Threat detection method, system, storage medium and cloud platform of container cluster

By deploying agent and control terminals on the cloud platform, local traffic collection and detection of container clusters are achieved, solving the problems of high bandwidth consumption and inadequate detection performance in cloud-native environments, and realizing flexible threat detection capabilities.

CN119728127BActive Publication Date: 2025-11-28QI AN XIN TECHNOLOGY GROUP INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311257079.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2025-11-28
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

In a cloud-native environment, existing technologies perform threat detection by sending out container network interface traffic, which results in high host bandwidth consumption and the inability of NDS devices to dynamically scale up or down, making them unable to adapt to changes in business elasticity.

Method used

Deploy the agent and control end on the cloud platform to achieve local traffic collection and detection. Dynamically adapt to changes in container clusters through traffic collection strategies and threat detection rules. Adopt a separate architecture for the agent and control end to achieve targeted traffic collection and detection.

Benefits of technology

It saves host bandwidth resources, improves the targeting and flexibility of threat detection, and can dynamically scale up and down with changes in business, adapting to the dynamic elasticity requirements of cloud-native environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728127B_ABST
    Figure CN119728127B_ABST
Patent Text Reader

Abstract

The application provides a threat detection method and system of a container cluster, a storage medium and a cloud platform. The system comprises an agent end. The agent end is used to acquire a traffic collection strategy and a threat detection rule, collect network card traffic of a business container according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic. The cloud native traffic is collected and detected locally, the traffic does not need to be sent out, a large amount of bandwidth resources of a host is saved, the threat detection system can be dynamically expanded and contracted according to business changes, and the threat detection performance is flexibly adapted to the dynamic elasticity of the cloud native.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of computer security, in particular, to a threat detection method and system of a container cluster, a storage medium and a cloud platform. BACKGROUND

[0002] Traditional environments generally use a method based on physical switch port mirroring to mirror traffic to a detection device such as a NDS (network threat detection device) for threat detection. In a cloud-native environment, traffic of a container network card is directly collected by deploying a traffic collection client, and the collected traffic is transmitted to a NDS through a GRE (generic routing encapsulation) or VXLAN (virtual extensible local area network) tunnel for threat detection. SUMMARY

[0003] The purpose of the embodiments of the present application is to provide a threat detection method and system of a container cluster, a storage medium and a cloud platform, to realize local collection and detection of cloud-native traffic, and save bandwidth resources.

[0004] In a first aspect, the embodiments of the present application provide a threat detection system of a container cluster, which is deployed in a cloud platform where the container cluster is located. The container cluster includes at least one business container. The system includes a proxy end. The proxy end is configured to obtain a traffic collection strategy and a threat detection rule, collect network card traffic of the business container according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic.

[0005] The threat detection system described above is deployed in a cloud platform where the container cluster is located, realizes local collection and detection of cloud-native traffic, and does not need to transmit traffic, thereby saving a large amount of bandwidth resources of a host. Meanwhile, the threat detection system can be dynamically scaled according to changes in business, thereby realizing flexible adaptation of threat detection performance to cloud-native dynamic elasticity.

[0006] In an optional embodiment, the traffic collection strategy includes a container searching sub-strategy, which is configured to indicate a target business container whose network card traffic needs to be collected. The proxy end is further configured to search for the target business container according to the container searching sub-strategy in the traffic collection strategy, and collect network card traffic of the target business container.

[0007] In the above embodiment, the target business container is obtained according to the traffic collection strategy, and traffic of the business container is collected, thereby realizing targeted traffic collection and improving the targeting of threat detection.

[0008] In an optional embodiment, the agent end is further configured to monitor changes of the service containers in the container cluster in real time, and when the target service container in the container cluster changes, the target service container is re-found according to the container finding sub-strategy in the traffic collection strategy.

[0009] In the above embodiment, the agent end can monitor changes of the containers in real time, re-find the target container according to the container changes, update the target container, and timely acquire the traffic of the changed target container, thereby improving the threat detection capability of the system.

[0010] In an optional embodiment, the system further comprises a control end, the control end is configured to control the traffic collection strategy, and is further configured to update and maintain the threat detection rule; and the control end is further configured to distribute the traffic collection strategy and the threat detection rule to the agent end.

