Resource security isolation method in containerized environment

By selecting appropriate container technologies in a containerized environment and generating isolation security policies, detecting abnormal behaviors in real time and regularly audits, the resource isolation and security issues between containers are solved, and the system's security and resource management efficiency are improved.

CN120277657APending Publication Date: 2025-07-08HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510703562.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In a containerized environment, resource conflicts and security vulnerabilities between containers lead to system stability and performance degradation, how to ensure resource isolation and security between containers.

Method used

By selecting container technology that meets the needs of resource security isolation, combining with the operating system environment to generate container isolation security policies, detect abnormal behaviors in real time, regularly audits and risk assessments, and ensure isolation between containers.

Benefits of technology

Improve the security, stability and reliability of the system, and optimize resource utilization and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277657A_ABST
    Figure CN120277657A_ABST
Patent Text Reader

Abstract

The invention provides a resource security isolation method in a containerization environment, which relates to the technical field of containerization, and comprises the following steps: selecting a target container technology meeting a resource security isolation requirement; obtaining a container isolation security policy based on a target container technology, and realizing a resource security isolation operation between the containers; abnormal behaviors of the containers are detected in real time, and regular auditing and risk assessment are carried out to ensure the isolation between the containers. By selecting a container technology meeting the current resource security isolation requirement, a container isolation security strategy is generated in combination with an operating system environment, and resource security isolation operation between containers is achieved; according to the method, abnormal behaviors of the containers are detected in real time, regular auditing and risk assessment are carried out, so that isolation between the containers is ensured, the safety, stability and reliability of the system are effectively improved, and resource utilization and management are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of containerization, and particularly to a method for resource security isolation in a containerized environment. Background Art

[0002] In recent years, with the continuous development and popularization of cloud computing technology, more and more enterprises have chosen to migrate their businesses to the cloud. Containerization technology, as one of the important technologies of cloud computing, improves the portability and scalability of application programs, and at the same time reduces the operation and maintenance costs, enabling enterprises to quickly deploy and expand applications according to actual needs.

[0003] However, in a containerized environment, since multiple containers share the resources of the same physical machine or virtual machine, resource conflicts between containers often occur, or security vulnerabilities or malicious behaviors in a certain container spread to other containers, resulting in a decline in the stability and performance of the system. Therefore, how to ensure the resource isolation and security between containers to ensure the stable and reliable operation of the system has become one of the current research focuses.

[0004] Therefore, the present invention provides a method for resource security isolation in a containerized environment. Summary of the Invention

[0005] The present invention provides a method for resource security isolation in a containerized environment, which is used to generate a container isolation security policy by selecting a container technology that meets the current resource security isolation requirements and combining the operating system environment, so as to realize the resource security isolation operation between containers; detect abnormal behaviors, conduct regular audits and risk assessments on containers in real time to ensure the isolation between containers, effectively improve the security, stability and reliability of the system, and optimize the resource utilization and management.

[0006] The present invention provides a method for resource security isolation in a containerized environment, including: Step 1: Select a target container technology that meets the resource security isolation requirements; Step 2: Obtain a container isolation security policy based on the target container technology to realize the resource security isolation operation between containers; Step 3: Detect abnormal behaviors, conduct regular audits and risk assessments on containers in real time to ensure the isolation between containers.

[0007] Preferably, selecting a target container technology that meets the resource security isolation requirements includes: Obtain a first container technology that meets the resource types and isolation levels to be isolated currently, and establish a list of the first container technology; Introduce a preset requirement index evaluation mechanism, and evaluate the satisfaction of all the first container technologies in the first container technology list based on the isolation requirement index to obtain the first index evaluation result; Summarize all the first evaluation results and conduct weighted analysis to obtain the comprehensive requirement evaluation value; Regard the first container technology with the largest comprehensive requirement evaluation value as the target container technology.

[0008] Preferably, the isolation requirement index includes a security requirement index, a compatibility requirement index, a performance requirement index, and a management requirement index.

[0009] Preferably, the calculation formula for the comprehensive requirement evaluation value is as follows: ; where z represents the comprehensive requirement evaluation value of the current first container technology; represents the first index evaluation result of the i-th isolation requirement index of the current first container technology, where, ; represents the contribution weight of the i-th isolation requirement index to the realization of resource security isolation requirements for the evaluation container technology; represents the total amount of evaluation data used to evaluate the comprehensive satisfaction degree of the first container technology for resource security isolation; represents the amount of evaluation data used to evaluate the satisfaction degree of the first container technology for the i-th isolation requirement index; represents the data evaluation preference correction factor of the i-th isolation requirement index; represents the loss compensation factor for calculating the index evaluation; represents the evaluation adjustment balance coefficient; ln represents the natural logarithm; e represents the mathematical constant, which is the base of the natural logarithm.

