Post-penetration attack traction method and system for cloud native environment
By building sensitive behavior baselines in cloud-native environments and using tag propagation algorithms and eBPF technology, we can identify and traction post-penetration attack behaviors, and solve the problem that post-penetration attack behaviors are difficult to efficiently traction in cloud-native environments, improving system security and providing convenience for attackers' method analysis.
Patent Information
- Application Number
- CN202411925984.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-25
AI Technical Summary
The post-penetration attack behavior in a cloud-native environment is difficult to efficiently pull, resulting in low system security and the attacker's attack methods are difficult to be effectively captured and analyzed.
By constructing sensitive behavior baselines and system call monitoring, combining tag propagation algorithms and eBPF technology, we identify and traction post-infiltration attack behaviors, and guide attackers to the Miwang cluster for trapping.
It realizes efficient traction of post-penetration attack behavior in cloud-native environments, improves the system's defense capabilities, and provides security personnel with convenient conditions to analyze attacker methods.
Smart Images

Figure CN119945727A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cloud native security and Linux host security, and specifically relates to a post-penetration attack traction method and system for a cloud native environment. Background Art
[0002] As the global digitalization trend gradually deepens, cloud computing has become an important digital infrastructure for the development of informatization in the world today. As enterprises continue to cloudify their IT infrastructure and migrate their businesses to the cloud, the network boundaries of enterprises are also expanding to the cloud. At the same time, due to the open, complex and decentralized nature of the cloud, the difficulty of protecting cloud security has also increased dramatically.
[0003] Security protection in a cloud-native environment can be divided into protection against external attacks and protection against post-penetration attacks. Post-penetration attacks refer to an attack method in which an attacker obtains an initial foothold in the system through some means, and then conducts detection, movement, and privilege escalation to find and control more valuable targets and further expand the impact of the attack. Post-penetration attacks mean that the attacker has reached the inside of the environment and has begun to compromise and damage the more vulnerable parts of the security architecture, which has a great impact.
[0004] Compared with external attacks, post-penetration attacks have longer attack cycles and attack paths. Among the existing security defense solutions, attack traction technology is very suitable for defending and trapping post-penetration attacks. Attack traction technology actively or passively tractions the attack to slow down the attacker and improve the system's defense capabilities. It can also obtain the attack payload and attack route used by the attacker by monitoring the network and host behavior. Therefore, based on an in-depth analysis of the cloud-native environment, designing a post-penetration attack traction framework for the cloud-native environment to improve system security and facilitate security personnel to analyze the attacker's attack methods has become an urgent problem to be solved. Summary of the invention
[0005] In response to the above problems, the present invention proposes a post-exploitation attack traction method and system for cloud-native environments. By constructing a sensitive behavior baseline and monitoring system calls, post-exploitation attack behaviors in cloud-native environments are identified and pulled in to capture attackers.
[0006] In order to achieve the above object, the specific technical solution adopted by the present invention is:
[0007] A post-penetration attack traction method for a cloud native environment, the steps of which include:
[0008] 1) The system call behavior of each attack method in the Kubernetes business cluster in the cloud native environment is regarded as a sensitive behavior to obtain a sensitive behavior list;
[0009] 2) For the target Kubernetes business cluster that needs attack traction protection, the target Kubernetes business cluster is run in a local area network isolated from the outside world; according to the execution of each sensitive behavior in the sensitive behavior list in the normal business of the target Kubernetes business cluster, a sensitive behavior baseline corresponding to the sensitive behavior is constructed to obtain a sensitive behavior baseline list;
[0010] 3) Desensitize and clone the target Kubernetes business cluster, and create a honeynet cluster for trapping attacks on the target Kubernetes business cluster;
[0011] 4) The target Kubernetes business cluster and the honeynet cluster are deployed on the public network and provide external services. The system call behavior in the target Kubernetes business cluster is monitored and recorded. When a sensitive behavior i is monitored and the call chain of the sensitive behavior i meets the sensitive behavior baseline in the sensitive behavior baseline list, it is regarded as a normal business operation; otherwise, the currently executed sensitive behavior i is judged to be a malicious behavior;
[0012] 5) Drag the detected malicious attacker to the honeynet cluster.
