IP Library › Granted Patent US 12,554,842
Granted Patent B2
US 12,554,842 · App. 17/809,586 · Granted Feb 17, 2026

Malware detection in containerized environments

Inventors: Boris Rozenberg (Ramat Gan, IL); Yehoshua Sagron (Haifa, IL); Lev Greenberg (Haifa, IL)
Assignee: International Business Machines Corporation
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,842
App. No.
17/809,586
Filed
Jun 29, 2022
Granted
Feb 17, 2026
Kind
B2
Examiner
LIU, ZHE
Art Unit
2493
USPC
726/23
Abstract

A method, computer system, and a computer program for malware detection in containerized environments are provided. The method may include monitoring operation of a container image by receiving a plurality of system calls performed during the operation of the container image. The method further includes comparing the plurality of system calls to prior container behavior associated with previous operation of a prior container image, and identifying a deviation from the prior container behavior. The method further includes isolating a subset of the plurality of system calls and classifying the subset to a malware class of a plurality of malware classes.

Claims (88)

1 . A computer-implemented method of malware detection in containerized environments, the method comprising:

monitoring, via a computing device, operation of a container image, the

monitoring comprising receiving a plurality of system calls performed during the operation of the container image by accessing a plurality of file and process paths;

compressing offline, via the computing device, the plurality of file and process paths into a profile based on a plurality of predefined parameters representing a plurality of malware classes;

comparing, via the computing device, the plurality of system calls to prior container behavior associated with previous operation of a prior container image;

identifying, via the computing device, a deviation from the prior container behavior; and

in response to identifying the deviation, isolating, via the computing device, a subset of the plurality of system calls and classifying the subset to a malware class of the plurality of malware classes;

wherein isolating the subset comprises a tree-structure analysis of the subset to detect a spawned malware based on an associate anomaly that is not a previously detected system call of the plurality of system calls performed during the operation of the container image and wherein the tree-structure analysis further comprises:

filtering the benign file and process paths of the plurality of file and process paths; and

aggregating the spawned malware into a deviation vector.

2 . The computer-implemented method of claim 1 , further comprising:

in response to identifying a confidence level included in the plurality of malware classes exceeding a pre-determined threshold, generating, via the computing device, an alert to notify of potential malware and at least one malware class of the plurality of malware classes.

3 . The computer-implemented method of claim 1 , wherein comparing the plurality of system calls comprising:

extracting, via the computing device, a plurality of malware-related features; wherein extracting the plurality of malware-related features comprises:

compressing, via the computing device, the plurality of system calls into the profile; and

filtering, via the computing device, the plurality of system calls for instances of malware based on the profile.

4 . The computer-implemented method of claim 3 , wherein extracting the plurality of malware-related features comprises:

generating, via the computing device, a malware vector including the plurality of malware-related features;

wherein the vector is compared to the prior container behavior.

5 . The computer-implemented method of claim 1 , wherein isolating the subset of the plurality of system calls comprises:

identifying, via the computing device, a plurality of processes relevant to the deviation;

selecting, via the computing device, a plurality of deviation related features derived from operations of the plurality of processes; and

transmitting, via the computing device, the deviation vector including the plurality of deviation related features to a classification model.

6 . The computer-implemented method of claim 5 , wherein classifying the subset of the plurality of system calls further comprises:

assigning, via the classification model, the deviation vector to at least one malware class of the plurality of malware classes; and

receiving, via the computing device, a confidence level associated with the deviation vector as an output of the classification model.

7 . The computer-implemented method of claim 1 , wherein prior container behavior comprises:

recording, via the computing device, operations of the container image based on a plurality of malware-related features for a period of time;

wherein the period of time terminates based on a determination, via the computing device, of a lack of new operations.

8 . A computer program product using a computing device for malware detection in containerized environments, comprising:

one or more non-transitory computer-readable storage media and program instructions stored on the one or more non-transitory computer-readable storage media, the program instructions, when executed by the computing device, cause the computing device to perform a method comprising:

monitoring operation of a container image, the

monitoring comprising receiving a plurality of system calls performed during the operation of the container image by accessing a plurality of file and process paths;

compressing offline the plurality of file and process paths into a profile based on a plurality of predefined parameters representing a plurality of malware classes;

comparing the plurality of system calls to prior container behavior associated with previous operation of a prior container image;

identifying a deviation from the prior container behavior; and

in response to identifying the deviation, isolating a

subset of the plurality of system calls and classifying the subset to a malware class of the plurality of malware classes;

wherein isolating the subset comprises a tree-structure analysis of the subset to detect a spawned malware based on an associate anomaly that is not a previously detected system call of the plurality of system calls performed during the operation of the container image and wherein the tree-structure analysis further comprises:

filtering the benign file and process paths of the plurality of file and process paths; and

aggregating the spawned malware into a deviation vector.

9 . The computer program product of claim 8 , comprising instructions to further cause the computing device to perform a method comprising:

in response to identifying, a confidence level included in the plurality of malware classes exceeding a pre-determined threshold, generating an alert to notify of potential malware and at least one malware class of the plurality of malware classes.

10 . The computer program product of claim 9 , wherein comparing the plurality of system calls comprises instructions to further cause the computing device to perform:

extracting a plurality of malware-related features;

wherein extracting the plurality of malware-related features comprises:

compressing the plurality of system calls into the profile; and

filtering the plurality of system calls for instances of malware based on the profile.

11 . The computer program product of claim 10 , wherein extracting the plurality of malware related features comprises instructions to further cause the computing device to perform:

generating a malware vector including the plurality of malware-related features;

wherein the vector is compared to the prior container behavior.

