DETECTING MUTATION EVENTS TO MONITOR INTEGRITY
Patent Information
- Application Number
- DE112020004487
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-09-22
- Filing Date
- 2020-09-22
- Publication Date
- 2026-10-01
- Estimated Expiration
- 2040-09-22
AI Technical Summary
Existing systems struggle to effectively monitor and maintain system and information integrity in compliance with standards like PCI/DSS and NIST, particularly in container orchestration systems where unintended mutations can cause abnormal behavior, making it difficult to distinguish between intended and unintended changes.
A system and method for detecting mutation events by creating process trees from change events within a cluster data processing system, comparing them with external commands, and generating a mutation event report to identify unintended changes, using components like processing units and API servers to filter out infrequent or occasional intended events.
The solution enables continuous monitoring of container integrity, identifying and reporting unintended changes, thereby ensuring compliance with standards and preventing malicious activity or abnormal behavior in container orchestration systems.
Abstract
Description
TECHNICAL AREA
[0001] The present invention relates generally to computer systems and in particular to the detection of mutation events for monitoring integrity. BACKGROUND
[0002] Monitoring system and information integrity may be required as part of compliance and audit standards. Such standards can include, but are not limited to, Payment Card Industry Data Security Standards (PCI / DSS) (e.g., PCI Requirement 11.5), National Institute of Standards and Technology (NIST) standards (e.g., NIST Special Publication 800-53 (SI-7)), etc. SUMMARY
[0003] According to one aspect of the present invention, a system is provided. The system comprises a storage unit for storing program code and at least one hardware processor functionally connected to the storage unit. The at least one hardware processor is configured to execute program code stored on the storage unit in order to generate one or more process trees based on one or more processes belonging to a change event or multiple change events within a cluster data processing system, to detect mutation events by comparing a root of each of the one or more process trees with one or more external instructions, and to generate a mutation event report based on the comparison.
[0004] According to a further aspect of the present invention, a computer-implemented method is provided. The method comprises generating one or more process trees based on one or more processes belonging to a change event or multiple change events within a cluster data processing system, detecting mutation events by comparing a root of each of the one or more process trees with one or more external instructions, and generating a mutation event report based on the comparison.
[0005] These and other features and advantages will become apparent from the following detailed description of illustrative embodiments, which should be read in conjunction with the accompanying drawings. List of characters
[0006] The following description provides details of preferred embodiments with reference to the following figures, in which: Fig. 1 a block diagram / flowchart of an overview of a cluster data processing system according to an embodiment of the present invention; Fig. 2 a block diagram for detecting and storing change events, which according to an embodiment of the present invention in the system of Fig. 1 can be implemented; Fig. 3 a block diagram / flowchart of a system / method for detecting mutation events in a cluster data processing system according to an embodiment of the present invention; Fig. 4 is a block diagram of a processing system according to an embodiment of the present invention; Fig. 5 is a block diagram of an exemplary cloud computing environment with one or more cloud computing nodes with which local data processing units used by cloud users exchange data according to an embodiment of the present invention; Fig. 6 is a block diagram of a set of functional abstraction layers provided by a cloud computing environment according to an embodiment of the present invention; and Fig. Figure 7 is a representation of an exemplary change event according to an embodiment of the present invention. DETAILED DESCRIPTION
[0007] The embodiments described here provide mutation event detection for cluster data processing systems. A cluster data processing system can have one or more groups of connected computing units, or clusters, that work together to perform tasks. In clusters, each group of nodes can perform the same tasks, which can be controlled and scheduled via software.
[0008] As used here, a mutation event refers to a change event that corresponds to an unintended change within a cluster. More specifically, the implementations described here can collect change events and extract mutation events from them. The change events can include low-level events, such as creating files, updating, deleting, and starting processes. The mutation events can be extracted (1) without program or image analysis and (2) with the ability to filter out non-mutation events that occur only occasionally or rarely (e.g., intended events).
[0009] The implementations described here can be implemented, for example, with a cluster data processing system that includes a container orchestration system to automate application deployment, scaling, and management. A container is a module that uses operating system-level virtualization to deliver software. Containers are isolated from each other and can bundle their own software, libraries, and configuration files. Because containers run from a single operating system kernel, they are simpler than, for example, virtual machines. The cluster can, for example, include a Kubernetes container orchestration system. Kubernetes is an open-source container orchestration system that can be used with a variety of container tools.