[0013] Furthermore, the method for obtaining the sensitive behavior list is:
[0014] 11) Categorize the attack methods available to attackers in Kubernetes business clusters in cloud-native environments;
[0015] 12) Use the automated post-penetration tools in the Kubernetes business cluster to attack the Kubernetes business cluster, monitor the system call behavior in the Kubernetes business cluster, and obtain the system call behavior corresponding to the automated attack method;
[0016] 13) Collect relevant CVEs of the Kubernetes business cluster, reproduce each CVE in the Kubernetes business cluster, and obtain the system call behavior that occurs during the reproduction process;
[0017] 14) Select the key system call behaviors in each attack process from the system call behaviors obtained in steps 12) and 13) as sensitive behaviors, obtain the sensitive behaviors corresponding to each attack method, and construct a sensitive behavior list.
[0018] Furthermore, the method for constructing the sensitive behavior baseline is:
[0019] 21) Record the system calls that occur during a period of normal business operation in the target Kubernetes business cluster;
[0020] 22) For each system call a recorded in step 21), if the system call a matches a sensitive behavior j in the sensitive behavior list, then trace back upward according to the parent-child process call relationship of sensitive behavior j to obtain the behavior chain of sensitive behavior j;
[0021] 23) Record the process name, parent-child process relationship, system call type, and system call parameter information in the behavior chain of each sensitive behavior as the sensitive behavior baseline of the corresponding sensitive behavior to obtain a sensitive behavior baseline list.
[0022] Furthermore, a label propagation algorithm is used to monitor and record the system call behavior in the target Kubernetes business cluster. The method is as follows:
[0023] 41) Create a process-label attribute mapping table, mark all system calls monitored in the target Kubernetes business cluster as benign labels, and form a mapping record with the corresponding process and label attribute, which is inserted into the process-label attribute mapping table;
[0024] 42) According to the parent process ID of the system call p monitored in step 41), the label of the parent process of the process to which the system call p belongs is searched in the process-label attribute mapping table to determine whether it is malicious. If it is a malicious label, the system call p is marked as a malicious label and recorded in the process-label attribute mapping table;
[0025] 43) Obtain the corresponding parent process name according to the parent process ID of the system call p, and search the child process called by the parent process name in the sensitive behavior baseline list according to the parent process name to obtain the parent process-child process call relationship; if the parent process name is not in the sensitive behavior baseline list, mark the system call p as a malicious label and record it in the process-label attribute mapping table;
[0026] 44) Determine whether the system call p is a sensitive behavior. If it is a sensitive behavior, then the system call p is a malicious behavior.
[0027] Furthermore, eBPF technology is used to pull malicious attackers into the honeynet cluster. The method is as follows:
[0028] 51) When establishing the target Kubernetes business cluster, a corresponding false sensitive file is created for each selected sensitive file, so that when an attacker reads the sensitive file, the system call parameters corresponding to the sensitive file are modified, so that the attacker reads the corresponding false sensitive file;
[0029] 52) modifying the parameters in the lateral movement operation command line for the attacker to continue the post-exploitation behavior in the honeynet cluster when the attacker connects to the database in the honeynet cluster;
[0030] 53) When using kubectl to access the API Server in the target Kubernetes business cluster and operate on the resources in the target Kubernetes business cluster, the attacker is allowed to access the API Server in the honeynet cluster by modifying the system call parameters and continue to operate on the resources in the honeynet cluster;
[0031] 54) When the attacker performs a rebound shell action on the target Kubernetes business cluster, the system call of the rebound shell action will be terminated, and the corresponding container or node in the honeynet cluster will be notified to perform a rebound shell, so that the attacker obtains the shell in the honeynet cluster and conducts subsequent attacks;
[0032] 55) Directly block other system calls executed by the attacker on the target Kubernetes business cluster.
[0033] Furthermore, secure inbound and outbound rules are set between the target Kubernetes business cluster and the honeynet cluster to achieve network isolation between the target Kubernetes business cluster and the honeynet cluster.