[0010] Preferably, based on the target container technology, obtain the container isolation security policy to implement the resource security isolation operation between containers, including: According to the operating system environment for implementing the target container technology currently, obtain the first container isolation policy that supports the target container technology to achieve resource security isolation; Summarize all the obtained first container isolation policies, and establish a resource isolation method set, a resource restriction method set, and a network isolation method set based on the isolation direction; When there is only a single operation method in the resource isolation method set, the resource restriction method set, or the network isolation method set, output the current operation method as the first security policy for the corresponding isolation direction; When there are multiple operation methods in the resource isolation method set, the resource restriction method set, or the network isolation method set, mark the corresponding method set as the method set to be screened; Regard all the operation methods in the method set to be screened as the methods to be screened; Extract the historical isolation data of performing corresponding isolation direction operations using the method to be screened within a preset time period, and compare it with the resource data that needs to be safely isolated currently to obtain the first similarity coefficient; Evaluate the operation performance of performing corresponding isolation direction operations within a preset time period for the method to be screened to obtain the first operation performance coefficient; Perform combined analysis on the first similarity coefficient and the first operation performance coefficient to determine the method matching degree; Take the method to be screened with the highest method matching degree as the first security policy for the corresponding isolation direction and output it; Combine the first security policies of all isolation directions with the preset permission management and access policies to generate a container isolation security policy, and implement the resource security isolation operation between containers.

[0011] Preferably, it further includes: Use a preset monitoring tool to collect the data of service monitoring performance indicators in real time to obtain service indicator data; Compare and analyze the service indicator data at the current moment with the set indicator threshold range to obtain the first absolute difference of indicators; If there is no service indicator data that does not belong to the set indicator threshold range, it is determined that the service demand of the current container is normal; If there is service indicator data that does not belong to the set indicator threshold range, it is determined that the service demand of the current container has changed; Based on the service indicator data, analyze and evaluate the change in service demand, generate a container management request, and then transmit it to the resource management system to dynamically adjust the resource quota of the container to achieve flexible resource limitation.

[0012] Preferably, analyzing and evaluating the change in service demand based on the service indicator data to generate a container management request includes: Calibrate the corresponding service monitoring performance indicators with service indicator data greater than the upper limit of the set indicator threshold and the first absolute difference of indicators greater than the set difference threshold of indicators as the first indicator; Calibrate the corresponding service monitoring performance indicators with service indicator data greater than the upper limit of the set indicator threshold and the first absolute difference of indicators not greater than the set difference threshold of indicators as the second indicator; Calibrate the corresponding service monitoring performance indicators with service indicator data less than the lower limit of the set indicator threshold and the first absolute difference of indicators greater than the set difference threshold of indicators as the third indicator; Calibrate the corresponding service monitoring performance indicators with service indicator data less than the lower limit of the set indicator threshold and the first absolute difference of indicators not greater than the set difference threshold of indicators as the fourth indicator; Based on the combined analysis of the first index, the second index, the third index, the fourth index, the corresponding absolute difference of the first index, and the influence degree of the index performance, the evaluation coefficient of the service demand change of the current container is calculated; When the evaluation coefficient of the service demand change is less than the set change evaluation threshold, it is determined that the change adjustment level of the service demand change of the current container is level two; Using the second change adjustment plan extracted from the level-adjustment plan table that matches the change adjustment level of level two, a container management request is generated; When the evaluation coefficient of the service demand change is not less than the set change evaluation threshold, it is determined that the change adjustment level of the service demand change of the current container is level one; Extract the first change adjustment plan from the level-adjustment plan table that matches the change adjustment level of level one; After adjusting the adjustment parameters in the first change adjustment plan by using the scaling coefficient, a container management request is generated; Among them, the calculation formula of the scaling coefficient is as follows: ; In the formula, K represents the scaling coefficient; represents the number of service monitoring performance indicators whose service index data is greater than the upper limit of the set index threshold; represents the corresponding absolute difference of the first index of the service monitoring performance indicator whose j-th service index data at the current moment is greater than the upper limit of the set index threshold, where, ; represents the upper limit of the set index threshold corresponding to the service monitoring performance indicator whose j-th service index data is greater than the upper limit of the set index threshold; represents the average index data value of the service monitoring performance indicator whose j-th service index data is greater than the upper limit of the set index threshold within the preset time period T; represents the influence weight of the service monitoring performance indicator whose j-th service index data is greater than the upper limit of the set index threshold on the adjusted resource quota; represents the data trend change coefficient of the service monitoring performance indicator whose j-th service index data is greater than the upper limit of the set index threshold within the preset time period T; represents the number of service monitoring performance indicators whose service index data is less than the lower limit of the set index threshold; represents the corresponding absolute difference of the first index of the service monitoring performance indicator whose g-th service index data at the current moment is less than the lower limit of the set index threshold, where, ; represents the average index data value of the service monitoring performance indicator whose g-th service index data is less than the lower limit of the set index threshold within the preset time period T; Denoted as the corresponding set index threshold lower limit of the service monitoring performance index where the g-th service index data is less than the set index threshold lower limit; Denoted as the data trend change coefficient of the service monitoring performance index where the g-th service index data is less than the set index threshold lower limit within the preset time period T; Denoted as the influence weight of the service monitoring performance index where the g-th service index data is less than the set index threshold lower limit on adjusting the resource quota; Denoted as the loss compensation factor.