[0010] The implementations described here can be used to comply with system and information integrity standards, for example, but not limited to, PCI / DSS (e.g., PCI requirement 11.5), NIST standards (e.g., NIST Special Publication 800-53 (SI-7)), etc. For instance, when PCI requirement 11.5 is applied to containers whose behavior is particularly well-defined, mutations in the container can predict an abnormal change in its behavior. Such behavioral changes can be evaluated by the system administrator for further investigation (after considering known changes expected in the container based on a whitelisted profile). The investigation may indicate malicious activity (new malicious files or processes), Bitcoin miners, or containers in a non-proprietary state.
[0011] A reference in the description to "an embodiment" and other variations thereof means that a specific feature, structure, or property, etc., described in connection with the embodiment, is included in at least one embodiment of the present invention. The phrase "in an embodiment" and other variations thereof, appearing at various points in the description, therefore need not necessarily refer to one and the same embodiment each time.
[0012] It should be noted that the use of " / ", "and / or", and "at least ... or" in the cases of "A / B", "A and / or B", and "at least A or B" is intended to include the selection of the first-listed option only (A), the selection of the second-listed option only (B), or the selection of both options (A and B). As a further example, the phrase in the cases of "A, B and / or C" and "at least A, B, or C" is intended to include the selection of the first-listed option only (A), the selection of the second-listed option only (B), the selection of the third-listed option only (C), the selection of the first and second-listed options only (A and B), the selection of the first and third-listed options only (A and C), the selection of the second and third-listed options only (B and C), or the selection of all three options (A, B, and C).It is obvious to an expert in this and similar fields that this can be extended to any number of terms.
[0013] The terminology used herein serves only to describe specific embodiments and is not intended to limit the invention. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise. It is further understood that the terms "have" and / or "having" and "comprising" as used herein specify the presence of specified features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0014] It should be noted that while the terms "first," "second," etc., can be used here to describe different elements, these elements are not intended to be restricted by these terms. These terms are used only to distinguish one element from another. Thus, a first element described below could be referred to as a second element without deviating from the scope of the present concept.
[0015] With reference now to the drawings in which identical numbers denote identical or similar elements, and with reference first to Fig. Section 1 provides an overview of a cluster data processing system 100. In one embodiment, the system 100 includes a container orchestration system. For example, the system 100 can include a Kubernetes container orchestration system.
[0016] The system can comprise one or more clusters. As shown in this illustrative embodiment, system 100 can comprise a plurality of clusters, including cluster 110-1 and cluster 110-2. Further details regarding clusters 110-1 and 110-2 are given below with reference to Fig. 2 described.
[0017] As further explained, System 100 can also include a database (DB) 120. DB 120 can store one or more change events received from clusters 110-1 and 110-2. As described in more detail below, these one or more change events can be collected to detect mutation events.
[0018] As further described, the system 100 can also include an API server (Application Programming Interface) 130. One or more external commands can be executed by a container platform within a container orchestration system. In one embodiment, the API server 130 could, for example, be a Kubernetes API server. As described in more detail below, the API server 130 can provide one or more external commands (e.g., one or more check commands) to detect mutation events in conjunction with change events.
[0019] As further explained, the system 100 also includes at least one processing unit 140. The at least one processing unit 140 is configured to detect mutation events based on one or more change events and one or more external commands.
[0020] For example, the at least one processing unit 140 can include an external command retrieval component 142 configured to retrieve one or more external commands (e.g., one or more check commands) from the API server 130. For instance, one or more external commands can be extracted from container definitions in the API server 130. Examples of external commands (e.g., check commands) include, but are not limited to, `liveness_probe` (executed periodically to check the activity state of a container), `readiness_probe` (executed periodically to check the readiness of a container), `lifecycle_post_start` (executed only once shortly after a container starts), `lifecycle_pre_stop` (executed only once shortly before a container stops), and so on.
[0021] The at least one processing unit 140 can further include a component for collecting change events 144, which is configured to collect one or more change events from the database 120. An example of a change event is given below with reference to Fig. 7 described in more detail.
[0022] The at least one processing unit 140 can further include a process tree generation component 146, configured to generate one or more process trees (or "mutation trees") based on one or more processes associated with the one or more change events. In a given process tree, the parent process might, for example, have all its child processes as branches. File change events could then be the child elements of the corresponding process in the form of a leaf of the branch. In particular, the one or more process trees can be generated based on process identifiers (PIDs) in each event. A PID is an identifier (e.g., a number) that can be used by an operating system kernel to identify an active process.Examples of PIDs that can be used to generate one or more process trees include, but are not limited to, PID, PPID (the PID of a parent process), PGID (the PID of a process group leader of a process group), etc.
