Program running method and device, equipment, medium and program product

By generating and configuring security data in container technology, the complexity and resource overhead of building an isolated environment separately are solved, and the security verification efficiency of program containers is improved.

CN120610772APending Publication Date: 2025-09-09TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410264254.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

In container technology, it is difficult to build an isolated environment independently, which leads to high complexity in application management and increased resource overhead. In addition, existing technologies make it difficult to effectively improve the security verification efficiency of program containers.

Method used

By obtaining the attribute data in the image file, generating the second attribute data under security conditions, and configuring it into the image file, the original attribute data is replaced with the self-built security data, avoiding the construction of a separate isolation environment and ensuring the safe operation of the program container.

Benefits of technology

It reduces the overhead of computing resources and improves the efficiency of program security verification, ensuring that the program container runs normally under safe conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120610772A_ABST
    Figure CN120610772A_ABST
Patent Text Reader

Abstract

The invention discloses a program running method and device, equipment, a medium and a program product, and relates to the technical field of computers. The method comprises the following steps: acquiring a mirror image file corresponding to a first application program; performing data analysis on the mirror image file to obtain attribute data used for indicating the program container in the running process in the mirror image file; generating second attribute data corresponding to the first attribute data based on the attribute data; and configuring the second attribute data into the mirror image file, and running the program container based on the second attribute data to obtain a container running result. Namely, a mode of replacing the original attribute data with the autonomously constructed security data avoids constructing an independent isolation environment to run the program container, so that the overhead of computing resources is reduced while the safe operation of the program container is ensured, and the verification efficiency of the program security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and in particular to a program execution method, apparatus, device, medium, and program product. Background Art

[0002] Container technology (Docker) refers to placing the running data corresponding to an application in a container for execution. After building an image file, the corresponding container process is run by loading the image file, thereby running the application in the program container and realizing program management of the application.

[0003] In related technologies, when an image file contains risky content that may cause aggressive behavior against a server, an independent network stack is usually configured for the image file corresponding to the program container to isolate it from other containers, thereby establishing an independent isolation environment for running the program container independently.

[0004] However, it is difficult to build an isolated environment alone, which leads to higher complexity in application management and increases the resource overhead of program operation. Summary of the Invention

[0005] The embodiments of the present application provide a program running method, apparatus, device, medium, and program product that not only avoids the need to build a separate isolated environment and reduces resource overhead, but also improves the efficiency of program container security verification. The technical solution is as follows:

[0006] In one aspect, a method for executing a program is provided, the method comprising:

[0007] Obtaining an image file corresponding to a first application, where the image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application in a program container;

[0008] Performing data analysis on the image file to obtain attribute data in the image file for indicating the program container during operation, wherein the attribute data includes first attribute data;

[0009] generating second attribute data corresponding to the first attribute data, where the second attribute data is used to simulate running the program container under a safe condition according to the first attribute data;

[0010] The second attribute data is configured into the image file, and the program container is run based on the second attribute data to obtain a container running result, where the container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

[0011] In another aspect, a program execution device is provided, the device comprising:

[0012] an acquisition module, configured to acquire an image file corresponding to a first application, wherein the image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application in a program container;

[0013] an analysis module, configured to perform data analysis on the image file to obtain attribute data in the image file for indicating the program container during operation, wherein the attribute data includes first attribute data;

[0014] a generating module, configured to generate second attribute data corresponding to the first attribute data, wherein the second attribute data is used to simulate the first attribute data and run the program container under a safe condition;

[0015] A running module is used to configure the second attribute data into the image file, and run the program container based on the second attribute data to obtain a container running result, wherein the container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

[0016] On the other hand, a computer device is provided, comprising a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement a program running method as described in any of the above-mentioned embodiments of the present application.

[0017] On the other hand, a computer-readable storage medium is provided, wherein the storage medium stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement a program running method as described in any of the above-mentioned embodiments of the present application.

[0018] In another aspect, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the program execution method described in any of the above embodiments.

[0019] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least:

[0020] Obtain an image file corresponding to a first application, and when the image file includes multiple running data for simulating the running of the first application in a program container, perform data analysis on the image file to obtain attribute data in the image file used to represent the program container during operation, including first attribute data, generate second attribute data corresponding to simulating the running of the program container under safe conditions using the first attribute data, configure the second attribute data into the image file, run the program container according to the second attribute data, obtain a container running result, and obtain the program security after the program container executes the program running path corresponding to the second attribute data based on the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, avoid constructing a separate isolated environment to run the program container, ensure the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 is a schematic diagram of an implementation environment provided by an exemplary embodiment of the present application;

[0023] Figure 2 is a flowchart of a program running method provided by an exemplary embodiment of the present application;

[0024] Figure 3 is a flowchart of a program running method provided by an exemplary embodiment of the present application;

[0025] Figure 4 is a flow chart of a data analysis process provided by an exemplary embodiment of the present application;

[0026] Figure 5 is a flowchart of a program running method provided by an exemplary embodiment of the present application;

[0027] Figure 6 is a flow chart of a method for generating second attribute data provided by an exemplary embodiment of the present application;

[0028] Figure 7 This is a flow chart of a method for generating attribute data with the same name provided by an exemplary embodiment of the present application;

[0029] Figure 8This is a schematic diagram of a program running method provided by an exemplary embodiment of the present application;

[0030] Figure 9 This is an interactive diagram of a program running method provided by an exemplary embodiment of the present application;

[0031] Figure 10 This is a schematic diagram of a method for generating second attribute data provided by an exemplary embodiment of the present application;

[0032] Figure 11 This is a structural block diagram of a program running device provided by an exemplary embodiment of the present application;

[0033] Figure 12 It is a structural block diagram of a computer device provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0034] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0035] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0036] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0037] It should be noted that the information and data involved in this application (including but not limited to the first data packet, the second data packet, account information, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0038] It should be understood that although the terms first, second, etc. may be used in this application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, a first parameter may also be referred to as a second parameter, and similarly, a second parameter may also be referred to as a first parameter. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0039] First, a brief introduction to the terms involved in the embodiments of this application is given:

[0040] Container technology (Docker): is an open source platform for developing, deploying, and running applications. Through containerization technology, the application and its dependent operating environment are packaged into a lightweight, portable, isolated, and secure image file, thereby enabling rapid construction, efficient distribution, and cross-platform operation of the application.

