Container Network Policy Automation for Microservice Intrusion Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing frameworks for microservices security are prone to human error and inefficiency, particularly when manually restricting access between compromised microservices, and predictive methods often result in false positives or negatives, leading to application failures and increased vulnerability to intrusion propagation.

Innovation Solution

A system that analyzes network information to determine dependencies between microservices, generates a network policy to restrict access based on these dependencies, and propagates this policy to a container orchestrator controller to limit the impact of a compromised microservice, thereby reducing the risk of intrusion propagation without relying on human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access restriction methods are used for compromised microservices, then human intervention is required, but this leads to human error and inefficiency

Engineering Contradiction:
Improveaccess restriction accuracyVSAvoidmanual intervention level
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system automatically detects intrusions and generates network policies without human intervention. The processor monitors microservice communications, identifies compromised services, and autonomously creates and applies access restriction policies through the container orchestrator controller.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated electronic systems. Human operators manually configuring access rules are substituted by a processor that electronically analyzes network traffic, determines dependencies, generates policies, and applies restrictions through automated communication with the container orchestrator.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If predictive access limitation methods are used, then automated decision-making is implemented, but this results in false positives or negatives

Engineering Contradiction:
Improveresponse speedVSAvoidaccess limitation accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors actual microservice communications and uses this real-time feedback to determine dependencies and generate accurate network policies. The processor analyzes actual traffic patterns rather than relying on predictions, adjusting access restrictions based on observed communication behavior.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of network communications to establish dependency relationships before generating access restriction policies. By pre-determining which microservices actually communicate with the compromised service based on observed traffic patterns, the system prepares accurate policy parameters in advance.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If broad access restrictions are applied to compromised microservices, then intrusion propagation is prevented, but this causes overprotective limitations on unaffected services

Engineering Contradiction:
Improveintrusion propagationVSAvoidservice accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies differentiated access restrictions based on the specific dependency relationships of each compromised microservice. Rather than applying uniform broad restrictions, the processor analyzes which services actually communicate with the compromised service and applies targeted restrictions only to those specific communication paths, allowing other services to operate normally.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments access restrictions into specific, targeted policies rather than applying a single broad restriction. The network policy is divided into specific allow/deny rules based on individual microservice dependencies, enabling fine-grained control that prevents intrusion propagation while maintaining service functionality.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If narrow access restrictions are applied to compromised microservices, then service functionality is maintained, but this leaves the network vulnerable to intrusion propagation

Engineering Contradiction:
Improveservice functionalityVSAvoidintrusion propagation risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system uses real-time feedback from monitored microservice communications to dynamically determine the scope of access restrictions. By continuously observing actual traffic patterns and dependency relationships, the system identifies the minimum necessary restrictions needed to prevent intrusion propagation while maintaining legitimate service functionality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240089291A1Automatic network policies generation in containerized environments
Publication Date: 2024.03.14 DELL PROD LP
  • US20240089291A1 patent drawing
  • US20240089291A1 patent drawing
  • US20240089291A1 patent drawing

AI summary

Technology described herein relates to limiting microservice operation in response to security compromise of the microservice. A method can comprise facilitating, by a system operatively coupled to a processor, transmitting, to a container orchestrator controller that is part of a communication network, a network policy that, in response to deployment, operates to restrict, according to a restriction defined by the network policy, access between a first microservice and a second microservice of the communication network different from the first microservice, and instructing, by the system, the network policy to be deployed by the container orchestrator controller, to restrict, according to the restriction and in response to detection of a malfunction of the first microservice related to an intrusion to the first microservice, first connections employed during a flow between the first microservice and the second microservice by default and second connections that are not employed by default during the flow.