[0023] The at least one processing unit 140 can further include a mutation detection component 148. The mutation detection component 148 can be configured to perform mutation detection by comparing the root of each of the one or more process trees with the one or more external instructions. The root of a given process tree is a process corresponding to an original process of events. If the root of the given process tree matches at least one of the external instructions, it is determined that the root of the given process tree is a process resulting from an external instruction. Thus, all events in the given process tree are generated by an external instruction, and no mutation is detected.However, if the root of the given process tree does not match at least one of the external instructions, it is determined that the root of the given process tree is not a process resulting from an external instruction. Thus, all events in the given process tree are generated by an external instruction, and a mutation is detected.
[0024] The mutation detection component 148 can be further configured to generate a mutation event report (“report”) 150 based on the comparison. For example, if the comparison reveals that the root of the given process tree is a process resulting from an external command and therefore does not represent a mutation, the given process tree can be omitted or removed from the report 150. Conversely, if the comparison reveals that the root of the given process tree is not a process resulting from an external command and therefore does not represent a mutation, the given process tree can be added to the report 150.
[0025] For example, in a container orchestration system, given a sample, at least one processing unit (PPU) 140 can continuously monitor a container for the state of its files and processes and report modulo state changes on a user interface. These changes are added to the profile whitelist as normal modifications for the container. The reports can be viewed as mutation notifications for each individual container, as well as a timeline for each container. Accordingly, at least one PPU 140 can meet the standards for monitoring container integrity.
[0026] In an illustrative embodiment, the database 120 can be configured to collect approximately 32,835 change events per hour, the process tree generation component 146 can be configured to generate approximately 4,011 process trees per hour, and 4 process trees per hour corresponding to a non-external command event (e.g., non-check commands) can be detected (e.g., only 2 containers per hour).
[0027] With reference to Fig. Figure 7 provides a diagram illustrating an example change event 700. In this illustrative embodiment, change event 700 is associated with a Kubernetes ("k8s") container orchestration system. As shown, change event 700 can include multiple fields, including "Time", "k8s.ns.name", "k8s.pod.name", "container.name", "proc.cmdline", "entry_proc", "proc.vpgid", and "proc.vpid".
[0028] The "Time" field provides a timestamp that corresponds to the change event.
[0029] The field “k8s.ns.name” specifies the name of the namespace (ns), which in this example is “cognitive-data”.
[0030] The field "k8s.pod.name" specifies the name of the pod, which in this example is "conv-a-s04-csfdev-data-exhaust-healthcheck-5c8cd97fd5-dllhf". A pod is a group of one or more containers with shared storage / network and a specification of how the containers should run.
[0031] The field “container.name” specifies a name for the container, which in this example is “data-exhaust-producer”.
[0032] The "proc.cmdline" field specifies the complete command line when the process is started.
[0033] The field “entry_proc” indicates whether the process is a different root process than the root process originating from the container entry point.
[0034] The field “proc.vpgid” specifies the process group identifier of the process that generates the event, as indicated by its current PID namespace.
[0035] The field “proc.vpgid” specifies the identifier of the process that generates the event, as indicated by its current PID namespace.
[0036] With reference to Fig. Figure 2 shows a System 200 comprising a Cluster 202-1 and a Cluster 202-2. As shown, Cluster 202-1 can include a node 210-1 and a plurality of containers 220-1 running on the node 210-1, and Cluster 202-2 can include a node 210-2 and a plurality of containers 220-2 running on the node 210-2. System 200 can also include a database (DB) 230.
[0037] The majority of containers 220-1 can contain a crawler container 222-1, and the majority of containers 220-2 can contain a crawler container 222-2. Crawler container 222-1 can be configured to monitor the containers 220-1 running on node 210-1, and crawler container 222-2 can be configured to monitor the containers 220-2 running on node 220-2. The data observed or detected by crawler containers 222-1 and 222-2 can then be sent to database 230. Database 230 can store the data to perform mutation event detection, for example, as described above. Fig. 1. Any suitable crawler container can be used to implement the crawler containers 222-1 and 222-2 according to the embodiments described herein. Suitable crawler containers include, but are not limited to, Sysdig.
