Multi-tenant security

The method addresses vulnerabilities in multi-tenant systems by migrating tenants to single-tenant hosts and using sandbox containers to isolate malicious activities, ensuring availability and functionality of benign tenants.

JP2025524814APending Publication Date: 2025-08-01INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025501897
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-27
Filing Date
2023-06-27
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

Multi-tenant systems are vulnerable to cyber security threats, where compromising one tenant can lead to the infection of multiple tenants due to shared virtual resources, resulting in loss of availability for all tenants.

Method used

A computer-implemented method that detects malicious activity on a compromised application in a multi-tenant host, performs live migration of tenants to single-tenant hosts, and isolates potentially malicious tenants in sandbox containers, while preserving workload availability using live migration techniques.

Benefits of technology

Effectively mitigates malicious activities in multi-tenant systems by isolating compromised tenants and maintaining availability and functionality of benign tenants through single-tenant hosting and sandbox container usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025524814000001_ABST
    Figure 2025524814000001_ABST
Patent Text Reader

Abstract

Techniques for multi-tenant security are described. The techniques include detecting malicious activity on an application that has been security compromised in a multi-tenant host. The techniques further include automatically performing a live migration of each tenant of the multi-tenant host to a respective single-tenant host. The techniques further include mitigating malicious activity on the security compromised application migrated to the single-tenant host, and automatically performing another live migration of each benign tenant to a new multi-tenant host.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] The present disclosure relates to computer security, and more specifically, to reducing malicious activities in a multi-tenant system.

[0002] Server hosting is an information technology (IT) service (e.g., from a cloud service provider) that provides remote access to off-premises virtual or physical servers and associated resources for a monthly fee or usage-based charges. Server hosting enables an IT team to provision and use application and data servers without the effort of upfront payment, delays, and purchasing, setting up, managing, and maintaining the physical server hardware itself.

[0003] Server hosting can include multi-tenant (e.g., shared) hosting or single-tenant (e.g., dedicated) hosting. In multi-tenant hosting, the resources of one physical server are virtualized and made available to multiple tenants (e.g., users, clients, etc.). In contrast, in single-tenant hosting, a single tenant has exclusive access to all resources of a single hardware server. Multi-tenant hosting is generally more cost-effective for smaller and simpler projects, while single-tenant hosting is generally more convenient for projects that require more control and / or higher performance (or a higher certainty of a certain level of performance).

[0004] Despite the advantages provided by a multi-tenant system, the multi-tenant system remains vulnerable to cyber security threats. In particular, in a multi-tenant system, if one tenant is compromised, due to the proximity of those compromised tenants to shared virtual resources, multiple other tenants may be at risk of infection. Thus, if one tenant is exploited in a multi-tenant system, all tenants in the multi-tenant system may lose availability while the exploitation of that one exploited tenant is mitigated.

Summary of the Invention

[0005] Aspects of the present disclosure are directed to a computer-implemented method comprising detecting malicious activity on a compromised application on a multi-tenant host. The method further comprises automatically performing a live migration of each tenant of the multi-tenant host to a respective single-tenant host. The method further comprises mitigating malicious activity on the compromised application migrated to the single-tenant host. The method further comprises automatically performing another live migration of each benign tenant to a new multi-tenant host.

[0006] Advantageously, the method described above mitigates malicious activity on the multi-tenant host while preserving the availability of tenant workloads by (i) migrating tenants to single-tenant hosts capable of executing tenant workloads; and (ii) using live migration techniques to preserve availability during migration from the multi-tenant host to the single-tenant host.

[0007] Additional aspects of the present disclosure are directed to a computer-implemented method comprising detecting an unauthorized clone of a first tenant on a multi-tenant host and automatically isolating the tenant of the multi-tenant host in a sandbox container. The method further comprises determining a secure image corresponding to the first tenant and reapplying the image of the first tenant on a new multi-tenant host using the secure image. The method further comprises verifying the security of each tenant in the sandbox container; and in response to verifying the security of each tenant in the sandbox container, migrating each tenant from the sandbox container to the new multi-tenant host.

[0008] Advantageously, the method described above mitigates malicious activities in the form of unauthorized clones on the multi-tenant host while preserving the availability of the tenant workload. More specifically, by using a sandbox container, the method described above balances the availability of the tenant workload and the isolation of potentially malicious tenants.

[0009] Additional aspects of the present disclosure are directed to a system and a computer program product configured to implement the method described above. The summary of the invention is not intended to represent each aspect, every implementation, or all embodiments of the present disclosure.

Brief Description of the Drawings

[0010] The drawings included in this application are incorporated herein and form a part hereof. They illustrate embodiments of the present disclosure and, together with this description, serve to explain the principles of the present disclosure. The drawings are merely illustrative of particular embodiments and do not limit the present disclosure.

[0011]

Figure 1

[0012]

Figure 2

[0013]

Figure 3

[0014]

Figure 4

[0015]

Figure 5

[0016]

Figure 6

[0017]

Figure 7

[0018]

Figure 8

[0019]

Figure 9

[0020]

Figure 10

[0021] The present disclosure is susceptible to various modifications and alternative forms, and specific details of the present disclosure are shown by way of example in the drawings and will be described in detail below. However, it should be understood that the present disclosure is not intended to be limited to the particular embodiments described. On the contrary, it is intended to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the present disclosure.

Best Mode for Carrying Out the Invention

[0022] Aspects of the present disclosure are directed to computer security, and more particularly, to reducing malicious activity in a multi-tenant system. Although not limited to such applications, embodiments of the present disclosure may be better understood in view of the foregoing context.

[0023] Aspects of the present disclosure are directed to identifying malicious activities on a multi-tenant host and isolating detected malicious activities. Malicious activities can be isolated by (i) migrating each tenant of the multi-tenant host to a single-tenant host and / or (ii) isolating one or more tenants of the multi-tenant host in a sandbox container. Once isolated, aspects of the present disclosure can mitigate malicious activities (e.g., by terminating an application, deleting an unauthorized clone, etc.). After verifying that benign tenants (e.g., tenants not infected by exploitation) are actually secure, aspects of the present disclosure can return the benign tenants to a secure multi-tenant host.

[0024] Advantageously, aspects of the present disclosure enable malicious activities on a multi-tenant host to be isolated and mitigated. Further, aspects of the present disclosure preserve the availability and functionality of benign tenants (e.g., by hosting benign tenants on single-tenant servers or in permitted sandbox containers). Still further, aspects of the present disclosure preserve the availability and functionality of benign tenants by using live migration techniques to maintain availability and functionality during the aforementioned migrations.

