Cloud Container Threat Detection for Spoofing and DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud container orchestration leads to resource fragmentation and decreased utilization, making cloud resources vulnerable to attacks like spoofing, tampering, and denial of service, which compromise application security and require improved threat detection measures.

Innovation Solution

A computing platform trains a threat detection model using deep reinforcement learning to identify and mitigate threats by deploying containers to optimal nodes, updating the model based on operating conditions, and sending graphical representations to user devices for threat visualization and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud container orchestration is used to manage and schedule resources, then resource allocation is improved, but resource utilization decreases and resource fragmentation occurs

Engineering Contradiction:
Improveresource allocationVSAvoidresource utilization
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements a feedback mechanism where the machine learning model continuously monitors container behavior, security events, and resource usage patterns. The model receives feedback from security incidents and performance metrics, then updates its predictions and recommendations for container placement and resource allocation, creating a closed-loop system that improves resource utilization while maintaining security

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically changes parameters such as container placement decisions, resource allocation levels, and security policy configurations based on real-time conditions. The machine learning model adjusts these parameters optimally by analyzing historical data and current system state, resolving the contradiction between allocation efficiency and utilization effectiveness

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional security measures are implemented, then security coverage is improved, but system performance and resource utilization worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces traditional rule-based and signature-based security mechanisms with a machine learning-based predictive security system. Instead of relying on predefined security rules that require extensive computational resources for pattern matching, the system uses trained models that make rapid predictions about container security states, significantly reducing performance overhead while maintaining or improving security coverage

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary security assessments by training machine learning models on historical data before deploying containers. Security risks are predicted in advance, allowing preventive measures to be taken before actual security incidents occur, rather than relying on reactive security measures that consume resources during incidents

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive threat detection is implemented, then security detection capability is improved, but computational complexity and resource consumption increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the threat detection problem into multiple specialized machine learning models, each trained to detect specific types of threats or analyze particular aspects of container behavior. This segmentation allows each model to be computationally efficient while collectively providing comprehensive threat detection coverage across different attack vectors and container states

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial monitoring and analysis by focusing computational resources on the most critical security parameters and high-risk containers. The machine learning model identifies and prioritizes which containers and security events require intensive analysis, avoiding unnecessary computational expenditure on low-risk elements while maintaining high detection precision for critical threats

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260058987A1Monitoring and preventing spoofing, tampering, and denial of service attacks on cloud containers
Publication Date: 2026.02.26 BANK OF AMERICA CORP
  • US20260058987A1 patent drawing
  • US20260058987A1 patent drawing
  • US20260058987A1 patent drawing

AI summary

A computing platform may train, using historical threat detection information, a threat detection model, which may configure the threat detection model to detect container threats for a plurality of containers deployed at a plurality of nodes on a cloud network. The computing platform may obtain, from a node monitoring system, operating conditions of the plurality of nodes. The computing platform may input, into the threat detection model, the operating conditions of the plurality of nodes, which may cause the threat detection model to identify a threat to at least one container deployed at the plurality of nodes. The computing platform may execute, based on identification of the threat, a security action to protect the at least one container. The computing platform may update, based on the operating conditions of the plurality of nodes and the threat, the threat detection model.