A cluster detection method, device, equipment, medium and product

By identifying the target container group and service account in the computing cluster and detecting related cluster audit events, the problem of difficulty in performing computing cluster security detection in the prior art is solved, and real-time security monitoring and threat identification of the computing cluster is realized.

CN119442282BActive Publication Date: 2025-05-30BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411546406.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2025-05-30
Estimated Expiration
2044-10-31

AI Technical Summary

Technical Problem

It is difficult for the prior art to conduct comprehensive security inspection during the operation of the computing cluster, especially after the information of high-authority service accounts is leaked, it is impossible to effectively detect and prevent unsafe access and operational behavior.

Method used

By determining the target container group from multiple container groups in the computing cluster, combining the container group information and role access control information, the target service account that needs to be paid attention to is identified. Then, detect the cluster audit event related to the target service account, determine whether there are unsafe access or operation behaviors, and generate the detection result of the computing cluster.

Benefits of technology

It realizes security detection of cluster dimensions during the operation of the computing cluster, can identify unsecure access and operation behaviors of high-permission service accounts, improves the security of the computing cluster, and prevents potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119442282B_ABST
    Figure CN119442282B_ABST
Patent Text Reader

Abstract

The present application provides a cluster detection method, apparatus, device, medium and product. The method includes: determining a target container group from multiple container groups deployed in a first computing cluster; in response to detecting at least one of the following events: a target file reading event for a container in a first container group and a critical event triggered by a container in a second container group, determining a target service account as the service account associated with at least one of the first container group and the second container group; in response to detecting a cluster audit event related to the target service account, determining a security identification result of the cluster audit event related to the target service account; and generating a detection result of the first computing cluster according to the security identification result. In this method, it is possible to implement security detection at the cluster level during the operation of the computing cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a cluster detection method, device, electronic device, computer-readable storage medium, and computer program product. Background Art

[0002] With the continuous development of computer technology, computing clusters have emerged. Computing clusters are usually composed of multiple computing nodes, which work together to provide high-performance computing capabilities.

[0003] Typically, access to and operations on computing cluster resources rely on accounts. For example, accounts in a computing cluster can be divided into user accounts representing real users, service accounts (SAs) representing non-real users, and system accounts used within the cluster.

[0004] In some types of computing clusters, account permissions can be managed based on a role-based access control (RBAC) mechanism. Specifically, RBAC assigns different permissions to different accounts by defining roles or cluster roles with different permissions and binding them to accounts.

[0005] If someone obtains the information of a service account with higher permissions, they can use that account to access and manipulate computing cluster resources. Because the service account has higher permissions, these access and manipulation behaviors can have a significant impact on computing cluster security and could potentially lead to a compromise of the cluster. Therefore, comprehensive cluster-level security testing is crucial. Summary of the Invention

[0006] This application provides a cluster detection method. This method can implement cluster-level security detection during the operation of a computing cluster. This application also provides a device, electronic device, computer-readable storage medium, and computer program product corresponding to the above method.

[0007] In a first aspect, the present application provides a cluster detection method, the method comprising:

[0008] Determine a target container group from multiple container groups deployed in the first computing cluster; wherein the target container group is determined based on at least one of container group information and role access control information;

[0009] In response to detecting at least one of the following events: a target file read event for a container in a first container group and a key event triggered by a container in a second container group, determining a service account associated with at least one of the first container group and the second container group as a target service account; wherein the first container group and the second container group are at least one container group in the target container group;

[0010] In response to detecting a cluster audit event associated with the target service account, determining a security identification result of the cluster audit event associated with the target service account;

[0011] A detection result of the first computing cluster is generated according to the security identification result.

[0012] In a second aspect, the present application provides a cluster detection device, the device comprising:

[0013] A first determination module is configured to determine a target container group from a plurality of container groups deployed in the first computing cluster; wherein the target container group is determined based on at least one of container group information and role access control information;

[0014] a second determining module configured to, in response to detecting at least one of the following events: a target file read event for a container in a first container group and a key event triggered by a container in a second container group, determine a service account associated with at least one of the first container group and the second container group as a target service account; wherein the first container group and the second container group are at least one container group in the target container group;

[0015] an identification module, configured to, in response to detecting a cluster audit event associated with the target service account, determine a security identification result of the cluster audit event associated with the target service account;

[0016] A detection module is configured to generate a detection result of the first computing cluster according to the security identification result.

[0017] In a third aspect, the present application provides an electronic device, comprising a processor and a memory. The processor and the memory communicate with each other. The processor is configured to execute instructions stored in the memory, causing the electronic device to perform the cluster detection method according to the first aspect or any implementation of the first aspect.

[0018] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, wherein the instructions instruct an electronic device to execute the cluster detection method described in the first aspect or any implementation manner of the first aspect.

[0019] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the cluster detection method described in the first aspect or any one of the implementations of the first aspect.

[0020] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods.

[0021] It can be seen from the above technical solutions that this application has the following advantages:

[0022] The present application provides a cluster detection method. The method first determines a target container group from multiple container groups of a first computing cluster, wherein the target container group is determined based on at least one of container group information and role access control information. In response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, a service account associated with at least one of the first container group and the second container group is determined as a target service account, wherein the first container group and the second container group are at least one container group in the target container group. In response to detecting a cluster audit event related to the target service account, a security identification result of the cluster audit event related to the target service account is determined. Then, a detection result of the first computing cluster is generated based on the security identification result.

