Key points are not available for this paper at this time.
This article discusses the problem of ensuring security in container systems, which is due to the rapid growth in the use of containerization technologies and microservice architectures in modern high-load computing systems. The increasing number of threats and vulnerabilities to microservice systems undermines the credibility of such systems and containerization technologies in general. To detect anomalies in container systems, the authors proposed a technique and developed a software prototype for detecting abnormal, previously unknown processes. The proposed solution is based on tracing system calls and building histograms of running processes, which serves as input data for the neural network model - an autoencoder. Currently, the task of marking up data (both normal, abnormal and malicious) is a time-consuming process that requires a lot of time and detailed data analysis. The article describes in detail the process of data collection and normalization, as well as the architecture and learning process of the model. Special attention is paid to the experimental verification of the proposed solution on real data. The experimental results demonstrate a sufficiently high accuracy in detecting previously unknown abnormal processes with a low level of false positives, which confirms the effectiveness of the proposed approach. It is also necessary to highlight the extremely low ability of the approach to detect some malicious processes, since these processes do not differ from legitimate ones.
Kotenko et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: