IP Library Granted Patent US 12,367,278
Granted Patent B2
US 12,367,278 · App. 17/815,231 · Granted Jul 22, 2025

Multi-tenant security

Inventors: Tyler Lisowski (Austin, TX); Spencer Thomas Reynolds (Austin, TX); Francisco Javier Rodriguez (Austin, TX); Kodie Glosser (Austin, TX); Dennis Warne (Pflugerville, TX); Lloyd Wellington Mascarenhas (White Plains, NY); Matthias Seul (Pleasant Hill, CA)
Assignee: International Business Machines Corporation
G06F21/554G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,278
App. No.
17/815,231
Granted
Jul 22, 2025
Kind
B2
Abstract

Described are techniques for multi-tenant security. The techniques include detecting malicious activity on a compromised application in a multi-tenant host. The techniques further include automatically performing a live migration of each tenant of the multi-tenant host to a respective single-tenant host. The techniques further include mitigating the malicious activity on the compromised application that is migrated to a single-tenant host, and automatically performing another live migration of each benign tenant to a new multi-tenant host.

Claims (60)

1. A computer-implemented method comprising:

detecting malicious activity on a compromised application in a multi-tenant host;

automatically performing a pre-copy memory migration of each tenant of the multi-tenant host to a respective single-tenant host, wherein the pre-copy memory migration re-copies changed memory pages until a rate of re-copied pages exceeds a rate of the changed memory pages;

mitigating the malicious activity on the compromised application that is migrated to a single-tenant host; and

automatically performing another pre-copy memory migration of each benign tenant to a new multi-tenant host.

2. The method of claim 1 , wherein the multi-tenant host comprises a plurality of virtual machines hosted on one or more shared servers, and wherein each respective single-tenant host comprises a dedicated server for a tenant associated with the respective single-tenant host.

3. The method of claim 1 , wherein the malicious activity is detected using a hash of a logged event sequence.

4. The method of claim 1 , wherein the malicious activity is detected using a machine learning model.

5. The method of claim 4 , wherein the method further comprises:

transmitting a notification based on the malicious activity to a cybersecurity administrator; and

updating parameters associated with the machine learning model based on feedback provided by the cybersecurity administrator.

6. The method of claim 1 , further comprising:

archiving activity logs of the compromised application and benign applications running on the multi-tenant host.

7. A system comprising:

one or more computer readable storage media storing program instructions; and

one or more processors which, in response to executing the program instructions, are configured to perform a method comprising:

detecting malicious activity on a compromised application in a multi-tenant host;

automatically performing a pre-copy memory migration of each tenant of the multi-tenant host to a respective single-tenant host, wherein the pre-copy memory migration re-copies changed memory pages until a rate of re-copied pages exceeds a rate of the changed memory pages;

mitigating the malicious activity on the compromised application that is migrated to a single-tenant host; and

automatically performing another pre-copy memory migration of each benign tenant to a new multi-tenant host.

8. The system of claim 7 , wherein the multi-tenant host comprises a plurality of virtual machines hosted on one or more shared servers, and wherein each respective single-tenant host comprises a dedicated server for a tenant associated with the respective single-tenant host.

9. The system of claim 7 , wherein the malicious activity is detected using a hash of a logged event sequence.

10. The system of claim 7 , wherein the malicious activity is detected using a machine learning model.

11. The system of claim 10 , wherein the method further comprises:

transmitting a notification based on the malicious activity to a cybersecurity administrator; and

updating parameters associated with the machine learning model based on feedback provided by the cybersecurity administrator.

12. The system of claim 7 , further comprising:

archiving activity logs of the compromised application and benign applications running on the multi-tenant host.

13. A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising instructions configured to cause one or more processors to perform a method comprising:

detecting malicious activity on a compromised application in a multi-tenant host;

automatically performing a post-copy memory migration of each tenant of the multi-tenant host to a respective single-tenant host;

mitigating the malicious activity on the compromised application that is migrated to a single-tenant host; and

automatically performing another post-copy memory migration of each benign tenant to a new multi-tenant host.

14. The computer program product of claim 13 , wherein the multi-tenant host comprises a plurality of virtual machines hosted on one or more shared servers, and wherein each respective single-tenant host comprises a dedicated server for a tenant associated with the respective single-tenant host.

15. The computer program product of claim 13 , wherein the malicious activity is detected using a hash of a logged event sequence.

16. The computer program product of claim 13 , wherein the malicious activity is detected using a machine learning model.

17. The computer program product of claim 16 , wherein the method further comprises:

transmitting a notification based on the malicious activity to a cybersecurity administrator; and

updating parameters associated with the machine learning model based on feedback provided by the cybersecurity administrator.

18. The computer program product of claim 13 , further comprising:

archiving activity logs of the compromised application and benign applications running on the multi-tenant host.