[0023] This method identifies target container groups within a computing cluster and, based on events related to these groups, identifies target service accounts requiring attention. Cluster audit events associated with these service accounts are then monitored to determine whether the service accounts have engaged in unsafe access or operations within the computing cluster. This enables cluster-wide security monitoring during computing cluster operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical methods of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments.

[0025] Figure 1 A schematic diagram of the architecture of a cluster detection system provided in an embodiment of the present application;

[0026] Figure 2 A schematic diagram of a cluster detection method provided in an embodiment of the present application;

[0027] Figure 3 A schematic diagram of a process for determining a target container group provided in an embodiment of the present application;

[0028] Figure 4 A schematic diagram of the structure of a cluster detection device provided in an embodiment of the present application;

[0029] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] The terms "first" and "second" in the embodiments of this application are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Therefore, features specified as "first" or "second" may explicitly or implicitly include one or more of the features.

[0031] First, some technical terms and application scenarios involved in the embodiments of this application are introduced.

[0032] Computing clusters typically consist of multiple compute nodes that work together to provide high-performance computing capabilities. Computing nodes can be either physical or virtual machines. Computing clusters are typically used to perform complex computing tasks that require extensive computing and storage resources, such as data analysis, machine learning, and graphics rendering.

[0033] In a computing cluster, a container group (POD) is the smallest unit that can be created and managed. In other words, a container group can be understood as the basic deployment unit in a computing cluster. A container group typically encapsulates one or more containers. Containers running in the same container group share network and storage resources.

[0034] With the continuous development of cloud computing technology, more and more users (such as organizations and enterprises) are adopting the microservices architecture to deploy business applications. In a microservices architecture, business applications are broken down into multiple small, independent services, each of which implements a specific business function.

[0035] Business applications using a microservices architecture can be deployed in a computing cluster. Specifically, each service within a business application can be packaged into separate containers within the computing cluster. These containers contain the dependencies and configurations required to run each service. Containerization provides isolation, ensuring environmental consistency across services, and ultimately improving the maintainability, scalability, and reliability of the business application.

[0036] The process of deploying microservices-based business applications in a computing cluster can be implemented using a container orchestration system. A container orchestration system, also known as a container orchestration platform or container orchestration engine, is a software system used to automatically deploy, scale, and manage business applications in a computing cluster. For example, the container orchestration system can be a Kubernetes (K8s) system.

[0037] Typically, access to and operations on computing cluster resources rely on accounts. For example, accounts in a computing cluster can be divided into user accounts representing real users, service accounts (SAs) representing non-real users, and system accounts used within the cluster.

[0038] In some types of computing clusters (such as K8s clusters), permissions for accounts in the computing cluster can be managed based on the role-based access control (RBAC) mechanism. Specifically, in the RBAC mechanism, different permissions are assigned to different accounts by defining roles or cluster roles with different permissions and binding the roles or cluster roles to accounts. For example, in the RBAC mechanism, role A is created, allowing role A to access and operate cluster resource B in the computing cluster. By binding role A to service account C, service account C can access and operate cluster resource B in the computing cluster.

[0039] If someone obtains the information of a service account with higher privileges, they can use that account to access and manipulate compute cluster resources. Because the service account has higher privileges, these access and manipulation behaviors can have a significant impact on the security of the compute cluster and potentially lead to a compromise of the cluster. In other words, if someone obtains the information of a service account with higher privileges, they could potentially use that account to launch cluster-wide escape and lateral penetration attacks, potentially impacting a wider area.

[0040] Specifically, let's take the Kubernetes container orchestration system as an example. When a container starts, the Kubernetes system mounts information related to the service account, such as a token and certificate, to the container. At the same time, the Kubernetes system creates a service named kubernetes.default for the container, allowing the container to communicate with the Kubernetes system. If someone else obtains information about the service account, they can use the token and certificate associated with the service account in the container to communicate with the Kubernetes system through the kubernetes.default service, accessing and manipulating computing cluster resources.

[0041] Related technologies typically use methods such as image vulnerability analysis and cluster configuration testing to monitor computing clusters. However, these methods typically rely on static files or configurations, and can only detect computing clusters before they occur, not during operation. During operation, the testing dimension is limited to individual containers and cannot be linked to the security monitoring of the entire computing cluster.

[0042] In view of this, the present application provides a cluster detection method, which first determines a target container group from multiple container groups of a first computing cluster, wherein the target container group is determined based on at least one of container group information and role access control information. In response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, a service account associated with at least one of the first container group and the second container group is determined as a target service account, wherein the first container group and the second container group are at least one container group in the target container group. In response to detecting a cluster audit event related to the target service account, a security identification result of the cluster audit event related to the target service account is determined. Then, based on the security identification result, a detection result of the first computing cluster is generated.

[0043] This method identifies target container groups within a computing cluster and, based on events related to these groups, identifies target service accounts requiring attention. Cluster audit events associated with these service accounts are then monitored to determine whether the service accounts have engaged in unsafe access or operations within the computing cluster. This enables cluster-wide security monitoring during computing cluster operation.

[0044] To facilitate understanding of the technical solutions provided in the embodiments of the present application, they will be described below with reference to the accompanying drawings.

[0045] See also Figure 1 The schematic diagram of the architecture of a cluster detection system is shown. The cluster detection system 10 includes an asset identifier 101 , a behavior detector 102 and a cluster detector 103 .

