed based on the historical normal system events of the target container, and is used to identify whether the real-time system event in the target container belongs to a normal system event.

[0029] In this embodiment, by utilizing the characteristics of container unity and stability, the normal events of the target container have certain rules, so that an event identification model can be established in advance based on the historical normal events of the target container. The event identification model can be used to identify whether any system event of the target container belongs to a normal system event. In this embodiment, the normal system event matching model is not limited to a model, such as a machine learning model that can arbitrarily realize the above function.

[0030] In practical applications, the real-time system events of the target container are acquired in real time, and the event identification model corresponding to the target container is called to perform event identification on the real-time system events, and determine whether the real-time system events are normal system events.

[0031] S202, if it is determined that the real-time system event is not a normal system event, invoke a preset intrusion detection rule to perform intrusion detection on the real-time system event, and determine whether the real-time system event is an intrusion event.

[0032] In this embodiment, after real-time system events are identified using the event identification model, if the real-time system event is determined to be a normal system event, a preset intrusion detection rule is invoked to perform intrusion detection on the real-time system event, thereby achieving the purpose of filtering the real-time system event. If the real-time system event cannot be determined to be a normal system event, if the real-time system event is a suspicious event, a preset intrusion detection rule is invoked to perform intrusion detection on the real-time system event, thereby more accurately determining whether the real-time system event is an intrusion event. Filtering normal system events reduces resource occupation, improves intrusion detection performance and efficiency, and realizes accelerated intrusion detection. Normally, the probability of an intrusion event occurring is relatively low. Through the above process, 99.99% of normal system events can be filtered from real-time system events, and the remaining 0.01% of suspicious events can be subjected to intrusion detection using the full amount of preset intrusion detection rules, thereby solving the problem of solving detection efficiency from data source headers and realizing accelerated intrusion detection.

[0033] Additionally, if a real-time system event is determined to be an intrusion event, an alert can be generated.

[0034] In an intrusion detection method for a container environment according to an embodiment, for a real-time system event of a target container, an event identification model corresponding to the target container is invoked to perform event identification on the real-time system event. The event identification model is a model constructed based on the historical normal system events of the target container and is used to identify whether the real-time system event of the target container belongs to a normal system event. If it is determined that the real-time system event is not a normal system event, a pre-configured intrusion detection rule is invoked to perform intrusion detection on the real-time system event to determine whether the real-time system event is an intrusion event. The embodiment of the present disclosure utilizes the characteristics of unity and stability of containers to construct an event identification model corresponding to the target container based on the historical normal system events of the target container, and can accurately identify whether the real-time system event is a normal system event based on the event identification model. Furthermore, real-time system events that belong to normal system events are filtered, and full intrusion detection is performed on the unfiltered real-time system events, thereby reducing the amount of intrusion detection data, reducing resource occupation, improving intrusion detection performance and efficiency, and realizing faster intrusion detection.

[0035] 3, which is a flowchart of an intrusion detection method for a container environment according to an embodiment of the present disclosure. Based on the above embodiment, the intrusion detection method for a container environment includes:

[0036] S301, feature extraction is performed on the real-time system events of the target container to obtain target feature information.

[0037] In this embodiment, multiple different types of system events can be collected in the target container, including but not limited to process execution events, file read / write events, network access events, and system capability call events. Normally, these events exhibit unity and periodicity in a single container. Any type of system event can be collected in real time and be considered as the real-time system event in this embodiment.

[0038] Alternatively, in practical applications, a process execution event is the most important system event, and other events, such as file read / write events and network access events, are triggered by the process execution event. Therefore, if a process execution event is determined to be a normal system event, other system call events triggered by the process execution event, such as file read / write events and network access events, are also likely to be normal system events. Therefore, in this embodiment, the real-time system event is preferably a process execution event, but it goes without saying that other system events may also be selected.

[0039] The real-time system event data can be collected in the target container execution process, specifically, by security probe technology on the server. The process execution event data mainly includes: Process name: curl Process bin (binary file): / bin / curl Parent process name: java Parent process bin: e.g. / bin / java Command line: curl http: / / aaaa.bbb.ccc Process parameters: http: / / dddd.eee.fff

[0040] Furthermore, feature extraction can be performed on the real-time system events to obtain target feature information, where the target feature information may be attribute information of the real-time system events, such as, for example, for a process execution event, the target feature information may include, but is not limited to, attribute information such as the process name, parent process name, standard input type, standard output type, parameter type, and parameter format included in the data.

[0041] Optionally, based on the characteristics of the attribute information, the attribute information included in the data of the real-time system event can be divided into two types: first type attribute information and second type attribute information.

[0042] Here, the first type of attribute information is a strong characteristic attribute, which has a fixed amount of information and a fixed mode, such as process name, process bin, parent process name, parent process bin, standard input type, and standard output type. Such strong characteristic attributes are highly reliable, and each type of attribute information has one or more candidate items, i.e., a fixed amount of information and a fixed mode (e.g., fixed format, fixed type, fixed quantity, etc.), and mismatching may not be allowed. If a mismatch occurs, a process execution event indicating an abnormality is identified. For example, the attribute information of process name has several fixed candidate process names, each of which represents one process. The process names of the same process are fixed, i.e., have a fixed mode. Therefore, when the attribute information of process name has a fixed amount of information and a fixed mode, and the process name of a certain process execution event does not match any of the candidate process names, the process execution event is an abnormal process execution event. The second type attribute information is a weak feature attribute, and its reliability is lower than that of the first type attribute information. The second type attribute information contains a large amount of information, the amount of information may not be constant, and the mode is not fixed. Therefore, it may not be usable without performing data transformation to extract features. For example, the type, format, and quantity of process parameters for different instructions are all different, and the process parameters for the same instruction are also different. Therefore, the second type attribute information needs to undergo data transformation (also called generalization) to derive stable feature dimensions.