19. A computer-implemented method comprising:

detecting an unauthorized clone of a first tenant in a multi-tenant host;

automatically isolating tenants of the multi-tenant host in a sandbox container;

determining, based on spot images snapshots of the first tenant, a secure image corresponding to the first tenant;

reimaging, using the secure image, the first tenant on a new multi-tenant system;

verifying a security of each tenant in the sandbox container; and

in response to verifying the security of each tenant in the sandbox container, migrating each tenant from the sandbox container to the new multi-tenant host.

20. The method of claim 19 , wherein the sandbox container comprises restricted permissions and continued availability for workloads associated with each tenant of the multi-tenant host.

21. The method of claim 19 , wherein the unauthorized clone is detected using a spot image based on a previous snapshot of the first tenant and a current snapshot of the first tenant.

22. The method of claim 19 , wherein the unauthorized clone is detected using a machine learning clone detection model.

23. A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising instructions configured to cause one or more processors to perform a method comprising:

detecting an unauthorized clone of a first tenant in a multi-tenant host;

automatically isolating tenants of the multi-tenant host in a sandbox container;

determining, based on spot images snapshots of the first tenant, a secure image corresponding to the first tenant;

reimaging, using the secure image, the first tenant on a new multi-tenant system;

verifying a security of each tenant in the sandbox container; and

in response to verifying the security of each tenant in the sandbox container, migrating each tenant from the sandbox container to the new multi-tenant host.

24. The computer program product of claim 23 , wherein the sandbox container comprises restricted permissions and continued availability for workloads associated with each tenant of the multi-tenant host.

25. The computer program product of claim 23 , wherein the unauthorized clone is detected using a spot image based on a previous snapshot of the first tenant and a current snapshot of the first tenant.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2022
From: LISOWSKI, TYLER; REYNOLDS, SPENCER THOMAS; RODRIGUEZ, FRANCISCO JAVIER; GLOSSER, KODIE; WARNE, DENNIS; MASCARENHAS, LLOYD WELLINGTON; SEUL, MATTHIAS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060635/0590 →
Continuity (1)
Related Publication 20240037226A1 · Feb 1, 2024
References Cited (28)
US 8620876B2 · Chan et al. · 2013 [cited by applicant]
US 9411964B1 · Moritz · 2016 [cited by applicant]
US 9471353B1 · Christopher · 2016 [cited by applicant]
US 9678774B2 · Khesin · 2017 [cited by applicant]
US 9779240B2 · Feroz · 2017 [cited by applicant]
US 9935971B2 · Hamilton, II · 2018 [cited by applicant]
US 10333981B2 · Lee · 2019 [cited by applicant]
US 10706144B1 · Moritz · 2020 [cited by applicant]
US 10768965B1 · Habusha · 2020 [cited by examiner]
US 10938837B2 · Kumar · 2021 [cited by applicant]
US 11140553B1 · Taylor · 2021 [cited by examiner]
US 11233804B2 · Arzani · 2022 [cited by applicant]
US 20150052520A1 · Crowell · 2015 [cited by applicant]
US 20160359914A1 · Deen · 2016 [cited by examiner]
US 20170104718A1 · Folco · 2017 [cited by applicant]
US 20210320950A1 · Li · 2021 [cited by applicant]
US 20220121741A1 · Araujo · 2022 [cited by examiner]
US 20220179991A1 · Jha · 2022 [cited by applicant]
US 20220191247A1 · Dhoble · 2022 [cited by examiner]
CN 106469083B · 2021 [cited by applicant]
EP 2663948A · 2013 [cited by applicant]
WO 2021236378A1 · 2021 [cited by applicant]
Business Wire, “Global Cloud Security Market (2021 to 2026)—by Application, Security Type, Service Model, Deployment, Organization Size, Industry Vertical and Geography—ResearchAndMarkets.com”, Aug. 5, 2021, 3 PGS, <htt… [cited by applicant]
IBM, “IBM Cloud Kubernetes Service”, 9 PGS, Accessed on May 10, 2022, <htps://www.ibm.com/cloud/kubernetes-service>. [cited by applicant]
Kocher et al., “Spectre Attacks” Exploiting Speculative Execution, 19 PGS, Access on May 10, 2022. [cited by applicant]
SelfKey identify Wallet, “All Data Breaches in 2019-2021—An Alarming Timeline”, Apr. 7, 2021, 23 PGS, <https://selfkey.org/data-breaches-in-2019/>. [cited by applicant]
Wikipedia, “Zero-Day (Computing)”, 8 PGS, Access May 10, 2022, <https://en.wikipedia.org/wiki/Zero-day_(computing)>. [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration for Application PCT/IB2023/056606, Oct. 6, 2023, 12 pages. [cited by applicant]
Cited By (1)
US 12,688,288