[0011] In the above embodiment, the agent end and the control end are respectively arranged, and the control end is configured to manage the agent end, thereby expanding the detection capability of the threat detection system. The server end and the agent end can dynamically expand or shrink with the service changes, thereby realizing the dynamic, elastic and flexible adaptation of the threat detection capability to the cloud native.

[0012] In an optional embodiment, the control end is further configured to acquire container information of all service containers in the container cluster through an interface of the container cluster, group the service containers in the container cluster according to the container information of the all service containers to obtain a plurality of container groups, and receive a selection instruction for the plurality of container groups, the selection instruction being configured to indicate a container group selected by a user and / or a service container in the container group, and generate the traffic collection strategy according to container information of the service container corresponding to the selection instruction.

[0013] In the above embodiment, the traffic collection strategy can be generated according to the selection of the user, the user can simply and conveniently control the traffic collection, and targeted traffic collection can be realized.

[0014] In an optional embodiment, the agent end comprises a first container and a second container, the first container is configured to acquire the traffic collection strategy and the threat detection rule, mirror network card traffic of a service container to a mirror network card of the second container according to the traffic collection strategy, and send the threat detection rule to the second container; and the second container is configured to receive the threat detection rule, listen to the mirror network card to acquire the network card traffic, collect the network card traffic according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic.

[0015] In the above embodiment, the control end is divided into the first container and the second container to perform different functions respectively, so as to reduce the failure probability and enhance the robustness and management capability of the control end.

[0016] In an optional embodiment, the traffic collection strategy includes a container searching sub-strategy used to indicate a target service container requiring to collect the network card traffic; and the first container is further configured to search the target service container according to the container searching sub-strategy in the traffic collection strategy, and mirror the network card traffic of the target service container to the mirror network card of the second container.

[0017] In the above embodiment, the target service container is searched according to the traffic collection strategy, and the traffic of the service container is collected, so as to realize targeted traffic collection and improve the targeting of threat detection.

[0018] In an optional embodiment, the first container is further configured to monitor changes of each service container in the container cluster in real time, and search the target service container according to the container searching sub-strategy in the traffic collection strategy when the target service container in the container cluster changes.

[0019] In the above embodiment, the agent end can monitor the changes of the containers in real time, search the target container according to the changes of the containers, update the target container, acquire the traffic of the changed target container in time, and thus improve the threat detection capability of the system.

[0020] In a second aspect, the embodiments of the present application provide a threat detection method of a container cluster, which is applied to an agent end, the agent end is deployed in a cloud platform to which the container cluster belongs, the container cluster includes at least one container, and the method includes: acquiring a traffic collection strategy and a threat detection rule; collecting network card traffic of a service container according to the traffic collection strategy; and performing threat detection according to the threat detection rule and the network card traffic.

[0021] In a fourth aspect, the embodiments of the present application provide a computer readable storage medium, which stores a computer program, and when the computer program is deployed in a computer, the system as described in any one of the first aspect is implemented. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0023] Figure 1 A schematic block diagram of a container cluster threat detection system provided by an embodiment of the present application is shown in FIG. 1.

[0024] Figure 2 A flowchart of a container cluster threat detection system provided by an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION

[0025] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0026] In the prior art, in a cloud native environment, the traffic of the container network card is directly collected by deploying a traffic collection client, and the collected traffic is externally transmitted to an NDS (network threat detection device) for threat detection through the GRE (generic routing encapsulation) or VXLAN (virtual extension local area network) tunnel mode.

[0027] However, in a cloud native environment, the east-west traffic is much larger than the north-south traffic. For example, the traffic collected by deploying a traffic collection client and externally transmitted to an NDS through the GRE or VXLAN tunnel mode belongs to east-west traffic. If all of the east-west traffic is externally transmitted, it will occupy a large amount of bandwidth of the host, affecting the stability of the business. If not all of the east-west traffic is externally transmitted, only part of the traffic can be collected and externally transmitted according to the business, but partial collection and external transmission of the traffic will lead to incomplete threat detection. At the same time, the external NDS device cannot dynamically expand or shrink according to the scale of the business container, so that the detection performance of the NDS device cannot adapt to the flexible changes of the cloud native environment.

