IP Library Granted Patent US 10,146,936
Granted Patent B1
US 10,146,936 · App. 14/939,562 · Granted Dec 4, 2018

Intrusion detection for storage resources provisioned to containers in multi-tenant environments

Inventor: Vaibhav Khanduja (Cupertino, CA)
Assignee: EMC IP Holding Company LLC
G06F21/552G06F9/45504G06F9/45533G06F9/45558G06F12/1458G06F2009/45583G06F2009/45587G06F2212/1052G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,146,936
App. No.
14/939,562
Filed
Nov 12, 2015
Granted
Dec 4, 2018
Kind
B1
Art Unit
2491
USPC
726/23
Abstract

An apparatus comprises at least one container host device implementing containers for respective tenants of a multi-tenant environment, a storage platform coupled to the container host device and implementing storage resources for utilization by the containers, a container storage controller associated with the container host device, and a storage intrusion detector. The container storage controller is configured to provision portions of the storage resources for respective ones of the containers including for each of the containers at least one storage volume. The storage intrusion detector is configured to detect a condition under which a process not associated with a given one of the containers attempts to access the storage volume provisioned for that container. An alert is generated responsive to the detected condition. The storage intrusion detector may comprise a monitoring component that interacts with a kernel module implemented in kernel space of the container host device operating system.

Claims (54)

1. An apparatus comprising:

at least one container host device implementing containers for respective tenants of a multi-tenant environment;

a storage platform coupled to the container host device and implementing storage resources for utilization by the containers;

a container storage controller associated with the container host device; and

a storage intrusion detector;

wherein the containers are implemented utilizing operating system kernel control groups of the container host device;

wherein the container storage controller is configured to provision portions of the storage resources for respective ones of the containers including for each of the containers at least one storage volume;

wherein the storage intrusion detector is configured to detect a condition under which a process not associated with a given one of the containers attempts to access the storage volume provisioned for that container; and

wherein an alert is generated responsive to the detected condition;

the storage intrusion detector comprising:

a monitoring component implemented in user space of an operating system of the container host device; and

a kernel module implemented in kernel space of the operating system of the container host device;

wherein the kernel module is configured to intercept system calls involving reading from or writing to the storage volume of the given container; and

wherein the monitoring component is configured to compare an identifier of the given container to process identifiers associated with a plurality of intercepted system calls, and to generate the alert if at least one of the process identifiers is inconsistent with the identifier of the given container.

2. The apparatus of claim 1 wherein the container host device comprises at least one processor coupled to a memory and wherein at least a portion of one or more of the container storage controller and the storage intrusion detector is implemented by the processor executing software stored in the memory.

3. The apparatus of claim 1 wherein the storage platform comprises at least one of a storage fabric and a storage array.

4. The apparatus of claim 1 wherein the storage intrusion detector is implemented at least in part within the container storage controller.

5. The apparatus of claim 1 wherein the kernel module is implemented at least in part in a system call interface of the kernel space of the operating system of the container host device.

6. The apparatus of claim 1 wherein the kernel module is implemented externally to a system call interface of the kernel space of the operating system of the container host device.

7. The apparatus of claim 1 wherein the kernel module is configured to populate information relating to the intercepted system calls into one or more data structures that are made accessible to the monitoring component.

8. The apparatus of claim 7 wherein the information relating to the intercepted system calls comprises at least one of the process identifiers, one or more file names and a namespace identifier for each of the intercepted system calls.

9. The apparatus of claim 1 wherein the monitoring component determines if at least one of the process identifiers is inconsistent with the identifier of the given container by comparing a namespace identifier associated with the process identifier to a namespace identifier of the given container.

10. The apparatus of claim 1 wherein the container storage controller is implemented at least in part as an application running on the container host device.

11. The apparatus of claim 1 wherein the container storage controller is configured to control starting and stopping of the containers and wherein the storage intrusion detector is started for the given container in conjunction with the starting of that container by the container storage controller.

12. An information processing system comprising the apparatus of claim 1 .

13. A method comprising:

implementing containers for respective tenants of a multi-tenant environment on at least one container host device;

provisioning portions of storage resources of a storage platform for respective ones of the containers including for each of the containers at least one storage volume;

detecting in a storage intrusion detector a condition under which a process not associated with a given one of the containers attempts to access the storage volume provisioned for that container; and

generating an alert responsive to the detected condition;

wherein the containers are implemented utilizing operating system kernel control groups of the container host device;

wherein the implementing, provisioning, detecting and generating are performed by at least one processing device comprising a processor coupled to a memory;

the storage intrusion detector comprising:

a monitoring component implemented in user space of an operating system of the container host device; and

a kernel module implemented in kernel space of the operating system of the container host device;

wherein the kernel module is configured to intercept system calls involving reading from or writing to the storage volume of the given container; and

wherein the monitoring component is configured to compare an identifier of the given container to process identifiers associated with a plurality of intercepted system calls, and to generate the alert if at least one of the process identifiers is inconsistent with the identifier of the given container.

14. The method of claim 13 further comprising providing the alert to the given container.

15. The method of claim 14 wherein at least one of the process identifiers is determined to be inconsistent with the identifier of the given container if a namespace identifier associated with the process identifier does not match a namespace identifier of the given container.

16. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the processing device:

to implement containers for respective tenants of a multi-tenant environment on at least one container host device;

to provision portions of storage resources of a storage platform for respective ones of the containers including for each of the containers at least one storage volume;

to detect in a storage intrusion detector a condition under which a process not associated with a given one of the containers attempts to access the storage volume provisioned for that container; and

to generate an alert responsive to the detected condition;

wherein the containers are implemented utilizing operating system kernel control groups of the container host device;

the storage intrusion detector comprising:

a monitoring component implemented in user space of an operating system of the container host device; and

a kernel module implemented in kernel space of the operating system of the container host device;

wherein the kernel module is configured to intercept system calls involving reading from or writing to the storage volume of the given container; and

wherein the monitoring component is configured to compare an identifier of the given container to process identifiers associated with a plurality of intercepted system calls, and to generate the alert if at least one of the process identifiers is inconsistent with the identifier of the given container.

17. The processor-readable storage medium of claim 16 wherein at least one of the process identifiers is determined to be inconsistent with the identifier of the given container if a namespace identifier associated with the process identifier does not match a namespace identifier of the given container.

18. The processor-readable storage medium of claim 16 wherein the kernel module is implemented at least in part in a system call interface of the kernel space of the operating system of the container host device.

19. The processor-readable storage medium of claim 16 wherein the kernel module is implemented externally to a system call interface of the kernel space of the operating system of the container host device.

20. The processor-readable storage medium of claim 16 wherein the kernel module is configured to populate information relating to the intercepted system calls into one or more data structures that are made accessible to the monitoring component.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2015
From: KHANDUJA, VAIBHAV
To: EMC CORPORATION
Reel/Frame 037026/0618 →
Cited By (5)
US 12,236,112 US 12,277,213 US 12,306,774 US 12,368,694 US 12,547,460