[0046] The asset identifier 101 is configured to determine a target container group from among multiple container groups deployed in the first computing cluster. Specifically, the asset identifier 101 may determine the target container group from among the multiple container groups deployed in the first computing cluster based on at least one of container group information and role access control information.

[0047] The behavior detector 102 is configured to detect behaviors related to the target container group and determine a target service account. Specifically, the behavior detector 102 may determine a service account associated with at least one of the first container group and the second container group as the target service account in response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, where the first container group and the second container group are at least one of the target container groups.

[0048] The cluster detector 103 is configured to generate a detection result for the computing cluster. Specifically, the cluster detector 102 may, in response to detecting a cluster audit event associated with a target service account, determine a security identification result of the cluster audit event associated with the target service account, and generate a detection result for the first computing cluster based on the security identification result.

[0049] In this way, information related to computing cluster assets can be used to identify target container groups requiring attention, and by detecting behaviors related to these target container groups, target service accounts requiring attention can be identified. During the operation of the computing cluster, real-time behavior of the computing cluster can be monitored from the perspective of cluster audit events. This focuses on characteristics related to the computing cluster and, combined with the characteristics of the target service accounts being exploited, determines the security of the computing cluster's real-time behavior, thereby achieving security monitoring for the computing cluster.

[0050] Based on the above-mentioned cluster detection system architecture diagram, the present application embodiment also provides a cluster detection method. Figure 2 The flowchart of a cluster detection method provided in an embodiment of the present application is shown, and the method specifically includes:

[0051] S201: Determine a target container group from multiple container groups deployed in a first computing cluster.

[0052] Among them, the first computing cluster can be understood as a computing cluster with cluster detection requirements. For example, the first computing cluster can be a computing cluster after the business application is deployed by the container orchestration system. When the container orchestration system is a K8s system, the first computing cluster can be a K8s computing cluster.

[0053] In the first computing cluster, multiple container groups are deployed. Each container group encapsulates at least one container, and various services of business applications can run in the containers of each container group.

[0054] The target container group can be understood as at least one container group that requires attention during the cluster detection process. In an embodiment of the present application, the target container group is determined based on at least one of container group information and role access control information. In other words, considering the large number of container groups in the first computing cluster, the container groups are identified based on the cluster asset information, and the target container groups that require attention are identified from these. On the one hand, the security level of the container groups is determined based on the cluster asset information, and target container groups with lower security levels are identified. On the other hand, the number of container groups that require subsequent attention is reduced, thereby improving cluster detection efficiency.

[0055] Among them, container group information can be understood as asset information related to the container group. For example, container group information can include the container group name, the container group namespace, the service account associated with the container group, the container group's operating status information, information about the containers in the container group, etc.

[0056] Role access control information can be understood as asset information related to role access control. For example, role access control information may include role information, cluster role information, role permission information, cluster role permission information, account information, association information between roles and accounts, association information between cluster roles and accounts, etc.

[0057] See also Figure 3 The flowchart of a process for determining a target container group is shown. In a specific implementation, at least one of the following information of multiple container groups deployed in a first computing cluster can be first obtained: container group information and role access control information. Then, at least one of the following is determined as the target container group: a container group whose container group information meets a first set condition and a container group associated with a service account whose role access control information meets a second set condition.

[0058] That is, in an embodiment of the present application, by obtaining container group information and / or role access control information, based on set conditions corresponding to the container group information and / or role access control information, a target container group with a lower security level and requiring attention is determined from multiple container groups in the first computing cluster.

[0059] The embodiment of the present application supports obtaining container group information and / or role access control information of multiple container groups of the first computing cluster in different ways. Figure 3 As shown, in some embodiments, in response to detecting a cluster audit event of the first computing cluster, at least one of the following information is extracted from the cluster audit event of the first computing cluster: container group information and role access control information.

[0060] Cluster audit events can be understood as events generated after accessing or operating computing cluster resources. In other words, when access or operation on computing cluster resources is triggered, cluster audit events can be detected.

[0061] In some possible implementations, cluster audit events in the first computing cluster may be detected based on an extended Berkeley packet filter technology.

[0062] The cluster audit event carries container group information and role access control information. By analyzing the cluster audit event, at least one of the container group information and the role access control information can be extracted from the cluster audit event.

[0063] Based on the example, cluster audit events can have the following format:

[0064]

[0065]

[0066] By extracting the content from user, role access control information is obtained, and by extracting the content from objectRef, container group information is obtained. In this way, by detecting cluster audit events, at least one of container group information and role access control information is passively obtained, and cluster asset information is updated in real time.

[0067] In other embodiments, an information acquisition interface of a container orchestration system is called to acquire at least one of the following information of multiple container groups of the first computing cluster: container group information and role access control information. The container orchestration system is used to manage the multiple container groups of the first computing cluster.

[0068] Container orchestration systems, such as K8s systems, typically provide an application programming interface (API) for obtaining cluster asset information. By calling the information acquisition interface provided by the container orchestration system, at least one of container group information and role access control information is actively obtained to update the cluster asset information.

[0069] After obtaining container group information and / or role access control information for multiple container groups in the first computing cluster, the container group information is judged based on a first set condition, or the role access control information is judged based on a second set condition, and a target container group is determined based on the judgment result. The first set condition may be a condition used to describe the container group information of the target container group, that is, the first set condition may describe a condition used to determine whether a container group has a low security level, presents a security risk, or requires attention.

