Security monitoring method and system for container, electronic device, storage medium, and program product

By establishing a data transmission channel between the container and the host, and leveraging the security monitoring capabilities of the host and server, the problem of container security monitoring resource consumption is solved, thereby improving container security performance.

WO2025248325A1PCT designated stage Publication Date: 2025-12-04CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/052983
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-27
Filing Date
2025-03-21
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

In existing technologies, container security monitoring methods require a large amount of container resources, making it difficult to guarantee the security performance of containers.

Method used

By establishing a data transmission channel between the container and the host, the data to be monitored is transmitted to the host, and the host receives the security monitoring results fed back by the server. By combining the security monitoring capabilities of the host and the server, the resource consumption of the container is reduced and the security performance is improved.

Benefits of technology

It improves container security performance and ensures effective container security monitoring without consuming excessive container resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025052983_04122025_PF_FP_ABST
    Figure IB2025052983_04122025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present disclosure are a security monitoring method and system for a container, an electronic device, a storage medium, and a program product. The method comprises: in the running process of an application program, acquiring data to be monitored generated by the application program in a container; transmitting said data to a host by means of a first data transmission channel between the container and the host, and controlling the host to receive a security monitoring result fed back by a server, wherein said data is transmitted by the host by means of a second data transmission channel between the host and the server to the server for security monitoring so as to obtain the security monitoring result, and the security monitoring result is used for representing a security performance index of the container; and acquiring the security monitoring result transmitted by the host by using the first data transmission channel. The present disclosure solves the technical problem that it is difficult to guarantee the security performance of the container.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]This disclosure claims priority to Chinese Patent Application No. 202410671234.2, filed with the China Patent Office on May 27, 2024, entitled "Security Monitoring Method, System, Electronic Device, Storage Medium, and Program Product for Containers," the entire contents of which are incorporated herein by reference. Technical Field This disclosure relates to the field of cloud computing, specifically to a security monitoring method, system, electronic device, storage medium, and program product for containers. Background Art Currently, with the popularization of cloud computing and the updating and iteration of software architecture, container technology, represented by Kubernetes (k8s), has developed rapidly. However, attacks against containers are increasing, making it crucial to ensure container security. In related technologies, container security typically involves directly installing client processes into the container. However, this method requires a large amount of container resources, contradicting the lightweight concept of containers and presenting technical problems in guaranteeing container security performance. To address the aforementioned problems, no effective solution has yet been proposed. This disclosure provides a container security monitoring method, system, electronic device, storage medium, and program product to at least solve the technical problem of difficulty in guaranteeing container security performance. According to one aspect of this disclosure, a container security monitoring method is provided. This method can be applied to a container and may include: acquiring monitoring data generated by the application in the container during application execution; transmitting the monitoring data to the host via a first data transmission channel between the container and the host, and controlling the host to receive security monitoring results fed back by the server, wherein the monitoring data is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, obtaining security monitoring results, which are used to characterize the container's security performance indicators; and acquiring the security monitoring results transmitted by the host using the first data transmission channel. According to another aspect of this disclosure, another container security monitoring method is also provided.This method can be applied to containers deployed in cloud computing scenarios and may include: acquiring monitoring data generated by the application in the container during the execution of cloud computing in the cloud computing scenario; transmitting the monitoring data to the host via a first data transmission channel between the container and the host in the cloud computing scenario, and controlling the host to receive the feedback security monitoring results, wherein the monitoring data is transmitted to the server via a second data transmission channel between the host and the server in the cloud computing scenario for security monitoring, and obtaining security monitoring results, which are used to characterize the security performance indicators of the container in the cloud computing scenario; and acquiring the security monitoring results transmitted by the host using the first data transmission channel. According to another aspect of this disclosure, another container security monitoring method is also provided. This method can be applied to a host and may include: acquiring monitoring data transmitted via a first data transmission channel between the host and the container, wherein the monitoring data is generated in the container during the application's execution; transmitting the monitoring data to the server via a second data transmission channel between the host and the server for security monitoring, and obtaining security monitoring results, wherein the security monitoring results are used to characterize the security performance indicators of the container; acquiring the security monitoring results transmitted by the server using the second data transmission channel; and transmitting the security monitoring results to the container via the first data transmission channel. According to another aspect of this disclosure, a container security monitoring system is also provided. This system may include a container, a host, and a server, wherein the container is used to acquire monitoring data generated by the application within the container during application execution; transmit the monitoring data to the host via a first data transmission channel between the container and the host; the host is used to transmit the monitoring data to the server via a second data transmission channel between the host and the server; the server is used to perform security monitoring on the monitoring data, obtain security monitoring results, and transmit the security monitoring results to the host using the second data transmission channel, wherein the security monitoring results are used to characterize the security performance indicators of the container. According to another aspect of this disclosure, an electronic device is also provided, which may include a memory and a processor: the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, wherein when the computer-executable instructions are executed by the processor, the container security monitoring method of any one of the above-mentioned methods is implemented. According to another aspect of this disclosure, a processor is also provided, which is used to run a program, wherein the container security monitoring method of any one of the above-mentioned methods is executed during program execution.According to another aspect of this disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to execute the container security monitoring method of any of the above-mentioned embodiments. According to another aspect of this disclosure, a computer program product is also provided, the computer program product including a computer program, wherein, when the computer program is executed by a processor, it executes the container security monitoring method of any of the above-mentioned embodiments. According to another aspect of this disclosure, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program, the computer program implementing the methods of various embodiments of this disclosure when executed by a processor. According to another aspect of this disclosure, a computer program implementing the methods of various embodiments of this disclosure when executed by a processor is also provided. In this disclosure, during application execution, data to be monitored generated by the application in the container is acquired; this data is transmitted to the host via a first data transmission channel between the container and the host, and the host is controlled to receive security monitoring results fed back by the server. The data to be monitored is then transmitted to the server via a second data transmission channel between the host and the server for security monitoring, resulting in security monitoring results used to characterize the container's security performance indicators. The security monitoring results transmitted by the host using the first data transmission channel are also acquired. In other words, this disclosure, combining the characteristics of the host and the container, fully utilizes the host's existing security capabilities, transmitting the data to be monitored through the first and second data transmission channels, avoiding excessive consumption of central processing, network, and memory resources by the container. This method not only reduces the consumption of container resources but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring container security performance. It is worth noting that the above general description and the following detailed description are merely illustrative and explanatory and do not constitute a limitation of this disclosure. The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this disclosure, illustrate exemplary embodiments of the present disclosure and are used to explain the disclosure, but do not constitute an undue limitation of the disclosure.In the accompanying drawings: Figure 1 is a hardware block diagram of a computer terminal (or mobile device) for implementing a container security monitoring method according to the present disclosure; Figure 2 is a block diagram of a computing environment according to the present disclosure; Figure 3 is a flowchart of a container security monitoring method according to the present disclosure; Figure 4 is a flowchart of another container security monitoring method according to the present disclosure; Figure 5 is a flowchart of another container security monitoring method according to the present disclosure; Figure 6 is a schematic diagram of a container security monitoring system according to the present disclosure; Figure 7 is a schematic diagram of communication between a container process and a host process according to the present disclosure; Figure 8 is a schematic diagram of reporting operational data and control data according to the present disclosure; Figure 9 is a schematic diagram of a data transmission process according to the present disclosure; Figure 10 is a hardware block diagram of a computer terminal (or mobile device) for implementing a container security monitoring method according to the present disclosure; Figure 11 is a block diagram of a service mesh according to the present disclosure; Figure 12 is a schematic diagram of a container security monitoring device according to the present disclosure; Figure 13 is a schematic diagram of another container security monitoring device according to the present disclosure; Figure 14 is a schematic diagram of another container security monitoring device according to the present disclosure; Figure 15 is a block diagram of a computer terminal according to the present disclosure. Figure 16 is a block diagram of an electronic device for a container safety monitoring method according to the present disclosure. Detailed Description: To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present disclosure, not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure. It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the present disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.First, some terms or nouns appearing in the description of this disclosure are to be interpreted as follows: Secure container: can be a technology for isolating and protecting applications and data; can be used to create a secure operating environment; can be an organic combination of virtualization technology and container technology; compared to ordinary containers (e.g., Linux containers), secure containers have better isolation; Host kernel: can be the kernel running on the host machine; Guest kernel: can be the kernel running within a container; Host security: can refer to ensuring the confidentiality, integrity, and availability of data storage and processing on the host, including the security of hardware, firmware, system software, and a series of additional security technologies and security management measures. Example 1: According to this disclosure, a container security monitoring method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than that shown here. The method embodiments provided in this disclosure can be executed in mobile terminals, computer terminals, or similar computing devices. Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a container security monitoring method according to the present disclosure. As shown in Figure 1, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, >, 102n in the figure) (processor 102 may include, but is not limited to, microprocessors (MCUs) or programmable logic devices (FPGAs), etc.), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface, a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that the structure shown in FIG1 is merely illustrative and does not limit the structure of the electronic device described above. For example, the computer terminal 10 may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.It should be noted that the one or more processors 102 and / or other data processing circuits described above are generally referred to herein as "data processing circuits". These data processing circuits can be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits can be a single, independent processing module, or integrated, in whole or in part, into any other element in the computer terminal 10 (or mobile device). As per this disclosure, the data processing circuits serve as processor control (e.g., selection of a variable resistor terminal path connected to an interface). The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the methods of this disclosure. