Microservice-based method for detecting forgery of container configuration image unit and operating service
By adding a tamper detection agent to container images and implementing a system for verifying layer integrity, the method addresses tampering issues in microservices, ensuring secure and reliable operation.
Patent Information
- Application Number
- PCT/KR2023/021609
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2023-12-26
- Publication Date
- 2025-07-03
AI Technical Summary
Existing methods fail to effectively detect and manage tampering in service units of microservices operating in container units, leading to potential operational issues and security vulnerabilities due to unverified layers in container images obtained from public repositories.
A method involving the addition of a tamper detection agent during container image creation to check layer integrity, with agents interacting to verify compliance through Heart-Beat or Check request/response using predefined policies, and a system comprising a processor and storage unit for managing and detecting tampering.
Prevents unexpected service failures and enhances security by detecting and blocking tampering in real-time, ensuring the integrity of microservice operations.
Smart Images

Figure KR2023021609_03072025_PF_FP_ABST
Abstract
Description
Microservice-based container configuration image unit forgery detection and service operation method
[0001] The present invention relates to container and microservice management, and more particularly, to a method for detecting tampering in service units operated in container units in a microservice operating environment.
[0002] In a microservice operating environment, containers that provide a runtime environment are structured around a basic base layer, with multiple layers that are set up with libraries and packages.
[0003] At this time, service code, libraries, and objects including the base layer can be written directly by the user, but it is also possible to obtain and utilize those stored in public repositories, etc.
[0004] However, when a service developer utilizes a layer image distributed to a public repository or other source during the process of configuring a container, its contents are in the form of a black box that cannot be directly verified.
[0005] Accordingly, it may cause unexpected problems in the operation of microservices implemented with developed containers, and may make operation difficult by providing loose security functions to microservices that require security.
[0006] The present invention has been devised to solve the above problems, and the purpose of the present invention is to provide a method for detecting and managing layer tampering and container tampering resulting therefrom in microservices and all other runtime environments operated in container units.
[0007] A container forgery detection method according to one embodiment of the present invention for achieving the above object includes: a step of acquiring layers to constitute a container image; a step of creating a container image by adding an agent for managing the status of layers to the acquired layers; and a step of creating a container using the created container image.
[0008] During the container image creation process, the agent can check the status of layers and determine whether the layers have been tampered with.
[0009] The created container can be used to compose microservices with other containers.
[0010] An agent can interact with agents in other containers to determine whether other containers have been tampered with.
[0011] Interactions can be HB (Heart-Beat) or Check request / response.
[0012] An agent can determine whether another container has been tampered with based on whether it can interact with agents in other containers using message specifications defined in the policy.
[0013] Policies can be determined in advance by service developers.
[0014] An agent can determine whether another container has been tampered with based on whether it is possible to interact with an agent in another container using a message containing a hash value defined in the policy.
[0015] Agents in other containers may be identified as tampered containers.
[0016] According to another aspect of the present invention, a container forgery detection system is provided, characterized by including: a processor for acquiring layers to constitute a container image, adding an agent for managing the status of the acquired layers to create a container image, and creating a container using the created container image; and a storage unit for providing storage space required by the processor.
[0017] According to another aspect of the present invention, a method for detecting container tampering is provided, comprising: a step of creating a container using a container image created by adding an agent for managing the state of layers to layers composing the container image; and a step of determining tampering of another container composing a microservice using the created container.
[0018] According to another aspect of the present invention, a container tampering detection system is provided, characterized by including: a processor for creating a container using a container image created by adding an agent for managing the state of layers to the layers that constitute a container image, and for determining tampering of another container that constitutes a microservice using the created container; and a storage unit for providing storage space required by the processor.
[0019] As described above, according to embodiments of the present invention, by detecting layer tampering and resulting container tampering in microservices and all other runtime environments operated in container units, it is possible to check whether each layer has been tampered with during the process of creating a container, and also to check whether a container has been tampered with while the microservice is being operated, thereby preventing unexpected service failures or security issues in microservice operation in advance.
[0020] Figure 1 is an example of container forgery.
[0021] Figure 2 is a method for detecting container forgery in one embodiment of the present invention.
[0022] Figure 3 is an example of a container including a tamper detection agent.
[0023] Figure 4 is a container forgery detection system according to another embodiment of the present invention.
[0024] Hereinafter, the present invention will be described in more detail with reference to the drawings.
[0025] In an embodiment of the present invention, a method for detecting and managing service unit forgery in a microservice operating environment is proposed.
[0026] This is a technology that detects layer tampering and resulting container tampering in microservices and all other runtime environments that operate in container units, thereby checking whether each layer has been tampered with during the process of creating a container, and further checking whether the container has been tampered with while the microservice is operating.
[0027] Microservices are composed of multiple services for a single application configuration, as illustrated in Figure 1. Each service is typically configured as a lightweight container.
[0028] A container for a service is composed of multiple layers, and various elements that make up the layers, such as service code, packages, and libraries, may be tampered with. If a container contains a tampered layer, unexpected operational problems may occur, as shown in Figure 1.
[0029] Figure 1 illustrates a problematic situation in which a container providing service C does not forward a request for information about database B of service A to service D, but instead records altered data in database A and returns the altered data to service A.
[0030] Accordingly, in an embodiment of the present invention, a method for detecting forgery contained in a container is presented. Fig. 2 is a diagram illustrating the flow of a method for detecting forgery of a container in one embodiment of the present invention.
[0031] To detect container tampering, the layers that make up the container image are first acquired (S110), as shown in the diagram. These layers can be created directly by the service developer or downloaded from a public repository. The latter approach primarily generates tampering issues.