[0025] Referring now to the figures, FIG. 1 shows a block diagram of an exemplary computing environment 100 implementing multi-tenant security in identifying a security-compromised tenant, according to some embodiments of the present disclosure. The exemplary computing environment 100 includes a multi-tenant host 102, a plurality of single-tenant hosts 106 (e.g., single-tenant host 1 106-1, single-tenant host 2 106-2, single-tenant host N 106-N, where N is any integer greater than or equal to 1), and an exploitation analysis system 110 communicatively coupled by a network 108.

[0026] Network 108 can be a local area network (LAN), wide area network (WAN), intranet, Internet, or any other network 108 or group of networks 108 that can connect the aforementioned components together, continuously, semi - continuously, or intermittently (either directly or indirectly).

[0027] Multi - tenant host 102, single - tenant host 106, and abuse analysis system 110 can be any computer, server, mainframe, virtual machine (VM), container, tablet, notebook, smartphone, other computer hardware (physical or virtualized), a plurality of the foregoing, and / or a combination of the foregoing. As will be understood by those skilled in the art, FIG. 1 represents some embodiments of the present disclosure and should not be construed as limiting. In other embodiments, there may be more or fewer similar or dissimilar components compared to the components shown in FIG. 1. Further, in various embodiments, the components shown in FIG. 1, if they exist, may be combined together into integrated components or separated into distinct components.

[0028] Multi - tenant host 102 can include computing resources (e.g., computing resources, storage resources, networking resources, etc.) shared among multiple tenants 104 (e.g., tenant 1 104 - 1, security - breached tenant 2 104 - 2, tenant N 104 - N). In contrast, single - tenant host 106 can include computing resources (e.g., computing resources, storage resources, networking resources, etc.) dedicated to an individual tenant. Abuse analysis system 110 can detect that security - breached tenant 2 104 - 2 has been security - breached by some type of malicious cyber - attack using threat detection model 112.

[0029] The threat detection model 112 can be any currently known or later developed model for automatically identifying cyber threats, cyber intrusions, cyber attacks, or other malicious behavior from internal actors and / or external actors. In some embodiments, the threat detection model 112 maintains (or accesses) a database of known exploit signatures. Such known exploit signatures can be in the form of hashes, digests, or other identifiers of known exploits reduced to alphanumeric sequences. In some embodiments, such known exploit signatures can be in the form of logged event sequences, hardware events, software events, and / or other events that can individually or collectively indicate an exploit.

[0030] In some embodiments, the threat detection model 112 utilizes machine learning to automate the threat detection process. In such embodiments, the threat detection model 112 can use any number of machine learning algorithms, including but not limited to natural language processing (NLP), decision tree learning, correlation rule learning, artificial neural networks, deep learning, inductive logic programming, support vector machines, clustering, Bayesian networks, reinforcement learning, representation learning, similarity / metric training, sparse dictionary learning, genetic algorithms, rule-based learning, and / or other machine learning techniques.

[0031] For example, the threat detection model 112 can be configured to perform machine learning on data generated by one or more multi-tenant hosts 102 and / or one or more tenants 104. Such data can include, for example, activity logs, access logs, CPU usage, memory usage, network bandwidth usage, characteristics of the executed instruction set, and / or other data generated by applications, portals, interfaces, hypervisors, operating systems, virtual machines, containers, and / or other components of the multi-tenant host 102 and / or tenant 104.The threat detection model 112 can be trained on the aforementioned data using, for example, machine learning algorithms such as the following exemplary techniques: K-Nearest Neighbor (KNN), Learning Vector Quantization (LVQ), Self-Organizing Map (SOM), Logistic Regression, Ordinary Least Squares Regression (OLSR), Linear Regression, Stepwise Regression, Multivariate Adaptive Regression Splines (MARS), Ridge Regression, Least Absolute Shrinkage and Selection Operator (LASSO), Elastic Net, Least Angle Regression (LARS), Probabilistic Classifier, Naive Bayes Classifier, Binary Classifier, Linear Classifier, Hierarchical Classifier, Canonical Correlation Analysis (CCA), Factor Analysis, Independent Component Analysis (ICA), Linear Discriminant Analysis (LDA), Multidimensional Scaling (MDS), Non-Negative Matrix Factorization (NMF), Partial Least Squares Regression (PLSR), Principal Component Analysis (PCA), Principal Component Regression (PCR), Sammon Mapping, t-Distributed Stochastic Neighbor Embedding (t-SNE), Bootstrap Aggregating, Harmonic Mean, Gradient Boosting Decision Tree (GBDT), Gradient Boosting Machine (GBM), Inductive Bias Algorithm, Q-Learning, State-Action-Reward-State-Action (SARSA), Temporal Difference (TD) Learning, Apriori Algorithm, Equivalence Class Transformation (ECLAT) Algorithm, Gaussian Process Regression, Gene Expression Programming, Group Method of Data Handling (GMDH), Inductive Logic Programming, Example-Based Learning, Logic Model Tree, Information Fuzzy Network (IFN), Hidden Markov Model, Gaussian Naive Bayes, Multinomial Naive Bayes, Averaged One-Dependence Estimator (AODE), Bayesian Network (BN), Classification and Regression Tree (CART), Chi-Square Automatic Interaction Detection (CHAID), Expectation Maximization Algorithm, Feed-Forward Neural Network, Logic Learning Machine, Self-Organizing Map, Single Linkage Clustering, Fuzzy Clustering, Hierarchical Clustering, Boltzmann Machine, Convolutional Neural Network, Recurrent Neural Network, Hierarchical Temporal Memory (HTM), or other machine learning techniques, and / or one or more of them. After training, the threat detection model 112 can take in data from the multi-tenant host 102 and / or tenant 104 and output the identification information of the tenant that has been security-infringed (e.g., the security-infringed tenant 2 104-2).

[0032] Figure 2 shows a block diagram of an exemplary computing environment 200 implementing multi-tenant security during live migration of multiple tenants 104 to a single-tenant host 106, according to some embodiments of the present disclosure. In some embodiments, the exemplary computing environment 200 is a subsequent figure to the exemplary computing environment 100 of FIG. 1. The exemplary computing environment 200 includes the single-tenant host 106, tenant 104, network 108, abuse analysis system 110, and threat detection model, as previously described with respect to FIG. 1.

[0033] However, in FIG. 2, in response to detecting a compromised tenant 2 104-2, aspects of the present disclosure may perform a live migration of tenant 104 from the multi-tenant host 102 to respective single-tenant hosts 106. Accordingly, tenant 1 104-1 is migrated to single-tenant host 1 106-1, compromised tenant 2 104-2 is migrated to single-tenant host 2 106-2, and tenant N 104-N is migrated to single-tenant host N 106-N. On the other hand, the multi-tenant host 102 is deactivated (as shown by the deactivated multi-tenant host 202). Advantageously, by performing a live migration of tenant 104 from the multi-tenant host 102 to the single-tenant host 106, aspects of the present disclosure may (i) limit the spread of detected abuse (e.g., by isolating the compromised tenant 2 104-2 to the single-tenant host 106), and (ii) maintain workload availability for most (if not all) tenants 104 (e.g., by enabling the workload associated with tenant 104 to remain functional during and after the live migration).