[0034] A post-penetration attack traction system for cloud-native environments, characterized by comprising a behavior monitoring module, an attack traction module and a honeynet cluster;
[0035] The behavior monitoring module is used to treat the system call behavior of each attack method in the Kubernetes business cluster in the cloud native environment as a sensitive behavior to obtain a sensitive behavior list; and for the target Kubernetes business cluster that needs attack traction protection, run the target Kubernetes business cluster in a local area network isolated from the outside world; according to the execution of each sensitive behavior in the sensitive behavior list in the normal business of the target Kubernetes business cluster, construct a sensitive behavior baseline corresponding to the sensitive behavior to obtain a sensitive behavior baseline list; and when the target Kubernetes business cluster and the honeynet cluster are both deployed on the public network and provide services to the outside, monitor and record the system call behavior in the target Kubernetes business cluster, and when a sensitive behavior i is monitored and the call chain of the sensitive behavior i meets the sensitive behavior baseline in the sensitive behavior baseline list, it is regarded as a normal business operation; otherwise, the currently executed sensitive behavior i is determined to be a malicious behavior;
[0036] The attack traction module is used to pull the detected attacker with malicious behavior to the honeynet cluster;
[0037] The honeynet cluster is used to trap attacks on the target Kubernetes business cluster; wherein the honeynet cluster is obtained by desensitizing and cloning the target Kubernetes business cluster.
[0038] The steps of the post-penetration attack traction method for a cloud native environment of the present invention include:
[0039] 1) Summarize and organize the attack methods in the Kubernetes business cluster in the cloud-native environment, reproduce the attack methods in the Kubernetes business cluster, observe and record the system call behavior during the reproduction process, and build a list of sensitive behaviors;
[0040] 2) For Kubernetes business clusters that provide real services to the outside world and need to be protected using the attack traction method, first run them in a local area network isolated from the outside world, and construct a sensitive behavior baseline for each sensitive behavior in the sensitive behavior list during normal business execution;
[0041] 3) Desensitize and clone the Kubernetes business cluster to create a similar honeynet cluster that will not affect normal business, which is used to trap attackers who are subsequently attracted;
[0042] 4) Deploy both the Kubernetes business cluster and the honeynet cluster on the public network and provide normal external services. Monitor and record the system call behavior in the Kubernetes business cluster, and use the label propagation algorithm to judge the sensitive behavior found in the monitoring. If the call chain of the sensitive behavior found in the monitoring meets the sensitive behavior baseline, it is considered a normal business operation; otherwise, the currently executed sensitive behavior is judged to be malicious behavior;
[0043] 5) For detected malicious behaviors, eBPF technology is used to modify system calls to achieve the effect of attack traction, prevent attackers from causing damage to the Kubernetes business cluster, and pull attackers to the honeynet cluster.
[0044] Furthermore, the sensitive behavior list is constructed through the following aspects:
[0045] 1) Based on the Kubernetes threat matrix proposed by Y. Weizman, roughly classify the attack methods that attackers may use in Kubernetes business clusters in cloud native environments;
[0046] 2) In-depth analysis of the functions and source code of the currently popular automated post-penetration tools in the Kubernetes business cluster, and attempts to run automated attacks in the Kubernetes business cluster, observing their system call behaviors and using them as system call behaviors for corresponding automated attack methods;
[0047] 3) Try to collect CVEs (Common Vulnerabilities and Exposures) related to Kubernetes business clusters in recent years, reproduce each CVE in the Kubernetes business cluster, and sort out the system call behaviors that occur in the reproduction process;
[0048] 4) Summarize and organize the system call behaviors obtained above, select the set key system call behaviors in each attack process as sensitive behaviors, and construct a sensitive behavior list.
[0049] Furthermore, the sensitive behavior baseline is constructed through the following steps:
[0050] 1) Record system calls that occur during a period of normal business operation;
[0051] 2) According to the existing sensitive behavior list, find each sensitive behavior in the sensitive behavior list in the recorded system calls, and trace back to restore the complete behavior chain of each sensitive behavior according to the parent process related information in the sensitive behavior system call information;
[0052] 3) Record the process name, parent-child process relationship, system call type, and system call parameter information in the behavior chain;
[0053] 4) Construct a corresponding sensitive behavior baseline for each item in the sensitive behavior list in turn to obtain a sensitive behavior baseline list.
