Intelligent agent escape detection and protection method and device, electronic equipment and storage medium

By detecting the system call sequence, namespace, access files and network traffic of the agent, combined with the risk level protection strategy, the problem of damage to the host and network by the agent's escape is solved, and effective protection and performance balance is achieved.

CN120596434APending Publication Date: 2025-09-05INSPUR TIANYUAN COMM INFORMATION SYST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510675572.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The escape of an agent causes damage to the host or network, resulting in serious consequences such as data leakage and system paralysis, and it is difficult for the existing technology to effectively detect and protect.

Method used

By obtaining the agent's system call sequence, namespace, access files and directories, network traffic and other information, the agent's escape behavior is detected, and corresponding protection policies are implemented according to the risk level, including restricting access rights, blocking network connections or repairing containers.

Benefits of technology

It realizes effective detection and protection of the escape behavior of the agent, reduces the damage to the operating environment, and balances the protection effect and system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120596434A_ABST
    Figure CN120596434A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent agent escape detection and protection method and device, electronic equipment and a storage medium, and belongs to the technical field of intelligent agents. The operation information of the intelligent agent comprises at least one of a system call sequence, a namespace, an access file and directory and network traffic; and detecting the escape behavior of the agent according to the operation information of the agent. According to the invention, the escape behavior of the intelligent agent can be detected according to the operation information of the intelligent agent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent agent technology, and in particular to an intelligent agent escape detection and protection method, device, electronic device and storage medium. Background Art

[0002] With the rapid development of artificial intelligence (AI) technology, intelligent agents are widely used in various application scenarios. However, the security of the intelligent agent's operating environment has become increasingly prominent, particularly the issue of operating environment escape. This occurs when an intelligent agent escapes its originally restricted operating environment, such as a container or virtual machine. This escape can damage the host machine or network, leading to serious consequences such as data leakage and system failure.

[0003] In order to avoid the damage caused by the escape of the intelligent agent, the problem of detecting the escape behavior of the intelligent agent needs to be solved. Summary of the Invention

[0004] The present invention provides an intelligent agent escape detection and protection method, device, electronic device and storage medium to solve the technical problem of how to detect intelligent agent escape behavior.

[0005] The present invention provides an intelligent agent escape detection method, comprising: Obtaining operation information of the agent; the operation information includes at least one of a system call sequence, a namespace, accessed files and directories, and network traffic; The escape behavior of the intelligent agent is detected according to the operation information.

[0006] According to an agent escape detection method provided by the present invention, the operation information includes the system call sequence; The detecting the escape behavior of the intelligent agent according to the operation information includes: Obtaining a normal system call pattern of the agent; If the system call sequence has a call pattern that is different from the normal system call pattern, it is determined that the agent has escaped.

[0007] According to an agent escape detection method provided by the present invention, the operation information includes the namespace; The detecting the escape behavior of the intelligent agent according to the operation information includes: If the namespace changes, it is determined that the agent has escaped.

[0008] According to an agent escape detection method provided by the present invention, the operation information includes the accessed files and directories; The detecting the escape behavior of the intelligent agent according to the operation information includes: Get the preset file and directory whitelist; If the accessed files and directories are outside the file and directory whitelist, it is determined that the agent has escaped.

[0009] According to an agent escape detection method provided by the present invention, the operation information includes the network traffic; The detecting the escape behavior of the intelligent agent according to the operation information includes: If it is identified based on the network traffic that the agent has abnormal network connection or abnormal data transmission behavior, it is determined that the agent has escaped.

[0010] The present invention further provides an agent escape protection method, comprising any of the above agent escape detection methods, further comprising: Determining a risk level of the agent's escape behavior; Execute the protection strategy corresponding to the risk level on the operating environment of the intelligent agent.

[0011] According to an intelligent agent escape protection method provided by the present invention, determining the risk level of the escape behavior of the intelligent agent includes: If the agent's escape behavior only affects the non-core processes of a single container, the agent occupies less than 10% of the hardware resources, the incremental storage space occupied is less than 5%, there is no cross-container communication, and the associated core business services remain in normal operation, then the risk level is determined to be mild. If the agent's escape behavior affects more than three containers on the same node, affects non-critical system services on the host, the agent occupies more than 30% of hardware resources, occupies between 30% and 50% of storage space, occupies more than 50% of the preset threshold of network bandwidth and persists for more than 5 minutes, or the response delay of the associated core business services exceeds 200ms, then the risk level is determined to be severe; If the escape behavior of the intelligent agent causes the host kernel to crash, critical system services to be paralyzed, related core business services to be interrupted, hardware resources to be completely exhausted, storage space to be full, network bandwidth to be continuously saturated by attacks, core business data to be encrypted, or system logs to be cleared, the risk level is determined to be severe.

