US 11,811,804 B1
System and method for detecting process anomalies in a distributed computation system utilizing containers
Joseph Altmaier, Mountain View, CA (US); Hillary Benson, Mountain View, CA (US); Robert A. Cochran, Mountain View, CA (US); Connor Gorman, Mountain View, CA (US); and Viswajith Venugopal, Mountain View, CA (US)
Assigned to Red Hat, Inc., Raleigh, NC (US)
Filed by Red Hat, Inc., Raleigh, NC (US)
Filed on Dec. 15, 2020, as Appl. No. 17/122,808.
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) [H04L 63/1416 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A server, comprising:
a processor; and
a memory connected to the processor, the memory storing instructions executed by the processor to:
collect operating signals from machines, wherein the operating signals characterize processes running in containers and each operating signal includes a process lineage and an executed file path for a process running in a container,
ascribe a container lifecycle phase to the processes, wherein the container lifecycle phase is characterized as one of container startup, container steady state and container shutdown,
identify a process anomaly when a process running in a container during the container lifecycle phase deviates from a baseline for the container during the container lifecycle phase, wherein the process anomaly corresponds to the process, and
present, on a display device, a user interface that lists processes running in the container and identifies the process anomaly.