- 专利标题: SECURITY RISK-AWARE SCHEDULING ON CONTAINER-BASED CLOUDS
-
申请号: US17340145申请日: 2021-06-07
-
公开(公告)号: US20220391532A1公开(公告)日: 2022-12-08
- 发明人: Michael Vu Le , Md Salman Ahmed , Hani Talal Jamjoom
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F21/62
- IPC分类号: G06F21/62 ; G06F21/57 ; G06F9/48 ; G06F9/455
摘要:
A method, apparatus and computer program product for scheduling placement of containers in association with a set of hosts. The technique utilizes metrics that characterize container-specific risks. A first metric is a host interface risk for a container that quantifies how similar or dissimilar the container is relative to other containers running on a host. Preferably, host interface risk is derived with respect to a system call interface comprising a set of system calls, and the metric is based at least in part on a measure of dissimilarity among system calls. A second metric is a data sensitivity score that quantifies a degree to which sensitive data accesses are associated to the container. Based at least in part on the host interface risk scores and the data sensitivity scores, one or more containers are automatically scheduled for placement on the set of hosts to minimize security risk for the set of hosts.
公开/授权文献
- US11921885B2 Security risk-aware scheduling on container-based clouds 公开/授权日:2024-03-05
信息查询