[0012] According to a method for protecting an intelligent agent from escape provided by the present invention, executing a protection strategy corresponding to the risk level on the operating environment of the intelligent agent includes: If the risk level is mild, restricting the agent's access rights to the host machine and the network; If the risk level is medium, blocking the connection between the agent and the external network; If the risk level is severe, the container infected by the agent is repaired or restarted.

[0013] The present invention also provides an intelligent agent escape detection device, comprising: An acquisition module, configured to acquire operation information of an intelligent agent; the operation information includes at least one of a system call sequence, a namespace, accessed files and directories, and network traffic; A detection module is used to detect the escape behavior of the intelligent agent based on the operation information.

[0014] The present invention also provides an intelligent agent escape protection device, comprising an intelligent agent escape detection device, and further comprising: a determination module, configured to determine a risk level of the escape behavior of the agent; A protection module is used to execute a protection strategy corresponding to the risk level on the operating environment of the intelligent agent.

[0015] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, it implements any of the above-described intelligent agent escape detection methods or intelligent agent escape protection methods.

[0016] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described intelligent agent escape detection methods or intelligent agent escape protection methods.

[0017] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described intelligent agent escape detection methods or intelligent agent escape protection methods.

[0018] The intelligent agent escape detection and protection method, device, electronic device and storage medium provided by the present invention can detect the escape behavior of the intelligent agent based on at least one information of the intelligent agent's system call sequence, namespace, access files and directories, and network traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 It is a flow chart of the intelligent agent escape detection method provided by the present invention.

[0021] Figure 2 It is a flow chart of the intelligent body escape protection method provided by the present invention.

[0022] Figure 3 It is a structural diagram of the intelligent body escape detection device provided by the present invention.

[0023] Figure 4 It is a structural diagram of the intelligent body escape protection device provided by the present invention.

[0024] Figure 5 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0026] It should be noted that, in the description of the present invention, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, the phrase "comprises a..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the elements. Terms such as "upper" and "lower" indicate positions or relationships based on those shown in the accompanying drawings and are intended solely to facilitate the description of the present invention and simplify the description. They are not intended to indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation, and are therefore not to be construed as limitations on the present invention. Unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be broadly construed, for example, to mean fixed, removable, or integral; mechanical or electrical; direct or indirect through an intermediary; or internal communication between two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0027] The terms "first," "second," and so forth, used herein are used to distinguish similar objects, not to describe a specific order or precedence. It should be understood that such terms are interchangeable where appropriate, allowing embodiments of the present invention to be implemented in an order other than that illustrated or described herein. Furthermore, the terms "first," "second," and so forth generally distinguish objects of a single type, and do not limit the number of objects. For example, the first object may be one or more. Furthermore, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the connected objects.

[0028] The following combination Figure 1-Figure 5 The present invention describes the intelligent agent escape detection and protection method, device, electronic device and storage medium provided by the present invention.

[0029] like Figure 1 As shown, the intelligent agent escape detection method provided by the present invention includes steps S1 and S2.

[0030] Step S1, obtaining the running information of the intelligent agent; the running information includes at least one of system call sequence, namespace, access files and directories, and network traffic.

[0031] Exemplarily, the intelligent agent may be an AI model or an automated program.

[0032] An agent's system call sequence is a chronological series of call records generated when the agent interacts with underlying hardware or resources through interfaces (system calls) provided by the operating system kernel during operation. These calls reflect the agent's behavior patterns, resource usage, and potential security risks. System call sequences typically include resource access, computational tasks, network communication, and process management. The call patterns before and after an agent escapes can differ, making system call sequences useful for detecting escape behavior.

[0033] An agent's namespace is an operating system-level isolation mechanism that partitions system resources (such as processes, networks, and file systems) into independent logical units, allowing the agent to exclusively access all system resources at runtime. Namespaces are a core foundation of containerization technologies (such as Docker and Kubernetes) and are key to enabling multiple agents to run concurrently without interfering with each other. Namespaces further include process IDs (preventing visibility into host processes), isolated network interfaces, and isolated file system mount points. The namespaces of agents before and after an escape attempt may differ, making them useful for detecting escape attempts.