[0034] Furthermore, as shown in the exemplary computing environment 200, the exploitation analysis system 110 collects and archives the activity logs 204 of the deactivated multi-tenant host. The activity logs 204 of the deactivated multi-tenant host can be obtained from the deactivated multi-tenant host 202 and include event information associated with the multi-tenant host 102 that may be useful for determining the nature of the exploitation, the extent of the exploitation, and / or preserving tenant information.

[0035] The exploitation analysis system 110 may further record the identifier 206 of the tenant whose security has been breached and the collocated tenant identifiers 208. The identifier 206 of the tenant whose security has been breached and the collocated tenant identifiers 208 can be application identifiers, instance identifiers, VM identifiers, container identifiers, and / or other identifiers useful for distinguishing the tenant whose security has been breached (e.g., the tenant 104-2 whose security has been breached in the case of the identifier 206 of the tenant whose security has been breached) from benign tenants (e.g., tenant 104-1 and tenant N 104-N) that are hosted on the same multi-tenant host 102 but are not exploited themselves.

[0036] FIG. 3 shows a block diagram of an exemplary computing environment 300 that implements multi-tenant security during the live migration of benign tenants to a new multi-tenant host 302, according to some embodiments of the present disclosure. In some embodiments, the exemplary computing environment 300 occurs after the exemplary computing environment 200 of FIG. 2. The exemplary computing environment 300 includes the deactivated multi-tenant host 202, tenant 104, single-tenant host N 106-N, network 108, exploitation analysis system 110, threat detection model 112, activity logs 204 of the deactivated multi-tenant host, identifier 206 of the tenant whose security has been breached, and collocated tenant identifiers 208, which were previously discussed in FIGS. 1 and 2.

[0037] However, FIG. 3 further includes a new multi-tenant host 302. Benign tenants (e.g., tenant 1 104-1 and tenant N 104-N) can be live migrated from the single-tenant host 106 to the new multi-tenant host 302, thereby enabling the benign tenants to be hosted in the same manner as before the detection of the compromised tenant 2 104-2. The new multi-tenant host 302 is shown as being separate from the deactivated multi-tenant host 202 (deactivated with respect to the multi-tenant host 102), but the new multi-tenant host 302 can be a new instance or, alternatively, a secure version of the deactivated multi-tenant host 202 in some embodiments. In some embodiments, additional tests or monitoring are performed to verify that the benign tenants are actually benign before the live migration of the benign tenants to the new multi-tenant host 302.

[0038] FIG. 3 further shows a notification 304 generated by the abuse analysis system 110. The notification 304 may include information such as an abuse signature 306 (e.g., a hash, digest, sequence of events, and / or other information indicating a particular abuse) and abuse details 308 (e.g., the activity log 204 of the disabled multi-tenant host, the identifier 206 of the tenant whose security has been breached, and / or information related to the co-occurring tenant identifier 206). In some embodiments, the notification 304 is sent to a security administrator who implements the final disposition of the security incident. For example, the security administrator may confirm the abuse and request that the single-tenant host 2 106-2 become the single-tenant host 310 that has been disabled, thereby terminating the workload associated with the tenant 2 104-2 whose security has been breached. As another example, the security administrator may consider the abuse to be a false positive, in which case the tenant 2 104-2 whose security has been breached may be reclassified as benign and migrated to the new multi-tenant host 302. In either case, the feedback (e.g., the final disposition) of the security administrator may be fed back to the threat detection model 112 for the purpose of refining the parameters associated with the threat detection model. For example, the feedback including the abuse signature 306 and / or the abuse details 308 may be used as a new instance of training data for the threat detection model 112.

[0039] FIG. 4 shows a flowchart of an exemplary method 400 for implementing multi-tenant security using a single-tenant host according to some embodiments of the present disclosure. In some embodiments, the method 400 is implemented by a multi-tenant cloud security program, the abuse analysis system 110, a server, a computer, a processor, a combination of hardware and software, and / or any combination of the foregoing.

[0040] Operation 402 includes detecting malicious activity on an application that has been compromised in a multi-tenant host. A multi-tenant host may be associated with underlying computing resources (e.g., servers) to serve workloads from multiple tenants. Thus, a multi-tenant host may include one or more VMs, containers, hypervisors, and / or other virtualization techniques useful for sharing a single set of computing resources among multiple tenants. Malicious activity may be detected using a threat detection model. Malicious activity may occur in a single application of a single tenant, multiple applications of a single tenant, or multiple applications of multiple tenants.

[0041] Operation 404 includes automatically performing a live migration of each tenant to a single-tenant host. Advantageously, the live migration preserves the availability of the applications of each tenant. As a result, the tenant experiences little or no perceivable downtime during the live migration. The live migration may utilize pre-copy memory migration technology, post-copy memory migration technology, or another live migration technology known currently or developed later. In pre-copy memory migration technology, the hypervisor may copy memory pages from a source to a destination, during which the associated VM remains operational at the source. The memory pages are recopied until the percentage of recopied pages exceeds the percentage of memory pages whose content has changed. Thereafter, the VM is stopped on the source, and the human-detected changed memory pages are recopied to the destination and the VM is restarted at the destination. In pre-copy memory migration, the VM may experience downtime in the range of milliseconds to seconds.

[0042] In post-copy memory migration technology, the VM is paused at the source, and a subset of the execution state of the VM (e.g., CPU state, registers, non-pagable memory, etc.) is transferred to the destination. The VM is then resumed at the destination, while the source performs pre-paging (e.g., pushing the remaining memory pages of the VM from the source to the destination). While executing at the destination, if the VM accesses a memory page that has not yet been transferred from the source to the destination, a page fault occurs, which is redirected to the source, and the source provides the fault page.

[0043] Operation 406 includes mitigating malicious activity on an application that has been security compromised on the migrated single-tenant host. Operation 406 may include generating a notification, terminating the security-compromised application, terminating (or isolating) the migrated single-tenant host, and / or other mitigation activities.

[0044] Operation 408 includes archiving the activity logs of security-compromised applications and benign applications that were running prior to the multi-tenant system. Operation 408 may store information related to the investigation of the period, extent, and / or nature of the exploitation. Additionally, operation 408 may store tenant data (e.g., if the security-compromised application was subsequently terminated on the migrated single-tenant host).

