Container Anomaly Detection Using Dynamic Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems are susceptible to malicious attacks due to their static nature, and current Moving Target Defense techniques are inadequate for dynamically changing network configurations of virtual machines and containers to prevent unauthorized access.

Innovation Solution

The method involves obtaining container profiles from a registry, monitoring the behavior of containers across different environments, and comparing their behavior to expected normal operation to detect anomalies, providing real-time notifications for any anomalous behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static computing system configurations are used, then system stability is maintained, but susceptibility to malicious attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidmalicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic container profiles that automatically update their network configurations, IP addresses, and operational parameters in real-time. This transforms the static computing system into a dynamic one where container identities and network mappings change continuously, making it difficult for attackers to maintain persistent access or map the network topology effectively.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary anomaly detection by comparing container behavior against established profiles before malicious activities can fully execute. The proactive monitoring and comparison mechanisms are in place beforehand to detect and respond to deviations from normal operation, preventing rather than merely reacting to security breaches.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If Moving Target Defense techniques are implemented to dynamically change network configurations, then attacker mapping difficulty increases, but detection capability is insufficient

Engineering Contradiction:
Improveattacker mapping difficultyVSAvoidanomaly detection capability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent establishes a feedback loop where container behavior is continuously monitored, compared against profiles, and anomalies are detected and reported. This closed-loop system provides real-time feedback on container operations, enabling the detection of deviations from expected behavior while the network configurations dynamically change, thus solving both the obfuscation and detection requirements.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes multiple parameters simultaneously including network IP addresses, container identifiers, and operational characteristics according to the dynamic profiles. This multi-parameter transformation approach increases attacker mapping difficulty while the anomaly detection system monitors these parameter changes to identify deviations from expected behavior patterns.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If container behavior is monitored across multiple environments, then anomaly detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates standardized container profiles that serve as reference copies of expected normal behavior across different environments. These profiles are replicated and applied consistently across multiple container instances and environments, providing a baseline for anomaly detection without requiring complex custom monitoring logic for each individual container or environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10824726B1Container anomaly detection using container profiles
Publication Date: 2020.11.03 EMC IP HLDG CO LLC
  • US10824726B1 patent drawing
  • US10824726B1 patent drawing
  • US10824726B1 patent drawing

AI summary

Methods, apparatus and computer program products are provided for detection of anomalies in containers using corresponding container profiles. An exemplary method comprises: obtaining at least one container and a corresponding container profile from a container registry, wherein the container profile characterizes an expected normal operation of an application executing in the container; comparing a behavior of the application executing in the container to the expected normal operation in the corresponding container profile to determine if the container exhibits anomalous behavior; and providing a notification of the anomalous behavior when the container exhibits the anomalous behavior. The container profile is obtained, for example, by monitoring a behavior of (i) a plurality of versions of the at least one container, and/or (ii) the at least one application executing in the at least one container on a plurality of different container host devices.