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the methods in the above embodiments. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, memory 104 may further include memory remotely located relative to processor 102, which can be connected to computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof. Transmission device 106 is used to receive or send data via a network. Specific examples of such networks may include wireless networks provided by the communication provider of computer terminal 10. In one instance, transmission device 106 includes a network interface controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In one instance, transmission device 106 may be a radio frequency (RF) module for wireless communication with the Internet. The display may be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of computer terminal 10 (or mobile device). The hardware structure block diagram shown in Figure 1 can serve as an exemplary block diagram not only for the computer terminal 10 (or mobile device) described above, but also as an exemplary block diagram for the server described above. In an optional embodiment, Figure 2 shows a block diagram of an embodiment using the computer terminal 10 (or mobile device) shown in Figure 1 as a computing node in the computing environment 201.Figure 2 is a structural block diagram of a computing environment according to the present disclosure. As shown in Figure 2, the computing environment 201 includes multiple computing nodes (such as servers) running on a distributed network (shown as 210-1, 210-2, ... in the figure). Each computing node contains local processing and memory resources. An end user 202 can remotely run applications or store data within the computing environment 201. Applications can be provided as multiple services 220-1, 220-2, 220-3, and 220-4 within the computing environment 201, representing services “A”, “D”, “E”, and “H”, respectively. The end user 202 can provide and access services through a web browser or other software applications on a client. In some embodiments, the provisioning and / or requests of the end user 202 can be provided to an ingress gateway 230. oIngress gateway 230 may include a corresponding agent to handle provisioning and / or requests for services (one or more services provided in computing environment 201). Services are provided or deployed according to various virtualization technologies supported by computing environment 201. In some embodiments, services may be provided according to virtual machine (VM) based virtualization, container-based virtualization, and / or similar methods. VM-based virtualization may involve simulating a real computer by initializing a virtual machine, executing programs and applications without directly accessing any actual hardware resources. While the machine is virtualized by a virtual machine, container-based virtualization may launch containers to virtualize an entire operating system (OS), allowing multiple workloads to run on a single OS instance. In one embodiment of container-based virtualization, several containers of a service may be assembled into a Pod (e.g., a Kubernetes Pod). For example, as shown in Figure 2, service 220-2 can be configured with one or more Pods 240T, 240-2, ..., 240-N (collectively referred to as Pods). A Pod can include a proxy 245 and one or more containers 242-1, 242-2, ..., 242-M (collectively referred to as containers). One or more containers in a Pod handle requests related to one or more corresponding functions of the service. The proxy 245 typically controls network functions related to the service, such as routing and load balancing. During operation, executing a user request from end user 202 may require calling one or more services in computing environment 201, and executing one or more functions of one service may require calling one or more functions of another service. As shown in Figure 2, service "A" 220-1 receives a user request from end user 202 from ingress gateway 230. Service "A" 220-1 can call service "D" 220-2, and service "D" 220-2 can request service "E" 220-3 to execute one or more functions. The aforementioned computing environment can be a cloud computing environment, where resource allocation is managed by cloud services, allowing functionality development without considering implementation, adjustment, or server scaling. This computing environment allows developers to execute event-responding code without building or maintaining complex infrastructure. Services can be divided into a set of functions that can automatically and independently scale, rather than scaling a single hardware device to handle potential loads. Within this operating environment, this disclosure provides a container security monitoring method as shown in Figure 3, which can be applied to containers.The container can be a security container, a user container, a virtualization container, a container in the client, etc., and can be a container host. This is only for illustrative purposes and there are no specific restrictions on the container type. Figure 3 is a flowchart of a container security monitoring method according to this disclosure. As shown in Figure 3, the method can include the following steps: Step S302, during the operation of the application, acquire the data to be monitored generated by the application in the container. In the technical solution provided by step S302 of this disclosure, the application can be a software program running on a computer, which can be run through a container. The data to be monitored can include application running data, container data, etc. Running data can refer to user data, which can include process network data, file data, etc., and the user has permission to view and operate the running data. Optionally, during the operation of the application, data to be monitored will be generated, such as application logs, performance indicators, network traffic, security events, etc. The data to be monitored can be acquired through container monitoring tools or log recording functions. For example, suppose there is an application running in a virtualized container (e.g., a Docker container). Monitoring data for the application can be obtained through monitoring tools or the application's internal logging function. Step S304: The monitoring data is transmitted to the host via the first data transmission channel between the container and the host, and the host is controlled to receive the security monitoring results fed back by the server. In the technical solution provided in step S304 of this disclosure, the first data transmission channel can be a data transmission channel between the container and the host for data transmission. It can be used to transmit the monitoring data generated in the container to the host, and can be a virtual input / output socket (Vsock) channel or an uplink channel. The host can include a cloud security shield, and can be a device in a cloud computing environment used to provide computing, storage, network, and other resources. It can be a physical host, a virtual host, or a host instance. The server can be a cloud security center control plane, a cloud security center server, etc., and can be used for data storage, distribution, configuration, and other operations. It can be a cloud security shield service. It should be noted that this is only an example, and there are no specific limitations on the host type, server type, or server function. Optionally, during application runtime, the container can acquire the monitoring data generated by the application within the container and transmit this data to the host via a first data transmission channel between the container and the host. The monitoring data transmitted by the container is then acquired by the host and transmitted to the server via a second data transmission channel.The server acquires the data to be monitored and performs security monitoring on it to obtain security monitoring results. These results are then transmitted to the host via a second data transmission channel. The security performance indicators of the container can be determined based on these results. Optionally, the second data transmission channel can be a management channel or downlink channel between the host and the server, and can be a Transmission Control Protocol (TCP) connection. The monitoring data can be container-related data, i.e., container data; it can be management data, referring to data related to host security software installed on the cloud server, including plugin heartbeats, configuration information, etc., and can be used to characterize the container's security performance indicators. Security monitoring can include operations such as data distribution, processing, storage, and management. It should be noted that this is only an example, and no specific restrictions are placed on the type of monitoring data or the type of security monitoring. Optionally, the container can be a virtualization technology used to create an independent runtime environment on the host to run applications. Step S306: Obtain the security monitoring results transmitted by the host using the first data transmission channel. In the technical solution provided by step S306 of this disclosure, the container can obtain the security monitoring results obtained by the host using the second data transmission channel through the first data transmission channel. Based on the security monitoring results, the security performance of the container can be determined. Optionally, the server can perform security monitoring on the data to be monitored to obtain monitoring data. Through the monitoring data, abnormal data in the container can be identified in a timely manner, and the abnormal data can be sent to the container through the first data transmission channel and the second data transmission channel. Based on the security monitoring results, it can be determined whether the container has been attacked. For example, an application running on a company's container (i.e., an internal server) generates data to be monitored. The data to be monitored can be obtained and transmitted to the host through the first data transmission channel. The host processes the data to be monitored and transmits the data to the server for security monitoring through the second data transmission channel between the host and the server. The server can analyze and process the data to be monitored to obtain monitoring data, and transmit the monitoring data as a security monitoring result to the host through the second data transmission channel. The host then transmits the monitoring data to the container via the first data transmission channel, which is used to characterize the container's security performance indicators. Through this process, the company's cybersecurity team can promptly understand the container's security performance indicators and make corresponding security adjustments.Through steps S302 to S306 of this disclosure, during the application's operation, the monitoring data generated by the application in the container is acquired; the monitoring data is transmitted to the host via a first data transmission channel between the container and the host, and the host is controlled to receive the security monitoring results fed back by the server. The monitoring data is then transmitted to the server via a second data transmission channel between the host and the server for security monitoring, resulting in security monitoring results used to characterize the container's security performance indicators. The security monitoring results transmitted by the host using the first data transmission channel are also acquired. In other words, this disclosure, combining the characteristics of the host and the container, fully utilizes the host's existing security capabilities, transmitting the monitoring data through the first and second data transmission channels, avoiding excessive consumption of central processing, network, and memory resources by the container. This method not only reduces the consumption of container resources but also increases container security, thereby achieving the technical effect of ensuring the container's security performance and solving the technical problem of difficulty in ensuring container security performance. The above method of this embodiment will be further described below. As an optional implementation, the method may further include: starting a container process in the container, wherein the resource consumption of the container process in the container is less than a resource threshold; and determining a first data transmission channel based on the container process. In this embodiment, the container (agent) process can be a deployed lightweight process, a process with low resource consumption and high versatility, and can be used to communicate with the host process in the host. The resource threshold can be a preset value or a value set according to actual conditions or requirements. It should be noted that this is only an example, and the method for determining the resource threshold is not specifically limited. Since directly configuring the client process in the container will result in a large amount of container resource consumption, to avoid the above problem, in this embodiment, a lightweight container process can be deployed inside the container, which can communicate with the host process to achieve the purpose of consuming very few container resources. The container can also communicate with the server (i.e., the cloud security center control plane) through the host. For example, the container process can be started in the container before the data to be monitored is transmitted to the host via the first data transmission channel between the container and the host. Alternatively, the container process can be started in the container after the data to be monitored has been acquired.Alternatively, when a lightweight container process exists within the container, the container process can be started within the container. It should be noted that the process can be started within the container before transmitting the monitored data using the first data transmission channel, and the first data transmission channel can be determined based on the container process. The timing of starting the container process to generate the