[0038] In this illustrative embodiment, System 200 is a cluster data processing system that includes a container orchestration system. However, such an embodiment is not to be considered restrictive, and the cluster data processing system may include any suitable orchestration system according to the embodiments described herein.
[0039] With reference to Fig. Figure 3 shows a block diagram / flowchart illustrating a system / procedure 300 for detecting mutation events in a cluster data processing system.
[0040] Block 310 collects one or more change events in a cluster data processing system. The cluster data processing system can comprise one or more clusters, each containing a corresponding node, and collecting the one or more change events can include detecting the one or more change events in the one or more clusters and storing the one or more detected change events in a database.
[0041] In one embodiment, the cluster data processing system can include a container orchestration system (e.g., a Kubernetes container orchestration system), wherein each cluster comprises a plurality of containers running on the corresponding cluster node. Specifically, a given container from among the plurality of containers within a given cluster of one or more clusters can be a crawler container configured to monitor the containers running on that cluster. Any suitable process can be used to collect the one or more change events according to the embodiments described herein.
[0042] Block 320 generates one or more process trees based on one or more processes associated with the one or more change events. In a given process tree, the parent process might, for example, have all its child processes as branches. File change events could then be the child elements of the corresponding process, represented as leaves of the branch. Specifically, the one or more process trees can be generated based on process identifiers (PIDs) in each event. Examples of PIDs that can be used to generate the one or more process trees include, but are not limited to, PID, PPID (the PID of a parent process), PGID (the PID of a process group leader of a process group), and so on.Any suitable process can be used to generate one or more process trees according to the embodiments described here.
[0043] Block 330 can retrieve one or more external commands. These one or more external commands can correspond to intended access patterns. For example, the one or more external commands can be executed by a container platform within a container orchestration system. In one embodiment, the one or more external commands can be retrieved from an API server (e.g., a Kubernetes API server). Retrieving the one or more external commands can involve extracting them from container definitions in the API server. Examples of external commands (e.g.,These check commands include, but are not limited to, `liveness_probe` (executed periodically to check the activity state of a container), `readiness_probe` (executed periodically to check the readiness of a container), `lifecycle_post_start` (executed only once shortly after a container starts), `lifecycle_pre_stop` (executed only once shortly before a container stops), and so on. Any suitable process can be used to invoke one or more external commands according to the embodiments described here.
[0044] In block 340, mutation event detection is performed by comparing the root of each process tree with one or more external instructions. If the root of the given process tree matches at least one of the external instructions, it is determined that the root of the given process tree is a process resulting from an external instruction. Thus, all events in the given process tree are generated by an external instruction, and no mutation is detected. However, if the root of the given process tree does not match at least one of the external instructions, it is determined that the root of the given process tree is not a process resulting from an external instruction. Thus, all events in the given process tree are generated by an external instruction, and a mutation is detected.
[0045] The steps performed in blocks 310 to 340 can extract “unintended” events from the one or more change events without program or image analysis and filter out all “intended” events or access patterns from the one or more change events that occur rarely or only occasionally.
[0046] In Block 350, a mutation event report can be automatically generated based on the comparison. The mutation event report can include change events structured as a process tree that are caused by unintended access (as opposed to intended access). For example, if the comparison determines that the root of a given process tree is a process resulting from an external command and therefore does not represent a mutation, the given process tree can be omitted or removed from the mutation event report. Conversely, if the comparison determines that the root of a given process tree is not a process resulting from an external command and therefore does represent a mutation, the given process tree can be added to the mutation event report.
[0047] In Block 360, the mutation event report can be transmitted to one or more data processing units. These units can be assigned to one or more system administrators. The mutation event report can be displayed in a user interface that informs the system administrator(s) about unintended changes (e.g., unintended changes to a container). The system administrator(s) can then take corrective action to rectify the unintended changes identified in the mutation event report.
[0048] For example, in a container orchestration system, given a sample, System / Procedure 300 can continuously monitor a container for the state of its files and processes and report modulo changes to this state on a user interface. These changes are then added to the profile whitelist as normal modifications for the container. The reports can be viewed as mutation alerts for each individual container, as well as a timeline for each container. Accordingly, System / Procedure 300 can meet the standards for monitoring container integrity.
[0049] With reference to Fig. Figure 4 shows an exemplary processing system 400 to which the present invention can be applied according to one embodiment. The processing system 400 includes at least one processor (CPU) 404, which is functionally connected to other components via a system bus 402. A cache 406, a read-only memory (ROM) 408, a random access memory (RAM) 410, an input / output (I / O) adapter 420, an audio adapter 430, a network adapter 440, a user interface adapter 450, and a display adapter 460 are functionally connected to the system bus 402.
