Container Anomaly Detection System Based on Improved-iForest and eBPF
Rattachement africain : cn. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Abstract: Container has become an important part of cloud-native architecture. More and more enterprises are deploying their core business on containers. The running status of containers is very important for the stability of their business. This paper proposes a container anomaly detection system based on the improved isolation forest algorithm and eBPF. The data is directly extracted from the kernel through eBPF, and the data fluctuating with time is corrected by the method of polynomial regression, and then the iTrees are constructed by the improved isolation forest algorithm, and the abnormal score is calculated to locate the abnormal container. Experiments show that the system improves the precision and recall rate compared with the classical isolation forest algorithm, and the resource overhead is very small.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Container Anomaly Detection System Based on Improved-iForest and eBPF
- Date Crossref
- 23/09/2022
- Éditeur
- ACM
- Type
- proceedings-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Les institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.