[0034] The files and directories that the agent is allowed to access are limited. One of the manifestations of the agent's escape behavior is accessing prohibited files or directories. Therefore, the agent's escape behavior can be detected through the files and directories that the agent accesses.

[0035] The network traffic before and after the agent escapes may be different, so the agent's escape behavior can be detected through the agent's network traffic.

[0036] Step S2: Detect the escape behavior of the intelligent agent based on the operation information.

[0037] If the execution information includes a system call sequence, and the calling pattern of the system call sequence differs from its normal calling pattern, the agent can be considered to have escaped. If the execution information includes namespaces, and changes in the namespaces indicate an escape, the agent can be considered to have escaped. If the execution information includes file and directory accesses, and the agent accesses prohibited files or directories, the agent can be considered to have escaped. If the execution information includes network traffic, changes in network traffic can be used to determine whether the agent has escaped.

[0038] Of course, if the running information includes multiple types of system call sequences, namespaces, accessed files and directories, and network traffic, it can also be considered that the intelligent agent has escaped if multiple conditions are met.

[0039] As can be seen from the above, the agent escape detection method of the present invention can detect the escape behavior of the agent based on at least one information of the agent's system call sequence, namespace, access files and directories, and network traffic.

[0040] In some embodiments, if the agent's operating information includes a system call sequence, step S2 may further include: Get the normal system call pattern of the agent; If the system call sequence has a call pattern that is different from the normal system call pattern, it is determined that the agent has escaped.

[0041] Of course, if the system call sequence is the same as the normal system call pattern, it does not mean that the agent has not escaped. Further judgment is needed from other angles.

[0042] The normal system call pattern of the agent includes normal system calls, normal call frequency, normal call order and normal call parameters. For example, normal system calls may include open, read, write, etc., and the normal call order may include "open" first, then "read" and finally "close".

[0043] The system call sequence has a call pattern that is different from the normal system call pattern. Specifically, this can manifest as an abnormal call frequency, abnormal call order, or abnormal call parameters. For example, an abnormal call order may include "open", then "fork", and then "execve", and abnormal call parameters may include tampering with system files.

[0044] In this way, we can determine whether the agent has escaped by comparing the agent's system call sequence with the normal system call pattern.

[0045] In some embodiments, if the agent's running information includes a namespace, step S2 may further include: If the namespace of the agent changes, it is determined that the agent has escaped.

[0046] Of course, if the namespace of the agent has not changed, it does not mean that the agent has not escaped. Further judgment is needed from other angles.

[0047] A change in an agent's namespace could mean: the agent has migrated from one container to another, the agent has broken through container isolation (e.g., escaped to the host), or the agent has been hijacked by a malicious program and switched namespaces. This change could manifest as an isolated network interface or isolated file system mount point moving from the container to the host.

[0048] You can deploy namespace monitoring tools, such as cgroups or seccomp, in containers. cgroups is a mechanism provided by the Linux kernel for limiting, recording, and isolating resource usage (such as CPU, memory, disk I / O, and network) for a process group. seccomp is a security mechanism in the Linux kernel that restricts the system calls (syscalls) that a process can execute. Use cgroups to monitor container resource usage and seccomp to restrict system calls made by processes in the container. Configure seccomp security policies to prohibit processes in the container from executing system calls that could potentially change the namespace (such as setns).

[0049] In this way, we can determine whether the agent has escaped by judging whether the namespace of the agent has changed.

[0050] In some embodiments, if the agent's operating information includes access to files and directories, step S2 may further include: Get the preset file and directory whitelist; If the accessed files and directories are outside the file and directory whitelist, it is determined that the agent has escaped.

[0051] The file and directory whitelist records the files and directories required for the operation of the agent, including the main program script, configuration files, dependency lists, pre-trained models, input data, output directories, containerized deployment-specific files, etc. The system only allows the agent to access files and directories in the file and directory whitelist. If the agent accesses other files or directories outside the whitelist, it can be considered that the agent has escaped.

[0052] In this way, the files and directories accessed by the agent can be used to determine whether the agent has escaped.