[0070] The following describes some possible first setting conditions:

[0071] 1. Host namespace: Disallow sharing of the host namespace. Check the spec.hostNetwork, spec.hostPID, and spec.hostIPC fields in the container group information. If the values ​​of these fields are not Undefined, nil, or false, the first condition is met.

[0072] 2. AppArmor: Prohibit overwriting or disabling the default policy (RuntimeDefault AppArmor configuration) and prohibit overwriting permissions for some configuration sets. The first setting condition is met by judging the spec.securityContext.appArmorProfile.type field, spec.containers[*].securityContext.appArmorProfile.type field, spec.initContainers[*].securityContext.appArmorProfile.type field, spec.ephemeralContainers[*].securityContext.app ArmorProfile.type field, and metadata.annotations["container.apparmor.security.beta.kubernetes.io / *"] field in the container group information. If the field value of the above fields is not Undefined, nil, Runtime, Default, or Localhost, then the first setting condition is met.

[0073] 3. SELinux: Setting SELinux-type operations is prohibited, and setting custom SELinux users or roles is prohibited. The spec.securityContext.seLinuxOptions.type field, spec.containers[*].securityContext.seLinuxOptions.type field, spec.initContainers[*].securityContext.seLinuxOptions.type field, and spec.ephemeralContainers[*].securityContext.seLinuxOptions.type field in the container group information are evaluated. If the value of these fields is not Undefined, container_t, container_kvm_t, or container_engine_t, the first setting condition is met. The spec.securityContext.seLinuxOptions.user field, spec.containers[*].securityContext.seLinuxOptions.user field, spec.initContainers[*].securityContext.seLinuxOptions.user field, spec.ephemeralContainers[*].securityContext.seLinuxOptions.user field, spec.securityContext.seLinuxOptions.role field, spec.containers[*].securityContext.seLinuxOptions.role field, spec.initContainers[*].securityContext.seLinuxOptions.role field, and spec.ephemeralContainers[*].securityContext.seLinuxOptions.role field in the container group information are judged. If the field value of the above field is not Undefined, the first setting condition is met.

[0074] 4. / proc mount type: Requires the use of the default / proc mask. Check the spec.containers[*].securityContext.procMount, spec.initContainers[*].securityContext.procMount, and spec.ephemeralContainers[*].securityContext.procMount fields in the container group information. If the values ​​of these fields are not Undefined, nil, or Default, the first setting condition is met.

[0075] 5. Seccomp: Setting the Seccomp configuration to Unconfined is prohibited. The spec.securityContext.seccompProfile.type field, spec.containers[*].securityContext.seccompProfile.type field, spec.initContainers[*].securityContext.seccompProfile.type field, and spec.ephemeralContainers[*].securityContext.seccompProfile.type field in the container group information are evaluated. If the value of these fields is not Undefined, nil, Runtime, Default, or Localhost, the first setting condition is met.

[0076] 6. Sysctls: Prohibit configurations except for the permitted subset. Check the spec.securityContext.sys ctls[*].name field in the container group information. If the value of the field is not Undefined, nil, kernel.shm_rmid_forced, net.ipv4.ip_local_port_range, net.ipv4.ip_unprivileged_port_start, net.ipv4.tcp_syncookies, net.ipv4.ping_group_range, net.ipv4.ip_local_reserved_ports, net.ipv4.tcp_keepalive_time, net.ip v4.tcp_fin_timeout, net.ipv4.tcp_keepalive_intvl, or net.ipv4.tcp_keepalive_probes, the first condition is met.

[0077] 7. Volume Type: Configurations other than permitted volume types are prohibited. Check the spec.volumes[*] field in the container group information. If the values ​​of spec.volumes[*].configMap, spec.volumes[*].csi, spec.volumes[*].downwar dAPI, spec.volumes[*].emptyDir, spec.volumes[*].ephemeral, spec.volumes[*].persistentVolumeClaim, spec.volumes[*].projected, and spec.volumes[*].secret in these fields are all empty, the first setting condition is met.

[0078] 8. Privilege escalation: Privilege escalation is prohibited. The spec.containers[*].securityContext.allowPrivilegeEscalation, spec.initContainers[*].securityContext.allowPrivilegeEscalation, and spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation fields in the container group information are checked. If the values ​​of these fields are not false, the first setting condition is met.

[0079] 9. Run as a non-root account: Requires the container to run as a non-root account. The first condition is met by checking the spec.securityContext.runAsNonRoot, spec.containers[*].securityContext.runAsNonRoot, spec.initContainers[*].securityContext.runAsNonRoot, and spec.ephemeralContainers[*].securityContext.runAsNonRoot fields in the container group information. If the values ​​of these fields are not true, Undefined, or nil, then the first condition is met.

[0080] 10. Non-root users: Do not set the container's runAsUser to 0. Check the spec.securityContext.runAsUser, spec.containers[*].securityContext.runAsUser, spec.initContainers[*].securityContext.runAsUser, and spec.ephemeralContainers[*].securityContext.runAs User fields in the container group information. If the values ​​of these fields are not non-zero, Undefined, or null, the first setting condition is met.

[0081] 11. Capabilities: Requires containers to discard all capabilities and only allow the addition of the NET_BIND_SERVICE capability. The spec.containers[*].securityContext.capabilities.add, spec.initContainers[*].securityContext.capabilities.add, and spec.ephemeralContainers[*].securityContext.capabilities.add fields in the container group information are checked. If the values ​​of these fields are not Undefined, nil, or NET_BIND_SERVICE, the first condition is met.

