IP Library › Granted Patent US 11,748,473
Granted Patent B2
US 11,748,473 · App. 17/071,055 · Granted Sep 5, 2023

Intrusion detection in micro-services through container telemetry and behavior modeling

Inventors: Frederico Araujo (White Plains, NY); Teryl Paul Taylor (Danbury, CT); Jiyong Jang (Chappaqua, NY); Will Blair (Boston, MA)
Assignee: International Business Machines Corporation
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,473
App. No.
17/071,055
Filed
Oct 15, 2020
Granted
Sep 5, 2023
Kind
B2
Art Unit
2431
USPC
726/23
Abstract

An intrusion detection system (IDS) for a micro-services environment identifies attacks in substantially real-time and at a container-level. In this approach, behavior models are generated from container images using a binary analysis. A behavior model is a graph data structure having nodes and edges, wherein an edge represents a system call made by at least one process represented as a node in the graph data structure. The model is co-located with a running container, thereby enabling detection of anomalies as the container executes in a container environment on a hardware node. A per-container IDS function is instantiated by checking whether system call telemetry generated by an image's running container satisfies the associated behavior model that has been generated for the container image. If the telemetry indicates activity that deviates from the behavior model, an automated action is then initiated to attempt to address the attack, preferably while it is in progress.

Claims (38)

1. A method for intrusion detection in a run-time container environment, comprising:

deploying a behavior model in association with a container executing in the run-time container environment, the behavior model having been generated from a container image and one or more library dependencies of the container image, the behavior model being a graph data structure having a set of nodes, and a set of edges, wherein a node represents one of: a process, a file and a network socket, and wherein an edge represents a system call made by at least one process represented in the graph data structure;

as the container image executes in the container, receiving system call telemetry;

responsive to receipt of the telemetry, determining whether the container image is executing in a manner inconsistent with the behavior model, thereby indicating an anomaly; and

upon a determination that the container image is executing in a manner inconsistent with the behavior model, taking an automated action to attempt to address the anomaly.

2. The method as described in claim 1 further including generating the behavior model for the container image by identifying the library dependencies.

3. The method as described in claim 2 wherein the behavior model is generated by a binary analysis that determines what library functions a given binary calls.

4. The method as described in claim 3 wherein the binary analysis determines what library functions a given binary calls by examining an inter-procedural call graph and finding a set of system calls reachable from the call graph.

5. The method as described in claim 3 wherein the binary analysis generates the behavior model by micro-executing code reachable from an entrypoint of the container image.

6. The method as described in claim 1 wherein the behavior model is instantiated in a hardware node in a Container Orchestration Engine (COE), and wherein the container image executes as a micro-service.

7. The method as described in claim 6 , further including enriching the behavior model based on information representing one or more valid system calls seen by one or more other containers running on the hardware node.

8. The method as described in claim 1 , wherein determining whether the container image is executing in a manner inconsistent with the behavior model is carried out continuously and the automated action is one of: mitigation, notification, sandboxing and logging.

9. Apparatus, comprising:

at least one hardware processor;

computer memory holding computer program instructions executed by the at least one hardware processor to perform intrusion detection in association with a container environment, the computer program instructions comprising program code configured to:

deploy a behavior model in association with a container executing in the run-time container environment, the behavior model having been generated from a container image and one or more library dependencies of the container image, the behavior model being a graph data structure having a set of nodes, and a set of edges, wherein a node represents one of: a process, a file and a network socket, and wherein an edge represents a system call made by at least one process represented in the graph data structure;

as the container image executes in the container, receive system call telemetry;

responsive to receipt of the telemetry, determine whether the container image is executing in a manner inconsistent with the behavior model, thereby indicating an anomaly; and

upon a determination that the container image is executing in a manner inconsistent with the behavior model, take an automated action to attempt to address the anomaly.

10. The apparatus as described in claim 9 wherein the computer program code is further configured to generate the behavior model for the container image by identifying the library dependencies.

11. The apparatus as described in claim 10 wherein the behavior model is generated by a binary analysis that determines what library functions a given binary calls.

12. The apparatus as described in claim 11 wherein the binary analysis determines what library functions a given binary calls by examining an inter-procedural call graph and finding a set of system calls reachable from the call graph.

13. The apparatus as described in claim 11 wherein the binary analysis generates the behavior model by micro-executing code reachable from an entrypoint of the container image.

14. The apparatus as described in claim 9 wherein the behavior model is instantiated in a hardware node in a Container Orchestration Engine (COE), and wherein the container image executes as a micro-service.

15. The apparatus as described in claim 14 , wherein the program code is further configured to enrich the behavior model based on information representing one or more valid system calls seen by one or more other containers running on the hardware node.

16. The apparatus as described in claim 9 , wherein the program code configured to determine whether the container image is executing in a manner inconsistent with the behavior model executes continuously and the automated action is one of: mitigation, notification, sandboxing and logging.

17. A computer program product in a non-transitory computer-readable medium for use in a data processing system, the computer program product holding computer program instructions executed by the data processing system to perform intrusion detection in association with a container environment, the computer program instructions comprising program code configured to:

deploy a behavior model in association with a container executing in the run-time container environment, the behavior model having been generated from a container image and one or more library dependencies of the container image, the behavior model being a graph data structure having a set of nodes, and a set of edges, wherein a node represents one of: a process, a file and a network socket, and wherein an edge represents a system call made by at least one process represented in the graph data structure;

as the container image executes in the container, receive system call telemetry;

responsive to receipt of the telemetry, determine whether the container image is executing in a manner inconsistent with the behavior model, thereby indicating an anomaly; and

upon a determination that the container image is executing in a manner inconsistent with the behavior model, take an automated action to attempt to address the anomaly.

18. The computer program product as described in claim 17 wherein the computer program code is further configured to generate the behavior model for the container image by identifying the library dependencies.

19. The computer program product as described in claim 18 wherein the behavior model is generated by a binary analysis that determines what library functions a given binary calls.

20. The computer program product as described in claim 19 wherein the binary analysis determines what library functions a given binary calls by examining an inter-procedural call graph and finding a set of system calls reachable from the call graph.

21. The computer program product as described in claim 18 wherein the binary analysis generates the behavior model by micro-executing code reachable from an entrypoint of the container image.

22. The computer program product as described in claim 17 wherein the behavior model is instantiated in a hardware node in a Container Orchestration Engine (COE), and wherein the container image executes as a micro-service.

23. The computer program product as described in claim 22 , wherein the program code is further configured to enrich the behavior model based on information representing one or more valid system calls seen by one or more other containers running on the hardware node.

24. The computer program product as described in claim 17 , wherein the program code configured to determine whether the container image is executing in a manner inconsistent with the behavior model executes continuously and the automated action is one of: mitigation, notification, sandboxing and logging.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2020
From: ARAUJO, FREDERICO; TAYLOR, TERYL PAUL; JANG, JIYONG; BLAIR, WILL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 054060/0619 →
Continuity (1)
Related Publication 20220121741A1 · Apr 21, 2022
Cited By (111)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,608,485 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896 US 12,726,495 US 12,730,899 US 12,739,266 US 12,739,267 US 12,743,523 US 12,744,799 US 12,744,800 US 12,744,802 US 12,750,382 US 12,750,383