International Business Machines Corporation
INTRUSION DETECTION IN MICRO-SERVICES THROUGH CONTAINER TELEMETRY AND BEHAVIOR MODELING

Last updated:

Abstract:

An intrusion detection system (IDS) for a micro-services environment identifies attacks in substantially real-time and at a container-level. In this approach, behavior models are generated from container images using a binary analysis. A behavior model is a graph data structure having nodes and edges, wherein an edge represents a system call made by at least one process represented as a node in the graph data structure. The model is co-located with a running container, thereby enabling detection of anomalies as the container executes in a container environment on a hardware node. A per-container IDS function is instantiated by checking whether system call telemetry generated by an image's running container satisfies the associated behavior model that has been generated for the container image. If the telemetry indicates activity that deviates from the behavior model, an automated action is then initiated to attempt to address the attack, preferably while it is in progress.

Status:
Application
Type:

Utility

Filling date:

15 Oct 2020

Issue date:

21 Apr 2022