first data transmission channel is merely illustrative and not specifically limited. As an optional implementation, determining the first data transmission channel based on the container process includes: identifying a host process on the host that is allowed to communicate with the container process; establishing a data transmission channel between the container process and the host process; and defining the established data transmission channel as the first data transmission channel. In this embodiment, the aforementioned host process can be a host cloud shield process, a host process, a host machine process, an existing process on the host machine, or a host cloud shield process. Optionally, identifying a host process on the host that is allowed to communicate with the container process can involve establishing a data transmission channel between the container process and the host process to obtain the first data transmission channel. The data transmission channel established above can be a VSock channel, or a channel constructed through network sockets, communication protocol interfaces, etc. It should be noted that this is merely an example, and no specific restrictions are placed on the construction method of the data transmission channel. As an optional implementation, in the host, the host processes allowed to communicate with the container processes are determined, including: determining the host's security components; and in the process set of the security components, determining the processes allowed to communicate with the container processes as host processes. In this embodiment, the aforementioned security components can be network security services, which can be used to provide services for protecting and monitoring host security, and can be used to detect and block security threats such as malware, hacker attacks, and data leaks to protect the security of the host system. For example, it can be a host cloud shield. Optionally, the host can contain security components to protect and monitor host security. In this embodiment, communication between the container process and the host process is completed through the first data transmission channel, thereby fully utilizing the security components in the host. Furthermore, it avoids the need to deploy cloud shield processes within the user's container, thereby reducing the user's resource overhead. For example, the security components of the host are identified, and the process set of these security components is obtained. This process set may include at least one process, such as: the host cloud shield process, the host process, the host machine process, existing processes on the host machine, the host cloud shield process, etc. The process in the process set that is allowed to communicate with the container process is identified, and this process is identified as the host process. It should be noted that the contents of the process set are only illustrative and are not specifically limited here.As an optional implementation, the first data transmission channel represents the data transmission channel between the container process in the container and the host process in the host. Transmitting the data to be monitored to the host via the first data transmission channel between the container and the host includes: transmitting the data to be monitored from the container process to the host process via the first data transmission channel. In this embodiment, the data to be monitored is acquired, and the first data transmission channel for data transmission between the container process in the container and the host process in the host is determined. The data to be monitored can be transmitted from the container process to the host process in the host via the first data transmission channel to complete the data transmission between the host and the container. The determination of the first data transmission channel and the acquisition of the data to be monitored can occur simultaneously or sequentially; the order of occurrence is not specifically limited here. For example, the data to be monitored can be an upstream data stream. The container process can transmit the upstream data stream generated in the container to the host process (e.g., the host cloud shield process) via the first data transmission channel. In this embodiment, the data to be monitored (i.e., runtime data) is reported via the first data transmission channel, thereby avoiding the occupation of the user's central processing unit, network, and memory resources. As an optional implementation, the method may further include: sending container identification information to a host security component, wherein the identification information is used to enable the host security component to maintain a first data transmission channel; and obtaining security monitoring results transmitted by the host using the first data transmission channel, including: when the host security component identifies the first data transmission channel based on the identification information, obtaining the security monitoring results transmitted by the host to the container process using the first data transmission channel. In this embodiment, since the identification information can be used to identify containers, the container identification information can be sent to the host security component so that the host security component maintains the first data transmission channel. Optionally, the security component can maintain a channel between each container process and the host process. The container identification information can be sent to the host security component, and the security component maintains the corresponding data transmission channel based on the identification information. Optionally, the identification information is unique, and different containers have different identification information. This identification information can be the container name, image name, or container identity information. For example, a container's identification information could be "webserver" (container name), "nginx:Iatest" (image name), or "a1b2c3d4e5f6" (container identity information). This identification information allows for quick identification and location of the corresponding container.It should be noted that the above is merely an illustrative example and does not impose specific limitations on the content of the identification information. In this embodiment, the container's identification information is sent to the host's security component. The host's security component can identify the first data transmission channel based on the identification information. If the host's security component can identify the first data transmission channel based on the identification information, it can obtain the security monitoring results transmitted by the host to the container process using the first data transmission channel. Optionally, the container process transmits the container's identification information and the data to be monitored to the host process through the first data transmission channel. The host process then transmits the data to be monitored to the server (also known as the server-side) through a second data transmission channel. The server-side distributes and processes the data to be monitored, obtaining the monitoring data (i.e., control data), and transmits the monitoring data as the security monitoring result to the security component through the second data transmission channel. The security component can obtain the identification information, identify the first data transmission channel based on the identification information, and transmit the security monitoring results to the container process through the first data transmission channel. The container process can then obtain the security monitoring results transmitted by the security component. As an optional implementation, during application execution, acquiring the monitoring data generated by the application within the container includes: acquiring the monitoring data generated by the application within the container from the container process within the container during application execution. In this embodiment, the monitoring data can be data generated by the application during execution, and can be acquired from the container process within the container. For example, monitoring tools can be integrated into the container to achieve the purpose of acquiring the monitoring data generated by the application from the container process. Furthermore, the monitoring data can be used to monitor and manage the application's running status in a timely manner. In this embodiment, by deploying a lightweight container process inside the container and utilizing the container process to communicate with the host process, communication between the host and the cloud security center control plane in the server can be completed using the control channel, thereby avoiding the deployment of the cloud shield process within the user's container and saving user resources. Optionally, the container process can communicate with the host process through VSock to complete tasks such as reporting running data and managing data. As an optional implementation, the application is started and run by the server. In this embodiment, the server starts the application in the container. When it is necessary to perform security monitoring on the data to be monitored generated during the operation of the application, the data to be monitored can be transmitted to the host through the first data transmission channel, and then transmitted to the server through the second data transmission channel.The cloud security service in the server can perform security monitoring on the data to be monitored in order to determine the security performance indicators of the container. Optionally, the server can be a cloud server. The cloud server can run applications in containers through Container Service for Devices (POD). In this embodiment, by combining the characteristics of the host and the container, and making full use of the existing security capabilities of the host, the data to be monitored is transmitted through the first data transmission channel and the second data transmission channel, avoiding the container from occupying too much central processing, network and memory resources. This method not only reduces the occupation of container resources, but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of the difficulty in ensuring the security performance of the container. This disclosure also provides another container security monitoring method, which can be applied to containers deployed in cloud computing scenarios, such as cloud containers. Figure 4 is a flowchart of another container security monitoring method according to this disclosure. As shown in Figure 4, the method can include the following steps: Step S402, during the process of the application performing cloud computing in the cloud computing scenario, the data to be monitored generated by the application in the container is obtained. In the technical solution provided in step S402 of this disclosure, the aforementioned cloud computing scenario can include scenarios such as data storage, virtualization, network services, and software development platforms. For example, a cloud computing scenario could be a scenario where an enterprise stores its data in the cloud and uses a cloud computing platform for virtualization computation, or a scenario where an application is developed using a cloud-based software development platform. The aforementioned data to be monitored can refer to various monitoring indicators generated by the application in the container, such as CPU utilization, memory usage, and network traffic, which can be used to monitor the application's running status, improve performance, and troubleshoot. It should be noted that this is only an example, and there are no specific limitations on the type and function of the data to be monitored. For example, in a cloud computing scenario, suppose there is an e-commerce website application running in a container. Monitoring tools can be set up in the container, such as custom monitoring scripts. These tools can track user behavior on the website, such as page views, access time, and user geographic location, to obtain the data to be monitored. Step S404: The data to be monitored is transmitted to the host via the first data transmission channel between the container and the host in the cloud computing scenario, and the host is controlled to receive the feedback security monitoring results. The data to be monitored is transmitted to the server via the second data transmission channel between the host and the server in the cloud computing scenario for security monitoring, and the security monitoring results are obtained. The security monitoring results are used to represent the security performance indicators of the container in the cloud computing scenario.In the technical solution provided in step S404 of this disclosure, the container can acquire the monitoring data generated by the application within the container during application execution, and transmit the monitoring data to the host via a first data transmission channel between the container and the host in the cloud computing scenario. The host acquires the monitoring data transmitted by the container and transmits it to the server via a second data transmission channel. The server acquires the monitoring data and performs security monitoring on it to obtain security monitoring results, which are then transmitted to the host via the second data transmission channel. The host then feeds back the received security monitoring results to the container via the first data transmission channel. Step S406: Acquire the security monitoring results transmitted by the host using the first data transmission channel. In the technical solution provided in step S406 of this disclosure, the container can acquire the security monitoring results obtained by the host using the second data transmission channel via the first data transmission channel. Based on the security monitoring results, the security performance indicators of the container in the cloud computing scenario can be determined. For example, in a cloud computing scenario, suppose there is an application running in a container, and the security performance indicators of that application need to be monitored. Furthermore, the system can acquire monitoring data generated by the application within the container, such as network traffic and system logs. This monitoring data is transmitted to the host via a first data transmission channel, and the host receives the security monitoring results. For example, monitoring tools can be used to analyze network traffic and derive security monitoring results. Through a second data transmission channel, the monitoring data is