Microservice Security Detection via Metric Sensitivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security threat detection software faces challenges in detecting security attacks on microservices due to their limited variation of code execution paths, necessitating real-time and effective detection mechanisms.
Innovation Solution
A metric-sensitive dependency-based observation engine monitors microservice behavior, applying principles of mathematical chaos theory to detect security attacks by analyzing resource utilization metrics, calculating statistics, and determining self-similarity to identify potential security threats through entropic events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security threat detection software is used on microservices, then detection mechanisms are in place, but detection effectiveness is poor due to limited variation of code execution paths
Solution Approach 1:
The patent replaces traditional rule-based and signature-based detection mechanisms with a machine learning-based anomaly detection system. The system uses unsupervised learning algorithms to analyze resource utilization metrics and behavioral patterns, substituting mechanical detection rules with adaptive statistical models that can identify novel attack patterns without requiring predefined execution paths.
Solution Approach 2:
The patent transforms the detection approach by changing from analyzing code execution paths to analyzing resource utilization parameters. It monitors metrics such as CPU usage, memory consumption, network traffic, and disk I/O, converting the detection problem from code-flow analysis to statistical parameter analysis, thereby overcoming the limitation of limited code path variation.
2Speed
If real-time detection is implemented, then detection speed improves, but computational resources and complexity increase
Solution Approach 1:
The patent implements preliminary action by continuously collecting and pre-processing resource utilization metrics in the background before attacks occur. It maintains baseline behavioral profiles and pre-computes statistical parameters, so that when an attack occurs, the system can perform rapid anomaly detection by comparing current metrics against pre-established patterns, reducing real-time computational burden.
Solution Approach 2:
The system employs self-service through automated baseline learning and adaptive threshold adjustment. The machine learning models automatically update their parameters based on observed normal behavior, eliminating the need for manual configuration and reducing ongoing computational complexity. The system serves itself by continuously refining its detection capabilities without external intervention.
Data Source
AI summary
A process includes aggregating a time sequence of samples. Each sample has a plurality of dimensions that correspond to respective metrics that are associated with a microservice. Each sample includes, for each dimension, a measurement of the metric that corresponds to the dimension. The process includes identifying a given sample of the time sequence of samples based on measurements of first samples of the time sequence of samples and determining a sensitivity dependency of the metrics based on the measurements of the given sample. The process includes determining whether the microservice has been subjected to a security attack based on the sensitive dependency.