[0028] Figure 1 A container cluster threat detection system 100 provided by an embodiment of the present application is deployed in a cloud platform where a container cluster is located. The container cluster includes at least one business container, and the system includes a proxy end 110.

[0029] A cloud platform is a computing resource and service providing platform based on cloud computing technology. The cloud platform can include one or more computers and various services running on the computers.

[0030] The cloud platform of the embodiment of the present application runs a container cluster, which is also called a container orchestration cluster, and is a collection for managing and deploying containerized applications. For example, a K8s cluster is a container cluster. Each container cluster should include at least one container. Containers are a lightweight virtualization technology that can encapsulate applications and their dependencies in an independent environment, thereby achieving more efficient deployment and portability. In the present application, the containers belonging to the container cluster on the cloud platform are referred to as business containers, which are distinguished from other containers on the cloud platform.

[0031] In the present application, the threat detection system 100 is also deployed on the cloud platform to detect the full-flow threats of the container cluster.

[0032] The threat detection system includes an agent end 110 that obtains a flow collection strategy and a threat detection rule. The flow collection strategy is used to indicate which flows need to be collected. For example, the flow collection strategy can indicate which containers are collected for flows, and / or which flows of the containers need to be collected. The threat detection rule is used to indicate when threat alert information needs to be output.

[0033] In an embodiment of the present application, the system further includes a control end 120, which is used to control the flow collection strategy and is further used for updating and maintaining the threat detection rule.

[0034] The control end is further used to issue the flow collection strategy and the threat detection rule to the agent end.

[0035] The control end 120 serves as a control plane and is responsible for the control of the flow collection strategy and the updating and maintenance of the threat detection rule. The control end 120 is further used to issue the flow collection strategy and the threat detection rule to the agent end 110.

[0036] The control end can manage the agent end. For example, the control end can manage multiple agent ends, and each agent end is responsible for multiple containers, thereby achieving the detection of the entire container cluster. However, using a single agent end cannot manage numerous nodes, or the different flow collection strategies and threat detection rules can be issued to different agent ends to achieve targeted detection.

[0037] In the above embodiment, the agent end and the control end are respectively arranged, and the control end manages the agent end, which can expand the detection capability of the threat detection system. The server end and the agent end can be dynamically scaled according to the changes in the business, thereby achieving the dynamic, elastic, and flexible adaptation of the threat detection capability to the cloud native.

[0038] In an embodiment of the present application, the control end is further configured to obtain container information of all service containers in the container cluster through an interface of the container cluster, group the service containers of the container cluster according to the container information of all the service containers, and obtain a plurality of container groups; and further configured to receive a selection instruction for the plurality of container groups, the selection instruction being used to indicate a container group selected by a user and / or a service container in the container group, and generate the traffic collection strategy according to the container information of the service container corresponding to the selection instruction.

[0039] The control end can be deployed in a cloud-native manner through Deployment. The replica containers of the Deployment are distributed on various nodes, and each node can run one or more replicas. A node refers to a virtual machine or a physical machine responsible for executing a request task assigned by the control plane of the cluster. In this way, the performance of the control end can be dynamically scaled according to changes in business.

[0040] The control end obtains container information of all service containers in the cluster through an interface such as an API (application programming interface) of the cluster. The container information is information used to describe a container, for example, the container information can be which container set the container belongs to. A container set refers to a container group deployed to a single node and containing one or more containers. The service containers of the container cluster cloud platform are grouped according to the container information, and a plurality of container groups are obtained. For example, all containers are grouped according to container groups according to the container information, containers belonging to the same container group are grouped, and a plurality of container groups are obtained.

[0041] The user can set the container group traffic collection strategy, for example, the user selects and generates a selection instruction. The selection instruction can be a selection of a container group. The user can select all container groups or select part of the groups for traffic collection.

[0042] The selection instruction can also be a selection of a service container in the container group. The selection instruction can also indicate a container group selected by the user and a container in the container group at the same time. For example, the user can select A and B container groups and select part of the containers in the C container group.

[0043] The control end receives a selection instruction for the plurality of container groups, and generates the traffic collection strategy according to the container information of the service container corresponding to the selection instruction. For example, when the user selects A and B container groups, the traffic collection strategy is generated according to the container information of the containers in the A container group: the containers belong to the A container set, and the container information of the containers in the B container group: the containers belong to the B container set, and the traffic of the containers in the A and B container sets is collected.