[0082] In this way, by setting a first setting condition for describing a container group associated with a security risk (e.g., a privileged container group), a target container group whose container group information meets the first setting condition and requires attention is identified from the container group information of multiple container groups in the first computing cluster.

[0083] The second condition can be used to describe the service account associated with the target container group. One container group is associated with one service account, meaning there is a corresponding relationship between one container group and one service account. In other words, the second condition can describe the conditions used to identify container groups associated with service accounts with low security levels that pose a risk of privilege escalation.

[0084] The following describes some possible second setting conditions:

[0085] 1. List Secrets: Determine whether the service account is allowed to perform get, list, or watch access to Secrets. If so, the second setting condition is met.

[0086] 2. Workload creation: Determine whether the namespace is used to isolate resources required by different trust levels or different tenants. If not, the second setting condition is met.

[0087] 3. Creation of persistent volumes: Determine whether the service account is allowed to create PersistentVolumes. If so, the second setting condition is met.

[0088] 4. Access the proxy subresource of the Node object: Determine whether the service account that has access to the proxy subresource of the Node object has access to the kubelet API. If so, the second setting condition is met.

[0089] 5. Esclate action: Determine whether the service account is involved in the esclate action. If so, the second setting condition is met.

[0090] 6. Bind action: Determine whether the service account involves a bind action. If so, the second setting condition is met.

[0091] 7. Impersonate action: Determine whether the service account involves the impersonate action. If so, the second setting condition is met.

[0092] 8. CSR and certificate issuance: Determine whether the service account has access to the CSR API. If so, the second setting condition is met.

[0093] 9. Token request: Determine whether the service account has the create permission for serviceaccounts / token. If so, the second setting condition is met.

[0094] 10. Control access to Webhook: Determine whether the service account has the authority to control validatingwebhookconfigurations or mutatingwebhookconfigurations. If so, the second setting condition is met.

[0095] 11. Namespace modification: Determine whether the service account has the authority to perform the patch operation on the namespace object. If so, the second setting condition is met.

[0096] In this way, by setting a second setting condition for describing service accounts with low security levels and risks of privilege escalation, service accounts whose role access control information meets the second setting condition are identified from the role access control information of multiple container groups in the first computing cluster, and then the container groups associated with the service accounts that meet the second setting condition are determined as target container groups that need attention.

[0097] S202: In response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, determine a service account associated with at least one of the first container group and the second container group as a target service account.

[0098] In this embodiment of the present application, the first container group and the second container group are at least one container group in the target container group. That is, if the detected cluster audit events include a target file read event for a container in one or more of the target container groups, or a critical event triggered by a container in one or more of the target container groups, the service account associated with the target file read event is determined as the target service account, and the service account associated with the critical event is determined as the target service account.

[0099] The target service account can be understood as a service account that needs attention. In the cluster detection scenario of the embodiment of the present application, the target service account can be understood as a service account with a risk of leakage of relevant information of the service account or a service account whose relevant information may be obtained by others.

[0100] The target file read event can be used to open or read a file in a container in the first container group. In some possible implementations, the target file read event for a container in the first container group includes an event in which a process other than the main process of the first computing cluster reads a file related to a service account in a container in the first container group.

[0101] That is, by detecting cluster audit events, file read events are filtered out from the cluster audit events, and then file read events that read files related to the service account are filtered out from the file read events. For example, the file path of the file read event that reads files related to the service account can be / var / run / secrets / kubernetes.io / serviceaccount. Then, file read events in which processes other than the main process of the first computing cluster perform file reads are filtered out to obtain the target file read event.

[0102] Considering that the files related to the service account (such as tokens and certificates) mounted in the container are for better use of computing cluster resources, other processes usually do not involve opening or reading files related to the service account during normal operation. Therefore, by detecting the target file read event, the unsafe file reading behavior in the target container group is identified, and then the service account associated with the first container group with unsafe file reading behavior is determined as the target service account that needs attention.

[0103] Critical events can be understood as events involving unsafe container behavior. Specifically, cluster audit events are detected to determine whether they are critical events. If so, the service account associated with the second container group that performed the unsafe container behavior is identified as a target service account requiring attention.

[0104] The embodiments of the present application do not limit the method for determining whether a cluster audit event is a critical event. For example, cluster audit events involving critical software execution, rebound shell, memory Trojan, backdoor residency, credential theft, container escape, port scanning, remote control, data transfer, etc. can be determined as critical events.

[0105] S203: In response to detecting a cluster audit event related to the target service account, determine a security identification result of the cluster audit event related to the target service account.

[0106] After determining the target service account that requires attention, the cluster audit events related to the target service account are detected to determine whether the cluster audit events related to the target service account are safe.

[0107] In a specific implementation, in response to detecting a cluster audit event of the first computing cluster, role access control information is extracted from the cluster audit event of the first computing cluster, and in response to the service account corresponding to the role access control information being the target service account, a security identification result of the cluster audit event is determined.

[0108] That is to say, the cluster audit events of the first computing cluster are detected, and based on the role access control information carried by the cluster audit events of the first computing cluster, it is determined whether the cluster audit events are related to the target service account, and then the cluster audit events related to the target service account are screened out from a large number of cluster audit events, and targeted security identification is performed on the cluster audit events related to the target service account.