[0054] Furthermore, the modification of system calls is mainly achieved by modifying system call parameters, such as modifying the file name opened by the attacker, or modifying the database connection information specified in the command line, etc. to achieve attack traction.
[0055] The positive effects of the present invention are as follows:
[0056] With the rapid development of cloud-native technology, the difficulty of security protection in cloud-native environments has also increased, and at the same time, there is a need to attract attackers to further capture and analyze their attack methods. In response to the problem that post-exploitation attack behaviors in cloud-native environments cannot be efficiently attracted, the present invention proposes a method that combines label propagation technology with eBPF technology to attract attackers who are performing post-exploitation behaviors to the Kubernetes cluster honeynet. Through the label propagation mechanism, the legitimacy of the execution path of sensitive behaviors is judged, and the attacker's post-exploitation behavior is discovered; through the attack traction technology based on eBPF, the malicious system call behavior is directly modified, which has a smaller time overhead than the traffic redirection and container cloning traction methods, and achieves efficient traction of post-exploitation behaviors. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 It is the overall flow chart of the system of the solution of the present invention.
[0058] Figure 2 It is the detection flow chart of label propagation algorithm.
[0059] Figure 3 It is a schematic diagram of the specific implementation method of the attack traction module. DETAILED DESCRIPTION
[0060] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention and to make the objects, features and advantages of the present invention more obvious and understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments.
[0061] This embodiment provides a post-penetration attack traction system for cloud native environments. Figure 1 As shown, the specific steps include:
[0062] Step 100: Desensitize sensitive data in the existing business cluster, including information in the database, containers, and nodes. After processing, clone the entire business cluster, create a honeynet cluster with the original business cluster architecture, and set secure inbound and outbound rules to achieve network isolation between the business cluster and the honeynet cluster.
[0063] Step 200: Take the key system call behaviors that appear in the process of reproducing various attack methods in the Kubernetes cluster as sensitive behaviors and build a sensitive behavior list. Run the Kubernetes business cluster without external interference, and build a sensitive behavior baseline during the cluster operation process based on the sorted sensitive behavior list. Record the system calls during the operation process, find the parent process of the sensitive system call and the system call operation of the parent process and record them. By continuously tracing back, record the system call type, system call parameters and process name information associated with each pair of parent and child processes, build a complete call chain baseline for each sensitive system call, and add it to the sensitive behavior baseline list.
[0064] Step 300: Run the Kubernetes business cluster in a real environment and deploy a behavior monitoring module to monitor system calls in the cluster. Use a label propagation-based method to combine the parent-child process call relationship and the sensitive behavior baseline to determine the label attributes, and determine whether the system call is malicious based on the label attributes.
[0065] Step 400: The attack traction module is used to process malicious sensitive system calls found in the Kubernetes business cluster, and induce attackers to attack the honeynet cluster by modifying system call parameters.
[0066] Figure 2 The flowchart shown is a flow chart of monitoring and detecting system calls using the label propagation algorithm designed by the present invention, which is specifically described as follows:
[0067] Step 310: Create a process-label attribute mapping table. For all system calls monitored in the Kubernetes business cluster, they are marked as benign labels. The corresponding process and label attributes form a mapping record and are inserted into the process-label attribute mapping table.
[0068] Step 320: Based on the parent process ID in the obtained system call information, check in a process-label attribute mapping table whether the label of the parent process of the process to which the system call belongs is malicious. If it is a malicious label, the system call will also be marked with a malicious label and recorded in the process-label attribute mapping table.
[0069] Step 330: Obtain the parent process name based on the parent process ID in the obtained system call information, and use the process corresponding to the current system call as the child process. Search for the parent process-child process call relationship in the sensitive behavior baseline list. If the call relationship does not conform to the sensitive behavior baseline, the system call will be labeled malicious and recorded in the process-label attribute mapping table.
[0070] Step 340: If the current system call is tagged with a malicious label, check whether the system call is in the sensitive behavior list. If the label is a malicious label and a sensitive behavior, the system will issue an alarm and hand it over to the attack traction module to process the system call.