[0045] Operation 410 includes automatically performing a live migration of each benign tenant to a new multi-tenant host. As discussed previously, the live migration can be pre-copy memory migration, post-copy memory migration, or another live migration technology known currently or developed later. Advantageously, method 400 reduces the likelihood that an exploitation on a first tenant infects other tenants on the multi-tenant host. Additionally, method 400 preserves the availability of the applications associated with the benign tenants.

[0046] FIG. 5 shows a flowchart of an exemplary method 500 for training and refining a threat detection model for multi-tenant security according to some embodiments of the present disclosure. In some embodiments, method 500 is implemented by a multi-tenant cloud security program, an exploit analysis system 110, a server, a computer, a processor, a combination of hardware and software, and / or any combination of the foregoing. In some embodiments, method 500 occurs in conjunction with one or more operations of method 400 of FIG. 4.

[0047] Operation 502 includes training a threat detection model. The threat detection model can be trained using any machine learning technique previously mentioned, otherwise known, or later developed.

[0048] Operation 504 includes detecting malicious activity using the trained threat detection model. As an example, operation 504 can detect malicious activity by matching the hash or digest of a known security exploit to the hash or digest of a running file, workload, and / or application on a multi-tenant host. As another example, operation 504 can detect malicious activity by matching the sequence of events and / or characteristics of a known security exploit to the sequence of events and / or characteristics observed in a running workload or application on a multi-tenant host. As yet another example, operation 504 can detect malicious activity by inputting a large amount of data into the trained threat detection model and receiving, as output from the trained threat detection model, an indication of an exploit (e.g., type of exploit, location of exploit, etc.) on a multi-tenant host.

[0049] Operation 506 includes receiving feedback related to malicious activity. For example, in response to sending a notification to a security administrator, the security administrator may identify malicious activity as a true exploit or a false positive.

[0050] Operation 508 includes refining parameters associated with a threat detection model based on the feedback. For example, operation 508 may include retraining all or part of the threat detection model using the feedback included as additional training data. In other embodiments, the parameters associated with the threat detection model may be adjusted manually or automatically based on the feedback.

[0051] FIG. 6 shows a block diagram of an exemplary computing environment 600 implementing multi-tenant security in identifying an unauthorized clone of a tenant, according to some embodiments of the present disclosure. The exemplary computing environment 600 includes a multi-tenant host 602, one or more sandbox containers 606, and an exploit analysis system 610 communicatively coupled to each other via a network 608. In some embodiments, the multi-tenant host 602 is consistent with the multi-tenant host 102 of FIG. 1, the network 608 is consistent with the network 108 of FIG. 1, and / or the exploit analysis system 610 is consistent with the exploit analysis system 110 of FIG. 1. The multi-tenant host 602 hosts a plurality of tenants 604 such as tenant 1 604-1, tenant 2 604-2, and tenant N 604-N, where N is any integer greater than or equal to 1.

[0052] The abuse analysis system 610 may include a clone detection model 612, which may detect unauthorized clones of the tenant 604 in the multi-tenant host 602. In some embodiments, the clone detection model 612 utilizes a machine learning algorithm as previously discussed with respect to the threat detection model 112 of FIG. 1. In some embodiments, the clone detection model 612 may utilize spot images 614 to identify unauthorized clones of the tenant. The spot images 614 refer to intermittent snapshots of the tenant 604, and by comparing these with each other, the original tenant 604 of such a tenant can be distinguished from unauthorized clones. For example, the clone detection model 612 may detect an unauthorized clone of tenant 2 604-3. When an unauthorized clone of tenant 2 604-3 is detected, aspects of the present disclosure may utilize one or more sandbox containers 606 to limit the spread of malicious activities associated with the unauthorized clone of tenant 2 604-3.

[0053] FIG. 7 shows a block diagram of an exemplary computing environment 700 implementing multi-tenant security during the separation of multiple tenants 604 in one or more sandbox containers 606, according to some embodiments of the present disclosure. In some embodiments, the computing environment 700 follows the computing environment 600 of FIG. 6.

[0054] In computing environment 700, multi-tenant host 602 is deactivated as shown by deactivated multi-tenant host 702. Further, tenant 604 is being migrated to one or more sandbox containers 606 (e.g., using live migration techniques). Sandbox containers 606 can refer to network containers with pre-configured controls configured to limit the spread or exploitation of malicious activities while allowing tenant 604 to continue workload execution. For example, when tenant 604 is placed in sandbox containers 606, they can have restrictions such as restrictions on remote login functionality, restrictions on the size of file uploads or downloads, access restrictions (e.g., read-only access only), disabling approval of unknown connection requests, and / or other restrictions useful for reducing the attack surface available to malicious entities. While tenant 604 is inside sandbox containers 606, they can be subject to enhanced monitoring to identify and resolve any detected malicious activities. Such monitoring can be related to configuration, application behavior, file behavior, user behavior, registry keys, traffic analysis, and binary file analysis, etc.

[0055] Sandbox containers 606 can be implemented as a new instance of multi-tenant host 602 or on a completely different host. While a single sandbox container 606 hosting all tenants 604 is shown, in other embodiments, multiple sandbox containers 606 are used, with each sandbox container 606 hosting at least one, but fewer than all, tenants 604.

[0056] In some embodiments, tenant 604 stays within sandbox container 606 for a preconfigured time (e.g., 24 hours, 48 hours, etc.) with enhanced monitoring, testing, and / or repair protocols appropriate to mitigate any detected malicious activity. For example, in some embodiments, abuse analysis system 610 can utilize spot image 614 to distinguish original tenant 2 604-2 from an unauthorized clone of tenant 2 604-3. As a result of the distinction, aspects of the present disclosure can (i) delete the unauthorized clone of tenant 2 604-3 and retain original tenant 2 604-2 if the original tenant 2 604-2 does not appear to have been otherwise compromised, or (ii) delete both the original tenant 2 604-2 and the unauthorized clone of tenant 2 604-3 and create a new tenant 2 with a reapplication of the image.

[0057] FIG. 8 shows a block diagram of an exemplary computing environment 800 implementing multi-tenant security during reapplication of an image of an unauthorized clone and its associated tenant and implementing a tenant provision or other benign tenant with a reapplication of the image on a new multi-tenant host 802, according to some embodiments of the present disclosure. In some embodiments, exemplary computing environment 800 occurs subsequent to exemplary computing environment 700 of FIG. 7.