[0043] Here, the conversion of the second type attribute information may be realized by feature extraction, and the extracted features may include, but are not limited to, the following dimensions: a) Whether it is a digital type or not. b) Whether it is a word type or not. c) Whether it is a script type or not. d) Whether or not a URL (Uniform Resource Locator) exists. e) Presence or absence of IP address. f) Presence or absence of UUID (Universally Unique Identifier). g) Other types.

[0044] The feature identification of the dimensional data can be analyzed by a known algorithm or regular expression, and the description thereof will be omitted here.

[0045] Therefore, as shown in FIG. 4, in this embodiment, the first type attribute information and the second type attribute information in the data of the real-time system event are obtained, a conversion process is performed on the second type attribute information to obtain derived attribute information, and the first type attribute information and the derived attribute information are further merged to obtain target feature information.

[0046] The target feature information of the process execution event is as follows: [Table 1]

[0047] S302: Call an event identification model corresponding to the target container, determine whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and perform event identification on the real-time system event based on the determination result.

[0048] In this embodiment, an event identification model is first constructed based on the historical normal system events of the target container, and the parameter length information and target feature information of the normal system events of the target container are learned and summarized in the event identification model. The event identification model may be a machine learning model or other model that can arbitrarily achieve the above-mentioned learning purpose.

[0049] Furthermore, for any real-time system event, the event identification model determines whether the parameter length and target feature information of the real-time system event deviate from those of a normal system event based on the target feature information of the real-time system event. If so, the real-time system event is determined to be a suspicious event; if not, the real-time system event is determined to be a normal system event. By utilizing the characteristics of container unity and stability, the parameter length and target feature information can be combined to reduce oversights and erroneous determinations. Here, this embodiment does not limit how the event identification model learns and summarizes the parameter length information and target feature information of normal events, and this embodiment also does not limit the model used in the event identification model. The above function may be realized by one model or by two or more models.

[0050] S303, if it is determined that the real-time system event is not a normal system event, invoke a pre-defined intrusion detection rule to perform intrusion detection on the real-time system event, and determine whether the real-time system event is an intrusion event.

[0051] The explanation of S202 above will be omitted here.

[0052] This embodiment utilizes the characteristics of container unity and stability to determine whether a real-time system event deviates from a normal system event from two aspects: the parameter length of the real-time system event and the target characteristic information, thereby filtering out real-time system events that do not deviate from normal system events with high accuracy, and performing complete intrusion detection for real-time system events that deviate from normal system events, thereby reducing the amount of intrusion detection data, reducing resource occupation, improving intrusion detection performance and efficiency, and realizing acceleration of intrusion detection.

[0053] Based on any of the above embodiments, in order to improve the effectiveness of the model and reduce the oversight rate and false positive rate, the event identification model is realized by adopting a dual-engine model, and includes a first event identification model and a second event identification model, wherein the first event identification model is a model constructed based on the parameter length of the historical normal system events of the target container and determines whether the parameter length of the real-time system events does not meet the parameter length of the normal system events, and the second event identification model is a model constructed based on the characteristic information of the historical normal system events of the target container and determines whether the target characteristic information of the real-time system events deviates from the characteristic information of the normal system events.

[0054] Therefore, as shown in Figure 5, the overall flow of the intrusion detection method for a container environment according to this embodiment is as follows: after the first event identification model and the second event identification model are judged, if the first event identification model determines that the parameter length of the real-time system event satisfies the parameter length of the normal system event and the second event identification model determines that the target feature information of the real-time system event does not deviate from the feature information of the normal system event, the real-time system event is determined to be a normal system event; if the first event identification model determines that the parameter length of the real-time system event does not satisfy the parameter length of the normal system event and / or the second event identification model determines that the target feature information of the real-time system event deviates from the feature information of the normal system event, the real-time system event is determined to be not a normal system event and is determined to be a suspicious event.

[0055] Furthermore, calling an event identification model corresponding to the target container, determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result, inputting the target feature information and the parameter length of the real-time system event into the first event identification model to determine whether the parameter length of the real-time system event does not meet the parameter length of a normal system event; inputting the target feature information into the second event identification model, and determining whether the target feature information deviates from feature information of normal system events.

[0056] More specifically, the first event identification model pre-learns and summarizes the parameter length rules of historical normal system events to obtain a pre-defined mapping relationship, which is a mapping relationship between keywords corresponding to normal system events and corresponding parameter length information, and can be stored using a key-value structure. The keyword Key is a keyword constructed based on the feature information of the historical normal system event, and the Value is the parameter length information of the historical normal system event. For example, the feature information of a certain historical normal system event is as follows: [Table 2]

[0057] A keyword Key is constructed based on the feature information of the historical normal system event. For example, each dimension of the feature information is overlapped and combined to obtain curl& / bin / curl&java& / bin / java&1&1&0&1&1&0, and Value is the average value and standard deviation, or minimum and maximum value, of the parameter length of the historical normal system event with the same Key. Taking the average value and standard deviation as an example, the preset mapping relationship is as follows: [Table 3]

[0058] For a real-time system event, a target keyword is constructed based on its target feature information, and a search is performed in a preset mapping relationship. By searching for a keyword identical to the target keyword in the preset mapping relationship, parameter length information of a normal system event corresponding to the keyword can be obtained. Furthermore, based on the parameter length X of the real-time system event and the parameter length information of the normal system event corresponding to the keyword, it is determined whether the parameter length X of the real-time system event does not meet the parameter length of the normal system event. For example, when the parameter length information of the normal system event has an average value u and a standard deviation σ, it can be calculated whether the parameter length X of the real-time system event meets the reliability threshold setting. Based on Chebyshev's inequality theorem, the reliability threshold calculation can be simplified as y=u±N*σ (u is the mean value, σ is the standard deviation, and N is the tolerance), i.e., the threshold interval is N times the standard deviation σ of the mean value u. If the parameter length X of the real-time system event is within the threshold interval, the real-time system event is considered to match the first event identification model, i.e., the parameter length of the real-time system event meets the parameter length of the normal system event; if not, it is determined that the real-time system event deviates from the first event identification model, i.e., it is determined that the parameter length of the real-time system event does not meet the parameter length of the normal system event.