[0071] Figure 3 The following is a specific implementation method of the attack traction module. It uses the eBPF technology to add mount points in the kernel and modify the system calls. Combined with the honeynet technology, it modifies the discovered malicious system calls to achieve the effect of attack traction or blocking, and induces attackers to switch from the Kubernetes business cluster to the honeynet cluster. The implementation methods are as follows:
[0072] 1) For the reading behavior of sensitive files such as kubeconfig, when the Kubernetes business cluster is established, similar false sensitive files are created. When the attacker reads the sensitive file, the attack traction module modifies its system call parameters so that the attacker reads the false sensitive file.
[0073] 2) For lateral movement operations such as connecting to a database, the attack traction module modifies the parameters in the command line, such as the database IP, so that the attacker can connect to the database in the honeynet cluster and continue the post-infiltration behavior in the honeynet cluster.
[0074] 3) For the behavior of using kubectl to access the API Server and operate the resources in the cluster, by modifying the system call parameters and using the kubeconfig of the Honeynet cluster, the attacker can access the API Server in the Honeynet cluster and then operate the resources in the Honeynet cluster.
[0075] 4) For the rebound shell behavior, the attack traction module will terminate the system call and notify the corresponding container or node in the honeynet cluster to rebound the shell, so that the attacker can obtain the shell in the honeynet cluster and carry out subsequent attacks.
[0076] 5) For other system calls, the attack traction module will directly block them to provide protection for the system.
[0077] Finally, it should be noted that the above implementation cases are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention is described in detail using examples, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention, which should be included in the scope of the claims of the present invention.
Claims
1. A post-penetration attack traction method for a cloud native environment, the steps of which include: 1) The system call behavior of each attack method in the Kubernetes business cluster in the cloud native environment is regarded as a sensitive behavior to obtain a sensitive behavior list; 2) For the target Kubernetes business cluster that needs attack traction protection, the target Kubernetes business cluster is run in a local area network isolated from the outside world; according to the execution of each sensitive behavior in the sensitive behavior list in the normal business of the target Kubernetes business cluster, a sensitive behavior baseline corresponding to the sensitive behavior is constructed to obtain a sensitive behavior baseline list; 3) Desensitize and clone the target Kubernetes business cluster, and create a honeynet cluster for trapping attacks on the target Kubernetes business cluster; 4) The target Kubernetes business cluster and the honeynet cluster are deployed on the public network and provide external services. The system call behavior in the target Kubernetes business cluster is monitored and recorded. When a sensitive behavior i is monitored and the call chain of the sensitive behavior i meets the sensitive behavior baseline in the sensitive behavior baseline list, it is regarded as a normal business operation; otherwise, the currently executed sensitive behavior i is judged to be a malicious behavior; 5) Drag the detected malicious attacker to the honeynet cluster.
2. The method according to claim 1, characterized in that: The method for obtaining the sensitive behavior list is: 11) Categorize the attack methods available to attackers in Kubernetes business clusters in cloud-native environments; 12) Use the automated post-penetration tools in the Kubernetes business cluster to attack the Kubernetes business cluster. And monitor the system call behavior in the Kubernetes business cluster to obtain the system call behavior corresponding to the automated attack method; 13) Collect relevant CVEs of the Kubernetes business cluster, reproduce each CVE in the Kubernetes business cluster, and obtain the system call behavior that occurs during the reproduction process; 14) Select the key system call behaviors in each attack process from the system call behaviors obtained in steps 12) and 13) as sensitive behaviors, obtain the sensitive behaviors corresponding to each attack method, and construct a sensitive behavior list.
3. The method according to claim 2, characterized in that The method for constructing the sensitive behavior baseline is: 21) Record the system calls that occur during a period of normal business operation in the target Kubernetes business cluster; 22) For each system call a recorded in step 21), if the system call a matches a sensitive behavior j in the sensitive behavior list, then trace back upward according to the parent-child process call relationship of sensitive behavior j to obtain the behavior chain of sensitive behavior j; 23) Record the process name, parent-child process relationship, system call type, and system call parameter information in the behavior chain of each sensitive behavior as the sensitive behavior baseline of the corresponding sensitive behavior to obtain a sensitive behavior baseline list.