[0058] In an exemplary computing environment 800, a new multi-tenant host 802 is created. The new multi-tenant host 802 can be a new instance of the original multi-tenant host 602, or a completely different multi-tenant host. Aspects of the present disclosure can migrate benign tenants (e.g., tenant 1 604-1 and tenant N 604-N) to the new multi-tenant host 802 (e.g., using live migration techniques). Further, aspects of the present disclosure can instantiate tenant 2 804-2 that has had an image reapplied on the new multi-tenant host 802. Tenant 2 804-2 that has had an image reapplied can replace the original tenant 2 604-2 and an illicit clone of tenant 2 604-3. Tenant 2 804-2 that has had an image reapplied can receive the image reapplied based on information in the spot image 614 associated with the original tenant 2 604-2. For example, tenant 2 804-2 that has had an image reapplied can be based on a snapshot associated with the original tenant 2 604-2 included in the non-exploited spot image 614.

[0059] Figure 9 shows a flowchart of an exemplary method 900 for implementing multi-tenant security using one or more sandbox containers, according to some embodiments of the present disclosure. In some embodiments, method 900 is implemented by a multi-tenant cloud security program, an exploitation analysis system 610, a server, a computer, a processor, a combination of hardware and software, and / or any combination of the foregoing.

[0060] Operation 902 includes detecting an unauthorized clone of a first tenant in a multi-tenant system. In some embodiments, operation 902 may detect the unauthorized clone using a clone detection model and / or one or more spot images (e.g., a collection of snapshots of various tenants over time). For example, operation 902 may randomly compare the current state of a tenant to a previous snapshot of the tenant in a spot image to detect a possible unauthorized clone. Similarly, operation 902 may analyze security file configurations, registry changes, traffic behavior, memory allocation, storage usage, auto-delete functions, CPU usage, running services, password changes, executed scripts, application history, startup services, disabled policies, file renaming, host names, storage locations, created files, file paths, binary libraries, modification dates and / or times, toolkits (e.g., vmkfstools), stasis, creation dates, modification dates, access dates, and / or other information as part of detecting unauthorized clones. In some embodiments, operation 902 utilizes a scoring function that includes some or all of the aforementioned characteristics to cumulatively determine the risk, likelihood, or probability of an unauthorized clone.

[0061] Operation 904 includes automatically isolating a tenant of a multi-tenant system in one or more sandbox containers. The sandbox containers may be implemented as new instances on a multi-tenant host or on a completely different host. In some embodiments, operation 904 involves performing a live migration of the tenant from the multi-tenant host to the sandbox containers. The sandbox containers may restrict the functionality of the tenant to constrain further malicious activities resulting from exploitation that causes unauthorized clones. However, nevertheless, the sandbox containers enable the continued availability of the workload associated with the tenant.

[0062] Operation 906 includes determining a secure image corresponding to the first tenant. Operation 906 may identify an unsullied snapshot of the first tenant that can be used for reapplying the image of the first tenant by utilizing the spot image.

[0063] Operation 908 includes reapplying the image of the first tenant on a new multi-tenant host using the secure image determined in operation 906. The new multi-tenant host can be a new instance of the original multi-tenant host or a completely new host.

[0064] Operation 910 includes verifying the security of each tenant in the sandbox container. Operation 910 includes verifying that each tenant remaining in the sandbox container is in fact a benign tenant (e.g., not exploited by abuse causing an unauthorized clone). In some embodiments, operation 910 includes implementing mitigation measures to remove any abuse on any other tenant in the sandbox container.

[0065] Operation 912 includes migrating each tenant from the sandbox container to the new multi-tenant host. In some embodiments, operation 912 performs a live migration as discussed previously.

[0066] Advantageously, FIGS. 6-8 illustrate embodiments of the present disclosure that can automatically detect malicious activities (e.g., unauthorized clones), isolate tenants of a multi-tenant host that exhibit malicious behavior in a sandbox container, resolve malicious activities in the sandbox container while preserving the usefulness of the tenants, and migrate the tenants to a new multi-host system after resolution of the malicious activities.

[0067] Various aspects of the present disclosure are illustrated by descriptions, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in embodiments of a computer program product (CPP). For any flowchart, depending on the technology involved, operations may be performed in an order different from that shown in a given flowchart. For example, again depending on the technology involved, two operations shown in blocks of consecutive flowcharts may be performed in reverse order, as a single integrated step, simultaneously, or at least partially overlapping in time.

[0068] An embodiment of a computer program product (a "CPP embodiment" or "CPP") is, in the present disclosure, a term used to describe any set of one or more storage media (also referred to as "media") collectively included in a set of one or more storage devices that collectively contain machine-readable code corresponding to instructions and / or data for performing the computer operations specified in a given CPP claim. A "storage device" is any tangible device capable of holding and storing instructions for use by a computer processor. A computer-readable storage medium can be, but is not limited to, an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these media are floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded devices (such as punch cards or pits / lands formed on the major surfaces of disks), or any suitable combination of the foregoing. A computer-readable storage medium is not to be construed as storage in the form of a transient signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide, an optical pulse passing through an optical fiber cable, an electrical signal communicated through a wire, and / or other transmission media, as the term is used in the present disclosure. As will be understood by those skilled in the art, data is typically moved during some irregular points in the normal operation of a storage device, such as during access, defragmentation, or garbage collection, but since the data is not transient while it is stored, the foregoing does not cause the storage device to be considered transient.

[0069] FIG. 10 shows a block diagram of an exemplary computing environment according to some embodiments of the present disclosure. Computing environment 1000 includes an example of an environment for the execution of at least some of the computer code associated with the implementation of the inventive method, such as multi-tenant security code 1200. In addition to multi-tenant security code 1200, computing environment 1000 includes, for example, computer 1001, wide area network (WAN) 1002, end user device (EUD) 1003, remote server 1004, public cloud 1005, and private cloud 1006. In this embodiment, computer 1001 includes a processor set 1010 (including processing circuit 1020 and cache 1021), communication fabric 1011, volatile memory 1012, persistent storage 1013 (including operating system 1022 and multi-tenant security code 1200 as identified above), a set of peripheral devices 1014 (including user interface (UI), device set 1023, storage 1024, and Internet of Things (IoT) sensor set 1025), and network module 1015. Remote server 1004 includes remote database 1030. Public cloud 1005 includes gateway 1040, cloud orchestration module 1041, host physical machine set 1042, virtual machine set 1043, and container set 1044.

[0070] Computer 1001 can take the form of a desktop computer, laptop computer, tablet computer, smartphone, smartwatch or other wearable computer, mainframe computer, quantum computer, or any other form of currently known or future-developed computer or mobile device capable of executing a program, accessing a network, or querying a database, such as remote database 1030. As is well understood in the field of computer technology and depending on the technology, the execution of computer-implemented methods can be distributed among multiple computers and / or between multiple locations. On the other hand, in this description of computing environment 1000, for the sake of keeping the description as concise as possible, the detailed discussion focuses on a single computer, specifically computer 1001. Although computer 1001 is not shown within the cloud in FIG. 10, it may be located within the cloud. On the other hand, computer 1001 does not need to exist within the cloud, except within any range that can be affirmatively shown.

