Container Behavior Identification Module for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing frequency of attacks and intrusions on container systems from third parties poses a significant security risk, as existing technologies lack effective methods to detect abnormal behavior and prevent unauthorized control of containers or hosts.

Innovation Solution

A computer device equipped with a processor and storage configured to detect container behavior through a container behavior identification module, which classifies behavior eigenvectors using machine learning algorithms to identify abnormal activity and notify users or central control centers, and optionally creates decoy containers to divert attacks away from primary containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If container behavior monitoring is implemented to detect attacks, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a behavior identification module as an intermediary component that sits between the container operations and the security analysis system. This module captures container behavior data and processes it through predefined identification rules, acting as a mediator that simplifies the overall system architecture while maintaining effective security monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring system is divided into distinct functional segments: a behavior identification module that captures container behavior, a rule storage module that holds identification rules, and an analysis component that applies rules to detect anomalies. This segmentation allows each component to be independently developed, maintained, and optimized, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Speed

If real-time container behavior detection is implemented, then attack detection speed is improved, but computational resource consumption increases

Engineering Contradiction:
Improveattack detection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system implements partial monitoring by focusing only on specific container behaviors that are relevant to security threats, rather than monitoring all container activities. The behavior identification module selectively captures and analyzes only those behaviors defined in the identification rules, reducing computational overhead while maintaining effective attack detection.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of detection from comprehensive continuous monitoring to rule-based event-triggered monitoring. By transforming the detection approach to only activate when specific behavioral parameters match predefined rules, the system achieves fast attack detection while minimizing continuous computational resource consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10726124B2Computer device and method of identifying whether container behavior thereof is abnormal
Publication Date: 2020.07.28 INSTITUTE FOR INFORMATION INDUSTRY
  • US10726124B2 patent drawing
  • US10726124B2 patent drawing
  • US10726124B2 patent drawing

AI summary

A computer device and a method of identifying whether container behavior thereof is abnormal are provided. The computer device detects container behavior of a container in a time interval, and identifies whether the container behavior of the container is abnormal according to a container behavior identification module, thereby determining whether there is an intrusion. In addition, a decoy container can be installed in the computer device to attract attacking or invading from a third party so as to reduce the risk of the container being attacked, and the container behavior identification module can be updated according to the container behavior of the decoy container.