[0053] In some embodiments, if the agent's operating information includes network traffic, step S2 may further include: If the network traffic identifies that the agent has abnormal network connection or abnormal data transmission behavior, it is determined that the agent has escaped.

[0054] An agent experiencing abnormal network connections or data transmission behavior indicates that the agent may be attempting to communicate with a malicious external server or leak data, potentially indicating an escape attempt. Examples of abnormal network connections or data transmission behavior include the agent suddenly accessing the Kubernetes API server or scanning other containers on the same node.

[0055] In this way, the network traffic of the intelligent agent can be used to determine whether the intelligent agent has escaped.

[0056] After determining that an agent has escaped, protection can be implemented to mitigate the damage to the operating environment. Because the risk of an agent escaping can vary, applying the same, relatively loose, protection strategy to all risk levels may fail to effectively mitigate the damage. Applying the same, relatively strict, protection strategy to all risk levels may result in system performance degradation or service interruption.

[0057] In order to balance the effect of agent escape protection and system performance, such as Figure 2 As shown, the present invention also provides an intelligent agent escape protection method, including any of the above intelligent agent escape detection methods and steps S3 and S4.

[0058] Step S3: Determine the risk level of the agent's escape behavior.

[0059] The risk level of an agent escape can be determined based on the objects affected by the agent escape. For example, if the agent escape only affects the container in which it is located, the risk level can be considered low; if the agent escape also affects other containers, the risk level can be considered medium; if the agent escape also affects the host machine, the risk level can be considered high.

[0060] Step S4: Execute the protection strategy corresponding to the risk level on the operating environment of the intelligent agent.

[0061] Specifically, if the risk level is mild, a more relaxed protection strategy can be implemented; if the risk level is moderate, a more moderate protection strategy can be implemented; if the risk level is severe, a more stringent protection strategy can be implemented.

[0062] In this way, corresponding protection strategies can be implemented according to the risk level of agent escape, balancing the effectiveness of agent escape protection and system performance.

[0063] In some embodiments, step S3 may further include: If the agent's escape behavior only affects the non-core processes of a single container, the agent occupies less than 10% of the hardware resources, the incremental storage space occupied is less than 5%, there is no cross-container communication, and the associated core business services remain in normal operation, the risk level is determined to be mild. If the agent's escape behavior affects more than three containers on the same node, affects non-critical system services on the host, the agent occupies more than 30% of hardware resources, occupies between 30% and 50% of storage space, occupies more than 50% of the preset threshold of network bandwidth and persists for more than 5 minutes, or the response delay of related core business services exceeds 200ms, the risk level is determined to be severe; If the escape behavior of the intelligent agent causes the host kernel to crash, critical system services to be paralyzed, related core business services to be interrupted, hardware resources to be completely exhausted, storage space to be full, network bandwidth to be continuously saturated by attacks, core business data to be encrypted, or system logs to be cleared, the risk level is determined to be severe.

[0064] The agent's escape behavior only affects the non-core processes of a single container and does not involve cross-container communication. This means that the agent's escape only affects the container in which it resides. The agent's escape behavior affects more than three containers on the same node, meaning that the agent's escape also affects other containers. The agent's escape behavior causes a kernel crash on the host machine, meaning that the agent's escape also affects the host machine.

[0065] The agent's hardware resource usage is less than 10%, and the increase in storage space usage is less than 5%, indicating that the agent's escape consumes relatively few resources. The core business services associated with the agent remain operational, indicating that the agent's escape has not affected business operations.

[0066] If the agent's hardware resource usage exceeds 30% and its storage space usage is between 30% and 50%, the agent's escape is consuming a significant amount of resources. If the agent's network bandwidth usage exceeds 50% of the preset threshold for more than five minutes, the agent's escape is impacting the network. If the agent's escape causes the response latency of non-critical system services or related core business services on the host to exceed 200ms, the agent's escape is impacting system services.

[0067] The escape of the intelligent agent causes the paralysis of key system services, the interruption of related core business services, the complete exhaustion of hardware resources, the fullness of storage space, the continuous saturation attack of network bandwidth, the encryption of core business data or the clearing of system logs. This means that the escape of the intelligent agent occupies too many resources and has a serious impact on the network and business.

[0068] In addition to the objects affected by the agent escape, superimposing the resources occupied by the agent and the impact on the business can improve the accuracy of the determined agent escape risk level.