[0071] Processor set 1010 includes one or more computer processors of any type currently known or future-developed. Processing circuit 1020 can be distributed among multiple packages, such as multiple packaged integrated circuit chips. Processing circuit 1020 can implement multiple processor threads and / or multiple processor cores. Cache 1021 is memory located within the processor chip package and is typically used for high-speed access to data or code that should be available to threads or cores executing on processor set 1010. Cache memory is typically organized into multiple levels depending on its relative proximity to the processing circuit. Alternatively, some or all of the cache for the processor set can be located "off-chip". In some computing environments, processor set 1010 can be designed to operate using qubits and perform quantum computing.

[0072] Computer-readable program instructions typically cause a series of operational steps to be performed on computer 1001 when loaded thereon and executed by the processor set 1010 of computer 1001, whereby the instructions so executed bring about a computer-implemented method instantiating the method (collectively referred to as the "inventive method") specified in the flowchart and / or descriptive description of the computer-implemented method included in this document. These computer-readable program instructions are stored in various types of computer-readable storage media such as cache 1021 and other storage media discussed below. The program instructions and associated data are accessed by the processor set 1010 to control and direct the execution of the method of the present invention. In computing environment 1000, at least some of the instructions for carrying out the inventive method may be stored in multi-tenant security code 1200 within persistent storage 1013.

[0073] Communication fabric 1011 is a signal conduction path that enables various components of computer 1001 to communicate with each other. Typically, this fabric is made up of switches and conductive paths such as buses, bridges, switches and conductive paths that make up physical input / output ports, etc. Other types of signal communication paths such as optical fiber communication paths and / or wireless communication paths may be used.

[0074] Volatile memory 1012 is any type of volatile memory known currently or developed in the future. Examples include dynamic random access memory (RAM) or static RAM. Typically, volatile memory is characterized by random access, although this is not essential unless affirmatively shown. In computer 1001, volatile memory 1012 is located within a single package and exists inside computer 1001, but alternatively or additionally, volatile memory may be distributed across multiple packages and / or located external to computer 1001.

[0075] The persistent storage 1013 is any form of non-volatile storage for a computer, known currently or developed in the future. The non-volatility of this storage means that the stored data is maintained regardless of whether power is directly supplied to the computer 1001 and / or to the persistent storage 1013. The persistent storage 1013 can be read-only memory (ROM), but usually at least a portion of the persistent storage enables writing, deleting, and rewriting of data. Some well-known forms of persistent storage include magnetic disks and solid-state storage devices. The operating system 1022 can take several forms, such as various known proprietary operating systems or an open-source portable operating system interface type of operating system that utilizes a kernel. The code included in the multi-tenant security code 1200 typically includes at least some of the computer code associated with the implementation of the method of the invention.

[0076] The peripheral device set 1014 includes a set of peripheral devices of the computer 1001. Data communication connections between the peripheral devices of the computer 1001 and other components may be implemented in various ways, such as Bluetooth (registered trademark) connections, near-field communication (NFC) connections, connections formed by cables (such as universal serial bus (USB) type cables), insertion type connections (e.g., secure digital (SD) cards), connections formed through local area communication networks, and even connections formed through wide area networks such as the Internet. In various embodiments, the UI device set 1023 may include components such as a display screen, speakers, microphones, wearable devices (such as goggles and smartwatches), keyboards, mice, printers, touch pads, game controllers, and haptic devices. The storage 1024 is external storage such as an external hard drive or insertable storage such as an SD card. The storage 1024 may be persistent and / or volatile. In some embodiments, the storage 1024 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where the computer 1001 is required to have a large amount of storage (e.g., when the computer 1001 locally stores and manages a large-scale database), this storage may be provided by a peripheral storage device designed to store a very large amount of data, such as a storage area network (SAN) shared by a plurality of geographically distributed computers. The IoT sensor set 1025 is composed of sensors that can be used in Internet of Things applications. For example, one sensor may be a thermometer, and another sensor may be a motion detector.

[0077] The network module 1015 is an aggregate of computer software, hardware, and firmware that enables the computer 1001 to communicate with other computers through the WAN 1002. The network module 1015 may include hardware such as a modem or a Wi-Fi (registered trademark) signal transceiver, software for packetizing and / or depacketizing data for communication over a communication network, and / or web browser software for communicating data over the Internet. In some embodiments, the network control function and the network transfer function of the network module 1015 are executed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software-Defined Networking (SDN)), the control function and the transfer function of the network module 1015 are executed on physically separate devices such that the control function manages several different network hardware devices. The computer-readable program instructions for executing the method of the present invention can typically be downloaded to the computer 1001 from an external computer or an external storage device through a network adapter card or a network interface included in the network module 1015.

[0078] The WAN 1002 is any wide area network (e.g., the Internet) capable of communicating computer data over non-local distances by any technique for communicating computer data known currently or developed in the future. In some embodiments, the WAN can be replaced and / or supplemented by a local area network (LAN) designed to communicate data between devices located in a local area, such as a Wi-Fi network. The WAN and / or the LAN typically includes computer hardware such as copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and edge servers.

[0079] The end - user device (EUD) 1003 is any computer system used and controlled by an end - user (e.g., a customer of the enterprise operating computer 1001) and can take any of the forms discussed above in relation to computer 1001. The EUD 1003 typically receives useful and beneficial data from the operation of computer 1001. For example, in a virtual case where computer 1001 is designed to provide recommendations to the end - user, this recommendation will typically be communicated from the network module 1015 of computer 1001, via the WAN 1002, to the EUD 1003. In this way, the EUD 1003 can display or otherwise present the recommendation to the end - user. In some embodiments, the EUD 1003 can be a client device such as a thin - client, a thick - client, a mainframe computer, and a desktop computer, etc.

[0080] The remote server 1004 is any computer system that provides at least some data and / or functions as a service to computer 1001. The remote server 1004 can be controlled and used by the same entity that operates computer 1001. The remote server 1004 represents a machine that collects and stores useful and beneficial data for use by other computers such as computer 1001. For example, in a virtual case where computer 1001 is designed and programmed to provide recommendations based on historical data, this historical data can be provided from the remote database 1030 of the remote server 1004 to computer 1001.