[0050] A first storage unit 422 and a second storage unit 424 are functionally connected to the system bus 402 via the I / O adapter 420. Storage units 422 and 424 can be any type of disk storage unit (e.g., a magnetic or optical disk storage unit), a magnetic semiconductor unit, etc. Storage units 422 and 424 can be of the same type or different types.
[0051] A loudspeaker 432 is functionally connected to the system bus 402 via the audio adapter 430. A transceiver 442 is functionally connected to the system bus 402 via the network adapter 440. A display unit 462 is functionally connected to the system bus 402 via the display adapter 460.
[0052] A first user input unit 452, a second user input unit 454, and a third user input unit 456 are functionally connected to the system bus 402 via the user interface adapter 450. The user input units 452, 454, and 456 can be a keyboard, a mouse, a keypad, an image capture unit, a motion tracking unit, a microphone, or a unit with the functionality of at least two of the preceding units, etc. Of course, other types of units can also be used. The user input units 452, 454, and 456 can be of the same type or different types. The user input units 452, 454, and 456 are used to input information into the system 400 and to output it from the system 900.
[0053] The Mutation Event Detection (MED) component 470 can be functionally connected to the system bus 402. The MED component 470 is configured to take samples in a formulation generation system as described above. The MED component 470 can be implemented as a standalone, dedicated hardware unit or as software stored on a memory unit. In the embodiment where the MED component 470 is implemented as software, although depicted as a separate component of the computer system 400, the MED component 470 can be stored, for example, on the first memory unit 422 and / or the second memory unit 424. Alternatively, the MED component 470 can also be stored on a separate memory unit (not shown).
[0054] As is evident to those skilled in the art, the processing system 400 can, of course, also contain other elements (not shown) and omit certain elements. As is evident to those skilled in the art, for example, various other input and / or output units can be included in the processing system 400, depending on the specific implementation. For instance, different types of wireless and / or wired input and / or output units can be used. Furthermore, as is evident to those skilled in the art, additional processors, control units, memory, etc., can also be used in various configurations. These and other variations of the processing system 400 are obvious to those skilled in the art in light of the teachings of the present invention provided herein.
[0055] Although the present disclosure contains a detailed description of cloud computing, it is understood that the implementation of the teachings set forth herein is not limited to a cloud computing environment. Instead, embodiments of the present invention can be implemented together with any type of data processing environment, now known or subsequently invented.
[0056] Cloud computing is a model for delivering a service that enables seamless, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management overhead or interaction with a service provider. This cloud model can include at least five properties, at least three service models, and at least four implementation models.
[0057] The properties are as follows: On-Demand Self-Service: A cloud user can unilaterally and automatically provide data processing functions such as server time and network storage as needed, without requiring human interaction with the service provider.
[0058] Broad Network Access: Functions are available over a network, accessed through standard mechanisms that support use by heterogeneous lightweight or power-intensive client platforms (e.g., mobile phones, laptops, and PDAs).
[0059] Resource pooling: The provider's data processing resources are pooled to serve multiple users using a multi-tenant model, with various physical and virtual resources being dynamically allocated and reassigned as needed. There is a perceived location independence, as the user generally has no control over or knowledge of the exact location of the provided resources, but may be able to define a location at a higher level of abstraction (e.g., country, state, or data center).
[0060] Rapid elasticity: Features can be deployed quickly and elastically for rapid horizontal scaling (scale out), in some cases automatically, and released quickly for rapid scale-in. To the user, the available features often appear unlimited and can be purchased in any quantity at any time.
[0061] Measured Service: Cloud systems automatically control and optimize resource usage by employing a measurement function at a certain level of abstraction appropriate for the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource utilization can be monitored, controlled, and reported, providing transparency for both the service provider and the user.
[0062] The following service models are available: Software as a Service (SaaS): The functionality provided to the user consists of using the provider's applications running in a cloud infrastructure. The applications are accessible from various client devices via a streamlined client interface, such as a web browser (e.g., web-based email). The user does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functions, with the possible exception of limited user-specific application configuration settings.
[0063] Platform as a Service (PaaS): The functionality provided to the user is to deploy applications created or obtained by the user, using programming languages and tools supported by the provider, within the cloud infrastructure. The user does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but has control over the deployed applications and potentially over configurations of the application's hosting environment.