[0013] Preferably, perform real-time detection of abnormal behaviors, regular auditing, and risk assessment on containers to ensure the isolation between containers, including: Real-time collect the network traffic data and container log data between containers, and perform preprocessing to obtain target detection data; Extract features from the network traffic data and container log data to obtain the first key feature and the second key feature respectively; Based on extracting a preset amount of historical network traffic data and historical container log data from the container database as training data, combine the first key feature and the second key feature, and train a neural network to obtain an anomaly recognition model; Deploy the anomaly recognition model to the current containerized environment, and perform anomaly detection on the target detection data; When an anomaly is detected, automatically trigger an alarm to notify relevant personnel for handling; According to the preset auditing technical solution, perform regular auditing on containers and generate a security audit report; Combine the security audit report with business requirements and security policies, and perform risk assessment based on preset risk assessment indicators to obtain a risk assessment result; According to the risk assessment result, relevant personnel select matching risk resolution measures to handle the risk problems in the security audit report.

[0014] Compared with the prior art, the beneficial effects of the present application are as follows: By selecting a container technology that meets the current resource security isolation requirements and combining the operating system environment to generate a container isolation security policy, realize the resource security isolation operation between containers; perform real-time detection of abnormal behaviors, regular auditing, and risk assessment on containers to ensure the isolation between containers, effectively improve the security, stability, and reliability of the system, and optimize the resource utilization and management.

[0015] Other features and advantages of the present invention will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present invention. The objectives and other advantages of the present invention may be realized and attained by the structure particularly pointed out in the written description and the drawings.

[0016] The technical solution of the present invention will be further described in detail below with reference to the drawings and embodiments. Description of the Drawings

[0017] The drawings are used to provide a further understanding of the present invention, and constitute a part of the description. They are used together with the embodiments of the present invention to explain the present invention, but do not constitute a limitation to the present invention. In the drawings: Figure 1 It is a flowchart of a resource security isolation method in a containerized environment in an embodiment of the present invention. Detailed Embodiments

[0018] The preferred embodiments of the present invention will be described below with reference to the drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not intended to limit the present invention.

[0019] An embodiment of the present invention provides a resource security isolation method in a containerized environment, as Figure 1 shown, including: Step 1: Select a target container technology that meets the requirements of resource security isolation; Step 2: Obtain a container isolation security policy based on the target container technology to implement resource security isolation operations between containers; Step 3: Detect abnormal behaviors, perform regular audits, and conduct risk assessments on the containers in real time to ensure the isolation between containers.

[0020] In this embodiment, the requirements for resource security isolation include resource type and isolation level requirements, security requirements, system and application compatibility requirements, resource utilization rate, network performance requirements, and management requirements.

[0021] In this embodiment, the target container technology refers to the container technology that best meets the current requirements for resource security isolation. Among them, the container technology is a kernel lightweight operating system layer virtualization technology, mainly used to improve resource utilization rate and business deployment efficiency; it includes Docker, OpenVZ, Linux Containers, and Rocket Container Runtime, etc.

[0022] In this embodiment, the container isolation security policy is a combination of the first security policies in all isolation directions and the preset permission management and access policies. Among them, the isolation directions include various resource isolations, resource restrictions, and network isolations. The various resource isolations refer to the isolations of resources such as the file system, inter-process communication resources, and process trees. The resource restrictions refer to the restrictions on the resource usage of containers, including CPU, memory, disk I / O, etc. The network isolation refers to using network policies (such as Kubernetes' Network Policies) to restrict the network communication between containers to ensure that sensitive data is not accessed without authorization.

[0023] In this embodiment, the first security policy refers to the security isolation method obtained from the first container isolation policy based on the combined analysis of the similarity of isolated data and the policy isolation performance. The first container isolation policy refers to the policy that supports the realization of resource security isolation for the target container technology obtained according to the operating system environment of the current target container technology implementation. For example, in the Linux operating system environment, the Docker container technology realizes resource isolation based on the Namespace mechanism and Cgroups mechanism provided by the Linux kernel. Among them, the operating system environment includes Linux, Windows, macOS, etc.

[0024] In this embodiment, the preset permission management and access policy refers to the method of presetting user permission management, identity authentication, role-based access control, and API access control, which is used to restrict the access permissions of containers to system resources.

[0025] In this embodiment, the security isolation operation refers to resource isolation, resource restriction, and network isolation. The regular audit refers to evaluating the security of the container and microservice environment. The risk assessment refers to, based on the security audit results, evaluating the risks of the identified security issues to determine the severity of the security issues, the possible losses and impacts.

[0026] The beneficial effects of the above technical solutions are as follows: By selecting the container technology that meets the current resource security isolation requirements and combining the operating system environment to generate the container isolation security policy, the resource security isolation operation between containers is realized; the abnormal behaviors of containers are detected in real time, regular audits and risk assessments are carried out to ensure the isolation between containers, effectively improving the security, stability and reliability of the system, and optimizing the resource utilization and management.