[0109] In some possible implementations, in response to detecting a cluster audit event related to a target service account, when the cluster audit event related to the target service account satisfies a third set condition, a security identification result indicating that the cluster audit event is insecure is determined.

[0110] The third setting condition can be used to describe an unsafe cluster audit event. Furthermore, the security identification result indicating the unsafe cluster audit event can be further divided according to the unsafe level. For example, the security identification result indicating the unsafe cluster audit event can be divided into different unsafe levels such as low risk and high risk.

[0111] The following describes some possible third setting conditions:

[0112] 1. Credential Abuse: Determine whether any cluster audit events related to the target service account abuse the ServiceAccount token using curl, abuse the ServiceAccount token using kubectl, abuse the ServiceAccount using penetration testing tools, obtain the secrets list, or obtain the contents of secrets. If so, the third set condition is met.

[0113] 2. Anonymous access: Determine whether there is anonymous access in the cluster audit events related to the target service account. If so, the third set condition is met.

[0114] 3. Configuration modification: Determine whether there is any DNS configuration modification behavior in the cluster audit events related to the target service account. If so, the third setting condition is met.

[0115] 4. Admission Webhook creation: Determine whether there is any action to create an admission controller in the cluster audit events related to the target service account. If so, the third setting condition is met.

[0116] 5. Authorization failure: Determine whether the cluster audit events related to the target service account include any authorization failures for creating a cronjob, obtaining configmaps, obtaining configmaps authentication, replicasets, secrets, pods, pods authentication, workloads authorization failure, multiple authorization failures for accessing different resources by the same username, or multiple authorization failures for accessing the same resource by different usernames. If so, the third condition is met.

[0117] 6. Abnormal command execution: Determine whether the cluster audit events related to the target service account include executing the attach command on pods, executing commands within pods, executing the curl command within pods, obtaining a list of pods, executing commands within containers, interacting with the API server, executing commands within pods to read SA tokens, executing the wget command within pods, executing the whoami command within pods, and executing the portforward command on pods. If so, the third set condition is met.

[0118] 7. Information Collection: Determine whether, in the cluster audit events related to the target service account, there is any behavior of using penetration testing tools to obtain cluster configmaps, any behavior of using penetration testing tools to obtain cluster PSP security configuration, and any behavior of using penetration testing tools to obtain ETCD information. If so, the third set condition is met.

[0119] 8. Permission detection: Determine whether the cluster audit events related to the target service account have multiple permissions detections by the same identity within a short period of time. If so, the third set condition is met.

[0120] 9. Key role creation: Determine in the cluster audit events related to the target service account whether there are any abnormal accounts creating cronjobs, creating NodePort type Services, creating ClusterRoleBindings bound to key ClusterRoles, creating RoleBindings bound to Roles in the system namespace, creating RoleBindings bound to key ClusterRoles, creating RoleBindings bound to key Roles, creating containers that mount host key directories, creating privileged containers, creating containers with key capabilities, and creating containers that share host networks. If so, the third set condition is met.

[0121] 10. Password theft: Determine whether any cluster audit events related to the target service account involve the use of penetration testing tools to obtain cluster secrets, the abuse of the kubelet account to enumerate secrets in all namespaces, the abuse of ServiceAccount to enumerate secrets in all namespaces, or the use of the BOtB tool to enumerate secrets in the default namespace. If so, the third set condition is met.

[0122] In this way, by comparing the cluster audit event related to the target service account with the third set condition, it is determined whether the cluster audit event related to the target service account is an unsafe cluster audit event, and a security identification result is obtained.

[0123] In other possible implementations, in response to detecting a cluster audit event related to a target service account, and the cluster audit event related to the target service account is an event for creating or modifying a container group, operating information of containers in the created or modified container group is obtained, and based on the operating information of the containers in the created or modified container group, a security identification result of the cluster audit event related to the target service account is determined.

[0124] That is, when a service account requiring attention creates or modifies a container group, others could exploit the service account to execute unsafe container behaviors in containers within the created or modified container group. Therefore, we monitor the running information of containers within the created or modified container group to determine whether cluster audit events involving the creation or modification of container groups by service accounts requiring attention are secure.

[0125] The embodiments of the present application do not limit the method for determining the security identification results of cluster audit events related to the target service account based on the running information of the containers in the created or modified container group. For example, if the running information of the containers in the created or modified container group involves behaviors such as critical software execution, rebound shell, memory Trojan, backdoor residency, credential theft, container escape, port scanning, remote control, data transfer, etc., a security identification result is determined to indicate that the cluster audit event is unsafe.

[0126] In this way, by detecting the cluster operation behavior of the target service account with information leakage risk, and detecting the container behavior of the container assets created by the target service account with information leakage risk, the cluster audit events related to the target service account can be securely identified.

[0127] S204: Generate a detection result of the first computing cluster according to the security identification result.

[0128] By performing security identification on cluster audit events of target service accounts with information leakage risks, the first computing cluster can be detected.

[0129] In some possible implementations, at least one security identification result within a set time period is obtained, and a detection result for the first computing cluster is generated based on the at least one security identification result within the set time period. In other words, the security status of cluster audit events related to the target service account within the set time period is statistically analyzed to comprehensively determine the detection result for the first computing cluster.

[0130] The set time period can be set based on actual business needs. For example, the set time period can be 2 hours.