[0064] Infrastructure as a Service (IaaS): The functionality provided to the user consists of supplying processing, storage, networking, and other basic data processing resources, enabling the user to deploy and run any software, including operating systems and applications. The user does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and potentially limited control over selected network components (e.g., host firewalls).
[0065] The following deployment models are available: Private Cloud: The cloud infrastructure is operated solely for one organization. It can be managed by the organization or a third party and can be located on the organization's own premises or on external premises.
[0066] Community Cloud: The cloud infrastructure is shared by multiple organizations and supports a specific user community with common concerns (e.g., tasks, security requirements, policies, and considerations regarding regulatory compliance). It can be managed by the organizations themselves or a third party and can be located on the organization's own premises or on external premises.
[0067] Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services.
[0068] Hybrid Cloud: The cloud infrastructure consists of two or more clouds (private, community or public) which remain separate entities but are connected by a standardized or proprietary technology that enables the transferability of data and applications (e.g. cloud audience distribution for load balancing between clouds).
[0069] A cloud computing environment is service-oriented and focuses primarily on statelessness, low coupling, modularity, and semantic interoperability. At its core, cloud computing is an infrastructure comprising a network of interconnected nodes.
[0070] With reference to now Fig. Figure 5 illustrates a cloud computing environment 550. As shown, the cloud computing environment 550 contains one or more cloud computing nodes 510, with which local data processing units used by cloud users, such as the personal digital assistant (PDA) or mobile phone 554A, the desktop computer 554B, the laptop computer 554C, and / or the automotive computer system 554N, can exchange data. The nodes 510 can exchange data with each other. They can be physically or virtually arranged in groups (not shown) in one or more networks, such as private, shared, public, or hybrid clouds as described above, or in a combination thereof. This enables the cloud computing environment 550 to offer infrastructure, platforms, and / or software as services, for which a cloud user does not need to maintain resources on a local data processing unit.It is evident that the types of data processing units 554A to N, which are in . Fig. The figures shown in Figure 5 are for illustrative purposes only, and the data processing nodes 510 and the cloud data processing environment 550 can exchange data with any type of computerized unit over any type of network and / or network-addressable connection (e.g., via a web browser).
[0071] With reference to now Fig. Figure 6 shows a set of functional abstraction layers used by the Cloud Computing Environment 550 ( Fig. 5) will be provided. It is understood in advance that the in Fig. The components, layers, and functions shown in Figure 6 are for illustrative purposes only, and embodiments of the invention are not limited to them. As shown, the following layers and corresponding functions are provided:
[0072] The hardware and software layer 660 contains hardware and software components. Examples of hardware components include: the mainframes 661; the servers 662 based on the RISC architecture (RISC = Reduced Instruction Set Computer); the servers 663; the blade servers 664; the storage units 665; and the networks and network components 666. In some embodiments, the software components include the network application server software 667 and the database software 668.
[0073] The virtualization layer 670 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 671; virtual storage 672; virtual networks 673; including virtual private networks; virtual applications and operating systems 674; and virtual clients 675.
[0074] In one example, the administration layer 680 can provide the functions described below. Resource provisioning 681 enables the dynamic provisioning of compute resources and other resources used to perform tasks in the cloud computing environment. Metering and pricing 682 provides cost tracking when using resources in the cloud computing environment, as well as billing or invoicing for the use of these resources. In one example, these resources could include licenses for application software. The security function provides identity verification for cloud users and tasks, as well as protection for data and other resources. A user portal 683 provides users and system administrators with access to the cloud computing environment.Service Level Management (684) provides the allocation and management of cloud computing resources to achieve the required service level. Service Level Agreement (SLA) Planning and Fulfillment (685) provides the pre-allocation and procurement of cloud computing resources based on forecasted future demand according to a Service Level Agreement.
[0075] The workload layer 690 provides examples of functionalities for which the cloud computing environment can be used. Examples of workloads and functions that can be provided by this layer include: mapping and navigation 691; software development and lifecycle management 692; delivery of training in virtual classrooms 693; data analytics processing 694; transaction processing 695; and mutation detection 696.
[0076] The present invention may be a system, a method, and / or a computer program product at any possible level of technical integration. The computer program product may comprise a computer-readable storage medium (or media) on which computer-readable program instructions are stored to induce a processor to execute aspects of the present invention.