[0059] If the parameter length information of the normal system event is a maximum value and a minimum value, the threshold interval is directly determined based on the maximum value and the minimum value. If the parameter length X of the real-time system event is within the threshold interval, the real-time system event is considered to match the first event identification model, i.e., the parameter length of the real-time system event satisfies the parameter length of the normal system event. Otherwise, it is determined that the real-time system event deviates from the first event identification model, i.e., the parameter length of the real-time system event does not satisfy the parameter length of the normal system event.

[0060] In addition, if the same keyword as the target keyword is not found in the pre-set mapping relationship, it is determined that the real-time system event deviates from the first event identification model, and in particular, the target keyword of the real-time system event deviates from the keyword of the normal system event, and the deviation between the target feature information of the real-time system event and the feature information of the normal system event is also explained.

[0061] In any of the above embodiments, since the second event identification model is used to determine whether the target feature information of a real-time system event deviates from the feature information of a normal system event, the second event identification model may be an out point judgment model, and the target feature information is input into the second event identification model, and it is determined whether the feature information corresponding to the target feature information is an out point, and if it is determined that the target feature information is an out point, it is determined that the target feature information is feature information that deviates from the normal system event.

[0062] Alternatively, the out point determination model used in the second event identification model may be an Isolation Forest model, which divides data using a binary tree and determines the depth of a data point in the binary tree in response to the degree of "separation" of the data, with the shallower the depth, the more likely the data point is an out point. In this embodiment, the second event identification model includes a binary tree structure in which a feature matrix of normal system events is constructed. The second event identification model further constructs a matrix based on target feature information of real-time system events, obtains the target feature matrix, matches the target feature matrix with the Isolation Forest model, and determines the depth of the target feature matrix in the binary tree to determine whether the target feature matrix is ​​an out point. When constructing a matrix based on target feature information of real-time system events, non-numeric feature information in the target feature information can be converted to a numeric type, for example, using a LabelEncoder or a one-hot algorithm, but this is not limited thereto.

[0063] Based on any of the above embodiments, the above first event identification model is obtained by the following steps:

[0064] S401, obtaining a plurality of historical normal system events of the target container;

[0065] S402: extracting features from each of the plurality of historical normal system events to obtain historical feature information corresponding to each of the historical normal system events.

[0066] S403, obtaining parameter length information of normal system events according to history feature information corresponding to the plurality of history normal system events and parameters of the plurality of history normal system events, and obtaining the first event identification model.

[0067] In this embodiment, multiple historical normal system events of the target container can be collected, for example, normal system events that occurred in a past period (for example, one or two days), and the feature extraction process and S201 are performed for each of the multiple historical normal system events. Furthermore, based on the historical feature information corresponding to the multiple historical normal system events and the parameters of the multiple historical normal system events, the parameter length information of the normal system events is learned, and a first event identification model is constructed.

[0068] Specifically, the parameter length information of the normal system event in the first event identification model includes a preset mapping relationship, and the preset mapping relationship is a mapping relationship between the keyword corresponding to the normal system event and the corresponding parameter length information. Therefore, the preset mapping relationship can be constructed based on the historical feature information corresponding to multiple historical normal system events and the parameters of multiple historical normal system events, and the process is as follows:

[0069] A corresponding keyword is constructed based on the historical feature information corresponding to each historical normal system event, and the keyword construction process can refer to the above embodiment.

[0070] The plurality of historical normal system events are grouped based on keywords to obtain a plurality of groups, and the historical normal system events in each group have the same keyword. Furthermore, parameters of each historical normal system event with the same keyword are obtained. Corresponding parameter length information, such as the average value and standard deviation, or the minimum and maximum values, of the parameter lengths of the historical normal system events with the same keyword are obtained based on the parameters of the historical normal system events with the same keyword. Next, a mapping relationship between each keyword and the corresponding parameter length information is established to obtain a preset mapping relationship, and the parameter length information of the normal system event can be stored using a key-value, where the key is the keyword and the value is the corresponding parameter length information.

[0071] Based on any of the above embodiments, the above second event identification model can be obtained by the following steps:

[0072] S501, obtaining a plurality of historical normal system events of the target container;

[0073] S502, extracting features from each of the historical normal system events to obtain historical feature information corresponding to each of the historical normal system events.

[0074] S503, performing unsupervised learning on the historical feature information corresponding to the plurality of historical normal system events to obtain the second event identification model.

[0075] In this embodiment, the multiple historical normal system events may be the same historical normal system event in S401, or may be different historical normal system events. The feature extraction process and the above S301 are performed for each of the multiple historical normal system events. If the multiple historical normal system events are the same historical normal system event in S401, the multiple historical normal system events of the target container are obtained. There is no need to perform feature extraction for each historical normal system event, and there is no need to perform it again, as shown in Figure 6.

[0076] After obtaining the historical feature information corresponding to the multiple historical normal system events, unsupervised learning can be performed based on the historical feature information corresponding to the multiple historical normal system events to obtain a second event identification model. The specific learning process can be distinguished using different out point determination models based on the second event identification model, and is not limited thereto.