[0027] The embodiment of the present invention provides a resource security isolation method in a containerized environment, which selects a target container technology that meets the resource security isolation requirements, including: Obtain the first container technology that meets the resource types and isolation levels to be isolated currently, and establish a list of the first container technologies; Introduce a preset requirement index evaluation mechanism to evaluate the satisfaction of requirements for all the first container technologies in the first container technology list based on the isolation requirement index, and obtain the first index evaluation result; Summarize all the first evaluation results and perform weighted analysis to obtain the comprehensive requirement evaluation value; Regard the first container technology with the largest comprehensive requirement evaluation value as the target container technology.

[0028] In this embodiment, the resource types include, for example, CPU, memory, disk I / O, network, etc.; the isolation level is used to characterize the isolation degree of different resources; the container technology is a kernel lightweight operating system layer virtualization technology, mainly used to improve resource utilization rate and business deployment efficiency; it includes Docker, OpenVZ, Linux Containers, and RocketContainer Runtime, etc.

[0029] In this implementation, the first container technology refers to the container technology that meets the resource types and isolation levels that need to be isolated currently; the first container technology list is composed of the first container technologies; the isolation requirement index includes security requirement index, compatibility requirement index, performance requirement index, and management requirement index. Among them, the security requirement index includes isolation requirement, encryption requirement, authentication and authorization requirements; the compatibility requirement index refers to the compatibility requirements between the container technology and the operating system and application programs; the performance requirement index refers to resource utilization rate and network performance; the management requirement index refers to deployment, monitoring, and maintenance requirements.

[0030] In this embodiment, the first evaluation result is used to represent the satisfaction degree of different first container technologies for the isolation requirement index; the comprehensive requirement evaluation result is obtained by summarizing and performing weighted analysis on the corresponding first evaluation results of all isolation requirement indexes, and is used to represent the comprehensive satisfaction degree of the first container technology for the resource security isolation requirement, so as to screen out the container technology that best meets the current resource security isolation requirement and regard it as the target container technology.

[0031] The beneficial effect of the above technical solution is: by determining and screening out the target container technology that best meets the requirements according to the current resource security isolation requirement, it provides technical support for subsequent resource security isolation and ensures the effective security isolation of resources.

[0032] The embodiment of the present invention provides a resource security isolation method in a containerized environment. The calculation formula of the comprehensive requirement evaluation value is as follows: ; where z represents the comprehensive requirement evaluation value of the current first container technology; represents the first index evaluation result of the i-th isolation requirement index of the current first container technology, where ; It represents the contribution weight of the i-th isolation requirement index to the evaluation of the resource security isolation requirement implementation of the container technology. It represents the total amount of evaluation data used to evaluate the comprehensive satisfaction degree of the first container technology for resource security isolation. It represents the amount of evaluation data used to evaluate the satisfaction degree of the first container technology for the i-th isolation requirement index. It represents the data evaluation preference correction factor of the i-th isolation requirement index. It represents the loss compensation factor for calculating the index evaluation. It represents the evaluation adjustment balance coefficient; ln represents the natural logarithm; e represents the mathematical constant, which is the base of the natural logarithm.

[0033] The beneficial effects of the above technical solution are: By calculating the comprehensive evaluation value of the requirements, the target container technology that meets the current resource isolation requirements can be accurately screened out, which is beneficial to realizing the technical support for subsequent resource security isolation and ensuring the security isolation of resources.

[0034] The embodiment of the present invention provides a resource security isolation method in a containerized environment. Based on the target container technology, a container isolation security policy is obtained to implement resource security isolation operations between containers, including: According to the operating system environment for implementing the target container technology currently, obtain the first container isolation policy that supports the target container technology to implement resource security isolation. Summarize all the obtained first container isolation policies, and establish a resource isolation method set, a resource limitation method set, and a network isolation method set based on the isolation direction. When there is only a single operation method in the resource isolation method set, the resource limitation method set, or the network isolation method set, output the current operation method as the first security policy for the corresponding isolation direction. When there are multiple operation methods in the resource isolation method set, the resource limitation method set, or the network isolation method set, mark the corresponding method set as a method set to be screened. Regard all the operation methods in the method set to be screened as methods to be screened. Extract the historical isolation data of performing operations in the corresponding isolation direction using the methods to be screened within a preset time period, and compare it with the resource data that needs to be securely isolated currently to obtain the first similarity coefficient. Evaluate the operation performance of performing operations in the corresponding isolation direction for the methods to be screened within a preset time period to obtain the first operation performance coefficient. Combine and analyze the first similarity coefficient and the first operation performance coefficient to determine the method matching degree. Output the method to be screened with the highest method matching degree as the first security policy for the corresponding isolation direction. Combine the first security policies in all isolation directions with the preset permission management and access policies to generate container isolation security policies, and implement resource security isolation operations between containers.

[0035] In this embodiment, container technology is a kernel lightweight operating system layer virtualization technology, mainly used to improve resource utilization rate and business deployment efficiency; it includes Docker, OpenVZ, Linux Containers, and Rocket Container Runtime, etc.; the target container technology refers to the container technology that best meets the current resource security isolation requirements.