[0077] A computer-readable storage medium can be a physical unit capable of retaining and storing instructions for use by a unit to execute instructions. For example, a computer-readable storage medium can be an electronic storage unit, a magnetic storage unit, an optical storage unit, an electromagnetic storage unit, a semiconductor storage unit, or any suitable combination thereof, without limitation. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer disk, a hard disk, random-access memory (RAM), read-only memory (ROM), and erasable programmable read-only memory (EPROM).Flash memory), static random-access memory (SRAM), portable compact storage disk-read-only memory (CD-ROM), DVD (digital versatile disc), USB flash drive, floppy disk, a mechanically coded unit such as punched cards or raised structures in a groove on which instructions are stored, and any suitable combination thereof. A computer-readable storage medium shall not, in its use herein, be understood as volatile signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses traveling through an optical fiber), or electrical signals transmitted by a wire.
[0078] The computer-readable program instructions described here can be downloaded from a computer-readable storage medium to individual data processing units (DPUs) or, via a network such as the internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network, to an external computer or storage device. The network may include copper cables, fiber optic cables, wireless transmission, routers, firewalls, switching units, gateway computers, and / or edge servers. A network adapter card or network interface in each DPU receives computer-readable program instructions from the network and forwards them for storage on a computer-readable storage medium within the respective DPU.
[0079] Computer-readable program instructions for executing work steps of the present invention may be assembler instructions, ISA (Instruction Set Architecture) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as SMALLTALK, C++, etc., as well as conventional procedural programming languages such as the programming language "C" or similar programming languages.The computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, via the internet using an internet service provider).In some embodiments, electronic circuits, including, for example, programmable logic circuits, field programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), can execute computer-readable program instructions by using state information from the computer-readable program instructions to personalize the electronic circuits to implement aspects of the present invention.
[0080] The terms "hardware processor subsystem" or "hardware processor" as used here can refer to a processor, memory, software, or combinations thereof, working together to perform one or more specific tasks. In suitable embodiments, the hardware processor subsystem may include one or more data processing elements (e.g., logistics circuits, processing circuits, instruction execution units, etc.). The one or more data processing elements may be contained in a central processing unit, a graphics processing unit, and / or a separate control unit based on a processor or a data processing element (e.g., logic gates, etc.). The hardware processor subsystem may include one or more integrated memories (e.g., caches, dedicated memory arrays, read-only memories, etc.).In some embodiments, the hardware processor subsystem may include one or more memories, which may be integrated or external, or which are specifically provided for use by the hardware processor subsystem (e.g., ROM, RAM, basic input / output system (BIOS), etc.).
[0081] In some embodiments, the hardware processor subsystem can include and execute one or more software elements. These software elements can include an operating system and / or one or more applications and / or specific code to achieve a particular result.
[0082] In other embodiments, the hardware processor subsystem may include specialized circuits that perform one or more electronic processing functions to achieve a specific result. Such circuits may include one or more application-specific integrated circuits (ASICs), FPGAs, and / or PLAs.
[0083] These and other variants of a hardware processor subsystem are also conceivable according to embodiments of the present invention.
[0084] Aspects of the present invention are described here with reference to flowcharts and / or block diagrams or diagrams of methods, devices (systems), and computer program products according to embodiments of the invention. It is pointed out that each block of the flowcharts and / or block diagrams or diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams or diagrams, can be executed by means of computer-readable program instructions.
[0085] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a specialized computer, or another programmable data processing device to create a machine such that the instructions executed by the processor of the computer or other programmable data processing device generate a means of implementing the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.These computer-readable program instructions may also be stored on a computer-readable storage medium capable of controlling a computer, programmable data processing device, and / or other units to function in a particular manner, such that the computer-readable storage medium on which instructions are stored has a manufacturing item, including instructions that implement aspects of the function / step specified in the block(s) of the flowchart and / or block diagrams or charts.
[0086] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing device, or other unit to cause the execution of a series of process steps on the computer or other programmable device or other unit in order to generate a process executed on a computer, such that the instructions executed on the computer, other programmable device, or other unit implement the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.
[0087] The flowcharts and block diagrams or charts in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this context, each block in the flowcharts or block diagrams or charts can represent a module, segment, or part of instructions that includes one or more executable instructions for performing the specific logical function(s). In some alternative embodiments, the functions specified in the block may occur in a different order than shown in the figures. For example, two blocks shown consecutively may in reality be executed essentially simultaneously, or the blocks may sometimes be executed in reverse order depending on the corresponding functionality.It should also be noted that each block of the block diagrams or charts and / or flowcharts, as well as combinations of blocks in the block diagrams or charts and / or flowcharts, can be implemented by special hardware-based systems that perform the specified functions or steps, or execute combinations of special hardware and computer instructions.
