Microservice Security via Bayesian Packet Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microservice-based cloud architectures face challenges in modeling user session states and predicting defects, leading to security risks such as denial-of-service attacks, due to their complex and distributed nature.

Innovation Solution

Implementing network packet monitoring using an additive Weibull distribution for resource provisioning and a Bayesian statistical framework to identify defective microservices and classify network packets as normal or attack traffic, enabling real-time threat detection and efficient resource scaling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If microservice-based cloud architectures are used to provide shared computing resources and services, then productivity and adaptability are improved, but security risks and device complexity increase

Engineering Contradiction:
Improveresource provisioning efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud service model as an intermediary layer between users and the underlying cloud infrastructure. This intermediary provides abstraction and control mechanisms that enable secure resource provisioning, monitoring, and management. The cloud service model acts as a mediator that can enforce security policies, monitor user activities, and control access to computing resources while maintaining the benefits of microservice-based distributed architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If microservices are deployed to serve multiple users with independent interfaces, then adaptability is improved, but difficulty of detecting and measuring security threats increases

Engineering Contradiction:
Improveservice configuration flexibilityVSAvoidthreat detection complexity
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a universal cloud service model that can handle multiple types of microservices, users, and security threats through a unified framework. This multi-functional approach consolidates security monitoring, threat detection, and resource management capabilities into a single system that can adapt to various service configurations and threat types, reducing the overall complexity of detecting and measuring security threats across diverse microservice environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If network traffic monitoring is implemented to detect attacks, then security is improved, but use of energy and processing resources increases

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements selective network traffic monitoring that focuses on specific packets, users, or service interactions that are more likely to contain security threats. Rather than monitoring all traffic equally, the system applies partial monitoring actions targeted at high-risk areas, maintaining security detection capability while reducing overall processing resource consumption and energy usage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10769274B2Security in microservice architectures
Publication Date: 2020.09.08 SAP SE
  • US10769274B2 patent drawing
  • US10769274B2 patent drawing
  • US10769274B2 patent drawing

AI summary

Methods, systems, and computer-readable storage media for inhibiting security threats in microservice architectures hosted on cloud infrastructures, implementations including receiving, by a microservice used in one or more microservice-based applications, a network packet including a set of features, determining, by the microservice, a probability for the set of features with respect to a set of categories, and identifying, by the microservice, that the network packet corresponds to a first category based on probabilities of the set of features, and, in response, executing an action.