Container Network Policy Automation for Microservice Intrusion Containment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing frameworks for microservices security are prone to human error and inefficiency, particularly when manually restricting access between compromised microservices, and predictive methods often result in false positives or negatives, leading to application failures and increased vulnerability to intrusion propagation.
Innovation Solution
A system that analyzes network information to determine dependencies between microservices, generates a network policy to restrict access based on these dependencies, and propagates this policy to a container orchestrator controller to limit the impact of a compromised microservice, thereby reducing the risk of intrusion propagation without relying on human intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual access restriction methods are used for compromised microservices, then human intervention is required, but this leads to human error and inefficiency
Solution Approach 1:
The system automatically detects intrusions and generates network policies without human intervention. The processor monitors microservice communications, identifies compromised services, and autonomously creates and applies access restriction policies through the container orchestrator controller.
Solution Approach 2:
The patent replaces manual mechanical processes with automated electronic systems. Human operators manually configuring access rules are substituted by a processor that electronically analyzes network traffic, determines dependencies, generates policies, and applies restrictions through automated communication with the container orchestrator.
2Productivity
If predictive access limitation methods are used, then automated decision-making is implemented, but this results in false positives or negatives
Solution Approach 1:
The system continuously monitors actual microservice communications and uses this real-time feedback to determine dependencies and generate accurate network policies. The processor analyzes actual traffic patterns rather than relying on predictions, adjusting access restrictions based on observed communication behavior.
Solution Approach 2:
The system performs preliminary analysis of network communications to establish dependency relationships before generating access restriction policies. By pre-determining which microservices actually communicate with the compromised service based on observed traffic patterns, the system prepares accurate policy parameters in advance.
3Object-affected harmful factors
If broad access restrictions are applied to compromised microservices, then intrusion propagation is prevented, but this causes overprotective limitations on unaffected services
Solution Approach 1:
The system applies differentiated access restrictions based on the specific dependency relationships of each compromised microservice. Rather than applying uniform broad restrictions, the processor analyzes which services actually communicate with the compromised service and applies targeted restrictions only to those specific communication paths, allowing other services to operate normally.
Solution Approach 2:
The patent segments access restrictions into specific, targeted policies rather than applying a single broad restriction. The network policy is divided into specific allow/deny rules based on individual microservice dependencies, enabling fine-grained control that prevents intrusion propagation while maintaining service functionality.
4Ease of operation
If narrow access restrictions are applied to compromised microservices, then service functionality is maintained, but this leaves the network vulnerable to intrusion propagation
Solution Approach 1:
The system uses real-time feedback from monitored microservice communications to dynamically determine the scope of access restrictions. By continuously observing actual traffic patterns and dependency relationships, the system identifies the minimum necessary restrictions needed to prevent intrusion propagation while maintaining legitimate service functionality.
Data Source
AI summary
Technology described herein relates to limiting microservice operation in response to security compromise of the microservice. A method can comprise facilitating, by a system operatively coupled to a processor, transmitting, to a container orchestrator controller that is part of a communication network, a network policy that, in response to deployment, operates to restrict, according to a restriction defined by the network policy, access between a first microservice and a second microservice of the communication network different from the first microservice, and instructing, by the system, the network policy to be deployed by the container orchestrator controller, to restrict, according to the restriction and in response to detection of a malfunction of the first microservice related to an intrusion to the first microservice, first connections employed during a flow between the first microservice and the second microservice by default and second connections that are not employed by default during the flow.