12 . The computer program product of claim 10 , wherein isolating the subset of the plurality of system calls comprises instructions to further cause the computing device to perform:

identifying a plurality of processes relevant to the deviation;

selecting a plurality of deviation related features derived from operations of the plurality of processes; and

transmitting the deviation vector including the plurality of deviation related features to a classification model.

13 . The computer program product of claim 12 , wherein classifying the subset of the plurality of system calls comprises instructions to further cause the computing device to perform:

assigning, via the classification model, the deviation vector to at least one malware class of the plurality of malware classes; and

receiving, via the computing device, the confidence level associated with the deviation vector as an output of the classification model.

14 . The computer program product of claim 10 , wherein prior container behavior comprises instructions to further cause the computing device to perform:

recording operations of the container image based on the plurality of malware-related features for a period of time;

wherein the period of time terminates based on a determination of a lack of new operations.

15 . A system for malware detection in containerized environments, said system comprising:

a computer system comprising, a processor, a computer readable storage medium, and program instructions stored on the computer readable storage medium being executable by the processor to cause the computer system to:

program instructions to monitor operation of a container image, the monitoring comprising receiving a plurality of system calls performed during the operation of the container image by accessing a plurality of file and process paths;

program instructions to compress offline the plurality of file and process paths into a profile based on a plurality of predefined parameters representing a plurality of malware classes;

program instructions to compare the plurality of system calls to prior container behavior associated with previous operation of a prior container image;

program instructions to identify a deviation from the prior container behavior; and

program instructions to in response to identifying the deviation, isolate a subset of the plurality of system calls and classifying the subset to a malware class of the plurality of malware classes;

wherein program instructions to isolate the subset comprises a tree-structure analysis of the subset to detect a spawned malware based on an associate anomaly that is not a previously detected system call of the plurality of system calls performed during the operation of the container image and wherein the tree-structure analysis further comprises:

program instructions to filter the benign file and process paths of the plurality of file and process paths; and

program instructions to aggregate the spawned malware into a deviation vector.

16 . The system of claim 15 , further comprising:

in response to identifying a confidence level included in the plurality of malware classes exceeding a pre-determined threshold, program instructions to generate an alert to notify of potential malware and at least one malware class of the plurality of malware classes.

17 . The system of claim 15 , wherein the program instructions to compare the plurality of system calls comprises:

program instructions to extract a plurality of malware-related features;

wherein program instructions to extract the plurality of malware-related features comprises:

program instructions to compress the plurality of system calls into the profile; and

program instructions to filter the plurality of system calls for instances of malware based on the profile.

18 . The system of claim 17 , wherein the program instructions to extract the plurality of malware-related features comprises:

program instruction to generate a malware vector including the plurality of malware-related features;

wherein the vector is compared to the prior container behavior.

19 . The system of claim 17 , wherein prior container behavior comprises:

program instructions to record operations of the container image based on the plurality of malware-related features for a period of time;

wherein the period of time terminates based on a determination of a lack of new operations.

20 . The system of claim 15 , wherein the program instructions to isolate the subset of the plurality of system calls comprises:

program instructions to identify a plurality of processes relevant to the deviation;

program instructions to select a plurality of deviation related features derived from operations of the plurality of processes; and

program instructions to transmit the deviation vector including the plurality of deviation related features to a classification model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2022
From: ROZENBERG, BORIS; SAGRON, YEHOSHUA; GREENBERG, LEV
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060349/0927 →
Continuity (1)
Related Publication 20240004993A1 · Jan 4, 2024
References Cited (27)
US 7069594B1 · Bolin · 2006 [cited by examiner]
US 8375450B1 · Oliver · 2013 [cited by examiner]
US 9794287B1 · Koster · 2017 [cited by applicant]
US 10397255B1 · Bhalotra · 2019 [cited by examiner]
US 10607011B1 · Orhan · 2020 [cited by examiner]
US 20150295945A1 · Canzanese, Jr. · 2015 [cited by examiner]
US 20160173516A1 · Raugas · 2016 [cited by examiner]
US 20170063890A1 · Muddu · 2017 [cited by applicant]
US 20170251003A1 · Rostami-Hesarsorkh · 2017 [cited by examiner]
US 20170262633A1 · Miserendino · 2017 [cited by applicant]
US 20190163901A1 · Tien · 2019 [cited by examiner]
US 20200162483A1 · Farhady · 2020 [cited by examiner]
US 20200193016A1 · Zeng · 2020 [cited by examiner]
US 20200296117A1 · Karpovsky · 2020 [cited by examiner]
US 20210105613A1 · San Miguel · 2021 [cited by examiner]
US 20210117544A1 · Kurtz · 2021 [cited by examiner]
US 20210263779A1 · Haghighat · 2021 [cited by examiner]
US 20220129551A1 · Collier · 2022 [cited by examiner]
US 20220292196A1 · Bhagi · 2022 [cited by examiner]
US 20230028394A1 · El-Moussa · 2023 [cited by examiner]
US 20230090689A1 · Knierim · 2023 [cited by examiner]
US 20230105087A1 · Borges · 2023 [cited by examiner]
US 20230124166A1 · Mohanty · 2023 [cited by examiner]
CN 112905421A · 2021 [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, pp. 1-7. [cited by applicant]
Tunde-Onadele, “A Study on Container Vulnerability Exploit Detection,” 2019 IEEE International Conference on Cloud Engineering (IC2E), IEEE Xplore, pp. 121-126, <https://ieeexplore.ieee.org/search/searchresult.jsp?newse… [cited by applicant]
Zhang, et al., “A Real-time Intrusion Detection System Based on OC-SVM for Containerized Applications,” 2021 IEEE 24th International Conference on Computational Science and Engineering (CSE 2021), IEEE Xplore, pp. 138-1… [cited by applicant]