[0077] When the second event identification model is an Isolation Forest model, the specific steps of unsupervised learning include:

[0078] A matrix is ​​constructed for the historical feature information corresponding to each of the historical normal system events, and the feature matrix for each of the historical normal system events is obtained. When constructing the matrix, non-numeric feature information in the historical feature information can be converted to numeric type, for example, by using a LabelEncoder or a one-hot algorithm, but this is not limited thereto. Furthermore, unsupervised learning of an Isolation Forest model can be performed based on the feature matrices of multiple historical normal system events. Here, a detailed description of the learning process of the Isolation Forest model is omitted here.

[0079] The first and second event identification models in the above embodiment are trained using multiple historical normal system events of the target container, utilizing the unity and stability characteristics of the container. The two models are also specific to the target container, and the two models are used to detect real-time system events of the target container, which effectively improves the accuracy of normal system event filtering, improves detection efficiency, and at the same time reduces the risks of oversight and false positives.

[0080] Based on any of the above embodiments, the real-time system events belonging to the normal system events filtered in steps S201 and S302, and step S303 can identify real-time system events that are not intrusion events and join them to historical normal system events, and by repeatedly training the first event identification model and the second event identification model, the models can achieve self-adaptation and improve the robustness of the system.

[0081] 7 is a structural block diagram of an intrusion detection device for a container environment according to an embodiment of the present disclosure. For convenience of explanation, only parts related to the embodiment of the present disclosure are shown. Referring to FIG. 7, the intrusion detection device for a container environment 600 includes an identification unit 601 and an intrusion detection unit 602.

[0082] Here, for a real-time system event of a target container, the identification unit 601 calls an event identification model corresponding to the target container to perform event identification on the real-time system event, and the event identification model is a model constructed based on the historical normal system events of the target container, and is used to identify whether the real-time system event in the target container belongs to a normal system event.

[0083] If the intrusion detection unit 602 determines that the real-time system event is not a normal system event, it invokes a pre-configured intrusion detection rule to perform intrusion detection on the real-time system event and determine whether the real-time system event is an intrusion event.

[0084] In one or more embodiments of the present disclosure, the container environment intrusion detection device 600 further includes a feature extraction unit 603 for performing feature extraction on the real-time system events to obtain target feature information.

[0085] The identification unit 601 is specifically configured to call an event identification model corresponding to the target container, determine whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and perform event identification on the real-time system event based on the determination result.

[0086] In one or more embodiments of the present disclosure, the event identification model includes a first event identification model and a second event identification model, where the first event identification model is constructed based on parameter lengths of historical normal system events of the target container, and the second event identification model is constructed based on feature information of historical normal system events of the target container.

[0087] In one or more embodiments of the present disclosure, when invoking an event identification model corresponding to the target container, determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and performing event identification for the real-time system event based on the determination result, the identification unit 601: inputting the target feature information and the parameter length of the real-time system event into the first event identification model to determine whether the parameter length of the real-time system event does not satisfy the parameter length of a normal system event; The target feature information is input to the second event identification model to determine whether the target feature information deviates from feature information of normal system events.

[0088] In one or more embodiments of the present disclosure, a preset mapping relationship is set in the first event identification model, and the preset mapping relationship is a mapping relationship between keywords corresponding to normal system events of the target container and corresponding parameter length information, and the keywords corresponding to the normal system events are constructed based on feature information of the normal system events.

[0089] The target feature information and the parameter length of the real-time system event are input into the first event identification model to determine whether the parameter length of the real-time system event does not meet the parameter length of the normal system event, the identification unit 601: constructing a target keyword based on the target feature information; Performing a search in a pre-defined mapping relationship based on the target keyword; If a keyword identical to the target keyword is found in the preset mapping relationship, parameter length information of a normal system event corresponding to the keyword is obtained; Determine whether the parameter length of the real-time system event does not meet the parameter length of the normal system event based on the parameter length information of the real-time system event and the parameter length information of the normal system event; If the keyword same as the target keyword is not found in the preset mapping relationship, it is determined that the target feature information is out of the normal system event.

[0090] In one or more embodiments of the present disclosure, the second event identification model is an out-point determination model. Accordingly, when the target feature information is input into the second event identification model to determine whether the target feature information deviates from the feature information of a normal system event, the identification unit 601: inputting the target feature information into the second event identification model, and determining whether the target feature information is an out point for feature information corresponding to a normal system event; If it is determined that the target feature information is an out point, it is determined that the target feature information is feature information that deviates from a normal systematic event.

[0091] In one or more embodiments of the present disclosure, the second event identification model is an isolation forest model constructed based on historical normal system events. Accordingly, when inputting the target feature information into the second event identification model and determining whether the target feature information is an out point for feature information corresponding to the historical normal system events, the identification unit 601: Construct a matrix based on the target feature information to obtain a target feature matrix; The target feature matrix is ​​matched with the Isolation Forest model to determine whether the target feature matrix is ​​an out point.

[0092] In one or more embodiments of the present disclosure, when performing feature extraction on the real-time system events of the target container to obtain target feature information, the feature extraction unit 603: Obtain first type attribute information and second type attribute information in the real-time system event data, where the first type attribute information is attribute information having a fixed amount of information and a fixed mode, and the second type attribute information is attribute information whose amount of information or mode is not fixed. performing a conversion process on the second type attribute information to obtain derived attribute information; The first type attribute information and the derived attribute information are merged to obtain the target feature information.

[0093] In one or more embodiments of the present disclosure, the device further includes a training unit that performs a training process on the first event identification model, and the training process is as follows. obtaining a plurality of historical normal lineage events for the target container; Performing feature extraction on each of the plurality of historical normal system events to obtain historical feature information corresponding to each of the historical normal system events; Parameter length information of normal system events is obtained based on historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events, and the first event identification model is obtained.

