CNIPA.AI
검색으로 돌아가기
기록

METHOD, DEVICE, AND STORAGE MEDIUM FOR DETECTING INTRUSION OF CONTAINER ENVIRONMENT

발명심사 중
21청구항 · 4 독립항
§ Ⅰ

개요

발명자

Chen ZHANG; Jianxin GUO

IPC 분류

G6F 21/55G6F 9/455G6F 18/243

CPC 분류

G6F21/554G6F9/45558G6F18/24323G6F2009/45587

A method, a device and a storage medium for detecting intrusion of a container environment. The method includes: performing event recognition on a real-time system event by calling an event recognition model corresponding to the target container, where the event recognition model is constructed based on a historical normal system event of the target container; in response to determining that the real-time system event is an abnormal system event, calling a predetermined intrusion detection rule to perform intrusion detection on the real-time system event, to determine whether the real-time system event is an intrusion event. Thus, a real-time system event that belongs to a normal system event may be filtered out, and a complete intrusion detection may be performed on the abnormal system event, thereby reducing the amount of data for intrusion detection, reducing resource occupation, and improving the performance and efficiency of the intrusion detection.

원문 (중국어)

A method, a device and a storage medium for detecting intrusion of a container environment. The method includes: performing event recognition on a real-time system event by calling an event recognition model corresponding to the target container, where the event recognition model is constructed based on a historical normal system event of the target container; in response to determining that the real-time system event is an abnormal system event, calling a predetermined intrusion detection rule to perform intrusion detection on the real-time system event, to determine whether the real-time system event is an intrusion event. Thus, a real-time system event that belongs to a normal system event may be filtered out, and a complete intrusion detection may be performed on the abnormal system event, thereby reducing the amount of data for intrusion detection, reducing resource occupation, and improving the performance and efficiency of the intrusion detection.