[0044] Further, the selection instruction includes filtering selection information, and the filtering information is used to indicate conditions for filtering traffic, such as filtering according to IP five-tuple conditions.

[0045] In another example of the present application, the control end obtains cloud-native assets through the interface of the cluster, and the cloud-native assets include a cluster, an application, a container, a node, an image, and the like. The control end automatically groups the cloud-native assets, and the user sets a traffic collection strategy through the asset grouping. The user can select to collect traffic of all assets or select to collect traffic of part of the assets, and filtering is performed according to IP five-tuple conditions and the like.

[0046] In the above examples, the traffic collection strategy can be generated according to user selection. The user can simply and conveniently control traffic collection, and targeted traffic collection can be achieved.

[0047] The agent end 110 collects the network card traffic of the business container in the container cluster according to the traffic collection strategy, and performs threat detection according to the threat detection rule and the network card traffic. Relative to the control end, the agent end 110 is responsible for receiving the traffic collection strategy and updating the threat detection rule, and outputs a threat detection alarm. The threat detection alarm supports the way of external sending of kafka or syslog.

[0048] In an embodiment of the present application, the method includes that the traffic collection strategy includes a container searching sub-strategy, and the container searching sub-strategy is used to indicate a target business container for which network card traffic needs to be collected; and the agent end is further used to search for the target business container according to the container searching sub-strategy in the traffic collection strategy, and collect the network card traffic of the target business container.

[0049] The agent end 110 receives the traffic collection strategy, and the traffic collection strategy includes a container searching sub-strategy. The container searching sub-strategy is used to indicate a target business container for which network card traffic needs to be collected. For example, the traffic collection strategy: collect the traffic of the containers in the A and B container set, in which collecting the traffic of the containers in the A and B container set is a container searching sub-strategy, and the container searching sub-strategy indicates that the business containers in the A and B container set are target business containers.

[0050] The agent end 110 searches for the target business container in the container cluster according to the container searching sub-strategy in the traffic collection strategy, and collects the traffic of the target business container.

[0051] In the above examples, the target business container is obtained according to the traffic collection strategy, and the traffic of the business container is collected. Targeted traffic collection can be achieved, and the targeting of threat detection can be improved.

[0052] In an embodiment of the present application, the agent end is further configured to monitor changes of the service containers in the container cluster in real time, and when the target service container in the container cluster changes, the target service container is found again according to the container finding sub-strategy in the traffic collection strategy.

[0053] The agent end 110 is further configured to monitor changes of the service containers in the container cluster in real time. The changes of the service containers can be various, such as addition or deletion of the service containers in the cluster, or addition or exit of a container set of service containers.

[0054] When the target service container in the cloud platform changes, such as addition of a service container in the B container set, the agent end finds the change through the interface of the cluster, and then finds the target service container according to the container finding sub-strategy in the traffic collection strategy, such as collecting the traffic of the containers in the A and B container sets. For example, the agent end can find the newly added service container in the B container set again according to the container finding sub-strategy, and directly take the newly added service container in the B container set as the target service container.

[0055] In the above embodiment, the agent end can monitor the changes of the containers in real time, find the target container again according to the changes of the containers, update the target container, and obtain the traffic of the changed target container in time, thereby improving the threat detection capability of the system.

[0056] In an embodiment of the present application, the agent end includes a first container and a second container. The first container is configured to obtain the traffic collection strategy and the threat detection rule, mirror the network card traffic of the service container to a mirror network card of the second container according to the traffic collection strategy, and further configured to send the threat detection rule to the second container. The second container is configured to receive the threat detection rule, and further configured to listen to the mirror network card to obtain the network card traffic, collect the network card traffic according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic.

[0057] The agent end is deployed in a cloud-native manner in the form of DaemonSet. DaemonSet deploys a container on each node that meets the matching condition, to ensure that a container replica is running on all (or some) nodes. The agent end can be horizontally scaled with the k8s node, and the second container in the agent end can dynamically perceive the size of the node traffic to realize vertical scaling of resources such as CPU and memory.