transmitted from the host to a server for security monitoring. The server can perform security monitoring on the received data to obtain security monitoring results, which can be used to determine the container's security performance metrics in a cloud computing scenario. The container can obtain the security monitoring results transmitted by the host using the first data transmission channel for subsequent security performance assessments or adjustments. Through steps S402 to S406 of this disclosure, during the execution of cloud computing in a cloud computing scenario, the monitoring data generated by the application in the container is acquired; the monitoring data is transmitted to the host via a first data transmission channel between the container and the host in the cloud computing scenario, and the host is controlled to receive the feedback security monitoring results. The monitoring data is then transmitted to the server via a second data transmission channel between the host and the server in the cloud computing scenario for security monitoring, resulting in security monitoring results. These results characterize the security performance indicators of the container in the cloud computing scenario, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring the security performance of the container.This disclosure also provides another container security monitoring method, which can be applied to a host. Figure 5 is a flowchart of another container security monitoring method according to this disclosure. As shown in Figure 5, the method may include the following steps: Step S502, acquiring the data to be monitored transmitted via a first data transmission channel between the host and the container, wherein the data to be monitored is generated in the container during the application's execution. In the technical solution provided by step S502 of this disclosure, the host and the container can transmit information through the first data transmission channel. When the application in the container generates the data to be monitored during its execution, the host can acquire the data to be monitored from the container through the first data transmission channel. Step S504, transmitting the data to be monitored to the server via a second data transmission channel between the host and the server for security monitoring, and obtaining a security monitoring result, wherein the security monitoring result is used to characterize the container's security performance indicators. In the technical solution provided by step S504 of this disclosure, the host and the server can communicate data through the second data transmission channel. Therefore, after the host obtains the data to be monitored through the first data transmission channel, it can transmit the data to be monitored to the server through the second data transmission channel for security monitoring, thereby obtaining monitoring data. This monitoring data can serve as the security monitoring result. Step S506: Obtain the security monitoring result transmitted by the server using the second data transmission channel. In the technical solution provided by step S506 of this disclosure, the host can obtain the security monitoring result fed back by the server through the second data transmission channel. Step S508: Transmit the security monitoring result to the container via the first data transmission channel. In the technical solution provided by step S508 of this disclosure, after the host obtains the security monitoring result, it can transmit the security monitoring result to the container through the first data transmission result to determine the container's security performance indicators. For example, the application to be monitored in the container can be obtained through a monitoring tool, and the data can be transmitted to the host for analysis through the first data transmission channel to obtain the feedback security monitoring result. Then, the data is transmitted to the server via the second data transmission channel for in-depth security monitoring, and finally the monitoring result returned by the server is obtained and further analysis is performed. In this way, the security performance indicators of the container in the cloud computing scenario can be obtained. As an optional implementation, the method may further include: identifying the security components of the server; establishing a data transmission channel between the security components of the host and the security components of the server; and designating the established data transmission channel as a second data transmission channel.In this embodiment, the aforementioned security component can be used to provide security protection and monitoring for the cloud computing environment, helping users protect cloud applications and data from malicious attacks, data leaks, and other security threats. For example, it can be used for cloud shield services. Optionally, the server can contain a security component. The server's security component can be determined, and a data transmission channel can be established between the host's security component and the server's security component. This established data transmission channel can be designated as a second data transmission channel. Through the second data transmission channel, communication between the host's security component and the server's security component can be achieved. As an optional implementation, transmitting the data to be monitored to the server via the second data transmission channel between the host and the server for security monitoring, and obtaining security monitoring results, includes: transmitting the data to be monitored to the server's security component via the second data transmission channel for security monitoring, and obtaining security monitoring results. In this embodiment, the security component in the host can obtain the data to be monitored sent by the container through the first data transmission channel. This data to be monitored can be application runtime data, including process network data, file data, etc. The security component in the host can transmit the data to be monitored to the server's security component through the second data transmission channel for security monitoring to obtain security monitoring results. For example, a lightweight process in a container can transmit the data to be monitored to the host cloud shield via a first data transmission channel. The host cloud shield can then transmit the data to be monitored to the server via a TCP connection. The server distributes and processes the acquired data to be monitored, transmitting it to a security component within the server. This security component can be the cloud shield service or a security component installed on the server. As an optional implementation, obtaining the security monitoring results transmitted by the server using a second data transmission channel includes: controlling the host's security component to receive the security monitoring results transmitted via the second data transmission channel through the server's security component. In this embodiment, the server's security component can perform security monitoring on the data to be monitored to obtain security monitoring results, and the security component can transmit these results to the server. The server transmits the data to the host's security component via the second data transmission channel. The security component can transmit the security monitoring results to the corresponding container based on the container's identification information. For example, a security component deployed on the server can perform security monitoring on the data to be monitored to obtain security monitoring results, where these results can be management data, including plugin heartbeats, configuration information, etc.The security component in the server can transmit security monitoring results to the server. The server, via a TCP connection, transmits the security monitoring results to the security component in the host, where the security component in the host can be a host cloud shield. The host cloud shield can transmit the security monitoring results to the container via a first data transmission channel. As an optional implementation, transmitting the security monitoring results to the container via the first data transmission channel includes: transmitting the security monitoring results, through the host process in the host's security component, to the container process of the container via the first data transmission channel. In this embodiment, a lightweight container process can be deployed inside the container, which can communicate with the host process. When the host's security component obtains the security monitoring results, it can transmit the security monitoring results to the container process of the container via the host process in the host's security component and the first data transmission channel. Optionally, the server starts an application, loads and executes the application in the container through a container service to generate the data to be monitored. The data to be monitored is transmitted to the host by utilizing communication between the container process and the host process. The host transmits the acquired data to be monitored to the server and obtains the security monitoring results obtained by the server from the security monitoring of the data to be monitored. Furthermore, after the host's security component obtains the security monitoring results, it transmits the security monitoring results to the container process of the container through the host process in the host security component via the first data transmission channel. That is, this embodiment utilizes the control channel between the host and the server (corresponding to the second data transmission channel mentioned above) to realize communication between the security components of the container and the server (which can be the cloud security center control plane), thereby avoiding the deployment of the cloud shield process within the container while also realizing the security monitoring of the data to be monitored, thus saving users' resource consumption. Optionally, the container process communicates with the host process through the first data transmission channel, and the communication process can perform tasks such as reporting runtime data and distributing control data. As an optional implementation, step S502, obtaining the data to be monitored transmitted via the first data transmission channel between the host and the container, includes: obtaining the data to be monitored transmitted via the first data transmission channel through the host process of the host, wherein the first data transmission channel is established between the container process of the container and the host process of the host. In this embodiment, the first data transmission channel is established between the container process of the container and the host process of the host. The transmission of the data to be monitored and the security monitoring results is completed through the first data transmission channel.In this disclosure, monitoring data is acquired via a first data transmission channel between the host and the container, wherein the monitoring data is generated in the container during application execution; the monitoring data is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, and security monitoring results are obtained, wherein the security monitoring results are used to characterize the security performance indicators of the container; the security monitoring results transmitted by the server using the second data transmission channel are acquired; the security monitoring results are transmitted to the container via the first data transmission channel, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring the security performance of the container. Embodiment 2 According to this disclosure, an embodiment of a container security monitoring system is also provided. Figure 6 is a schematic diagram of a container security monitoring system according to this disclosure. As shown in Figure 6, the container security monitoring system 600 may include: a container 602, a host 604, and a server 606. oContainer 602 is used to acquire monitoring data generated by the application within the container during application execution; and to transmit the monitoring data to the host via a first data transmission channel between the container and the host. In this embodiment, container 602 may contain a container service. The server starts the application and loads and executes the application in container 602 through the container service. Container 602 can acquire monitoring data generated by the application during execution and transmit the monitoring data to host 604 via the first data transmission channel. Host 604 is used to transmit the monitoring data to the server via a second data transmission channel between the host and the server. In this embodiment, host 604 can acquire the monitoring data transmitted by container 602 through the first data transmission channel and transmit the monitoring data to server 606 via the second data transmission channel. Server 606 is used to perform security monitoring on the monitoring data, obtain security monitoring results, and transmit the security monitoring results to the host using the second data transmission channel, wherein the security monitoring results are used to characterize the security performance indicators of the container. In this embodiment, server 606 acquires the data to be monitored transmitted by host 602 through the second data transmission channel, performs security monitoring on the data to be monitored, and obtains a security monitoring result. Server 606 can use the security monitoring result as the security monitoring result and transmit it to host 604 through the second data transmission channel. Host 604 acquires the security monitoring result and transmits it to container 602 through the first data transmission channel. Optionally, container 602 can acquire the data to be monitored generated by the application in container 602 during application execution, and transmit the data to be monitored to host via the first data transmission channel between container 602 and host 604. Host 604 acquires the data to be monitored transmitted by container 602 and transmits it to server 606 through the second data transmission channel. Server 606 acquires the data to be monitored, performs security monitoring on the data to be monitored to obtain a security monitoring result, and transmits the security monitoring result as the security monitoring result to host 604 through the second data transmission channel. The host 604 then feeds back the received security monitoring results to the container 602 through the first data transmission channel.In