IP Library Granted Patent US 10,769,274
Granted Patent B2
US 10,769,274 · App. 15/677,728 · Granted Sep 8, 2020

Security in microservice architectures

Inventor: Ahmad Hassan (Belfast, GB)
Assignee: SAP SE
G06F21/55H04L41/08H04L41/142H04L63/0227H04L63/1425H04L63/1458H04L67/10H04L67/1031H04L67/1097H04L67/141H04L67/42H04L69/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,769,274
App. No.
15/677,728
Granted
Sep 8, 2020
Kind
B2
Abstract

Methods, systems, and computer-readable storage media for inhibiting security threats in microservice architectures hosted on cloud infrastructures, implementations including receiving, by a microservice used in one or more microservice-based applications, a network packet including a set of features, determining, by the microservice, a probability for the set of features with respect to a set of categories, and identifying, by the microservice, that the network packet corresponds to a first category based on probabilities of the set of features, and, in response, executing an action.

Claims (154)

1. A computer-implemented method for inhibiting security threats in microservice architectures hosted on a cloud infrastructure, the method being executed by one or more processors and comprising:

receiving, by a first microservice used in one or more microservice-based applications hosted on the cloud infrastructure, a network packet comprising a set of features F;

determining, by the first microservice, a probability P that the set of features F corresponds to a category c i in a set of categories C using a probabilistic model, the probabilistic model applying a rule for detecting a maximum probability:

P

(

c

i

|

F

)

=

P

c

i

×

P

(

F

|

c

i

)

i

=

1

m

P

c

i

×

P

(

F

|

c

i

)

where m is a number of categories in the set of categories and i is a counter that increases from 1 to m;

determining, by the first microservice, substantially in near real time that the network packet corresponds to a first category within the set of categories C based on the probability P; and

in response to determining that the network packet corresponds to the first category, executing, by the first microservice, an action comprising shutting down a defective microservice on the cloud infrastructure and instantiating another instance of the defective microservice on the cloud infrastructure.

2. The method of claim 1 , wherein the first category comprises an attack category, and the action comprises inhibiting execution of one or more functions of the microservice.

3. The method of claim 1 , wherein the first category comprises a normal category, and the action comprises allowing execution of one or more functions of the microservice.

4. The method of claim 3 , wherein the one or more functions comprise transmitting data to a second microservice.

5. The method of claim 3 , wherein the one or more functions comprise transmitting data to an operating system of the cloud infrastructure.

6. The method of claim 1 , wherein the network packet is received from a client-side computing device.

7. The method of claim 1 , wherein the network packet is received from a second microservice on the cloud infrastructure.

8. A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations for inhibiting security threats in microservice architectures hosted on a cloud infrastructure, the operations comprising:

receiving, by a first microservice used in one or more microservice-based applications hosted on the cloud infrastructure, a network packet comprising a set of features F;

determining, by the first microservice, a probability P that the set of features F corresponds to a category c i in a set of categories C using a probabilistic model, the probabilistic model applying a rule for detecting a maximum probability:

P

(

c

i

|

F

)

=

P

c

i

×

P

(

F

|

c

i

)

i

=

1

m

P

c

i

×

P

(

F

|

c

i

)

where m is a number of categories in the set of categories and i is a counter that increases from 1 to m;

determining, by the first microservice, substantially in near real time that the network packet corresponds to a first category within the set of categories C based on the probability P; and

in response to determining that the network packet corresponds to the first category, executing, by the first microservice, an action comprising shutting down a defective microservice on the cloud infrastructure and instantiating another instance of the defective microservice on the cloud infrastructure.

9. The computer-readable storage medium of claim 8 , wherein the first category comprises an attack category, and the action comprises inhibiting execution of one or more functions of the microservice.

10. The computer-readable storage medium of claim 8 , wherein the first category comprises a normal category, and the action comprises allowing execution of one or more functions of the microservice.

11. The computer-readable storage medium of claim 10 , wherein the one or more functions comprise transmitting data to a second microservice.

12. The computer-readable storage medium of claim 10 , wherein the one or more functions comprise transmitting data to an operating system of the cloud infrastructure.

13. The computer-readable storage medium of claim 8 , wherein the network packet is received from a client-side computing device.

14. The computer-readable storage medium of claim 8 , wherein the network packet is received from a second microservice on the cloud infrastructure.

15. A system, comprising:

a computing device; and

a computer-readable storage device coupled to the computing device and having instructions stored thereon which, when executed by the computing device, cause the computing device to perform operations for inhibiting security threats in microservice architectures hosted on a cloud infrastructure, the operations comprising:

receiving, by a first microservice used in one or more microservice-based applications hosted on the cloud infrastructure, a network packet comprising a set of features F;

determining, by the first microservice, a probability P that the set of features F corresponds to a category c i in a set of categories C using a probabilistic model, the probabilistic model applying a rule for detecting a maximum probability:

P

(

c

i

|

F

)

=

P

c

i

×

P

(

F

|

c

i

)

i

=

1

m

P

c

i

×

P

(

F

|

c

i

)

where m is a number of categories in the set of categories and i is a counter that increases from 1 to m;

determining, by the first microservice, substantially in near real time that the network packet corresponds to a first category within the set of categories C based on the probability P; and

in response to determining that the network packet corresponds to the first category, executing, by the first microservice, an action comprising shutting down a defective microservice on the cloud infrastructure and instantiating another instance of the defective microservice on the cloud infrastructure.

16. The system of claim 15 , wherein the first category comprises an attack category, and the action comprises inhibiting execution of one or more functions of the microservice.

17. The system of claim 15 , wherein the first category comprises a normal category, and the action comprises allowing execution of one or more functions of the microservice.

18. The system of claim 17 , wherein the one or more functions comprise transmitting data to a second microservice.

19. The system of claim 17 , wherein the one or more functions comprise transmitting data to an operating system of the cloud infrastructure.

20. The system of claim 17 , wherein the network packet is received from a client-side computing device.

Assignments (3)
MERGER Recorded Oct 29, 2019
From: HYBRIS AG
To: SAP (SCHWEIZ) AG
Reel/Frame 050855/0414 →
MERGER Recorded Oct 29, 2019
From: SAP (SCHWEIZ) AG
To: SAP SE
Reel/Frame 050855/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: HASSAN, AHMAD
To: HYBRIS AG
Reel/Frame 043564/0409 →
Continuity (1)
Related Publication 20190057213A1 · Feb 21, 2019
Cited By (1)
US 12,739,280