Invention Grant
- Patent Title: Security risk-aware scheduling on container-based clouds
-
Application No.: US17340145Application Date: 2021-06-07
-
Publication No.: US11921885B2Publication Date: 2024-03-05
- Inventor: Michael Vu Le , Md Salman Ahmed , Hani Talal Jamjoom
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Stosch Sabo
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F9/455 ; G06F9/48 ; G06F21/57 ; G06F21/62

Abstract:
A method, apparatus and computer program product for scheduling placement of containers in association with a set of hosts. The technique utilizes metrics that characterize container-specific risks. A first metric is a host interface risk for a container that quantifies how similar or dissimilar the container is relative to other containers running on a host. Preferably, host interface risk is derived with respect to a system call interface comprising a set of system calls, and the metric is based at least in part on a measure of dissimilarity among system calls. A second metric is a data sensitivity score that quantifies a degree to which sensitive data accesses are associated to the container. Based at least in part on the host interface risk scores and the data sensitivity scores, one or more containers are automatically scheduled for placement on the set of hosts to minimize security risk for the set of hosts.
Public/Granted literature
- US20220391532A1 SECURITY RISK-AWARE SCHEDULING ON CONTAINER-BASED CLOUDS Public/Granted day:2022-12-08
Information query