[0058] For example, the agent container can be set as the first container, and the dp container can be set as the second container, and the agent and the dp container form the agent end.

[0059] The agent container is responsible for receiving a control end 120 command, obtaining a traffic collection strategy, mirroring network card traffic of a service container to a mirror network card of the second container according to the traffic collection strategy, and sending a threat detection rule obtained by the agent container through the control end 120 to the second container.

[0060] The dp container obtains the mirror traffic of the service container by listening to the mirror network card thereof, performs threat detection, and outputs threat alarm information. The alarm information can be externally sent through a kafka or syslog.

[0061] The dp container also regularly communicates with the agent container to realize dynamic updating of an alarm rule.

[0062] The agent end is implemented through the first container and the second container, so that the separation of traffic collection and detection is realized, the robustness of traffic detection is increased, and the management of the first container on the second container can be realized based on the architecture, for example, when the second container fails, the first container can restart the second container, and the management capability of the system is increased.

[0063] In the above embodiment, the control end is divided into the first container and the second container to perform different functions, so that the failure probability is reduced, and the robustness and management capability of the control end are enhanced.

[0064] In an embodiment of the present application, the traffic collection strategy includes a container searching sub-strategy, and the container searching sub-strategy is used to indicate a target service container whose network card traffic needs to be collected; and the first container is further used to search for the target service container according to the container searching sub-strategy in the traffic collection strategy, and mirror the network card traffic of the target service container to the mirror network card of the second container.

[0065] The container searching sub-strategy in the traffic collection strategy is used to indicate a target service container whose network card traffic needs to be collected. After the agent container receives the traffic collection strategy, the target service container is searched according to the container searching sub-strategy in the traffic collection strategy, so that the binding of the collection strategy and the service container is realized. The network card traffic of the target service container is mirrored to the mirror network card of the dp container

[0066] In another example of the present application, the agent container takes the traffic collection strategy, binds the collection strategy and the container asset, collects traffic, and filters according to IP five-tuple conditions.

[0067] In the above embodiment, the target service container is obtained according to the traffic collection strategy, the traffic of the service container is collected, targeted traffic collection can be realized, and the targeting of threat detection can be improved.

[0068] In an embodiment of the present application, the first container is further configured to monitor changes of each service container in the container cluster in real time, and when the target service container in the container cluster changes, the target service container is searched again according to the container searching sub-strategy in the traffic collection strategy.

[0069] The agent container obtains container information of the container cluster through an interface of the container cluster, monitors changes of service containers in the container cluster in real time through the container information, and when the target service container in the container cluster changes, the target service container is searched again according to the container searching sub-strategy.

[0070] In an example of the present application, the agent container monitors changes of the container asset in real time, and dynamically adjusts the collection strategy and the binding relationship of the container asset according to the changes of the container asset.

[0071] In the above embodiment, the agent can monitor changes of the container in real time, search for the target container again according to the changes of the container, implement updates of the target container, and obtain traffic of the changed target container in time, thereby improving the threat detection capability of the system.

[0072] The threat detection system is deployed in a cloud platform where the container cluster is located, realizes a way of local collection and local detection of cloud-native traffic, does not need to send out traffic, saves a large amount of bandwidth resources of the host, and simultaneously the threat detection system can dynamically scale according to changes of the business, thereby realizing adaptive matching of the threat detection performance to the dynamic elasticity and flexibility of the cloud-native.

[0073] Figure 2 A threat detection method of a container cluster is provided in an embodiment of the present application, the method is applied to an agent, the agent is deployed in a cloud platform to which a container cluster belongs, the container cluster includes at least one container, and the method includes the following steps. Figure 2 The method includes the following steps.

[0074] In step 210, a traffic collection strategy and a threat detection rule are obtained.

[0075] In step 220, network card traffic of a service container is collected according to the traffic collection strategy.

[0076] In step 230, threat detection is performed according to the threat detection rule and the network card traffic.

[0077] A cloud platform is provided in an embodiment of the present application, and includes the threat detection system of the container cluster in any of the above embodiments.

[0078] The computer readable storage medium provided in the embodiments of the present application stores a computer program, and the computer program instructs a computer to implement the threat detection system of the container cluster in any of the above embodiments when the computer is deployed.

