検索に戻る
案件記録

METHOD, DEVICE, AND STORAGE MEDIUM FOR DETECTING INTRUSION OF CONTAINER ENVIRONMENT

発明審査中
2閲覧数
21請求項 · 4 独立
§ Ⅰ

案件概要

発明者

Chen ZHANG; Jianxin GUO

IPC分類

G6F 21/55G6F 9/455G6F 18/243

CPC分類

G6F21/554G6F9/45558G6F18/24323G6F2009/45587

A method, a device and a storage medium for detecting intrusion of a container environment. The method includes: performing event recognition on a real-time system event by calling an event recognition model corresponding to the target container, where the event recognition model is constructed based on a historical normal system event of the target container; in response to determining that the real-time system event is an abnormal system event, calling a predetermined intrusion detection rule to perform intrusion detection on the real-time system event, to determine whether the real-time system event is an intrusion event. Thus, a real-time system event that belongs to a normal system event may be filtered out, and a complete intrusion detection may be performed on the abnormal system event, thereby reducing the amount of data for intrusion detection, reducing resource occupation, and improving the performance and efficiency of the intrusion detection.

原文(中国語)

A method, a device and a storage medium for detecting intrusion of a container environment. The method includes: performing event recognition on a real-time system event by calling an event recognition model corresponding to the target container, where the event recognition model is constructed based on a historical normal system event of the target container; in response to determining that the real-time system event is an abnormal system event, calling a predetermined intrusion detection rule to perform intrusion detection on the real-time system event, to determine whether the real-time system event is an intrusion event. Thus, a real-time system event that belongs to a normal system event may be filtered out, and a complete intrusion detection may be performed on the abnormal system event, thereby reducing the amount of data for intrusion detection, reducing resource occupation, and improving the performance and efficiency of the intrusion detection.

外部リソース