[0094] In one or more embodiments of the present disclosure, when obtaining parameter length information of normal system events according to historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events to obtain the first event identification model, the training unit: constructing a corresponding keyword based on historical feature information corresponding to each of the historical normal system events; Grouping the plurality of historical normal system events according to a keyword, obtaining parameters of the historical normal system events with the same keyword, and obtaining corresponding parameter length information according to the parameters of the historical normal system events with the same keyword; establishing a mapping relationship between each keyword and corresponding parameter length information, and obtaining the preset mapping relationship as the parameter length information of the normal system event.

[0095] In one or more embodiments of the present disclosure, the training unit further performs a training process on the second event identification model, and the training process is as follows: obtaining a plurality of historical normal system events for the target container; Performing feature extraction on each of the historical normal system events to obtain historical feature information corresponding to each of the historical normal system events; Unsupervised learning is performed on historical feature information corresponding to the plurality of historical normal system events to obtain the second event identification model.

[0096] In one or more embodiments of the present disclosure, when the second event identification model is an isolation forest model constructed based on historical normal system events, the training unit performs unsupervised learning on historical feature information corresponding to the plurality of historical normal system events: constructing a matrix for historical feature information corresponding to each of the historical normal system events to obtain a feature matrix for each of the historical normal system events; An Isolation Forest model is trained unsupervised based on the feature matrices of the multiple historical normal system events.

[0097] The apparatus according to this embodiment may be configured to implement the technical solutions of the above method embodiments, and the realization principles and technical effects thereof are similar, so the description thereof will be omitted here.

[0098] FIG. 8 is a schematic diagram illustrating the configuration of an electronic device 900 suitable for implementing an embodiment of the present disclosure. The electronic device 700 may be a terminal device or a server. Here, the terminal device may include, but is not limited to, mobile devices such as mobile phones, laptops, digital broadcast receivers, personal digital assistants (PDAs), tablet PCs (Portable Android Devices, PADs), portable multimedia players (abbreviated as PMPs), and in-vehicle devices (e.g., in-vehicle navigation devices), as well as fixed devices such as digital TVs and desktop computers. The electronic device illustrated in FIG. 8 is merely an example and does not impose any limitations on the functionality and scope of use of the embodiment of the present disclosure.

[0099] 8, electronic device 700 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 701 that can execute various appropriate operations and processes based on programs stored in read only memory (abbreviated as ROM) 702 or programs loaded from a storage device 708 into random access memory (abbreviated as RAM) 703. RAM 703 also stores various programs and data necessary for the operation of electronic device 700. Processing unit 701, ROM 702, and RAM 703 are interconnected by a bus 704. An input / output (I / O) interface 705 is also connected to bus 704.

[0100] Typically, the following devices include an I / O interface 705: input devices 706 including, for example, a touch screen, touch pad, keyboard, mouse, camera, microphone, accelerometer, gyroscope, etc.; output devices 707 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 708 including, for example, a magnetic tape, hard disk, etc.; and communication devices 709. The communication devices 709 may allow the electronic device 700 to communicate wirelessly or via wires with other devices to exchange data. While FIG. 8 illustrates the electronic device 700 having various devices, it is not required that all devices be implemented or included. Alternatively, the electronic device may include more or fewer devices.

[0101] In particular, according to embodiments of the present disclosure, the processes described with reference to the flowcharts above may be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product including a computer program containing program code for performing the methods illustrated in the flowcharts. In such embodiments, the computer program may be downloaded and installed from a network via the communication device 709, installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, it performs the functions defined in the methods of the embodiments of the present disclosure.

[0102] It should be noted that the computer-readable medium described in this disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above. The computer-readable storage medium may be, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or any combination thereof. More specific examples of the computer-readable storage medium may include, but are not limited to, an electrical connection having one or more conductors, a portable computer magnetic disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this disclosure, the computer-readable storage medium may be any tangible medium containing a program, which may instruct the use of or be used in connection with a system, device, or apparatus. In this disclosure, the computer-readable signal medium may include a data signal propagating in baseband or as part of a carrier wave, with computer-readable program code embodied therein. Such a propagated data signal may take various forms, including, but not limited to, an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium, which can transmit, propagate, or transmit an instruction execution system, apparatus, or device, or a program used in conjunction therewith. Program code contained in a computer-readable medium may be transmitted using, but is not limited to, any suitable medium.

[0103] The computer-readable medium may be included in the electronic device, or may exist independently of the electronic device.

[0104] The computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to perform the methods illustrated in the above embodiments.

[0105] Computer program code for performing operations of the present disclosure can be written in one or more programming languages, or combinations thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and further including "C" or similar programming languages. The program code may run entirely on the user computer, partially on the user computer, as a separate software package, partially on the user computer or partially on a remote computer, or entirely on a remote computer or server. When referring to a remote computer, the remote computer may be connected to the user computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet Service Provider).

[0106] The flowcharts and block diagrams in the figures illustrate possible system architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, block, or portion of code that includes one or more executable instructions for implementing a predetermined logical function. It should be noted that the functions described in the blocks may alternatively occur in an order different from that described in the figures. For example, two blocks shown in succession may actually be executed essentially in parallel, or they may be executed in the reverse order, as determined by such functionality. It should be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented in a system using dedicated hardware that performs the predetermined functions or operations, or may be implemented using a combination of dedicated hardware and computer instructions.

[0107] The units mentioned in the embodiments of the present disclosure may be implemented in a software manner or a hardware manner, and the unit names do not limit the units themselves, for example, the first acquisition unit may be described as "a unit for acquiring at least two Internet Protocol addresses."

[0108] Here, the functions described above may be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), dedicated standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), etc.

