Containers are widely embraced in the era of cloud computing due to their lightweight, flexible, and easy-to-deploy nature. Nevertheless, their shared kernel characteristics render them susceptible to potential security risks. This paper proposes an anomaly detection method for containers based on system call sequences, employing the attention mechanism and convolutional neural networks. The method utilizes data generated by running container processes to detect anomalies in process behavior. It was validated using publicly available datasets and real-world attack data. The results demonstrate the method’s capability to detect anomalies in the behavior of in-container processes, outperforming comparative methods such as Random Forest and LSTM in metrics such as precision and accuracy.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Unsupervised Anomaly Detection for Container via Attention Mechanisms and Convolutional Neural Networks

  • Zekun Yuan,
  • Wei Li

摘要

Containers are widely embraced in the era of cloud computing due to their lightweight, flexible, and easy-to-deploy nature. Nevertheless, their shared kernel characteristics render them susceptible to potential security risks. This paper proposes an anomaly detection method for containers based on system call sequences, employing the attention mechanism and convolutional neural networks. The method utilizes data generated by running container processes to detect anomalies in process behavior. It was validated using publicly available datasets and real-world attack data. The results demonstrate the method’s capability to detect anomalies in the behavior of in-container processes, outperforming comparative methods such as Random Forest and LSTM in metrics such as precision and accuracy.