[0036] In this embodiment, the first container isolation policy refers to the operating system environment that currently implements the target container technology, and obtains the policy that supports the target container technology to achieve resource security isolation; the isolation directions include various resource isolations, resource limitations, and network isolations; the resource isolation method set is a set composed of methods that support resource isolations such as isolated file systems, inter-process communication resources, and process trees in the current operating system environment; the resource limitation method set is obtained from a set of methods that limit the resource usage of containers, including CPU, memory, disk I / O, etc.; the network isolation method set is obtained from a set of methods that implement the limitation of network communication between containers.

[0037] In this embodiment, the first security policy refers to the methods selected from the resource isolation method set, the resource limitation method set, or the network isolation method set that are applicable to the current isolation directions; the method set to be screened refers to the method set with multiple operation methods.

[0038] In this embodiment, the preset time period is set in advance; the first similarity value coefficient is used to represent the similarity degree between the historical isolation data of resource isolation achieved by using the method to be screened and the resource data that needs to be securely isolated currently; the first operation performance coefficient is used to represent the security isolation performance of the method to be screened; the method matching degree is used to represent the applicability of the method to be screened to the resource security isolation at the current moment; the preset permission management and access policies refer to the methods of pre-setting user permission management, identity authentication, role-based access control, and API access control, which are used to limit the access permissions of containers to system resources.

[0039] The beneficial effects of the above technical solution are: By combining the analysis of the current operating system environment and the target container technology, container isolation security policies are generated, and resource security isolation operations between containers are implemented, which can help improve the overall security and resource utilization rate of the system.

[0040] The embodiment of the present invention provides a resource security isolation method in a containerized environment, further including: Use a preset monitoring tool to collect data on service monitoring performance indicators in real time to obtain service indicator data; Compare and analyze the service metric data at the current moment with the set metric threshold range to obtain the first absolute metric difference; If there is no service metric data that does not belong to the set metric threshold range, it is determined that the service demand of the current container is normal; If there is service metric data that does not belong to the set metric threshold range, it is determined that the service demand of the current container has changed; Based on the service metric data, analyze and evaluate the change in service demand, generate a container management request, and then transmit it to the resource management system to dynamically adjust the resource quota of the container, realizing flexible resource limitation.

[0041] In this embodiment, the preset monitoring tool is set in advance, such as Prometheus, JMX, statsD; the service monitoring performance metrics include the response time of the container, network latency, CPU usage rate, disk space usage rate, memory utilization rate, etc.; the service metric data is the service monitoring performance metric data collected in real time by the preset monitoring tool; the set metric threshold range is set in advance; the first absolute metric difference refers to the absolute value of the difference between the service metric data and the upper or lower limit in the set metric threshold range; container management request; resource management system.

[0042] In this embodiment, for example, there are service metric data l1, l2, l3 of container x1, where the service metric data l1, l2 are greater than the corresponding set metric threshold upper limit, and the service metric data l3 is less than the corresponding set metric threshold lower limit. At this time, it is determined that the service demand of container x1 has changed.

[0043] The beneficial effects of the above technical solution are: by analyzing the change in the service demand of the container, generating a container management request and transmitting it to the resource management system to dynamically adjust the resource quota of the container, effectively preventing a certain container from over-occupying resources and causing network congestion, and improving resource utilization rate, avoiding resource idleness and waste.

[0044] The embodiment of the present invention provides a resource security isolation method in a containerized environment. Based on the service metric data, analyze and evaluate the change in service demand, generate a container management request, including: Calibrate the corresponding service monitoring performance metrics where the service metric data is greater than the set metric threshold upper limit and the first absolute metric difference is greater than the set metric difference threshold as the first metric; Calibrate the corresponding service monitoring performance metrics where the service metric data is greater than the set metric threshold upper limit and the first absolute metric difference is not greater than the set metric difference threshold as the second metric; Calibrate the corresponding service monitoring performance metrics where the service metric data is less than the set metric threshold lower limit and the first absolute metric difference is greater than the set metric difference threshold as the third metric; The service monitoring performance indicators where the service metric data is less than the lower limit of the set metric threshold and the absolute difference of the first metric is not greater than the set metric difference threshold are calibrated as the fourth metric; Based on the combined analysis of the first metric, the second metric, the third metric, and the fourth metric, as well as their corresponding absolute differences of the first metric and the degree of influence on metric performance, the service demand change evaluation coefficient of the current container is calculated; When the service demand change evaluation coefficient is less than the set change evaluation threshold, it is determined that the change adjustment level of the service demand change of the current container is level two; Using the second change adjustment plan extracted from the level - adjustment plan table that matches the change adjustment level of level two, a container management request is generated; When the service demand change evaluation coefficient is not less than the set change evaluation threshold, it is determined that the change adjustment level of the service demand change of the current container is level one; Extract the first change adjustment plan from the level - adjustment plan table that matches the change adjustment level of level one; After adjusting the adjustment parameters in the first change adjustment plan by using the scaling coefficient, a container management request is generated; Among them, the calculation formula of the scaling coefficient is as follows: ; In the formula, K represents the scaling coefficient; represents the number of service monitoring performance indicators where the service metric data is greater than the upper limit of the set metric threshold; represents the corresponding absolute difference of the first metric of the service monitoring performance indicator where the j - th service metric data is greater than the upper limit of the set metric threshold at the current moment, where, ; represents the upper limit of the set metric threshold corresponding to the service monitoring performance indicator where the j - th service metric data is greater than the upper limit of the set metric threshold; represents the average metric data value of the service monitoring performance indicator where the j - th service metric data is greater than the upper limit of the set metric threshold within the preset time period T; represents the influence weight of the service monitoring performance indicator where the j - th service metric data is greater than the upper limit of the set metric threshold on adjusting the resource quota; represents the data trend change coefficient of the service monitoring performance indicator where the j - th service metric data is greater than the upper limit of the set metric threshold within the preset time period T; represents the number of service monitoring performance indicators where the service metric data is less than the lower limit of the set metric threshold; represents the corresponding absolute difference of the first metric of the service monitoring performance indicator where the g - th service metric data is less than the lower limit of the set metric threshold at the current moment, where, ; It represents the average index data value of the service monitoring performance index where the g-th service index data is less than the lower limit of the set index threshold within the preset time period T; It represents the corresponding set index threshold lower limit of the service monitoring performance index where the g-th service index data is less than the lower limit of the set index threshold; It represents the data trend change coefficient of the service monitoring performance index where the g-th service index data is less than the lower limit of the set index threshold within the preset time period T; It represents the influence weight of the service monitoring performance index where the g-th service index data is less than the lower limit of the set index threshold on the adjustment of resource quota; It represents the loss compensation factor.