this embodiment, during the application's execution, the application acquires the data to be monitored generated within the container via container 602; the data to be monitored is transmitted to the host via a first data transmission channel between the container and the host; the host 604 transmits the data to be monitored to the server via a second data transmission channel between the host and the server; the server 606 performs security monitoring on the data to be monitored, obtains the security monitoring results, and transmits the security monitoring results to the host via the second data transmission channel. The security monitoring results are used to characterize the container's security performance indicators, thereby achieving the technical effect of ensuring the container's security performance and solving the technical problem of difficulty in ensuring container security performance. Example 3: Currently, with the popularization of cloud computing and the updating and iteration of software architecture, container technology, represented by container orchestration, has developed rapidly. Container technology has become dominant in enterprise infrastructure. However, container attacks are increasing, and enterprises are paying more and more attention to container security. As an entity distinct from the host, a container possesses the characteristics of flexibility, lightweightness, portability, and scalability. However, cloud containers belong to the user, and the traditional host security features, such as high resource consumption and high invasiveness, can severely impact user work in container scenarios. Current container security technologies typically limit themselves to vulnerability detection within the container, neglecting network defense and other security capabilities. This results in poor scalability and technical challenges in guaranteeing container security performance. Furthermore, after years of development, containers now dominate application infrastructure, widely used from microservices to Function Compute (FC). Containers and traditional hosts differ significantly in computing paradigms and resource utilization; applying host security methods to container security is ill-suited to the characteristics of containers, leading to technical difficulties in guaranteeing container security performance. In another alternative embodiment, the client process can be directly installed into the container. However, this method consumes a significant amount of container resources, especially in cloud computing scenarios, where cloud computing itself is a multi-tenant system. Deploying the process on a client machine would further consume user resources. To address these issues, this embodiment proposes a container security scheme based on host resource sharing. This method combines the characteristics of both the host and the container, fully utilizes existing security components on the host, and adopts a lightweight approach to reduce the consumption of container resources, thereby enhancing container security. This achieves the technical effect of ensuring container security performance and solves the technical problem of the difficulty in guaranteeing container security performance.In this embodiment, by utilizing existing processes on the container host, a lightweight process can be deployed inside the container to communicate with the host process. This allows communication between the host and server-side management channels and the cloud security center's management plane. This approach not only avoids deploying the cloud shield process within the user's container, saving user resources, but also ensures that the agent in the container consumes fewer resources, is more versatile, and can communicate with the host process via VSock, including reporting runtime data and managing data. Optionally, the aforementioned cloud security center management plane (which can be simply referred to as the management plane) can be a server. The relationship between this management plane and the management channel is that the configuration and rules of the management plane can be distributed through the management channel. These configurations and rules can be managed by security operations personnel. Figure 7 is a schematic diagram illustrating communication between a container process and a host process according to this disclosure. As shown in Figure 7, container 703 may contain container process 704 (agent), container service 702 (POD Service), container kernel module 705 (guest kernel), and cloud security center real-time task agent platform 707 (Real Task Agent Platform, abbreviated as RTAP). The cloud security center real-time task agent platform 707 can distribute specified tasks to clients for real-time execution via a channel. The aforementioned client may include a host and a container. Optionally, cloud server 701 runs applications in container 703 through container service 702, and the container process 704 corresponding to the application data communicates with host process 708 through virtualization technology 706 (VSock). VSock can serve as a channel between the agent and the host cloud security process. The cloud server can be a server or a cloud-based server. In this embodiment, operational data and management data can be reported through the host channel, thereby avoiding the occupation of user resources such as central processing unit, network, and memory. Figure 8 is a schematic diagram of operational data and management data reporting according to this disclosure. As shown in Figure 8, the container group 801 may include a container 802, a container process 803, a monitoring tool 804 (e.g., detect), a host intrusion prevention system 805 (e.g., hips), a network 806, and RTAP 807. Optionally, the container process 803 of container 802 can transmit the data to be monitored detected by the monitoring tool 804 to the host cloud shield through the first data transmission channel.The host cloud shield can report samples or issue heartbeat warnings via TCP connections to transmit the data to be monitored to the cloud shield service 808 on server 809. The cloud shield service 808 stores and processes the acquired data to obtain security monitoring results, confirms these results as security monitoring results, and distributes the security monitoring data as a file. According to the configuration rules, the security monitoring data is transmitted to the host cloud shield via a second data transmission channel. Optionally, since each user's container configuration is different—for example, due to differences in the release of new features during gray-scale testing or in paid versions—in this embodiment, the configuration and rules can be processed by the run and management control 810 (RunD management) to obtain relevant container information. For example, the run and management control 810 can identify the container's identification information to determine the container group corresponding to the data to be monitored. The container identification information can be container identity information. Optionally, server 809 transmits the data to be monitored to cloud shield service 808. Cloud shield service 808 can process the acquired data to be monitored, including storage, reporting, alarms, and file distribution. The data to be monitored can be samples, reports, alarms, heartbeats, etc. Simultaneously, cloud shield service 808 can further process the security monitoring results according to configuration, rules, or commands. For example, Figure 9 is a schematic diagram of a data transmission process according to this disclosure. As shown in Figure 9, the uplink data stream (which may include running data) generated by the application running in client 904 can be sent to host cloud shield via the VSock channel through the container process. Host cloud shield 901 can send it to server 902 via a TCP connection. When host cloud shield 901 transmits running data to server 902, it will include the unique identifier of the container corresponding to the running data. Furthermore, the host process maintains each channel between itself and the container process. Server 902 distributes and processes the acquired runtime data, obtaining downlink data from the management service 903 after security monitoring of the monitored data, i.e., security monitoring results or management data. Server 902 acquires the management data and sends it to Host Cloud Shield 901 via a TCP connection. Host Cloud Shield 901 sends the security monitoring results to the corresponding container process based on the container identification information in the protocol. Optionally, Client 904 may include a host and a container. Host Cloud Shield may be deployed on the host. In this embodiment, by combining the host's security capabilities and through architectural modifications, the host's security capabilities are fully extended to the container, avoiding the occupation of user container resources and fully meeting the needs of lightweight scenarios such as function computing.In this disclosure, by combining the characteristics of the host and the container, and fully utilizing the existing security capabilities of the host, the data to be monitored is transmitted through a first data transmission channel and a second data transmission channel. This avoids the container consuming excessive central processing, network, and memory resources. This method not only reduces the resource consumption of the container but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring the security performance of containers. The method embodiments provided in this disclosure 1 can be executed in mobile terminals, computer terminals, or similar computing devices. Figure 10 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a container security monitoring method according to the present disclosure. As shown in Figure 10, the computer terminal 100 (or mobile device) may include one or more processors 1002 (shown as 1002a, 1002b, ..., 1002n in the figure), including but not limited to microprocessors (MCUs) or programmable logic devices (FPGAs), a memory 1004 for storing data, and a transmission device 1006 for communication functions. In addition, it may include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that the structure shown in Figure 10 is merely illustrative and does not limit the structure of the aforementioned electronic device. For example, the computer terminal 100 may include more or fewer components than those shown in FIG. 10, or have a different configuration than those shown in FIG. 10. The hardware structure block diagram shown in FIG. 10 can serve not only as an exemplary block diagram of the aforementioned computer terminal 100 (or mobile device), but also as an exemplary block diagram of the aforementioned server. In an optional embodiment, FIG. 2 illustrates an embodiment using the aforementioned computer terminal 100 (or mobile device) as a computing node in the computing environment 201. The memory 1004 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the container security monitoring method of this disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 1004, thereby implementing the aforementioned container security monitoring method.Memory 1004 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, memory 1004 may further include memory remotely configured relative to the processor, which can be connected to computer terminal 100 via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof. Transmission device 1006 is used to receive or transmit data via a network. Specific examples of such networks may include wireless networks provided by the communication provider of computer terminal 100. In one instance, transmission device 1006 includes a network interface controller (NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one instance, transmission device 1006 may be a radio frequency (RF) module for wireless communication with the Internet. The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 100 (or mobile device). In another alternative embodiment, FIG11 illustrates, in block diagram, an example using the computer terminal 80 (or mobile device) shown in FIG8 above as a service mesh. FIG11 is a structural block diagram of a service mesh according to the present disclosure. As shown in FIG11, the service mesh 1100 is mainly used to facilitate secure and reliable communication between multiple microservices. A microservice refers to decomposing an application into multiple smaller services or instances, distributed across different clusters / machines. As shown in FIG11, the microservices may include application service instance 1109 and application service instance 1106, which form the functional application layer of the service mesh 1100. In one implementation, application service instance 1109 runs as a container / process 1108 on machine / workload container group 1114 (POD), and application service instance 1106 runs as a container / process 1110 on machine / workload container group 1116 (POD). In one implementation, application service instance 1109 may be a data copy service, and application service instance 1106 may be a data transfer service.As shown in Figure 11, application service instance 1109 and grid agent (sitecar) 1103 coexist in machine workload container group 1114, and application service instance 1106 and grid agent 1105 coexist in machine workload container 1114. Grid agents 1103 and 1105 form the data plane layer of service mesh 1100. Grid agents 1103 and 1105 run as container / process 1104, which can receive requests 1112 for product query services, and grid agent 1106. Grid agents 1103 and 1109 can communicate bidirectionally, as can grid agents 1105 and 1106. Furthermore, grid agents 1103 and 1105 can also communicate bidirectionally. In one implementation, all traffic from application service instance 1109 is routed to the appropriate destination via mesh proxy 1103, and all network traffic from application service instance 1106 is routed to the appropriate destination via mesh proxy 1105. It should be noted that the network traffic mentioned here includes, but is not limited to, Hypertext Transfer Protocol (HTTP), Representational State Transfer (REST), high-performance, general-purpose open-source frameworks (googIe Remote Procedure Call, g-RPC), and open-source in-memory data structure storage systems (Redis). In one implementation, the functionality of extending the data plane layer can be achieved by writing custom filters for the proxy (Envoy) in service mesh 1100. Service mesh proxy configuration can be used to enable the service mesh to correctly proxy service traffic, achieving service interoperability and service governance.Mesh agents 1103 and 1105 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability. As shown in Figure 11, the service mesh 1100 also includes a control plane layer. This control plane layer can consist of a set of services running in a dedicated namespace, hosted by a managed control plane component 1101 within machine / workload container groups (pods) 1102. As shown in Figure 11, the managed control plane component 1101 communicates bidirectionally with mesh agents 1103 and 1105. The managed control plane component 1101 is configured to perform several control and management functions. For example, the managed control plane component 1101 receives telemetry data transmitted by grid agents 1103 and 1105, and can further aggregate this telemetry data. In addition, the managed control plane component 1101 can also provide user-facing application programming interfaces (APIs) to facilitate manipulation of network behavior and provision of configuration data to grid agents 1103 and 1105. