IP Library Granted Patent US 12,445,478
Granted Patent B2
US 12,445,478 · App. 18/053,838 · Granted Oct 14, 2025

Adaptive profiling of cloud services using machine learning for malware detection

Inventor: Hirendra Rathor (Broadlands, VA)
Assignee: CrowdStrike, Inc.
H04L63/1433H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,478
App. No.
18/053,838
Granted
Oct 14, 2025
Kind
B2
Abstract

A cloud-service malware detection application detects, in real time or in near real time, malware infecting cloud services. The cloud-service malware detection application monitors incoming communications, outgoing communications, API calls, and other inter-service activities conducted between different cloud services in a cloud-computing environment. Because the cloud-computing environment may have many different cloud services, the cloud-service malware detection application detects a malware attack that spans multiple hosts and cloud services. The cloud-service malware detection application adaptively profiles each individual cloud service using machine learning, thus providing quicker, more accurate, and more scalable malware detection.

Claims (42)

1. A computer that detects a cloud malware infecting containerized services, comprising:

at least one central processing unit; and

at least one memory device storing instructions that, when executed by the at least one central processing unit, perform operations, the operations comprising:

monitoring inter-container activities conducted between the containerized services hosted by different network nodes in a cloud-computing environment;

identifying a service identifier associated with an inter-container activity of the inter-container activities conducted between the containerized services hosted by the different network nodes;

identifying a container-specific service behavioral profile that is associated with the service identifier;

comparing the inter-container activity to the container-specific service behavioral profile generated by a machine learning model trained using historical inter-container activities historically conducted between the containerized services hosted by the different network nodes;

determining that the inter-container activity fails to conform to the container-specific service behavioral profile generated by the machine learning model; and

in response to the determining that the inter-container activity fails to conform to the container-specific service behavioral profile, generating a malware alert notification indicating the cloud malware is detected in the containerized services.

2. The computer of claim 1 , wherein the operations further comprise training the machine learning model using a cloud configuration data, a service topology, a runtime network instrumentation, Domain Name Service (DNS) records, and an Internet Protocol reputation.

3. The computer of claim 2 , wherein the operations further comprise generating a statistical model using the cloud configuration data, the service topology, the runtime network instrumentation, the DNS records, and the Internet Protocol reputation.

4. The computer of claim 1 , wherein in response to the determining that the inter-container activity fails to conform to the container-specific service behavioral profile, further comprising isolating at least one of the containerized services.

5. The computer of claim 1 , wherein the operations further comprise comparing inter-container communications conducted between the containerized services to the container-specific service behavioral profile.

6. The computer of claim 1 , wherein the operations further comprise installing a detection agent that reports the inter-container activities conducted between the containerized services.

7. The computer of claim 1 , wherein the operations further comprise comparing application programming interfaces called by any of the containerized services to the container-specific service behavioral profile.

8. A memory device storing instructions that, when executed by at least one central processing unit, perform operations that detect a cloud malware infecting containerized services, the operations comprising:

monitoring inter-container activities conducted between the containerized services hosted by different network nodes in a cloud-computing environment;

identifying a service identifier associated with an inter-container activity of the inter-container activities conducted between the containerized services hosted by the different network nodes;

identifying a container-specific service behavioral profile by querying a database having entries that specify different container-specific service behavioral profiles to their corresponding service identifiers including an entry that specifies the container-specific service behavioral profile for the inter-container activity associated with the service identifier;

comparing the inter-container activity to the container-specific service behavioral profile generated by a machine learning model trained using historical observations of the inter-container activities also associated with the service identifier;

determining that the inter-container activity fails to conform to the container-specific service behavioral profile generated by the machine learning model; and

in response to the determining that the inter-container activity fails to conform to the container-specific service behavioral profile, generating a malware alert notification indicating the cloud malware is detected in the containerized services.

9. The memory device of claim 8 , wherein the operations further comprise comparing inter-container communications conducted between the containerized services to the service behavioral profile.

10. The memory device of claim 8 , wherein the operations further comprise training the machine learning model using a cloud configuration data, a service topology, a runtime network instrumentation, Domain Name Service (DNS) records, and an Internet Protocol reputation.

11. The memory device of claim 10 , wherein the operations further comprise generating a statistical model using the cloud configuration data, the service topology, the runtime network instrumentation, the Domain Name Service (DNS) records, and the Internet Protocol reputation.

12. The memory device of claim 8 , wherein the operations further comprise comparing application programming interfaces called by any of the containerized services to the container-specific service behavioral profile.

13. The memory device of claim 8 , wherein in response to the determining that the inter-container activity fails to conform to the container-specific service behavioral profile, further comprising isolating at least one of the containerized services.

14. The memory device of claim 8 , wherein the operations further comprise:

determining that the inter-container activity conforms to the container-specific service behavioral profile generated by the machine learning model; and

executing a containerized service of the containerized services.

15. A method that detects a cloud malware infecting containerized services, comprising:

monitoring inter-container activities conducted between the containerized services hosted by different network nodes in a cloud-computing environment;

identifying a service identifier associated with an inter-container activity of the inter-container activities conducted between the containerized services hosted by the different network nodes;

identifying a container-specific service behavioral profile that is associated with the service identifier;

comparing the inter-container activity to the container-specific service behavioral profile generated by a machine learning model trained using historical inter-container activities historically conducted between the containerized services hosted by the different network nodes;

determining that the inter-container activity fails to conform to the container-specific service behavioral profile generated by the machine learning model; and

in response to the determining that the inter-container activity fails to conform to the container-specific service behavioral profile, generating a malware alert notification indicating the cloud malware is detected in the containerized services.

16. The method of claim 15 , further comprising training the machine learning model using a cloud configuration data, a service topology, a runtime network instrumentation, Domain Name Service (DNS) records, and an Internet Protocol reputation.

17. The method of claim 16 , further comprising generating a statistical model using the cloud configuration data, the service topology, the runtime network instrumentation, the DNS records, and the Internet Protocol reputation.

18. The method of claim 15 , further comprising comparing inter-container communications conducted between the containerized services to the container-specific service behavioral profile.

19. The method of claim 15 , further comprising installing a detection agent that reports the inter-container activities conducted between the containerized services.

20. The method of claim 15 , further comprising comparing application programming interfaces called by any of the containerized services to the container-specific service behavioral profile.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2022
From: RATHOR, HIRENDRA
To: CROWDSTRIKE, INC.
Reel/Frame 061705/0352 →
Continuity (1)
Related Publication 20240154987A1 · May 9, 2024
References Cited (11)
US 10936717B1 · Herman Saffar · 2021 [cited by examiner]
US 11122058B2 · Abu-Nimeh · 2021 [cited by applicant]
US 20130036470A1 · Zhu · 2013 [cited by examiner]
US 20150195299A1 · Zoldi et al. · 2015 [cited by applicant]
US 20190020665A1 · Surcouf · 2019 [cited by examiner]
US 20210051160A9 · Abu-Nimeh · 2021 [cited by applicant]
US 20210273957A1 · Boyer et al. · 2021 [cited by applicant]
EP 3414683 · 2018 [cited by applicant]
Osnat, Rani, “Preventing Container Breakouts with Dynamic System Call Profiling,” Aqua Blog, Aug. 2, 2018. [cited by applicant]
PaloAlto Networks, “Runtime defense for containers,” Techdocs, Sep. 18, 2022. [cited by applicant]
Extended European Search Report mailed Dec. 19, 2023 in European Application No. 23202855.5, 8 pages. [cited by applicant]