Minimal OS Master Container Intrusion Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection and recovery methods in cloud infrastructure face challenges such as a non-zero time gap between detection and remediation, partial system control by intruders during recovery, and incomplete recovery due to limitations in existing techniques like firewalls and intrusion detection systems.

Innovation Solution

A method involving a minimalistic Operating System (OS) that deploys a master container with access to a Storage Area Network (SAN) and Distributed Configuration Management (DCM) module, invoking an Intrusion Detection Module (IDM) to detect and re-deploy the container upon intrusion notification, ensuring read-only access and private network operations to maintain system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional intrusion detection systems and firewalls are deployed, then detection capability is improved, but response time is delayed due to non-zero gap between detection and remediation

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring immutable container images with all necessary software and configurations before deployment. When intrusion is detected, the system can immediately instantiate a fresh container from the pre-prepared image, eliminating the time-consuming manual recovery process and achieving near-instantaneous response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates exact copies of the trusted system state through container images. Instead of attempting to repair the compromised system in place, the system copies the entire system state into a new container instance, ensuring that recovery is both fast and complete, with the new container being an identical replica of the pre-security-hardened original.

Inventive Principle:
Principle #26Copying

2Reliability

If manual fixing and system restoration techniques are used, then recovery completeness is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improverecovery completenessVSAvoidrecovery process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service recovery through automated container orchestration. When intrusion is detected, the system automatically terminates the compromised container and instantiates a new one from the immutable image without requiring manual intervention. The orchestration system handles the entire recovery process autonomously, eliminating complex manual procedures while ensuring complete recovery.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system segments the system state into immutable container images that can be independently managed and replicated. This segmentation allows the recovery process to operate at the container level rather than requiring system-wide manual intervention, simplifying the recovery process while ensuring completeness through isolated, self-contained recovery units.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If system configurations are restored from backup, then data recovery is improved, but security risks increase due to potentially compromised backup data

Engineering Contradiction:
Improvedata recoveryVSAvoidsecurity risk from compromised backups
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security hardening by creating immutable container images with security best practices embedded before deployment. These pre-configured images serve as the source for recovery, ensuring that restored systems inherit the security posture of the original trusted image rather than potentially compromised backup data, thus preventing security risks while maintaining data recovery capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11385807B1System and method for recovering a node in a cloud infastructure after an intrusion
Publication Date: 2022.07.12 VIRTUOZZO INT GMBH
  • US11385807B1 patent drawing
  • US11385807B1 patent drawing
  • US11385807B1 patent drawing

AI summary

Disclosed herein are systems and method for recovering a computing device after an intrusion is detected. In one aspect, an exemplary method comprises, by a minimalistic operating system running on the computing device, deploying a master container, wherein the deploying of the master container comprises creating and starting the master container from a container image, providing, to the master container, access to a storage area network (SAN) volume, providing, to the master container, read-only access to a Distributed Configuration Management (DCM) module domain, the domain being where a configuration of the computing device is stored, and invoking an Intrusion Detection Module (IDM) to start detecting intrusions into the master container; and upon receiving a notification from the IDM, re-deploying, by the minimalistic OS, the master container from the container image, wherein the deployed master container acts as a default runtime environment on the computing device.