[0081] The public cloud 1005 is any computer system available for use by multiple organizations that provides on-demand availability of computer system resources and / or other computer functions, particularly data storage (cloud storage) and computing power, without direct active management by the user. Cloud computing typically exploits resource sharing to achieve coherence and economies of scale. The direct active management of the computing resources of the public cloud 1005 is performed by the computer hardware and / or software of the cloud orchestration module 1041. The computing resources provided by the public cloud 1005 are typically implemented by virtual computing environments that run on various computers that make up the host physical machine set 1042, which is the universe of physical computers within and / or available in the public cloud 1005. Virtual computing environments (VCEs) typically take the form of virtual machines from the virtual machine set 1043 and / or containers from the container set 1044. It is understood that these VCEs can be stored as images and transferred either as images or after instantiation of the VCE, within and among various physical machine hosts. The cloud orchestration module 1041 manages the transfer and storage of images, deploys new instantiations of the VCE, and manages the active instantiation of VCE deployments. The gateway 1040 is a collection of computer software, hardware, and firmware that enables the public cloud 1005 to communicate via the WAN 1002.

[0082] Some further explanation of a virtualized computing environment (VCE) is provided here. A VCE can be stored as an "image". A new active instance of a VCE can be instantiated from the image. Two well-known types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to a feature of the operating system where the kernel enables the existence of multiple isolated instances of user space, called containers. These isolated instances of user space typically behave as actual computers from the perspective of the programs running within them. A computer program running on a normal operating system can utilize all the resources of that computer, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, a program running inside a container can only use the contents of the container and the devices allocated to the container, and this feature is known as containerization.

[0083] The private cloud 1006 is similar to the public cloud 1005, except that computing resources are available only for use by a single enterprise. The private cloud 1006 is shown as being in communication with the WAN 1002, but in other embodiments, the private cloud may be completely disconnected from the Internet and accessible only via a local / private network. A hybrid cloud is a composite of multiple different types of clouds (e.g., private cloud, community cloud, or public cloud types), and is often implemented by different vendors. Each of the multiple clouds remains a separate discrete entity, but the larger hybrid cloud architecture is coupled by standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the constituent clouds. In this embodiment, both the public cloud 1005 and the private cloud 1006 are part of a larger hybrid cloud.

[0084] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or subset of instructions that include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions described in the blocks may occur in an order different from that depicted in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may be executed in the reverse order depending on the functions involved. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified function or operation, or by a combination of dedicated hardware and computer instructions.

[0085] Process software (e.g., any software configured to implement any part of the methods described above and / or implement any of the functions described above) can be deployed in a client, server, and proxy computer by directly and manually loading it via loading a storage medium such as a CD, DVD, etc. On the other hand, process software can also be deployed automatically or semi-automatically in a computer system by sending the process software to a central server or a group of central servers. The process software is then downloaded to the client computer that will execute the process software. Alternatively, the process software is sent directly to the client system via email. The process software then either detaches from the directory or is loaded into the directory by executing a set of program instructions that detach the process software from the directory. Another alternative is to send the process software directly to a directory on the client computer hard drive. If a proxy server exists, the process selects the proxy server code, determines on which computer to place the proxy server code, sends the proxy server code, and then installs the proxy server code on the proxy computer. The process software is sent to the proxy server and then stored on the proxy server.

[0086] Embodiments of the present invention can also be delivered as part of a service engagement to a client company, non-profit organization, government agency, or internal organizational structure, etc. These embodiments can include configuring a computer system to perform some or all of the methods described herein, and deploying software, hardware, and web services that implement some or all of the methods. These embodiments can also include analyzing client behavior, creating recommendations in response to the analysis, building a system to implement a subset of the recommendations, integrating the system into existing processes and infrastructure, measuring the use of the system, assigning costs to users of the system, and billing, invoicing (e.g., generating an invoice), or otherwise receiving payment for the use of the system.

[0087] The terms used in this specification are for the purpose of describing particular embodiments only and are not intended to limit the various embodiments. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. The terms "includes" and / or "including", as used herein, specify the presence of the features, integers, steps, operations, elements, and / or components described, but it will be further understood that they do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. In the foregoing detailed description of exemplary embodiments of the various embodiments, reference has been made to the accompanying drawings (where like reference numerals represent like elements), which are a part of this specification, and in which are shown, by way of illustration, specific exemplary embodiments by which the various embodiments may be practiced. These embodiments have been described in sufficient detail to enable those skilled in the art to practice the embodiments, but other embodiments may be used and logical, mechanical, electrical, and other changes may be made without departing from the scope of the various embodiments. In the foregoing description, numerous specific details have been set forth in order to provide a thorough understanding of the various embodiments. However, the various embodiments may be practiced without these specific details. In other instances, well-known circuits, structures, and techniques have not been shown in detail so as not to obscure the embodiments.

[0088] As used herein, different instances of the word "embodiment" do not necessarily refer to the same embodiment, although they may. Any data and data structures illustrated or described herein are merely examples, and in other embodiments, different amounts of data, types of data, fields, numbers and types of fields, field names, numbers and types of rows, records, entries, or organization of data may be used. Additionally, any data can be combined with logic, thereby eliminating the need for separate data structures. Accordingly, the previous detailed description should not be taken in a limiting sense.

[0089] The descriptions of the various embodiments of the present disclosure have been presented for purposes of illustration, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been selected to best explain the principles of the embodiments, the practical application, or the technical improvement found in the marketplace, or to enable others skilled in the art to understand the embodiments disclosed herein.

[0090] The present disclosure has been described with respect to specific embodiments, but it is expected that modifications and variations will become apparent to those skilled in the art. Accordingly, the following claims are intended to be construed to cover all such modifications and variations that fall within the true spirit and scope of the present disclosure.

[0091] Any advantages discussed in the present disclosure are exemplary advantages, and embodiments of the present disclosure may exist that, while remaining within the spirit and scope of the present disclosure, achieve all, some, or none of the advantages discussed.

[0092] To demonstrate some aspects of the present disclosure, the following is a non-limiting list of examples. Example 1 is a computer-implemented method. The method includes detecting malicious activity on a security-compromised application in a multi-tenant host; automatically performing live migration of each tenant of the multi-tenant host to respective single-tenant hosts; mitigating the malicious activity on the security-compromised application migrated to the single-tenant host; and automatically performing another live migration of each benign tenant to a new multi-tenant host.

[0093] Example 2 includes the features of Example 1. In this example, the multi-tenant host has a plurality of virtual machines hosted on one or more shared servers, and each single-tenant host has a dedicated server for the tenant associated with the respective single-tenant host.

[0094] Example 3 includes the features of any one of Examples 1-2. In this example, the malicious activity is detected using an activity signature.