[0109] In the context of this disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in connection with an instruction execution system, device, or apparatus. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium includes, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination thereof. More specific examples of machine-readable storage media include one or more wire-based electrical connections, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0110] According to a first aspect, in accordance with one or more embodiments of the present disclosure, there is provided a method for intrusion detection in a container environment, the method comprising: For a real-time system event of a target container, an event identification model corresponding to the target container is invoked to perform event identification on the real-time system event, wherein the event identification model is a model constructed based on the historical normal system events of the target container, and is used to identify whether the real-time system event in the target container belongs to a normal system event; If it is determined that the real-time system event is not a normal system event, invoking a pre-configured intrusion detection rule to perform intrusion detection on the real-time system event to determine whether the real-time system event is an intrusion event.

[0111] According to one or more embodiments of the present disclosure, invoking an event identification model corresponding to the target container to perform event identification on the real-time system event includes: performing feature extraction on the real-time system events to obtain target feature information; Invoking an event identification model corresponding to the target container, determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result.

[0112] According to one or more embodiments of the present disclosure, the event identification model includes a first event identification model and a second event identification model, where the first event identification model is constructed based on parameter lengths of historical normal system events of the target container, and the second event identification model is constructed based on feature information of historical normal system events of the target container.

[0113] According to one or more embodiments of the present disclosure, invoking an event identification model corresponding to the target container, determining whether the parameter length and the target feature information of the real-time system event deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result, includes: inputting the target feature information and the parameter length of the real-time system event into the first event identification model to determine whether the parameter length of the real-time system event does not meet the parameter length of a normal system event; inputting the target feature information into the second event identification model, and determining whether the target feature information deviates from feature information of normal system events.

[0114] According to one or more embodiments of the present disclosure, a preset mapping relationship is set in the first event identification model, and the preset mapping relationship is a mapping relationship between keywords corresponding to normal system events of the target container and corresponding parameter length information, and the keywords corresponding to the normal system events are constructed based on feature information of the normal system events.

[0115] Invoking an event identification model corresponding to the target container and determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container; constructing target keywords based on the target feature information; performing a search in a pre-defined mapping relationship based on the target keyword; When a keyword identical to the target keyword is found in the preset mapping relationship, parameter length information of a normal system event corresponding to the keyword is obtained; determining whether the parameter length of the real-time system event does not meet the parameter length of the normal system event based on the parameter length information of the real-time system event and the parameter length information of the normal system event; If the same keyword as the target keyword is not found in the preset mapping relationship, determining that the target feature information is out of a normal system event.

[0116] According to one or more embodiments of the present disclosure, the second event identification model is an out-point determination model, and correspondingly, inputting the target feature information into the second event identification model and determining whether the target feature information deviates from feature information of a normal system event includes: inputting the target feature information into the second event identification model, and determining whether the target feature information is an out point for feature information corresponding to a normal system event; If it is determined that the target feature information is an out point, determining that the target feature information is feature information that deviates from a normal systematic event.

[0117] According to one or more embodiments of the present disclosure, the second event identification model is an Isolation Forest model constructed based on historical normal system events. Correspondingly, inputting the target feature information into the second event identification model and determining whether the target feature information is an out point for feature information corresponding to the historical normal system events includes: constructing a matrix based on the target feature information to obtain a target feature matrix; Matching the target feature matrix with the Isolation Forest model and determining whether the target feature matrix is ​​an out-point.

[0118] According to one or more embodiments of the present disclosure, performing feature extraction on real-time system events of a target container to obtain target feature information includes: Acquiring first type attribute information and second type attribute information in the data of the real-time system event, wherein the first type attribute information is attribute information having a fixed information amount and a fixed mode, and the second type attribute information is attribute information whose information amount or mode is not fixed; performing a conversion process on the second type attribute information to obtain derived attribute information; and merging the first type attribute information and the derived attribute information to obtain the target feature information.

[0119] According to one or more embodiments of the present disclosure, the first event identification model is obtained by the following steps. A plurality of historical normal system events of the target container are obtained. Feature extraction is performed on each of the plurality of historical normal system events, and historical feature information corresponding to each of the historical normal system events is obtained. Parameter length information of normal system events is obtained based on historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events, and the first event identification model is obtained.

[0120] According to one or more embodiments of the present disclosure, obtaining parameter length information of normal system events based on historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events, and obtaining the first event identification model, includes: constructing a corresponding keyword based on historical feature information corresponding to each of the historical normal system events; Grouping the plurality of historical normal system events according to a keyword, obtaining parameters of the historical normal system events with the same keyword, and obtaining corresponding parameter length information according to the parameters of the historical normal system events with the same keyword; establishing a mapping relationship between each keyword and corresponding parameter length information, and obtaining the preset mapping relationship as the parameter length information of the normal system event.

[0121] According to one or more embodiments of the present disclosure, the second event identification model is obtained by the following steps. A plurality of historical normal system events of the target container are obtained. Feature extraction is performed on each of the historical normal system events to obtain historical feature information corresponding to each of the historical normal system events. Unsupervised learning is performed on historical feature information corresponding to the plurality of historical normal system events to obtain the second event identification model.

[0122] According to one or more embodiments of the present disclosure, when the second event identification model is an isolation forest model constructed based on historical normal system events, performing unsupervised learning on historical feature information corresponding to the plurality of historical normal system events includes: constructing a matrix for historical feature information corresponding to each of the historical normal system events to obtain a feature matrix for each of the historical normal system events; and performing unsupervised learning of an Isolation Forest model based on the feature matrices of the plurality of historical normal system events.

[0123] In a second aspect, according to one or more embodiments of the present disclosure, there is provided an intrusion detection device for a container environment, the device comprising: an identification unit for identifying a real-time system event of a target container by calling an event identification model corresponding to the target container to perform event identification on the real-time system event, the event identification model being a model constructed based on the historical normal system event of the target container, and being used to identify whether the real-time system event in the target container belongs to a normal system event; and an intrusion detection unit that, if it is determined that the real-time system event is not a normal system event, invokes a pre-configured intrusion detection rule to perform intrusion detection on the real-time system event and determines whether the real-time system event is an intrusion event.