[0088] Having described preferred embodiments of systems and methods for mutation event detection (whereby the embodiments are intended to be illustrative and not limiting), it should be noted that modifications and adaptations can be made by those skilled in the art based on the foregoing teachings. It is therefore understood that modifications can be made to the particular disclosed embodiments that fall within the scope of the invention as set forth in the accompanying claims. Having thus described aspects of the invention with the details and features required by patent law, the accompanying claims set forth what is claimed and is to be protected by a patent.
Claims
[1] System that has: a memory unit for storing program code; and at least one hardware processor operatively connected to the storage unit and configured to execute the program code stored on the storage unit to: create one or more process trees based on one or more processes associated with the one or more change events in a cluster data processing system; detect mutation events by comparing a root of each of the one or more process trees with one or more external instructions; and to generate a mutation event report based on the comparison. [2] The system of claim 1, further comprising: a database communicating with the at least one processor unit and configured to store the one or more change events; and a server with an application programming interface (API) that exchanges data with the at least one hardware processor. [3] The system of claim 2, wherein the at least one hardware processor is further configured to execute program code stored in the memory unit to: collect one or more change events from a database; and to retrieve one or more external commands via a server with an application programming interface (API). [4] The system of claim 1, wherein: the cluster computing system comprises one or more containers; the at least one hardware processor is further configured to collect the one or more change events from the one or more containers; and which executes one or more external commands from a container platform. [5] The system of claim 1, wherein the one or more external commands comprise one or more test commands. [6] The system of claim 1, wherein the at least one hardware processor is further configured to generate the mutation event report based on the comparison by: Determine that the root of a given process tree is a process resulting from one of the external instructions; and Omitting the given process tree in the mutation event report. [7] The system of claim 1, wherein the at least one hardware processor is further configured to transmit the mutation event report to one or more computing devices. [8] The system of claim 1, wherein the cluster computing system comprises a Kubernetes cluster computing system. [9] A computer-implemented method comprising: Creating one or more process trees based on one or more processes associated with the one or more change events in a cluster data processing system; performing the detection of mutation events by comparing a root of each of the one or more process trees with one or more external instructions; and Generate a mutation event report based on the comparison. [10] The method of claim 9, further comprising: Collecting the one or more change events; and Retrieve one or more external commands. [11] The method of claim 10, wherein: the cluster computing system comprises one or more containers; Collecting the one or more change events further comprises collecting the one or more change events from the one or more containers; and which executes one or more external commands from a container platform. [12] The method of claim 9, wherein the one or more external commands comprise one or more test commands. [13] The method of claim 9, wherein generating the mutation event report based on the comparison further comprises: Determine that the root of a given process tree is a process resulting from one of the external instructions; and Omitting the given process tree from the mutation event reports. [14] The method of claim 9, further comprising transmitting the mutation event report to one or more data processing units. [15] A computer program product comprising a computer-readable storage medium having program instructions embodied thereon, the program instructions being executable by a computer to cause the computer to perform a method comprising: Creating one or more process trees based on one or more processes associated with the one or more change events in a cluster data processing system; performing the detection of mutation events by comparing a root of each of the one or more process trees with one or more external instructions; and Generate a mutation event report based on the comparison. [16] The computer program product of claim 15, wherein the method further comprises: Collecting the one or more change events; and Retrieve one or more external commands. [17] A computer program product according to claim 16, wherein: the cluster computing system comprises one or more containers; Collecting the one or more change events further comprises collecting the one or more change events from the one or more containers; and which executes one or more external commands from a container platform. [18] The computer program product of claim 15, wherein the one or more external instructions comprise one or more test instructions. [19] The computer program product of claim 15, wherein generating the mutation event report based on the comparison further comprises: Determine that the root of a given process tree is a process resulting from one of the external instructions; and Omitting the given process tree from the mutation event reports. [20] The computer program product of claim 15, wherein the method further comprises transmitting the mutation event report to one or more data processing units.
Citation Information
Patent Citations
System for comparison and merging of versions in edited websites and interactive applications
US20150154164A1
Process risk classification
US20160357967A1