[0079] In the embodiments provided in the present application, the embodiments can be combined with each other to form new embodiments without conflict.

[0080] In the embodiments provided in the present application, multiple refers to two or more than two.

[0081] In the embodiments provided in the present application, it should be understood that, if the functions are realized in the form of software function modules and sold or used as independent products, the software function modules can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts of the technical solutions that make contributions to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0082] In this document, relational terms such as first and second and the like can merely be used to distinguish one entity or action from another, without necessarily requiring or implying any such actual relationship or order between or among the entities or actions.

[0083] The above only describes the embodiments of the present application and does not limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A threat detection system for a cluster of containers, the system comprising: The system is deployed in a cloud platform where a container cluster is located, the container cluster includes at least one business container, and the system includes an agent end; The agent end is configured to acquire a traffic collection strategy and a threat detection rule, collect network card traffic of the business container according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic; The system further includes a control end, which is configured to control the traffic collection strategy, and further configured to update and maintain the threat detection rule; and the control end is further configured to distribute the traffic collection strategy and the threat detection rule to the agent end; The control end is further configured to acquire container information of all business containers in the container cluster through an interface of the container cluster, group the business containers in the container cluster according to the container information of all the business containers to obtain a plurality of container groups, and receive a selection instruction for the plurality of container groups, the selection instruction being configured to indicate a container group selected by a user and / or a business container in the container group, and generate the traffic collection strategy according to container information of a business container corresponding to the selection instruction.

2. The system of claim 1, wherein, The traffic collection strategy includes a container searching sub-strategy, and the container searching sub-strategy is configured to indicate a target business container for which network card traffic needs to be collected; The agent end is further configured to search for the target business container according to the container searching sub-strategy in the traffic collection strategy, and collect network card traffic of the target business container.

3. The system of claim 2, wherein, The agent end is further configured to monitor changes of the business containers in the container cluster in real time, and search for a target business container according to the container searching sub-strategy in the traffic collection strategy when the target business container in the container cluster changes.

4. The system of any one of claims 1 to 3, wherein, The agent end includes a first container and a second container, wherein The first container is configured to acquire the traffic collection strategy and the threat detection rule, mirror network card traffic of a business container to a mirror network card of the second container according to the traffic collection strategy, and send the threat detection rule to the second container; The second container is configured to receive the threat detection rule, listen to the mirror network card to acquire the network card traffic, collect the network card traffic according to the traffic collection strategy, and perform threat detection according to the threat detection rule and the network card traffic.

5. The system of claim 4, wherein, The traffic collection strategy includes a container searching sub-strategy, and the container searching sub-strategy is configured to indicate a target business container for which network card traffic needs to be collected; The first container is further configured to search for the target business container according to the container searching sub-strategy in the traffic collection strategy, and mirror network card traffic of the target business container to a mirror network card of the second container.

6. The system of claim 4, wherein, The first container is further configured to monitor changes of the business containers in the container cluster in real time, and search for a target business container according to the container searching sub-strategy in the traffic collection strategy when the target business container in the container cluster changes. 7.A method for detecting a threat of a container cluster, the method comprising: The method is applied to an agent end deployed in a cloud platform to which a container cluster belongs, the container cluster including at least one service container, and the method includes: acquiring a traffic collection strategy and a threat detection rule; collecting network card traffic of the service container according to the traffic collection strategy; performing threat detection according to the threat detection rule and the network card traffic; The cloud platform further includes a control end, which is configured to control the traffic collection strategy, update and maintain the threat detection rule, and distribute the traffic collection strategy and the threat detection rule to the agent end. The control end is further configured to acquire container information of all service containers in the container cluster through an interface of the container cluster, group the service containers in the container cluster according to the container information of all the service containers to obtain a plurality of container groups, receive a selection instruction for the plurality of container groups, and generate the traffic collection strategy according to container information of service containers corresponding to the selection instruction.

8. A cloud platform, characterized by, The system includes: The system according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program instructs a computer to implement the system according to any one of claims 1 to 6 when the computer is deployed.

Citation Information

Patent Citations

  • Docker-based data acquisition method and device, computer equipment and storage medium

    CN110457555A

  • Integrated network security detection method and device

    CN111935074A