首页> 外文会议>IEEE International Conference on Big Data >Highly-Scalable Container Integrity Monitoring for Large-Scale Kubernetes Cluster
【24h】

Highly-Scalable Container Integrity Monitoring for Large-Scale Kubernetes Cluster

机译:大型Kubernetes集群的高度可扩展容器完整性监控

获取原文

摘要

Container integrity monitoring is defined as key requirements for regulatory compliance, such as PCI-DSS, in which any unexpected changes such as file updates or program runs must be logged for later audit. Syscall monitoring provides comprehensive monitoring of such change events on container, while it suffered from large amount of false alarms unless well-defined allowlist rules are coordinated before deploying container. Defining such comprehensive allowlist is not feasible especially when managing various kinds of application workloads in large-scale enterprise cluster. We propose new approach for identifying real anomaly of syscall events effectively without relying on any predefined allowlist configuration in this paper. Our novel filtering algorithm based on the knowledge acquired autonomously from Kubernetes cluster control plane reduces 99.999 % noise effectively and distilling only abnormal events in real time. Our experiment with real applications on more than 4000 containers demonstrates its effectiveness even on large-scale cluster.
机译:容器完整性监控被定义为法规遵从性的关键要求,例如PCI-DSS,其中必须记录任何意外更改,例如文件更新或程序运行以供以后审核。 Syscall Monitoring在容器上进行全面监控该更改事件,而在部署容器之前协调齐全的AllowList规则,则遭受大量误报。定义如此全面的允许列表是不可行的,特别是在大规模企业集群中管理各种应用程序工作负载时。我们提出了新方法,用于有效地识别Syscall事件的真正异常,而无需依赖本文中的任何预定义的arwarlist配置。我们基于从Kubernetes群集控制平面获取的知识的新型过滤算法在实时降低了99.999%的噪音,实时才能蒸馏异常事件。我们对4000多个集装箱的实际应用的实验即使在大规模集群上也表现出其有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号