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse. It should be noted that, for the foregoing method embodiments, for the sake of simplicity, they are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, because according to this disclosure, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this disclosure. Embodiment 4 According to this disclosure, a container security monitoring device for implementing the container security monitoring method shown in FIG3 above is also provided. This device can be applied to containers. FIG12 is a schematic diagram of a container security monitoring device according to this disclosure. As shown in FIG12, the container security monitoring device 1200 may include: a first acquisition unit 1202, a first transmission unit 1204, and a second acquisition unit 1206. The first acquisition unit 1202 is used to acquire the data to be monitored generated by the application in the container during the running of the application. The first transmission unit 1204 is used to transmit the data to be monitored to the host via a first data transmission channel between the container and the host, and to control the host to receive the security monitoring results fed back by the server. The data to be monitored is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, and the security monitoring results are used to characterize the security performance indicators of the container. The second acquisition unit 1206 is used to acquire the security monitoring results transmitted by the host using the first data transmission channel. Here, the first acquisition unit 1202, the first transmission unit 1204, and the second acquisition unit 1206 correspond to steps S302 to S306 in Embodiment 1. The three units and the corresponding steps implement the same examples and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above units can be hardware or software components stored in memory (e.g., memory 1004) and processed by one or more processors (e.g., processors 1002a, 1002b, 1002n). The above units can also be part of a device and run in the computer terminal 100 provided in Embodiment 3. According to this disclosure, a container security monitoring device is also provided for implementing the container security monitoring method shown in Figure 4 above. This device can be applied to containers deployed in cloud computing scenarios.Figure 13 is a schematic diagram of another container security monitoring device according to the present disclosure. As shown in Figure 13, the container security monitoring device 1300 may include: a fourth acquisition unit 1302, a processing unit 1304, and a fifth acquisition unit 1306. The fourth acquisition unit 1302 is used to acquire monitoring data generated by the application in the container during the process of the application executing cloud computing in a cloud computing scenario. The processing unit 1304 is used to transmit the monitoring data to the host via a first data transmission channel between the container and the host in the cloud computing scenario, and control the host to receive the feedback security monitoring results. The monitoring data is transmitted to the server via a second data transmission channel between the host and the server in the cloud computing scenario for security monitoring. The obtained security monitoring results are transmitted from the server to the host via the second data transmission channel. The security monitoring results are used to represent the security performance indicators of the container in the cloud computing scenario. The fifth acquisition unit 1306 is used to acquire the security monitoring results transmitted by the host using the first data transmission channel. It should be noted that the fourth acquisition unit 1302, processing unit 1304, and fifth acquisition unit 1306 mentioned above correspond to steps S402 to S406 in Embodiment 1. The three units and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above units can be hardware or software components stored in memory (e.g., memory 1004) and processed by one or more processors (e.g., processors 1002a, 1002b, 1002n). The above units can also be part of the device and run in the computer terminal 100 provided in Embodiment 3. According to this disclosure, a container security monitoring device for implementing the container security monitoring method shown in FIG. 5 is also provided. This device can be applied to a host. FIG. 14 is a schematic diagram of another container security monitoring device according to this disclosure. As shown in FIG. 14, the container security monitoring device 1400 may include: a sixth acquisition unit 1402, a second transmission unit 1404, a seventh acquisition unit 1406, and a third transmission unit 1408. oThe sixth acquisition unit 1402 is used to acquire the data to be monitored transmitted via the first data transmission channel between the host and the container, wherein the data to be monitored is generated in the container during the application's execution. The second transmission unit 1404 is used to transmit the data to be monitored to the server via the second data transmission channel between the host and the server for security monitoring, and obtain security monitoring results, wherein the security monitoring results are used to characterize the container's security performance indicators. The seventh acquisition unit 1406 is used to acquire the security monitoring results transmitted by the server using the second data transmission channel. The third transmission unit 1408 is used to transmit the security monitoring results to the container via the first data transmission channel. It should be noted that the above-mentioned sixth acquisition unit 1402, second transmission unit 1404, seventh acquisition unit 1406 and third transmission unit 1408 correspond to steps S502 to S508 in Embodiment 1. The four units and the corresponding steps implement the same examples and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above-mentioned unit can be a hardware component or software component stored in a memory (e.g., memory 1004) and processed by one or more processors (e.g., processors 1002a, 1002b, 1002n). The above-mentioned unit can also be part of the device and run in the computer terminal 100 provided in Embodiment 3. In this container security monitoring device, combining the characteristics of the host and the container, the existing security capabilities of the host are fully utilized, and the data to be monitored is transmitted through the first data transmission channel and the second data transmission channel, avoiding the container from occupying too much central processing, network and memory resources. This method not only reduces the occupation of container resources, but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring the security performance of the container. Embodiment 5 The embodiments of this disclosure can provide a computer terminal, which can be any computer terminal device in a group of computer terminals. Optionally, in this embodiment, the above-mentioned computer terminal can also be replaced by a mobile terminal or other terminal device. Optionally, in this embodiment, the above-mentioned computer terminal can be located in at least one of multiple network devices in a computer network.In this embodiment, the computer terminal can execute the program code for the following steps in the container security monitoring method: during the application's operation, acquiring the data to be monitored generated by the application in the container; transmitting the data to be monitored to the host via a first data transmission channel between the container and the host, and controlling the host to receive the security monitoring results fed back by the server, wherein the data to be monitored is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, obtaining security monitoring results, which are used to characterize the container's security performance indicators; acquiring the security monitoring results transmitted by the host using the first data transmission channel. Optionally, FIG15 is a structural block diagram of a computer terminal according to the present disclosure. As shown in FIG15, the computer terminal 1508 may include: one or more (only one is shown in the figure) processors 1502, memory 1504, and transmission devices 1506. o The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the container safety monitoring method and apparatus of this disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned container safety monitoring method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to computer terminal 1508 via a network. oExamples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: During application execution, acquire monitoring data generated by the application in the container; transmit the monitoring data to the host via a first data transmission channel between the container and the host, and control the host to receive security monitoring results fed back by the server, wherein the monitoring data is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, obtaining security monitoring results, which are used to characterize the security performance indicators of the container; acquire the security monitoring results transmitted by the host using the first data transmission channel. Optionally, the processor can also execute program code for the following steps: start a container process in the container, wherein the amount of resources occupied by the container process in the container is less than a resource threshold; determine the first data transmission channel based on the container process. Optionally, the processor can also execute program code for the following steps: in the host, determine the host process allowed to communicate with the container process; establish a data transmission channel between the container process and the host process; determine the established data transmission channel as the first data transmission channel. Optionally, the processor may also execute program code that performs the following steps: Determine the host's security component; In the process set of the security component, determine the process allowed to communicate with the container process as the host process. Optionally, the processor may also execute program code that performs the following steps: Transmit the data to be monitored through the container process to the host process via a first data transmission channel. Optionally, the processor may also execute program code that performs the following steps: Send the container's identification information to the host's security component, wherein the identification information is used to enable the host's security component to maintain the first data transmission channel; Obtain the security monitoring results transmitted by the host using the first data transmission channel, including: If the host's security component identifies the first data transmission channel based on the identification information, obtain the security monitoring results transmitted by the host to the container process using the first data transmission channel. Optionally, the processor may also execute program code that performs the following steps: During application execution, obtain the data to be monitored generated by the application in the container from the container process in the container.The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: During the execution of cloud computing in a cloud computing scenario, acquire monitoring data generated by the application in the container; transmit the monitoring data to the host via a first data transmission channel between the container and the host in the cloud computing scenario, and control the host to receive the feedback security monitoring results. The monitoring data is then transmitted to the server via a second data transmission channel between the host and the server in the cloud computing scenario for security monitoring, obtaining security monitoring results used to characterize the security performance indicators of the container in the cloud computing scenario. Alternatively, the processor can invoke information and applications stored in memory via a transmission device to perform the following steps: acquire monitoring data transmitted via the first data transmission channel between the host and the container, wherein the monitoring data is generated in the container during application execution; transmit the monitoring data to the server via the second data transmission channel between the host and the server for security monitoring, obtaining security monitoring results used to characterize the security performance indicators of the container; acquire the security monitoring results transmitted by the server using the second data transmission channel; and transmit the security monitoring results to the container via the first data transmission channel. Optionally, the processor may also execute program code for the following steps: determining the security component of the server; establishing a data transmission channel between the security component of the host and the security component of the server; and designating the established data transmission channel as a second data transmission channel. Optionally, the processor may also execute program code for the following steps: transmitting the data to be monitored to the security component of the server via the second data transmission channel for security monitoring, and obtaining security monitoring results. Optionally, the processor may also execute program code for the following steps: controlling the security component of the host to receive the security monitoring results transmitted by the security component of the server via the second data transmission channel. Optionally, the processor may also execute program code for the following steps: transmitting the security monitoring results to the container process of the container via the first data transmission channel through the host process of the host's security component. Optionally, the processor may also execute program code for the following steps: obtaining the data to be monitored transmitted via the first data transmission channel through the host process of the host, wherein the first data transmission channel is established between the container process of the container and the host process of the host.By employing this disclosure, combining the characteristics of the host and the container, and fully utilizing the existing security capabilities of the host, the data to be monitored is transmitted through a first data transmission channel and a second data transmission channel. This avoids the container consuming excessive central processing, network, and memory resources. This method not only reduces the resource consumption of the container but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring container security performance. Those skilled in the art will understand that the structure shown in Figure 15 is merely illustrative, and the computer terminal 1508 can also be a smartphone (such as an Android phone, iOS phone, etc.), tablet computer, PDA, mobile Internet Device (MID), PAD, and other terminal devices. Figure 15 does not limit the structure of the computer terminal 1508 described above. For example, the computer terminal 1508 may also include more or fewer components (such as network interfaces, display devices, etc.) than shown in Figure 15, or have a different configuration than shown in Figure 15. Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. This program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc. Embodiment 6: The embodiments of this disclosure also provide a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the container security monitoring method provided in Embodiment 1. Optionally, in this embodiment, the computer-readable storage medium can be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: During application execution, acquiring monitoring data generated by the application in the container; transmitting the monitoring data to the host via a first data transmission channel between the container and the host, and controlling the host to receive security monitoring results fed back by the server, wherein the monitoring data is transmitted to the server via a second data transmission channel between the host and the server for security monitoring, obtaining security monitoring results, which are used to characterize the security performance indicators of the container; acquiring the security monitoring results transmitted by the host using the first data transmission channel. Optionally, the computer-readable storage medium may also execute program code for the following steps: starting a container process within the container, wherein the resource amount occupied by the container process in the container is less than a resource amount threshold; determining a first data transmission channel based on the container process. Optionally, the computer-readable storage medium may also execute program code for the following steps: determining, in the host, a host process allowed to communicate with the container process; establishing a data transmission channel between the container process and the host process; and determining the established data transmission channel as the first data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: determining the host's security component; and identifying, within the process set of the security component, the process allowed to communicate with the container process as the host process. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: transmitting the data to be monitored from the container process to the host process via a first data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: sending the container's identification information to the host's security component, wherein the identification information is used to enable the host's security component to maintain the first data transmission channel; and obtaining the security monitoring results transmitted by the host using the first data transmission channel, including: if the host's security component identifies the first data transmission channel based on the identification information, obtaining the security monitoring results transmitted by the host to the container process using the first data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: during application execution, obtaining the data to be monitored generated by the application in the container from the container process within the container.A computer-readable storage medium can invoke information and applications stored in the memory via a transmission device to perform the following steps: During the execution of cloud computing in a cloud computing scenario, acquire monitoring data generated by the application in the container; transmit the monitoring data to the host via a first data transmission channel between the container and the host in the cloud computing scenario, and control the host to receive feedback security monitoring results, wherein the monitoring data is transmitted to the server via a second data transmission channel between the host and the server in the cloud computing scenario for security monitoring, and obtain security monitoring results, which are used to characterize the security performance indicators of the container in the cloud computing scenario. Alternatively, a computer-readable storage medium can invoke information and applications stored in the memory via a transmission device to perform the following steps: acquire monitoring data transmitted via a first data transmission channel between the host and the container, wherein the monitoring data is generated in the container during application execution; transmit the monitoring data to the server via a second data transmission channel between the host and the server for security monitoring, and obtain security monitoring results, wherein the security monitoring results are used to characterize the security performance indicators of the container; acquire the security monitoring results transmitted by the server using the second data transmission channel; and transmit the security monitoring results to the container via the first data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: determining the security component of the server; establishing a data transmission channel between the security component of the host and the security component of the server; and designating the established data transmission channel as a second data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: transmitting the data to be monitored to the security component of the server via the second data transmission channel for security monitoring, and obtaining security monitoring results. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: controlling the security component of the host to receive the security monitoring results transmitted by the security component of the server via the second data transmission channel. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: transmitting the security monitoring results to the container process of the container via the first data transmission channel through the host process of the host's security component. Optionally, the computer-readable storage medium may also execute program code that performs the following steps: obtaining the data to be monitored transmitted via the first data transmission channel through the host process of the host, wherein the first data transmission channel is established between the container process of the container and the host process of the host.In this disclosure, combining the characteristics of the host and the container, and fully utilizing the existing security capabilities of the host, the data to be monitored is transmitted through the first data transmission channel and the second data transmission channel. This avoids the container consuming excessive central processing, network, and memory resources. This method not only reduces the consumption of container resources but also increases container security, thereby achieving the technical effect of ensuring the security performance of the container and solving the technical problem of difficulty in ensuring the security performance of the container. Example 7: An embodiment of this disclosure also provides a computer program product. Optionally, in this embodiment, the above-mentioned computer program product may include a computer program, which, when executed by a processor, implements the method provided in the above embodiments. Example 8: An embodiment of this disclosure also provides a computer program product. Optionally, the above-mentioned computer program product may include a non-volatile computer-readable storage medium, which can be used to store a computer program, which, when executed by a processor, implements the method provided in the above embodiments. Example 9: An embodiment of this disclosure also provides a computer program. Optionally, in this embodiment, when executed by a processor, the above-mentioned computer program implements the method provided in the above embodiments. Example 10: An embodiment of this disclosure may provide an electronic device, which may include a memory and a processor. Figure 16 is a block diagram of an electronic device for a container security monitoring method according to the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein. As shown in Figure 16, device 1600 includes a computing unit 1601, which can perform various appropriate actions and processes according to a computer program stored in read-only memory (ROM) 1602 or loaded from storage unit 1608 into random access memory (RAM) 1603. The RAM 1603 can also store various programs and data required for the operation of the device 1600. The computing unit 1601, RAM 1602, and RAM 1603 are interconnected via bus 1604.The input / output (I / O) interface 1605 is also connected to the bus 1604. oMultiple components in device 1600 are connected to I / O interface 1605, including: input unit 1606, such as keyboard, mouse, etc.; output unit 1604, such as various types of monitors, speakers, etc.; storage unit 1608, such as disk, optical disk, etc.; and communication unit 1609, such as network card, modem, wireless transceiver, etc. Communication unit 1609 allows device 1600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks. Computing unit 1601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Examples of computing unit 1601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 1601 performs the various methods and processes described above, such as data verification methods. For example, in some embodiments, the data verification method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 1608. In some embodiments, part or all of the computer program may be loaded and / or installed on device 1600 via ROM 1602 and / or communication unit 1609. When the computer program is loaded into RAM 1603 and executed by computing unit 1601, one or more steps of the data verification method described above can be performed. Alternatively, in other embodiments, computing unit 1601 can be configured to perform the data verification method by any other suitable means (e.g., by means of firmware). According to this disclosure, a container security monitoring method is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases the steps shown or described can be performed in a different order than that shown here.The various implementations of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implementation in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transferring data and instructions to the storage system, the at least one input device, and the at least one output device. Program code for implementing the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine as a standalone software package, or entirely on a remote machine or server. In the context of this disclosure, a machine-readable medium may be a tangible medium that may contain or store programs for use by or in conjunction with an instruction execution system, apparatus, or device. Machine-readable media can be machine-readable signal media or machine-readable storage media. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any suitable combination of the foregoing.More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display, monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or pathball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input). The systems and techniques described herein can be implemented in computing systems including back-end components (e.g., as a data server), or computing systems including middleware components (e.g., an application server), or computing systems including front-end components (e.g., a user computer with a graphical user interface or web browser through which the user interacts with the implementations of the systems and techniques described herein), or including such back-end components, middleware components, etc. In a computing system, or any combination of front-end components, the components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include Local Area Networks (LANs), Wide Area Networks (WANs), and the Internet. The computer system may include clients and servers. Clients and servers are generally geographically distant and typically interact via a communication network. Client-server relationships are created by computer programs running on respective computers and having client-server relationships with each other. Servers may be cloud servers, distributed system servers, or servers incorporating blockchain technology. It should be noted that the serial numbers used in this disclosure are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.In the above embodiments of this disclosure, the descriptions of each embodiment have their own emphasis. Parts not described in detail in a certain embodiment can be referred to in the relevant descriptions of other embodiments. It should be understood that the disclosed technical content can be implemented in other ways in the several embodiments provided in this disclosure. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between units or modules, and may be electrical or other forms. Units described as separate components may or may not be physically separate. Components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this disclosure. The aforementioned storage medium includes: USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk, and other media capable of storing program code. The above are merely preferred embodiments of this disclosure. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this disclosure, and these improvements and modifications should also be considered within the scope of protection of this disclosure.