[0131] In some embodiments, when the number of security identification results indicating that cluster audit events are unsafe reaches a set threshold (eg, 3) within a set time period, the detection result of the first computing cluster is determined to be unsafe, and there is a possibility that the computing cluster may be compromised.

[0132] In other embodiments, the security identification results indicating that the cluster audit event is unsafe are further divided according to the level of unsafety. In this case, if the number of different unsafety levels in the security identification results indicating that the cluster audit event is unsafe within a set time period meets the corresponding set threshold (for example, the number of high-risk unsafety levels reaches 2, and the number of low-risk unsafety levels reaches 1), the detection result of the first computing cluster is determined to be unsafe, and there is a possibility that the computing cluster may be compromised.

[0133] Among them, the threshold value can be set based on actual business needs, and the embodiments of the present application do not limit this.

[0134] Furthermore, when the detection result of the first computing cluster is unsafe, an alarm message may be generated to inform the user (eg, a security operator) that the computing cluster may be compromised, so as to facilitate rapid disposal.

[0135] This method identifies target container groups within a computing cluster and, based on events related to these groups, identifies target service accounts requiring attention. Cluster audit events associated with these service accounts are then monitored to determine whether the service accounts have engaged in unsafe access or operations within the computing cluster. This enables cluster-wide security monitoring during computing cluster operation.

[0136] Combined with the above Figures 1 to 3 The cluster detection method provided in the embodiment of the present application is introduced in detail. The following will introduce the device and equipment provided in the embodiment of the present application with reference to the accompanying drawings.

[0137] See also Figure 4 The schematic diagram of the structure of the cluster detection device shown in FIG. 40 includes:

[0138] A first determination module 401 is configured to determine a target container group from multiple container groups deployed in the first computing cluster; wherein the target container group is determined based on at least one of container group information and role access control information;

[0139] The second determining module 402 is configured to, in response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, determine a service account associated with at least one of the first container group and the second container group as a target service account; wherein the first container group and the second container group are at least one container group in the target container group;

[0140] an identification module 403 for determining a security identification result of the cluster audit event related to the target service account in response to detecting the cluster audit event related to the target service account;

[0141] The detection module 404 is configured to generate a detection result of the first computing cluster according to the security identification result.

[0142] In some possible implementations, the first determining module 401 is specifically configured to:

[0143] Obtain at least one of the following information of multiple container groups deployed in the first computing cluster: container group information and role access control information;

[0144] At least one of the following is determined as a target container group: a container group whose container group information meets a first set condition and a container group associated with a service account whose role access control information meets a second set condition.

[0145] In some possible implementations, the first determining module 401 is specifically configured to:

[0146] In response to detecting a cluster audit event of the first computing cluster, at least one of the following information is extracted from the cluster audit event of the first computing cluster: container group information and role access control information.

[0147] In some possible implementations, the first determining module 401 is specifically configured to:

[0148] Calling an information acquisition interface of a container orchestration system to obtain at least one of the following information of multiple container groups deployed by a first computing cluster: container group information and role access control information; wherein the container orchestration system is used to manage the multiple container groups deployed by the first computing cluster.

[0149] In some possible implementations, the target file read event for a container in the first container group includes an event in which a process other than a main process of the first computing cluster reads a file related to a service account in a container in the first container group.

[0150] In some possible implementations, the identification module 403 is specifically configured to:

[0151] In response to detecting a cluster audit event of a first computing cluster, extracting role access control information from the cluster audit event of the first computing cluster;

[0152] In response to the service account corresponding to the role access control information being the target service account, a security identification result of the cluster audit event is determined.

[0153] In some possible implementations, the identification module 403 is specifically configured to:

[0154] In response to detecting a cluster audit event related to the target service account, when the cluster audit event related to the target service account satisfies a third set condition, determining a security identification result indicating that the cluster audit event is unsafe.

[0155] In some possible implementations, the identification module 403 is specifically configured to:

[0156] In response to detecting a cluster audit event related to the target service account, where the cluster audit event related to the target service account is an event for creating or modifying a container group, obtaining running information of containers in the created or modified container group;

[0157] Determine a security identification result of a cluster audit event related to the target service account based on the running information of the container in the created or modified container group.

[0158] In some possible implementations, the detection module 404 is specifically configured to:

[0159] Obtaining at least one of the security identification results within a set time period;

[0160] A detection result of the first computing cluster is generated according to at least one of the security identification results within the set time period.

[0161] The cluster detection device 40 according to the embodiment of the present application may correspond to executing the method described in the embodiment of the present application, and the above and other operations and / or functions of each module / unit of the cluster detection device 40 are respectively to achieve Figure 2 For the sake of brevity, the corresponding processes of the various methods in the illustrated embodiments are not described again here.

[0162] The embodiment of the present application also provides an electronic device. The electronic device is specifically used to implement Figure 4 The functions of the cluster detection device 40 in the illustrated embodiment.

[0163] Figure 5 A structural diagram of an electronic device 500 is provided. Figure 5 As shown, the electronic device 500 includes a bus 501, a processor 502, a communication interface 503, and a memory 504. The processor 502, the memory 504, and the communication interface 503 communicate with each other via the bus 501.

[0164] The bus 501 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0165] The processor 502 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0166] The communication interface 503 is used for communicating with the outside, for example, the communication interface 503 can be used for communicating with a terminal.

[0167] The memory 504 may include volatile memory, such as random access memory (RAM), or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0168] The memory 504 stores executable codes, and the processor 502 executes the executable codes to perform the aforementioned cluster detection method.