[0045] In this embodiment, the set index threshold is set in advance; the first index absolute difference refers to the absolute value of the difference between the service index data and the upper or lower limit of the set index threshold; the set index difference threshold is set in advance; the index performance influence degree refers to the correlation degree of the service monitoring performance index to the evaluation of the service demand change degree; the service demand change evaluation coefficient is used to characterize the service demand change degree of the current container; the set change evaluation threshold is set in advance.

[0046] In this embodiment, the change adjustment levels are divided into four levels: level one, level two, level three, and level four.

[0047] In this embodiment, for example, the service demand change evaluation coefficients of containers 1 and 2 are a1 and a2 respectively, where a1 is greater than the set change evaluation threshold and a2 is less than the set change evaluation threshold. At this time, it is determined that the change adjustment level of the service demand change of container 1 is level one, and the change adjustment level of the service demand change of container 2 is level two.

[0048] In this embodiment, the change adjustment plan refers to the realization of the allocation and adjustment of resources, such as increasing or decreasing the number of container replicas; the container management request is used to apply to the resource management system for resource quota adjustment, where the resource management system is used to manage the resource quota and define the resource upper limit that each namespace or project can use, such as CPU, memory, network bandwidth, etc.; the scaling coefficient is used to adjust the adjustment parameters in the change adjustment plan, where the adjustment parameters include the number of container replicas, the resource quota of a single container, etc.; the data trend change coefficient is used to express the change range of the historical service index data of the service monitoring performance index within the preset time period T.

[0049] The beneficial effects of the above technical solution are as follows: By comparing and analyzing service metric data with set metric thresholds, a service demand change evaluation coefficient is generated to determine the change adjustment level of the service demand of the current container. Then, a matching change adjustment plan is obtained for adjustment, and a container management request is generated, which helps to achieve dynamic adjustment of the resource quota of the container, effectively prevent a certain container from over-occupying resources and causing network congestion, and improve resource utilization.

[0050] An embodiment of the present invention provides a resource security isolation method in a containerized environment, which performs real-time detection of abnormal behaviors, regular auditing, and risk assessment on containers to ensure isolation between containers, including: Real-time collect network traffic data and container log data between containers, and perform preprocessing to obtain target detection data; Extract features from the network traffic data and container log data to obtain first key features and second key features respectively; Based on extracting a preset amount of historical network traffic data and historical container log data from the container database as training data, and combining the first key features and second key features, train a neural network to obtain an anomaly recognition model; Deploy the anomaly recognition model to the current containerized environment to perform anomaly detection on the target detection data; When an anomaly is detected, an alarm is automatically triggered to notify relevant personnel for handling; According to a preset auditing technical solution, perform regular auditing on the containers and generate a security audit report; Combine the security audit report with business requirements and security policies, and perform risk assessment based on preset risk assessment indicators to obtain a risk assessment result; According to the risk assessment result, relevant personnel select matching risk resolution measures to handle the risk problems in the security audit report.

[0051] In this embodiment, the network traffic data, including packet size, source address, destination address, port number, etc., is collected by using a preset packet capture tool; the container log data refers to the log information data collected from containers, application programs, and host machines; the target detection data is obtained by performing data cleaning, formatting, and aggregation on the real-time collected network traffic data and container log data; the first key features are obtained by extracting features from the network traffic data, such as traffic size, number of packets, source / destination IP address, port number, protocol type; the second key features are obtained by extracting features from the container log data, such as error code, access time, user behavior.