[0095] Example 4 includes the features of any one of Examples 1-2. In this example, the malicious activity is detected using a machine learning model. Optionally, the method further includes sending a notification to a cybersecurity administrator based on the malicious activity; and updating parameters associated with the machine learning model based on feedback provided by the cybersecurity administrator.

[0096] Example 5 includes the features of any one of Examples 1-4, with optional functions included or excluded. In this example, the method further includes archiving activity logs of the security-compromised application and benign applications running on the multi-tenant host.

[0097] Example 6 is a computer implementation method. The method includes the steps of detecting an unauthorized clone of a first tenant in a multi-tenant host; automatically separating the tenants of the multi-tenant host in a sandbox container; determining a secure image corresponding to the first tenant; reapplying the image of the first tenant on a new multi-tenant host using the secure image; verifying the security of each tenant in the sandbox container; and migrating each tenant from the sandbox container to the new multi-tenant host in response to verifying the security of each tenant in the sandbox container.

[0098] Example 7 includes the features of Example 6. In this example, the sandbox container has restricted permissions and continued availability for the workloads associated with each tenant of the multi-tenant host.

[0099] Example 8 includes the features of any one of Examples 6 to 7. In this example, the unauthorized clone is detected using a spot image based on a previous snapshot and a current snapshot of the first tenant.

[0100] Example 9 includes the features of any one of Examples 6 to 7. In this example, the unauthorized clone is detected using a machine learning clone detection model.

[0101] Example 10 is a system. The system includes one or more computer-readable storage media storing program instructions; and one or more processors configured to perform the method described in any one of Examples 1 to 9, including or excluding optional functions, in response to executing the program instructions.

[0102] Example 11 is a computer program product. The computer program product includes one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media. The program instructions include instructions configured to cause one or more processors to perform the method according to any one of Examples 1 to 9, including or excluding optional functions.

Claims

1. Detecting malicious activities on a security - compromised application in a multi - tenant host; Automatically performing live migration of each tenant of the multi - tenant host to respective single - tenant hosts; Mitigating the malicious activities on the security - compromised application migrated to the single - tenant host; and Automatically performing another live migration of each benign tenant to a new multi - tenant host A computer - implemented method comprising the above steps.

2. The multi - tenant host has a plurality of virtual machines hosted on one or more shared servers, and each single - tenant host has a dedicated server for the tenant associated with each respective single - tenant host. The method according to claim 1.

3. The malicious activities are detected using activity signatures. The method according to claim 1.

4. The malicious activities are detected using a machine - learning model. The method according to claim 1.

5. The method further comprises: Sending a notification to a cyber - security administrator based on the malicious activities; and Updating parameters associated with the machine - learning model based on feedback provided by the cyber - security administrator The method according to claim 4 further comprising the above steps.

6. Archiving activity logs of the security - compromised application and benign applications running on the multi - tenant host The method according to claim 1 further comprising the above step.

7. One or more computer - readable storage media storing program instructions; and In response to execution of the program instructions, Detecting malicious activities on a security - compromised application in a multi - tenant host; Automatically performing live migration of each tenant of the multi - tenant host to respective single - tenant hosts; Mitigating the malicious activities on the security - compromised application migrated to the single - tenant host; and Automatically performing another live migration of each benign tenant to a new multi-tenant host One or more processors configured to implement a method having A system comprising **Claim 8** The system according to claim 7, wherein the multi-tenant host has a plurality of virtual machines hosted on one or more shared servers, and each single-tenant host has a dedicated server for a tenant associated with the respective single-tenant host **Claim 9** The system according to claim 7, wherein the malicious activity is detected using an activity signature **Claim 10** The system according to claim 7, wherein the malicious activity is detected using a machine learning model **Claim 11** The method being Sending a notification to a cybersecurity administrator based on the malicious activity; and Updating parameters associated with the machine learning model based on feedback provided by the cybersecurity administrator The system according to claim 10, further comprising **Claim 12** The method being Archiving activity logs of the security-compromised applications and benign applications running on the multi-tenant host The system according to claim 7, further comprising **Claim 13** One or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions causing one or more processors to Detect malicious activity on a security-compromised application in a multi-tenant host; Automatically perform a live migration of each tenant of the multi-tenant host to a respective single-tenant host; Mitigate the malicious activity on the security-compromised application migrated to the single-tenant host; and Automatically perform another live migration of each benign tenant to a new multi-tenant host Having instructions configured to implement a method including A computer program product **Claim 14** The multi-tenant host has a plurality of virtual machines hosted on one or more shared servers, and each single-tenant host has a dedicated server for a tenant associated with each respective single-tenant host, the computer program product according to claim 13.

15. The malicious activity is detected using an activity signature, the computer program product according to claim 13.

16. The malicious activity is detected using a machine learning model, the computer program product according to claim 13.

17. The method is: sending a notification to a cyber security administrator based on the malicious activity; and updating parameters associated with the machine learning model based on feedback provided by the cyber security administrator further comprising, the computer program product according to claim 16.

18. The method is: archiving activity logs of the security-compromised applications and benign applications running on the multi-tenant host further comprising, the computer program product according to claim 13.

19. detecting an unauthorized clone of a first tenant in a multi-tenant host; automatically separating tenants of the multi-tenant host in a sandbox container; determining a secure image corresponding to the first tenant; reapplying the image of the first tenant on a new multi-tenant system using the secure image; verifying the security of each tenant in the sandbox container; and in response to verifying the security of each tenant in the sandbox container, migrating each tenant from the sandbox container to the new multi-tenant host comprising, a computer-implemented method.

20. The sandbox container has restricted permissions and continued availability for workloads associated with each tenant of the multi-tenant host, the method according to claim 19.

21. The method according to claim 19, wherein the unauthorized clone is detected using a spot image based on a previous snapshot of the first tenant and a current snapshot of the first tenant.

22. The method according to claim 19, wherein the unauthorized clone is detected using a machine learning clone detection model.

23. One or more computer-readable storage media, and program instructions collectively stored on the one or more computer-readable storage media, the program instructions to one or more processors: detecting an unauthorized clone of a first tenant in a multi-tenant host; automatically separating the tenants of the multi-tenant host in a sandbox container; determining a secure image corresponding to the first tenant; reapplying the image of the first tenant on a new multi-tenant system using the secure image; verifying the security of each tenant in the sandbox container; and in response to verifying the security of each tenant in the sandbox container, migrating each tenant from the sandbox container to the new multi-tenant host comprising instructions configured to implement a method having a computer program product.

24. The computer program product according to claim 23, wherein the sandbox container has restricted permissions and continued availability for the workloads associated with each tenant of the multi-tenant host.

25. The computer program product according to claim 23, wherein the unauthorized clone is detected using a spot image based on a previous snapshot of the first tenant and a current snapshot of the first tenant.