[0169] Specifically, in the implementation Figure 4 In the case of the embodiment shown, and Figure 4 When each module or unit of the cluster detection device 40 described in the embodiment is implemented by software, Figure 4 The software or program code required for the functions of each module / unit in the system may be partially or completely stored in the memory 504. The processor 502 executes the program code corresponding to each unit stored in the memory 504 to perform the aforementioned cluster detection method.

[0170] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the cluster detection method applied to the cluster detection device 40.

[0171] The present application also provides a computer program product comprising one or more computer instructions that, when loaded and executed on a computing device, fully or partially generate the process or function described in the present application.

[0172] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0173] When the computer program product is executed by a computer, the computer performs any of the aforementioned cluster detection methods. The computer program product may be a software installation package, which can be downloaded and executed on a computer when any of the aforementioned cluster detection methods is needed.

[0174] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to the various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the prescribed logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0175] The units involved in the embodiments described in this application may be implemented in software or hardware, wherein the name of a unit / module does not, in some cases, constitute a limitation on the unit itself.

[0176] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0177] In the context of the present application embodiment, machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0178] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0179] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0180] It should also be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0181] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0182] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A cluster detection method, characterized in that: The method comprises: Determine a target container group from multiple container groups deployed in the first computing cluster; wherein the target container group is determined based on at least one of container group information and role access control information; In response to detecting at least one of the following events: a target file read event for a container in a first container group and a key event triggered by a container in a second container group, determining a service account associated with at least one of the first container group and the second container group as a target service account; wherein the first container group and the second container group are at least one container group in the target container group; In response to detecting a cluster audit event associated with the target service account, determining a security identification result of the cluster audit event associated with the target service account; A detection result of the first computing cluster is generated according to the security identification result.

2. The method according to claim 1, characterized in that The step of determining a target container group from a plurality of container groups deployed in the first computing cluster includes: Obtain at least one of the following information of multiple container groups deployed by the first computing cluster: container group information and role access control information; At least one of the following is determined as the target container group: a container group whose container group information satisfies a first set condition and a container group associated with a service account whose role access control information satisfies a second set condition.

3. The method according to claim 2, characterized in that The obtaining of at least one of the following information of the plurality of container groups deployed by the first computing cluster: container group information and role access control information, includes: In response to detecting a cluster audit event of the first computing cluster, extracting at least one of the following information from the cluster audit event of the first computing cluster: container group information and role access control information.

4. The method according to claim 2, characterized in that: The obtaining of at least one of the following information of the plurality of container groups deployed by the first computing cluster: container group information and role access control information, includes: Calling an information acquisition interface of a container orchestration system to obtain at least one of the following information of multiple container groups deployed by the first computing cluster: container group information and role access control information; wherein the container orchestration system is used to manage the multiple container groups deployed by the first computing cluster.

5. The method according to claim 1, characterized in that The target file reading event for the container in the first container group includes: an event in which other processes except the main process of the first computing cluster read files related to the service account of the container in the first container group.

6. The method according to claim 1, characterized in that In response to detecting a cluster audit event related to the target service account, determining a security identification result of the cluster audit event related to the target service account includes: In response to detecting a cluster audit event of a first computing cluster, extracting role access control information from the cluster audit event of the first computing cluster; In response to the service account corresponding to the role access control information being the target service account, a security identification result of the cluster audit event is determined.

7. The method according to claim 1, characterized in that In response to detecting a cluster audit event related to the target service account, determining a security identification result of the cluster audit event related to the target service account includes: In response to detecting a cluster audit event related to the target service account, when the cluster audit event related to the target service account satisfies a third set condition, a security identification result indicating that the cluster audit event is unsafe is determined.

8. The method according to claim 1, characterized in that In response to detecting a cluster audit event related to the target service account, determining a security identification result of the cluster audit event related to the target service account includes: In response to detecting a cluster audit event related to the target service account, and the cluster audit event related to the target service account is an event for creating or modifying a container group, obtaining operation information of a container in the created or modified container group; Determine a security identification result of a cluster audit event related to the target service account according to the running information of the container in the created or modified container group.

9. The method according to any one of claims 1 to 8, characterized in that: Generating a detection result of the first computing cluster according to the security identification result includes: Obtaining at least one of the security identification results within a set time period; A detection result of the first computing cluster is generated according to at least one of the security identification results within the set time period.

10. A cluster detection device, characterized in that: The device comprises: A first determination module, configured to determine a target container group from a plurality of container groups deployed in the first computing cluster; wherein the target container group is determined based on at least one of container group information and role access control information; a second determination module, configured to, in response to detecting at least one of the following events: a target file read event for a container in the first container group and a key event triggered by a container in the second container group, determine a service account associated with at least one of the first container group and the second container group as a target service account; wherein the first container group and the second container group are at least one container group in the target container group; an identification module, configured to, in response to detecting a cluster audit event associated with the target service account, determine a security identification result of the cluster audit event associated with the target service account; A detection module is used to generate a detection result of the first computing cluster according to the security identification result.

11. An electronic device, characterized in that: The electronic device comprises a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that: The method comprises instructions, wherein the instructions instruct an electronic device to execute the method as claimed in any one of claims 1 to 9.

13. A computer program product, characterized in that The computer program product comprises computer readable instructions for implementing the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Computing system, container network configuration method and storage medium

    CN115086166A

  • Web application access method, device and system and computing equipment

    CN116170274A