[0052] In this embodiment, the preset quantity is set in advance; the anomaly recognition model is a model obtained by training a neural network by using training data and combining the first key feature and the second key feature, and is used to detect anomalies in a timely manner by detecting network traffic data and container log data between containers; the alarm methods include emails, text messages, Slack, etc., and their purpose is to quickly notify relevant personnel to ensure timely response measures.

[0053] In this embodiment, the preset audit technical solution is pre-set, including elements such as the audit objectives, scope, time, and resources, and is used to regularly audit the container configuration, security policies, resource usage, etc.; the security audit report is the result obtained by regularly auditing the container by using the preset audit technical solution; the business requirements refer to; the preset risk assessment indicators include threat levels, container and microservice environment vulnerabilities, risk tolerance, etc.; the risk assessment results; the risk resolution measures, including risk avoidance, risk reduction, risk acceptance, etc.

[0054] The beneficial effects of the above technical solution are: by detecting abnormal behaviors, regularly auditing, and risk assessing containers in real time, abnormal behaviors can be discovered and responded to in a timely manner, thereby protecting the security of data and application programs in the containers, improving the security of the container environment, ensuring the safe isolation of resources between containers, and effectively ensuring the stability and reliability of the system.

[0055] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.

Claims

1. A resource security isolation method in a containerized environment, characterized in that Including: Step 1: Select a target container technology that meets the requirements of resource security isolation; Step 2: Obtain a container isolation security policy based on the target container technology to implement resource security isolation operations between containers; Step 3: Detect abnormal behaviors of containers in real time, conduct regular audits, and perform risk assessments to ensure the isolation between containers.

2. The resource security isolation method in a containerized environment according to claim 1, wherein Selecting a target container technology that meets the requirements of resource security isolation includes: Obtain a first container technology that meets the resource types and isolation levels to be isolated currently, and establish a list of the first container technologies; Introduce a preset requirement index evaluation mechanism, and evaluate the satisfaction of all the first container technologies in the list of the first container technologies based on the isolation requirement indexes to obtain a first index evaluation result; Summarize all the first evaluation results and perform weighted analysis to obtain a comprehensive requirement evaluation value; Regard the first container technology with the largest comprehensive requirement evaluation value as the target container technology.

3. A resource security isolation method in a containerized environment according to claim 2, characterized in that The isolation requirement indexes include security requirement indexes, compatibility requirement indexes, performance requirement indexes, and management requirement indexes.

4. A resource security isolation method in a containerized environment according to claim 2, characterized in that, The calculation formula of the comprehensive requirement evaluation value is as follows: ; where z represents the comprehensive evaluation value of the requirements for the current first container technology; represents the first index evaluation result of the i-th isolation requirement index for the current first container technology, where ; represents the contribution weight of the i-th isolation requirement index to the realization of the resource security isolation requirement of the evaluation container technology; represents the total amount of evaluation data used to evaluate the comprehensive satisfaction degree of the first container technology for resource security isolation; represents the amount of evaluation data used to evaluate the satisfaction degree of the first container technology for the i-th isolation requirement index; represents the data evaluation preference correction factor of the i-th isolation requirement index; represents the loss compensation factor for calculating the index evaluation; represents the evaluation adjustment balance coefficient; ln represents the natural logarithm; e represents the mathematical constant, which is the base of the natural logarithm.

5. A resource security isolation method in a containerized environment according to claim 1, characterized in that, Obtaining a container isolation security policy based on the target container technology to implement resource security isolation operations between containers includes: According to the operating system environment for implementing the target container technology currently, obtain a first container isolation policy that supports the target container technology to achieve resource security isolation; Summarize all the obtained first container isolation policies, and establish a resource isolation method set, a resource limitation method set, and a network isolation method set based on the isolation direction; When there is only a single operation method in the resource isolation method set, the resource limitation method set, or the network isolation method set, use the current operation method as the first security policy for the corresponding isolation direction and output it; When there are multiple operation methods in the resource isolation method set, the resource limitation method set, or the network isolation method set, mark the corresponding method set as a method set to be screened; Regard all the operation methods in the method set to be screened as methods to be screened; Extract the historical isolation data of performing operations in the corresponding isolation direction using the methods to be screened within a preset time period, and compare it with the resource data to be securely isolated currently to obtain a first similarity coefficient; Evaluate the operation performance of performing operations in the corresponding isolation direction using the methods to be screened within a preset time period to obtain a first operation performance coefficient; Combine and analyze the first similarity coefficient and the first operation performance coefficient to determine the method matching degree; Use the method to be screened with the highest method matching degree as the first security policy for the corresponding isolation direction and output it; Combine the first security policies in all isolation directions with a preset permission management and access policy to generate a container isolation security policy to implement resource security isolation operations between containers.