[0069] In this way, the risk level of the agent escape can be comprehensively determined with high accuracy based on the objects affected by the agent escape and the impact of the resources occupied by the agent on the business.

[0070] In some embodiments, step S4 may further include: If the risk level is mild, the agent's access rights to the host machine and network are restricted; If the risk level is medium, the agent's connection to the external network is blocked; If the risk level is severe, repair or restart the container infected by the agent.

[0071] Among them, limiting the access rights of the intelligent agent to the host machine and the network can isolate the intelligent agent that has escaped in an independent environment to prevent it from affecting other containers or the host machine. This can be regarded as a relatively loose protection strategy; using firewalls, network access control and other technologies to block the connection between the intelligent agent and the external network can prevent data leakage and malicious attacks. This can be regarded as a more moderate protection strategy; repairing or restarting the container infected by the intelligent agent can ensure the normal operation of the container, but it will cause system performance degradation or business interruption. This can be regarded as a more stringent protection strategy.

[0072] This allows for the execution of appropriate protection strategies based on the risk level of the agent escaping.

[0073] like Figure 3 As shown, the intelligent escape detection device provided by the present invention includes: An acquisition module is used to obtain the running information of the intelligent agent; the running information includes at least one of a system call sequence, a namespace, access files and directories, and network traffic; The detection module is used to detect the escape behavior of the intelligent agent based on the running information.

[0074] It should be noted that the intelligent agent escape detection device provided by the present invention can execute the intelligent agent escape detection method of any of the above embodiments during specific operation, which will not be described in detail in this embodiment.

[0075] In some embodiments, the agent's operational information may include a system call sequence; The detection module can also be used to: Get the normal system call pattern of the agent; If the system call sequence has a call pattern that is different from the normal system call pattern, it is determined that the agent has escaped.

[0076] In some embodiments, the agent's operational information may include a namespace; The detection module can also be used to: If the namespace changes, it is determined that the agent has escaped.

[0077] In some embodiments, the agent's operational information may include access to files and directories; The detection module can also be used to: Get the preset file and directory whitelist; If the accessed files and directories are outside the file and directory whitelist, it is determined that the agent has escaped.

[0078] In some embodiments, the agent's operational information may include network traffic; The detection module can also be used to: If the network traffic identifies that the agent has abnormal network connection or abnormal data transmission behavior, it is determined that the agent has escaped.

[0079] like Figure 4 As shown, the intelligent escape protection device provided by the present invention includes: An acquisition module is used to obtain the running information of the intelligent agent; the running information includes at least one of a system call sequence, a namespace, access files and directories, and network traffic; The detection module is used to detect the escape behavior of the intelligent agent based on the operation information; A determination module is used to determine the risk level of the agent's escape behavior; The protection module is used to implement protection strategies corresponding to the risk level of the intelligent agent's operating environment.

[0080] It should be noted that the intelligent agent escape protection device provided by the present invention can execute the intelligent agent escape protection method of any of the above embodiments during specific operation, which will not be described in detail in this embodiment.

[0081] In some implementations, the determination module may also be configured to: If the agent's escape behavior only affects the non-core processes of a single container, the agent occupies less than 10% of the hardware resources, the incremental storage space occupied is less than 5%, there is no cross-container communication, and the associated core business services remain in normal operation, the risk level is determined to be mild. If the agent's escape behavior affects more than three containers on the same node, affects non-critical system services on the host, the agent occupies more than 30% of hardware resources, occupies between 30% and 50% of storage space, occupies more than 50% of the preset threshold of network bandwidth and persists for more than 5 minutes, or the response delay of related core business services exceeds 200ms, the risk level is determined to be severe; If the escape behavior of the intelligent agent causes the host kernel to crash, critical system services to be paralyzed, related core business services to be interrupted, hardware resources to be completely exhausted, storage space to be full, network bandwidth to be continuously saturated by attacks, core business data to be encrypted, or system logs to be cleared, the risk level is determined to be severe.

[0082] In some embodiments, the protection module may also be used to: If the risk level is mild, the agent's access rights to the host machine and network are restricted; If the risk level is medium, the agent's connection to the external network is blocked; If the risk level is severe, repair or restart the container infected by the agent.

[0083] Figure 5 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 5 As shown, the electronic device may include: a processor, a communications interface, memory, and a communications bus, wherein the processor, communications interface, and memory communicate with each other via the communications bus. The processor may invoke logic instructions in the memory to execute the intelligent agent escape detection or protection method.