[0124] According to one or more embodiments of the present disclosure, the container environment intrusion detection device further includes a feature extraction unit for performing feature extraction on the real-time system events to obtain target feature information.

[0125] The identification unit is specifically configured to call an event identification model corresponding to the target container, determine whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and perform event identification on the real-time system event based on the determination result.

[0126] According to one or more embodiments of the present disclosure, the event identification model includes a first event identification model and a second event identification model, where the first event identification model is constructed based on parameter lengths of historical normal system events of the target container, and the second event identification model is constructed based on feature information of historical normal system events of the target container.

[0127] According to one or more embodiments of the present disclosure, when invoking an event identification model corresponding to the target container, determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result, the identification unit: inputting the target feature information and the parameter length of the real-time system event into the first event identification model to determine whether the parameter length of the real-time system event does not satisfy the parameter length of a normal system event; The target feature information is input to the second event identification model to determine whether the target feature information deviates from feature information of normal system events.

[0128] According to one or more embodiments of the present disclosure, a preset mapping relationship is set in the first event identification model, and the preset mapping relationship is a mapping relationship between keywords corresponding to normal system events of the target container and corresponding parameter length information, and the keywords corresponding to the normal system events are constructed based on feature information of the normal system events.

[0129] The target feature information and the parameter length of the real-time system event are input into the first event identification model to determine whether the parameter length of the real-time system event does not meet the parameter length of the normal system event, the identification unit: constructing a target keyword based on the target feature information; Performing a search in a pre-defined mapping relationship based on the target keyword; If a keyword identical to the target keyword is found in the preset mapping relationship, parameter length information of a normal system event corresponding to the keyword is obtained; Determine whether the parameter length of the real-time system event does not meet the parameter length of the normal system event based on the parameter length information of the real-time system event and the parameter length information of the normal system event; If the keyword same as the target keyword is not found in the preset mapping relationship, it is determined that the target feature information is out of the normal system event.

[0130] According to one or more embodiments of the present disclosure, the second event identification model is an out-point determination model. Accordingly, when inputting the target feature information into the second event identification model and determining whether the target feature information deviates from the feature information of a normal system event, the identification unit: inputting the target feature information into the second event identification model, and determining whether the target feature information is an out point for feature information corresponding to a normal system event; If it is determined that the target feature information is an out point, it is determined that the target feature information is feature information that deviates from a normal systematic event.

[0131] According to one or more embodiments of the present disclosure, the second event identification model is an Isolation Forest model constructed based on historical normal system events. Accordingly, when inputting the target feature information into the second event identification model and determining whether the target feature information is an out point for feature information corresponding to the historical normal system events, the identification unit: Construct a matrix based on the target feature information to obtain a target feature matrix; The target feature matrix is ​​matched with the Isolation Forest model to determine whether the target feature matrix is ​​an out point.

[0132] According to one or more embodiments of the present disclosure, when the feature extraction unit performs feature extraction on the real-time system events of the target container to obtain target feature information, Obtaining first type attribute information and second type attribute information in the data of the real-time system event, where the first type attribute information is attribute information having a fixed information amount and a fixed mode, and the second type attribute information is attribute information whose information amount or mode is not fixed; performing a conversion process on the second type attribute information to obtain derived attribute information; The first type attribute information and the derived attribute information are merged to obtain the target feature information.

[0133] According to one or more embodiments of the present disclosure, the apparatus further includes a training unit that performs a training process on the first event identification model, where the training process is as follows. A plurality of historical normal system events of the target container are obtained. Feature extraction is performed on each of the plurality of historical normal system events, and historical feature information corresponding to each of the historical normal system events is obtained. Parameter length information of normal system events is obtained based on historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events, and the first event identification model is obtained.

[0134] According to one or more embodiments of the present disclosure, when obtaining parameter length information of normal system events based on historical feature information corresponding to the plurality of historical normal system events and parameters of the plurality of historical normal system events, and obtaining the first event identification model, the training unit: Constructing corresponding keywords based on historical feature information corresponding to each of the historical normal system events; Grouping the plurality of historical normal system events based on a keyword, obtaining parameters of the historical normal system events with the same keyword, and obtaining corresponding parameter length information based on the parameters of the historical normal system events with the same keyword; A mapping relationship between each keyword and the corresponding parameter length information is established, and the preset mapping relationship is obtained as the parameter length information of the normal system event.

[0135] According to one or more embodiments of the present disclosure, the training unit further performs a training process on the second event identification model, and the training process is as follows: A plurality of historical normal system events of the target container are obtained. Feature extraction is performed on each of the historical normal system events to obtain historical feature information corresponding to each of the historical normal system events. Unsupervised learning is performed on historical feature information corresponding to the plurality of historical normal system events to obtain the second event identification model.

[0136] According to one or more embodiments of the present disclosure, when the second event identification model is an Isolation Forest model constructed based on historical normal system events, the training unit, when performing unsupervised learning on historical feature information corresponding to the plurality of historical normal system events, constructing a matrix for historical feature information corresponding to each of the historical normal system events to obtain a feature matrix for each of the historical normal system events; An Isolation Forest model is trained unsupervised based on the feature matrices of the multiple historical normal system events.

[0137] According to a third aspect, in accordance with one or more embodiments of the present disclosure, there is provided an electronic device, including at least one processor and a memory. The memory stores computer-executable instructions. The at least one processor executes computer-executable instructions stored in the memory, causing the at least one processor to perform the intrusion detection method for a container environment described in the first aspect and various possible designs of the first aspect above.

[0138] According to a fourth aspect, in accordance with one or more embodiments of the present disclosure, there is provided a computer-readable storage medium having stored thereon computer-executable instructions, which, when executed by a processor, result in a method for intrusion detection in a container environment as set forth in the first aspect above and various possible designs of the first aspect.