6. A resource security isolation method in a containerized environment according to claim 5, characterized in that, It also includes: Use a preset monitoring tool to collect data of service monitoring performance indexes in real time to obtain service index data; Compare and analyze the service index data at the current moment with the set index threshold range to obtain a first index absolute difference; If there is no service index data that does not belong to the set index threshold range, it is determined that the service requirements of the current container are normal; If there is service metric data that does not fall within the set metric threshold range, it is determined that the service demand of the current container has changed; Based on the analysis and evaluation of the service demand change using the service metric data, a container management request is generated and then transmitted to the resource management system to dynamically adjust the resource quota of the container, achieving flexible resource limitation.

7. A resource security isolation method in a containerized environment according to claim 6, wherein Based on the analysis and evaluation of the service demand change using the service metric data, a container management request is generated, including: Calibrate the corresponding service monitoring performance metric with service metric data greater than the upper limit of the set metric threshold and the absolute difference of the first metric greater than the set metric difference threshold as the first metric; Calibrate the corresponding service monitoring performance metric with service metric data greater than the upper limit of the set metric threshold and the absolute difference of the first metric not greater than the set metric difference threshold as the second metric; Calibrate the corresponding service monitoring performance metric with service metric data less than the lower limit of the set metric threshold and the absolute difference of the first metric greater than the set metric difference threshold as the third metric; Calibrate the corresponding service monitoring performance metric with service metric data less than the lower limit of the set metric threshold and the absolute difference of the first metric not greater than the set metric difference threshold as the fourth metric; Based on the combined analysis of the first metric, second metric, third metric, and fourth metric and their corresponding absolute differences of the first metric and the degree of impact on metric performance, calculate the service demand change evaluation coefficient of the current container; When the service demand change evaluation coefficient is less than the set change evaluation threshold, determine that the change adjustment level of the service demand change of the current container is level two; Generate a container management request using the second change adjustment plan extracted from the level-adjustment plan table that matches the change adjustment level of level two; When the service demand change evaluation coefficient is not less than the set change evaluation threshold, determine that the change adjustment level of the service demand change of the current container is level one; Extract the first change adjustment plan from the level-adjustment plan table that matches the change adjustment level of level one; After adjusting the adjustment parameters in the first change adjustment plan using the scaling coefficient, generate a container management request; Among them, the calculation formula of the scaling coefficient is as follows: ; where K represents the expansion / contraction coefficient; represents the number of service monitoring performance indicators whose service indicator data is greater than the upper limit of the set indicator threshold; represents the corresponding first indicator absolute difference of the service monitoring performance indicator whose j-th service indicator data at the current moment is greater than the upper limit of the set indicator threshold, where ; represents the corresponding set indicator threshold upper limit of the service monitoring performance indicator whose j-th service indicator data is greater than the upper limit of the set indicator threshold; represents the average indicator data value of the service monitoring performance indicator whose j-th service indicator data is greater than the upper limit of the set indicator threshold within the preset time period T; represents the influence weight of the service monitoring performance indicator whose j-th service indicator data is greater than the upper limit of the set indicator threshold on adjusting the resource quota; represents the data trend change coefficient of the service monitoring performance indicator whose j-th service indicator data is greater than the upper limit of the set indicator threshold within the preset time period T; represents the number of service monitoring performance indicators whose service indicator data is less than the lower limit of the set indicator threshold; represents the corresponding first indicator absolute difference of the service monitoring performance indicator whose g-th service indicator data at the current moment is less than the lower limit of the set indicator threshold, where ; represents the average indicator data value of the service monitoring performance indicator whose g-th service indicator data is less than the lower limit of the set indicator threshold within the preset time period T; represents the corresponding set indicator threshold lower limit of the service monitoring performance indicator whose g-th service indicator data is less than the lower limit of the set indicator threshold; represents the data trend change coefficient of the service monitoring performance indicator whose g-th service indicator data is less than the lower limit of the set indicator threshold within the preset time period T; represents the influence weight of the service monitoring performance indicator whose g-th service indicator data is less than the lower limit of the set indicator threshold on adjusting the resource quota; represents the loss compensation factor.

8. A resource security isolation method in a containerized environment according to claim 1, wherein, Perform real-time detection of abnormal behaviors, regular audits, and risk assessments on containers to ensure the isolation between containers, including: Real-time collect the network traffic data and container log data between containers and perform preprocessing to obtain target detection data; Extract features from the network traffic data and container log data to obtain the first key feature and the second key feature respectively; Based on extracting a preset amount of historical network traffic data and historical container log data from the container database as training data, combined with the first key feature and the second key feature, train a neural network to obtain an anomaly recognition model; Deploy the anomaly recognition model to the current containerized environment to perform anomaly detection on the target detection data; Automatically trigger an alarm when an anomaly is detected and notify relevant personnel for handling; Conduct regular audits on containers according to the preset audit technical plan and generate a security audit report; Combine the security audit report with business requirements and security policies, and perform risk assessment based on preset risk assessment indicators to obtain a risk assessment result; According to the risk assessment results, relevant personnel select matching risk mitigation measures to address the risk issues in the security audit report.

Citation Information

Cited By

  • Linux container security isolation system

    CN121523806A

  • Intelligent fusion terminal micro-application resource isolation method based on container technology

    CN122220035A

  • Intelligent converged terminal micro application resource isolation method based on container technology

    CN122220035B