Container Anomaly Detection Using Dynamic Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems are susceptible to malicious attacks due to their static nature, and current Moving Target Defense techniques are inadequate for dynamically changing network configurations of virtual machines and containers to prevent unauthorized access.
Innovation Solution
The method involves obtaining container profiles from a registry, monitoring the behavior of containers across different environments, and comparing their behavior to expected normal operation to detect anomalies, providing real-time notifications for any anomalous behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static computing system configurations are used, then system stability is maintained, but susceptibility to malicious attacks increases
Solution Approach 1:
The patent implements dynamic container profiles that automatically update their network configurations, IP addresses, and operational parameters in real-time. This transforms the static computing system into a dynamic one where container identities and network mappings change continuously, making it difficult for attackers to maintain persistent access or map the network topology effectively.
Solution Approach 2:
The system performs preliminary anomaly detection by comparing container behavior against established profiles before malicious activities can fully execute. The proactive monitoring and comparison mechanisms are in place beforehand to detect and respond to deviations from normal operation, preventing rather than merely reacting to security breaches.
2Object-affected harmful factors
If Moving Target Defense techniques are implemented to dynamically change network configurations, then attacker mapping difficulty increases, but detection capability is insufficient
Solution Approach 1:
The patent establishes a feedback loop where container behavior is continuously monitored, compared against profiles, and anomalies are detected and reported. This closed-loop system provides real-time feedback on container operations, enabling the detection of deviations from expected behavior while the network configurations dynamically change, thus solving both the obfuscation and detection requirements.
Solution Approach 2:
The system changes multiple parameters simultaneously including network IP addresses, container identifiers, and operational characteristics according to the dynamic profiles. This multi-parameter transformation approach increases attacker mapping difficulty while the anomaly detection system monitors these parameter changes to identify deviations from expected behavior patterns.
3Measurement precision
If container behavior is monitored across multiple environments, then anomaly detection accuracy improves, but system complexity increases
Solution Approach 1:
The patent creates standardized container profiles that serve as reference copies of expected normal behavior across different environments. These profiles are replicated and applied consistently across multiple container instances and environments, providing a baseline for anomaly detection without requiring complex custom monitoring logic for each individual container or environment.
Data Source
AI summary
Methods, apparatus and computer program products are provided for detection of anomalies in containers using corresponding container profiles. An exemplary method comprises: obtaining at least one container and a corresponding container profile from a container registry, wherein the container profile characterizes an expected normal operation of an application executing in the container; comparing a behavior of the application executing in the container to the expected normal operation in the corresponding container profile to determine if the container exhibits anomalous behavior; and providing a notification of the anomalous behavior when the container exhibits the anomalous behavior. The container profile is obtained, for example, by monitoring a behavior of (i) a plurality of versions of the at least one container, and/or (ii) the at least one application executing in the at least one container on a plurality of different container host devices.