[0084] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.

[0085] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the intelligent agent escape detection or protection method provided in the above-mentioned embodiments.

[0086] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the intelligent agent escape detection or protection method provided in the above-mentioned embodiments.

[0087] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0088] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for detecting escape of an intelligent agent, characterized in that: include: Obtaining operation information of the agent; the operation information includes at least one of a system call sequence, a namespace, accessed files and directories, and network traffic; The escape behavior of the intelligent agent is detected according to the operation information.

2. The method for detecting escape of an intelligent agent according to claim 1, wherein: The operation information includes the system call sequence; The detecting the escape behavior of the intelligent agent according to the operation information includes: Obtaining a normal system call pattern of the agent; If the system call sequence has a call pattern that is different from the normal system call pattern, it is determined that the agent has escaped.

3. The method for detecting escape of an intelligent agent according to claim 1, wherein: The operation information includes the namespace; The detecting the escape behavior of the intelligent agent according to the operation information includes: If the namespace changes, it is determined that the agent has escaped.

4. The method for detecting escape of an intelligent agent according to claim 1, wherein: The operation information includes the accessed files and directories; The detecting the escape behavior of the intelligent agent according to the operation information includes: Get the preset file and directory whitelist; If the accessed files and directories are outside the file and directory whitelist, it is determined that the agent has escaped.

5. The intelligent agent escape detection method according to claim 1, characterized in that: The operation information includes the network traffic; The detecting the escape behavior of the intelligent agent according to the operation information includes: If it is identified based on the network traffic that the agent has abnormal network connection or abnormal data transmission behavior, it is determined that the agent has escaped.

6. An agent escape protection method, comprising the agent escape detection method according to any one of claims 1 to 5, characterized in that: Also includes: Determining a risk level of the agent's escape behavior; Execute the protection strategy corresponding to the risk level on the operating environment of the intelligent agent.

7. The intelligent agent escape protection method according to claim 6, characterized in that: Determining the risk level of the escape behavior of the intelligent agent includes: If the agent's escape behavior only affects the non-core processes of a single container, the agent occupies less than 10% of the hardware resources, the incremental storage space occupied is less than 5%, there is no cross-container communication, and the associated core business services remain in normal operation, then the risk level is determined to be mild. If the agent's escape behavior affects more than three containers on the same node, affects non-critical system services on the host, the agent occupies more than 30% of hardware resources, occupies between 30% and 50% of storage space, occupies more than 50% of the preset threshold of network bandwidth and persists for more than 5 minutes, or the response delay of the associated core business services exceeds 200ms, then the risk level is determined to be severe; If the escape behavior of the intelligent agent causes the host kernel to crash, critical system services to be paralyzed, related core business services to be interrupted, hardware resources to be completely exhausted, storage space to be full, network bandwidth to be continuously saturated by attacks, core business data to be encrypted, or system logs to be cleared, the risk level is determined to be severe.

8. The intelligent agent escape protection method according to claim 6, characterized in that: The executing of the protection strategy corresponding to the risk level on the operating environment of the agent includes: If the risk level is mild, restricting the agent's access rights to the host machine and the network; If the risk level is medium, blocking the connection between the agent and the external network; If the risk level is severe, the container infected by the agent is repaired or restarted.

9. An intelligent agent escape detection device, characterized in that: include: An acquisition module, configured to acquire operation information of an intelligent agent; the operation information includes at least one of a system call sequence, a namespace, accessed files and directories, and network traffic; A detection module is used to detect the escape behavior of the intelligent agent based on the operation information.

10. An intelligent agent escape protection device, comprising the intelligent agent escape detection device according to claim 9, characterized in that: Also includes: a determination module, configured to determine a risk level of the escape behavior of the agent; A protection module is used to execute a protection strategy corresponding to the risk level on the operating environment of the intelligent agent.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the intelligent agent escape detection method according to any one of claims 1 to 5 or the intelligent agent escape protection method according to any one of claims 6 to 8 is implemented.

12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the intelligent agent escape detection method according to any one of claims 1 to 5 or the intelligent agent escape protection method according to any one of claims 6 to 8 is implemented.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the intelligent agent escape detection method according to any one of claims 1 to 5 or the intelligent agent escape protection method according to any one of claims 6 to 8 is implemented.