Microservice Security Detection via Metric Sensitivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security threat detection software faces challenges in detecting security attacks on microservices due to their limited variation of code execution paths, necessitating real-time and effective detection mechanisms.

Innovation Solution

A metric-sensitive dependency-based observation engine monitors microservice behavior, applying principles of mathematical chaos theory to detect security attacks by analyzing resource utilization metrics, calculating statistics, and determining self-similarity to identify potential security threats through entropic events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security threat detection software is used on microservices, then detection mechanisms are in place, but detection effectiveness is poor due to limited variation of code execution paths

Engineering Contradiction:
Improvedetection effectivenessVSAvoidcode execution path variation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional rule-based and signature-based detection mechanisms with a machine learning-based anomaly detection system. The system uses unsupervised learning algorithms to analyze resource utilization metrics and behavioral patterns, substituting mechanical detection rules with adaptive statistical models that can identify novel attack patterns without requiring predefined execution paths.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the detection approach by changing from analyzing code execution paths to analyzing resource utilization parameters. It monitors metrics such as CPU usage, memory consumption, network traffic, and disk I/O, converting the detection problem from code-flow analysis to statistical parameter analysis, thereby overcoming the limitation of limited code path variation.

Inventive Principle:
Principle #35Parameter changes

2Speed

If real-time detection is implemented, then detection speed improves, but computational resources and complexity increase

Engineering Contradiction:
Improvedetection timeVSAvoidcomputational complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by continuously collecting and pre-processing resource utilization metrics in the background before attacks occur. It maintains baseline behavioral profiles and pre-computes statistical parameters, so that when an attack occurs, the system can perform rapid anomaly detection by comparing current metrics against pre-established patterns, reducing real-time computational burden.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs self-service through automated baseline learning and adaptive threshold adjustment. The machine learning models automatically update their parameters based on observed normal behavior, eliminating the need for manual configuration and reducing ongoing computational complexity. The system serves itself by continuously refining its detection capabilities without external intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240364720A1Detecting microservice security attacks based on metric sensitive dependencies
Publication Date: 2024.10.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20240364720A1 patent drawing
  • US20240364720A1 patent drawing
  • US20240364720A1 patent drawing

AI summary

A process includes aggregating a time sequence of samples. Each sample has a plurality of dimensions that correspond to respective metrics that are associated with a microservice. Each sample includes, for each dimension, a measurement of the metric that corresponds to the dimension. The process includes identifying a given sample of the time sequence of samples based on measurements of first samples of the time sequence of samples and determining a sensitivity dependency of the metrics based on the measurements of the given sample. The process includes determining whether the microservice has been subjected to a security attack based on the sensitive dependency.