[0032] In the following step S110, a tamper detection agent is added to the layers acquired to create a container image (S220). In other words, during the container image creation process, a tamper detection agent is added in addition to the layers. The tamper detection agent is an agent that manages the status of the layers that make up the container.
[0033] In this case, during the container image creation process in step S220, the tamper detection agent checks the status of the layers to determine whether the layers have been tampered with (S230).
[0034] Afterwards, a container is created using the container image generated in step S220, and a microservice is configured with other containers (S240). The microservice configured in step S240 is illustrated in Fig. 3.
[0035] In Figure 3, it can be seen that the containers that constitute services A, B, and C include a 'checker', which corresponds to a tamper detection agent that checks the status of the aforementioned layers.
[0036] Agents in containers that constitute a microservice can interact with agents in other containers to determine whether other containers have been tampered with (S250). In the case of the microservice presented in Fig. 3, the checkers in the containers that constitute services A, B, and C determine that the container that constitutes service D has been tampered with.
[0037] Interactions for container tampering detection can be performed via Heartbeat (HB) transmission and reception between container checkers or via Check request / response. Interactions are performed using message specifications and hash values defined in policies predefined by service developers.
[0038] Therefore, if the HB or Check request / response transmitted between checkers does not conform to the standard or the hash value is incorrect, the container can be determined to be a tampered container.
[0039] In addition, as shown in Fig. 3, a container that constitutes service C, to which a checker is not added during the container creation process, cannot interact with the checkers of other containers A, B, and C, and is therefore naturally treated as a tampered container.
[0040] FIG. 4 is a diagram illustrating the hardware configuration of a container forgery detection system according to another embodiment of the present invention. The container forgery detection system according to an embodiment of the present invention can be implemented as a cloud / server system comprising a communication unit (210), a processor (220), and a storage unit (230), as illustrated.
[0041] The communication unit (210) is a communication interface for connection with an external network or external device. The processor (220) creates containers according to the aforementioned container forgery detection method, detects layer forgery, and detects container forgery through interaction between containers. The storage unit (230) provides the storage space necessary for the processor (220) to function and operate.
[0042] So far, we have described in detail a preferred embodiment of a method for detecting and managing service unit tampering in a microservice operating environment.
[0043] In the above embodiment, by detecting layer tampering and resulting container tampering in microservices and all other runtime environments operated in container units, it is possible to check whether each layer has been tampered with during the process of creating a container, and also to check whether a container has been tampered with while the microservice is being operated.
[0044] This allows for preemptive blocking of layer tampering before containers are created, and if this is not possible, forgery can be detected through interactions between containers, thereby preventing unexpected service failures or security issues in microservice operations.
[0045] Meanwhile, it goes without saying that the technical idea of the present invention can also be applied to a computer-readable recording medium containing a computer program that performs the functions of the device and method according to the present embodiment. In addition, the technical idea according to various embodiments of the present invention can be implemented in the form of computer-readable code recorded on a computer-readable recording medium. The computer-readable recording medium can be any data storage device that can be read by a computer and store data. For example, the computer-readable recording medium can be a ROM, a RAM, a CD-ROM, a magnetic tape, a floppy disk, an optical disk, a hard disk drive, etc. In addition, the computer-readable code or program stored on the computer-readable recording medium can be transmitted through a network connected between computers.
[0046] In addition, although the preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above, and various modifications can be made by a person having ordinary skill in the art to which the present invention pertains without departing from the gist of the present invention as claimed in the claims, and such modifications should not be understood individually from the technical idea or prospect of the present invention.
Claims
1. Step for acquiring layers that constitute the container image; A step for creating a container image by adding an agent to the acquired layers to manage the state of the layers; A method for detecting container forgery, characterized by comprising: a step of creating a container using the created container image.
2. In claim 1, The agent, A container forgery detection method characterized by checking the status of layers during the container image creation process to determine whether the layers have been forged.
3. In claim 2, The created container is, A method for detecting container tampering, characterized by composing microservices with other containers.
4. In claim 3, The agent, A container tampering detection method characterized by interacting with an agent of another container to determine whether another container has been tampered with.
5. In claim 4, The interaction is, A container forgery detection method characterized by HB (Heart-Beat) or Check request / response.
6. In claim 4, The agent, A container tampering detection method characterized by determining whether another container has been tampered with based on whether interaction can be performed according to a message specification defined by an agent and policy of another container.
7. In claim 6, The policy is, A method for detecting container forgery, characterized in that the service developer is determined in advance.
8. In claim 4, The agent, A container tampering detection method characterized by determining whether another container has been tampered with based on whether interaction can be performed with a message containing a hash value defined by an agent and policy of another container.
9. In claim 4, Agents in other containers, A method for detecting container forgery, characterized in that the container is determined to be forged.
10. A processor that acquires layers to compose a container image, adds an agent to manage the status of the acquired layers, creates a container image, and creates a container using the created container image; and A container forgery detection system, characterized by including a storage unit providing storage space required by a processor.
11. A step for creating a container using the created container image by adding an agent to manage the status of the layers to the layers that constitute the container image; and A method for detecting container tampering, characterized by including a step of determining tampering of another container that constitutes a microservice using the created container.
12. A processor that creates a container using the created container image by adding an agent to manage the state of the layers in the layers that compose the container image, and determines forgery of other containers that compose the microservice using the created container; and A container forgery detection system, characterized by including a storage unit providing storage space required by a processor.
Citation Information
Patent Citations
Application management method and device of connected car mounted machine
JP2019066926A
A differential MEMS-readout circuit and a method of using the same
KR1020230001532A
Method for preventing forgery of clould container image and checking vulnerability diagnosis
KR102403014B1
Method, device and computer-readable recording medium for analyzing and processing malicious code for container images
KR102518980B1
Methods and system for packet control and inspection in containers and meshed environments
US20210006569A1