[0139] According to a fifth aspect, in accordance with one or more embodiments of the present disclosure, there is provided a computer program product comprising computer-executable instructions that, when executed by a processor, implements the method for intrusion detection in a container environment as set forth in the first aspect above and various possible designs of the first aspect.

[0140] The above is only a description of the preferred embodiments and operational technical principles of the present disclosure. Those skilled in the art should understand that the scope of the present disclosure is not limited to the specific combination of the above technical features, and also includes other technical solutions formed by any combination of the above technical features or their equivalent features, as long as they do not deviate from the concept of the above disclosure. For example, the above features are technical means formed by mutually substituting technical features having similar functions (not limited to) disclosed in the present disclosure.

[0141] Also, although operations are described in a particular order, these operations need not be performed chronologically according to the order shown. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although the above includes several specific implementation details, these should not be construed as limiting the scope of the present disclosure. Some features that are described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments alone or in any suitable subcombination.

[0142] Although the present subject matter has been described in language specifying structural features and / or methodological acts, it is to be understood that claimed subject matter is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above merely implement example forms of the claims.

Claims

1. For a real-time system event of a target container, an event identification model corresponding to the target container is invoked to perform event identification on the real-time system event, where the event identification model is a model constructed based on the historical normal system events of the target container, and is used to identify whether the real-time system event in the target container belongs to a normal system event; If the real-time system event is determined not to be the normal system event, invoking a pre-configured intrusion detection rule to perform intrusion detection on the real-time system event to determine whether the real-time system event is an intrusion event. Intrusion detection methods for container environments.

2. Invoking an event identification model corresponding to the target container to perform event identification on the real-time system event, performing feature extraction on the real-time system events to obtain target feature information; Invoking an event identification model corresponding to the target container, determining whether the parameter length and the target feature information of the real-time system event deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result. The method of claim 1.

3. The event identification model includes a first event identification model and a second event identification model, the first event identification model is a model constructed based on a parameter length of a historical normal system event of the target container, and the second event identification model is a model constructed based on feature information of a historical normal system event of the target container. The method of claim 2.

4. Invoking an event identification model corresponding to the target container, determining whether the parameter length and the target feature information of the real-time system event deviate from the normal system event of the target container, and performing event identification on the real-time system event based on the determination result; inputting the target feature information and the parameter length of the real-time system event into the first event identification model to determine whether the parameter length of the real-time system event does not satisfy the parameter length of a normal system event; inputting the target feature information into the second event identification model, and determining whether the target feature information deviates from feature information of a normal system event. The method of claim 3.

5. A preset mapping relationship is set in the first event identification model, the preset mapping relationship being a mapping relationship between keywords corresponding to the normal system events of the target container and corresponding parameter length information, and the keywords corresponding to the normal system events are constructed according to feature information of the normal system events; Invoking an event identification model corresponding to the target container and determining whether the parameter length of the real-time system event and the target feature information deviate from the normal system event of the target container, constructing target keywords based on the target feature information; searching in the pre-defined mapping relationship based on the target keyword; When a keyword identical to the target keyword is found in the preset mapping relationship, parameter length information of a normal system event corresponding to the keyword is obtained; determining whether the parameter length of the real-time system event does not meet the parameter length of the normal system event based on the parameter length information of the real-time system event and the parameter length information of the normal system event; and determining that the target feature information is out of the normal system event if a keyword identical to the target keyword is not found in the preset mapping relationship. The method of claim 3.

6. The second event identification model is an out-point determination model, and correspondingly, inputting the target feature information into the second event identification model and determining whether the target feature information deviates from feature information of the normal system event includes: inputting the target feature information into the second event identification model, and determining whether the target feature information is an out point for feature information corresponding to a normal system event; If it is determined that the target feature information is an out point, determining that the target feature information is feature information that deviates from a normal systematic event. The method of claim 4.

7. The second event identification model is an Isolation Forest model constructed based on a history normal system event, and correspondingly, inputting the target feature information into the second event identification model, and determining whether the target feature information is an out point for feature information corresponding to the history normal system event, includes: constructing a matrix based on the target feature information to obtain a target feature matrix; and matching the target feature matrix with the Isolation Forest model to determine whether the target feature matrix is ​​an out-point. The method of claim 6.

8. performing the feature extraction on the real-time system event of the target container to obtain the target feature information, Acquiring first type attribute information and second type attribute information in the data of the real-time system event, wherein the first type attribute information is attribute information having a fixed information amount and a fixed mode, and the second type attribute information is attribute information in which the information amount or mode is not fixed; performing a conversion process on the second type attribute information to obtain derived attribute information; Merging the first type attribute information and the derived attribute information to obtain the target feature information. The method according to any one of claims 2 to 7.

9. an identification unit for identifying a real-time system event of a target container by calling an event identification model corresponding to the target container to perform event identification on the real-time system event, the event identification model being a model constructed based on the historical normal system event of the target container, and being used to identify whether the real-time system event in the target container belongs to a normal system event; an intrusion detection unit that, when it is determined that the real-time system event is not the normal system event, performs intrusion detection on the real-time system event by invoking a pre-configured intrusion detection rule to determine whether the real-time system event is an intrusion event; An intrusion detection device for a container environment, comprising:

10. An electronic device comprising at least one processor and a memory, the memory stores computer-executable instructions; the at least one processor executing computer-executable instructions stored in the memory, thereby causing the at least one processor to perform the method of any one of claims 1 to 8; electronic equipment.

11. A computer readable storage medium having stored thereon computer executable instructions which, when executed by a processor, implement the method of any one of claims 1 to 8.

12. A computer program product comprising computer-executable instructions which, when executed by a processor, implements the method of any one of claims 1 to 8.