Serverless Runtime Security Analytics via Container Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional sandbox products are ineffective in detecting runtime security threats in serverless computing and FaaS environments due to the lack of a traditional computing environment to mimic.

Innovation Solution

A controlled and monitored environment is created to execute serverless functions within container instances, capturing runtime data which is then analyzed using machine-learning models to detect potential security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional sandbox products are used to detect security threats, then malware detection capability is improved, but applicability to serverless environments deteriorates

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidapplicability to serverless environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtualized execution environment that copies the essential characteristics of serverless computing platforms. Instead of using traditional sandboxing that emulates desktop or server environments, the system replicates the container-based, event-driven architecture of serverless platforms, allowing malware detection while maintaining environmental adaptability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the fundamental parameters of the execution environment from traditional virtual machine-based sandboxes to container-based isolated environments. This includes modifying resource allocation models, execution triggers, and monitoring mechanisms to match serverless platform characteristics, thereby enabling both reliable detection and environmental adaptability

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If container-based execution environment is used, then environment adaptability is improved, but security isolation capability deteriorates

Engineering Contradiction:
Improveenvironment adaptabilityVSAvoidsecurity isolation capability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements fine-grained segmentation of container resources and execution contexts. By dividing the container environment into isolated execution zones with controlled resource access and separate monitoring domains, the system maintains security isolation while preserving container-based environment adaptability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer between the container execution environment and the underlying infrastructure. This intermediary provides enhanced security controls, monitoring, and isolation mechanisms while allowing containers to maintain their native environment adaptability, effectively decoupling security concerns from environmental compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12277210B2Runtime security analytics for serverless workloads
Publication Date: 2025.04.15 CISCO TECHNOLOGY INC
  • US12277210B2 patent drawing
  • US12277210B2 patent drawing
  • US12277210B2 patent drawing

AI summary

Runtime security threats are detected and analyzed for serverless functions developed for hybrid clouds or other cloud-based deployment environments. One or more serverless functions may be received and executed within a container instance executing in a controlled and monitored environment. The execution of the serverless functions is monitored, using a monitoring layer in the controlled environment to capture runtime data including container application context statistics, serverless function input and output data, and runtime parameter snapshots of the serverless functions. Execution data associated with the serverless functions may be analyzed and provided to various supervised and/or unsupervised machine-learning models configured to detect and analyze runtime security threats.