4. The method according to claim 1, 2 or 3, characterized in that: The label propagation algorithm is used to monitor and record the system call behavior in the target Kubernetes business cluster. The method is as follows: 41) Create a process-label attribute mapping table, mark all system calls monitored in the target Kubernetes business cluster as benign labels, and form a mapping record with the corresponding process and label attribute, which is inserted into the process-label attribute mapping table; 42) According to the parent process ID of the system call p monitored in step 41), the label of the parent process of the process to which the system call p belongs is searched in the process-label attribute mapping table to determine whether it is malicious. If it is a malicious label, the system call p is marked as a malicious label and recorded in the process-label attribute mapping table; 43) Obtain the corresponding parent process name according to the parent process ID of the system call p, and search the child process called by the parent process name in the sensitive behavior baseline list according to the parent process name to obtain the parent process-child process call relationship; if the parent process name is not in the sensitive behavior baseline list, mark the system call p as a malicious label and record it in the process-label attribute mapping table; 44) Determine whether the system call p is a sensitive behavior. If it is a sensitive behavior, then the system call p is a malicious behavior.
5. The method according to claim 1, 2 or 3, characterized in that: Use eBPF technology to pull malicious attackers to the honeynet cluster. The method is as follows: 51) When establishing the target Kubernetes business cluster, a corresponding false sensitive file is created for each selected sensitive file, so that when an attacker reads the sensitive file, the system call parameters corresponding to the sensitive file are modified, so that the attacker reads the corresponding false sensitive file; 52) modifying the parameters in the lateral movement operation command line for the attacker to continue the post-exploitation behavior in the honeynet cluster when the attacker connects to the database in the honeynet cluster; 53) When using kubectl to access the API Server in the target Kubernetes business cluster and operate on the resources in the target Kubernetes business cluster, the attacker is allowed to access the API Server in the honeynet cluster by modifying the system call parameters, and continue to operate on the resources in the honeynet cluster; 54) When the attacker performs a rebound shell action on the target Kubernetes business cluster, the system call of the rebound shell action will be terminated, and the corresponding container or node in the honeynet cluster will be notified to perform a rebound shell, so that the attacker obtains the shell in the honeynet cluster and conducts subsequent attacks; 55) Directly block other system calls executed by the attacker on the target Kubernetes business cluster.
6. The method according to claim 1, 2 or 3, characterized in that: Secure inbound and outbound rules are set between the target Kubernetes business cluster and the honeynet cluster to achieve network isolation between the target Kubernetes business cluster and the honeynet cluster.
7. A post-penetration attack traction system for cloud native environments, characterized in that: Includes behavior monitoring module, attack traction module and honeynet cluster; The behavior monitoring module is used to treat the system call behavior of each attack method in the Kubernetes business cluster in the cloud native environment as a sensitive behavior to obtain a sensitive behavior list; And for the target Kubernetes business cluster that needs attack traction protection, run the target Kubernetes business cluster in a local area network isolated from the outside world; according to the execution of each sensitive behavior in the sensitive behavior list in the normal business of the target Kubernetes business cluster, construct a sensitive behavior baseline corresponding to the sensitive behavior to obtain a sensitive behavior baseline list; When the target Kubernetes business cluster and the honeynet cluster are both deployed on the public network and provide external services, the system call behavior in the target Kubernetes business cluster is monitored and recorded. When a sensitive behavior i is monitored and the call chain of the sensitive behavior i conforms to the sensitive behavior baseline in the sensitive behavior baseline list, it is regarded as a normal business operation; Otherwise, the currently executed sensitive behavior i is determined to be a malicious behavior; The attack traction module is used to pull the detected attacker with malicious behavior to the honeynet cluster; The honeynet cluster is used to trap attacks on the target Kubernetes business cluster; wherein the honeynet cluster is obtained by desensitizing and cloning the target Kubernetes business cluster.
Citation Information
Patent Citations
Network attack event traceability processing method and device, equipment and storage medium
CN111935192A
Honeypot cluster detection method and system based on directional drainage
CN113992368A
Application active spoofing defense method and system under cloud native, equipment and storage medium
CN116192506A
Real-time attack detection method and system based on label transfer and event baseline learning
CN118827248A
Large scale high-interactive honeypot farm
US20210194925A1