Claims

CLAIM 1. A method of safety monitoring of a container, wherein, The application is applied to a container, and includes: obtaining to-be-monitored data generated by an application in the container in a process in which the application runs; transmitting the to-be-monitored data to a host via a first data transmission channel between the container and the host, and controlling the host to receive a security monitoring result fed back by a server, wherein the to-be-monitored data is transmitted to the server for security monitoring via a second data transmission channel between the host and the server by the host, the security monitoring result is obtained, and the security monitoring result is used to represent a security performance index of the container; and obtaining the security monitoring result transmitted by the host via the first data transmission channel.

2. The method of claim 1, wherein, The method further includes: starting a container process in the container, wherein an amount of resources occupied by the container process in the container is less than a resource amount threshold; and determining the first data transmission channel based on the container process.

3. The method of claim 2, wherein, The method further includes: determining, in the host, a host process allowed to communicate with the container process; establishing a data transmission channel between the container process and the host process; and determining the established data transmission channel as the first data transmission channel.

4. The method of claim 3, wherein, The method further includes: determining, in the host, a security component of the host; and determining, in a process set of the security component, a process allowed to communicate with the container process as the host process.

5. The method according to any one of claims 1 to 4, wherein, The first data transmission channel is used to represent a data transmission channel between a container process in the container and a host process in the host, and the to-be-monitored data is transmitted to the host via the first data transmission channel between the container and the host, including: transmitting the to-be-monitored data to the host process of the host via the first data transmission channel by the container process.

6. The method according to any one of claims 1 to 5, wherein, The method further includes: sending identification information of the container to a security component of the host, wherein the identification information is used for the security component of the host to maintain the first data transmission channel; and obtaining the security monitoring result transmitted by the host via the first data transmission channel, including: obtaining the security monitoring result transmitted by the host to the container process via the first data transmission channel, in a case where the security component of the host identifies the first data transmission channel based on the identification information.

7. The method according to any one of claims 1 to 6, wherein, The to-be-monitored data generated by the application in the container in a process in which the application runs is obtained, including: obtaining the to-be-monitored data generated by the application in the container from a container process in the container in the process in which the application runs.

8. The method according to any one of claims 1 to 7, wherein, The application is started and run by the server.

9. A method of security monitoring of a container, wherein, The application is applied to a container deployed in a cloud computing scenario, and includes: In the process that an application performs cloud computing in the cloud computing scenario, obtaining to-be-monitored data generated by the application in the container; transmitting the to-be-monitored data to a host in the cloud computing scenario via a first data transmission channel between the container and the host, and controlling the host to receive a feedback security monitoring result, wherein the to-be-monitored data is transmitted to a server in the cloud computing scenario for security monitoring via a second data transmission channel between the host and the server by the host, and the security monitoring result is obtained, and the security monitoring result is used to represent a security performance index of the container in the cloud computing scenario; and obtaining the security monitoring result transmitted by the host via the first data transmission channel.

10. A method of security monitoring of a container, wherein, The application is applied to a host, and includes: obtaining to-be-monitored data transmitted via a first data transmission channel between the host and a container, wherein the to-be-monitored data is generated in the container in the process that an application runs; transmitting the to-be-monitored data to a server for security monitoring via a second data transmission channel between the host and the server, and obtaining a security monitoring result, wherein the security monitoring result is used to represent a security performance index of the container; obtaining the security monitoring result transmitted by the server via the second data transmission channel; and transmitting the security monitoring result to the container via the first data transmission channel.

11. The method of claim 10, wherein, The method further includes: determining a security component of the server; establishing a data transmission channel between a security component of the host and the security component of the server; and determining the established data transmission channel as the second data transmission channel.

12. The method according to claim 10 or 11, wherein, Transmitting the to-be-monitored data to the server for security monitoring via the second data transmission channel and obtaining a security monitoring result includes: transmitting the to-be-monitored data to a security component of the server via the second data transmission channel for security monitoring and obtaining the security monitoring result.

13. The method according to any one of claims 10 to 12, wherein, Obtaining the security monitoring result transmitted by the server via the second data transmission channel includes: controlling the security component of the host to receive the security monitoring result transmitted by the security component of the server via the second data transmission channel.

14. The method according to any one of claims 10 to 13, wherein, Transmitting the security monitoring result to the container via the first data transmission channel includes: transmitting the security monitoring result to a container process of the container via the first data transmission channel by a host process in the security component of the host.

15. The method according to any one of claims 10 to 14, wherein, Obtaining the to-be-monitored data transmitted via a first data transmission channel between the host and the container, comprising: obtaining, by a host process of the host, the to-be-monitored data transmitted via the first data transmission channel, wherein the first data transmission channel is established based on a container process of the container and a host process of the host.

16. A security monitoring system of a container, wherein, The container, the host and the server, comprising: the container, configured to, in a process of running an application, obtain to-be-monitored data generated by the application in the container; transmit the to-be-monitored data to the host via a first data transmission channel between the container and the host; the host, configured to transmit the to-be-monitored data to the server via a second data transmission channel between the host and the server; the server, configured to perform security monitoring on the to-be-monitored data to obtain a security monitoring result, and transmit the security monitoring result to the host using the second data transmission channel, wherein the security monitoring result is used to represent a security performance index of the container; and the host is configured to transmit the security monitoring result to the container via the first data transmission channel. Comprising:

17. An electronic device, wherein, a memory, storing an executable program; a processor, configured to run the program, wherein the program, when running, performs the method in any one of claims 1 to 15. The computer-readable storage medium comprises a stored executable program, wherein the device where the storage medium is located is controlled to perform the method in any one of claims 1 to 15 when the executable program runs.

18. A computer-readable storage medium, wherein, The computer program, when executed by a processor, implements the method according to any one of claims 1 to 15.

19. A computer program product, wherein, ​

Citation Information

Patent Citations

  • Application program monitoring method, device and system

    CN109960634A

  • Container abnormity monitoring method and monitoring system

    CN110830289A

  • Abnormality detection method and device

    CN114168951A

  • Container monitoring processing method and device, host machine, system, storage medium and program product

    CN115048272A

  • Offloading anomaly detection from server to host

    US20210026720A1