[0041] An image file is a read-only file used to define and run a container. It contains the container's file system and configuration parameters. An image file consists of multiple layers, each corresponding to a file system change. Layers are stacked together using a Union File System to create a complete image file.

[0042] Containers are a lightweight virtualization technology used to run applications. Created from image files, they can perform various operations, such as starting, stopping, and deleting, in an isolated environment. A container consists of a read-only image layer and a writable container layer. The container layer stores the runtime state and data of the container, and changes to the container layer do not affect the image layer.

[0043] An image entrypoint is a parameter that specifies a command or script to run when a container starts. This allows the container to run as an executable program without requiring you to specify the command to run each time. When the container starts, the command specified by the image entrypoint is immediately executed.

[0044] First, the implementation environment involved in the embodiments of this application is described. For schematic illustration, please refer to Figure 1 The implementation environment involves a server 120 , a communication network 140 and a terminal 100 , wherein the terminal 100 and the server 120 are connected via the communication network 140 .

[0045] A container client is running in the terminal 100. By compiling the image file content corresponding to the first application in the container client, the file content corresponding to the compiled image file is sent to the server 120 for running the corresponding program container according to the image file.

[0046] After receiving the file content corresponding to the image file, the server 120 performs data analysis on the image file to obtain attribute data in the image file for indicating the program container during operation, wherein the attribute data includes first attribute data.

[0047] The server 120 generates second attribute data corresponding to the first attribute data based on the attribute data, wherein the second attribute data is used to simulate the first attribute data to run the program container under safe conditions, and configures the second attribute data into the image file, so as to run the program container according to the second attribute data to obtain the container running result, obtain the program security result of the program container according to the container running result, and feed back the program security result to the terminal 100 for display.

[0048] It is worth noting that the above-mentioned terminal can be a mobile phone, tablet computer, desktop computer, portable laptop computer, smart TV, car terminal, smart home device and other terminal devices in various forms, and the embodiments of the present application are not limited to this.

[0049] It is worth noting that the above-mentioned servers can be independent physical servers, or they can be server clusters or distributed systems composed of multiple physical servers. They can also be cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), as well as big data and artificial intelligence platforms.

[0050] Cloud technology refers to a hosting technology that unifies hardware, software, and network resources within a wide area network (WAN) or local area network (LAN) to enable data computing, storage, processing, and sharing. Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, and application technology, all based on the cloud computing business model. It can form a resource pool that can be used on demand with flexibility and convenience. Cloud computing technology will become a crucial support. Backend services for technical network systems, such as video websites, image websites, and more portals, require significant computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identification mark and will need to be transmitted to backend systems for logical processing. Data of varying levels will be processed separately, and data from all industries will require a strong system backend, which can only be achieved through cloud computing.

[0051] In some embodiments, the above-mentioned server can also be implemented as a node in a blockchain system.

[0052] In combination with the above-mentioned noun introduction and application scenarios, the program running method provided by this application is described. The method can be executed by a server or a terminal, or by both a server and a terminal. In the embodiment of this application, the method is described as being executed by a server. Figure 2 As shown, Figure 2 FIG1 is a flowchart of a program running method provided by an exemplary embodiment of the present application. The method includes the following steps.

[0053] Step 210: Obtain the image file corresponding to the first application.

[0054] The image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application in the program container.

[0055] Illustratively, the first application is a pre-developed application.

[0056] Schematically, the image file corresponding to the first application is a file system including static data.

[0057] That is, the image file does not contain any dynamic data or running status information, it is just a static collection of files.

[0058] In some embodiments, the running data refers to data used to run the program container corresponding to the image file, that is, the running process of the program container is realized by executing the running instructions corresponding to the running data.

[0059] Optionally, the running data in the image file includes at least one of the following data contents:

[0060] 1. Application file data: Files required to run the application container, which are packaged into an image file for use by the application container during runtime. The file data includes the binary files, library files, configuration files, etc. of the first application;

[0061] 2. Configuration parameters: These are parameter data configured for the container runtime, including anonymous volumes, user names, etc. Configuration parameters are used when the container is started to configure the behavior and operating environment of the program container;

[0062] An anonymous volume is a volume without an explicitly specified name, which is used to store persistent data of a program container. If the program container is deleted and then recreated, the data stored in the anonymous volume can still be retained and used.

[0063] 3. Attribute data: used to define the runtime configuration and container properties of the program container, including: the name and label of the image file, author, description, creation date, environment variables, commands, etc.

[0064] It is worth noting that the above data content regarding the operating data is only an illustrative example and is not limited to this embodiment of the present application.

[0065] Optionally, a single image file supports running a single program container; or, a single image file supports running multiple different program containers, which is not limited.

[0066] In this embodiment, the image file contains everything needed to run the first application: code, runtime environment, system tools, libraries, and configuration files. The program container is an operating instance launched based on the image file. Therefore, when a program container is launched and run using the image file, the program container creates an operating instance based on the image file. During the program container's operation, it simulates the operation of the first application based on the operating data in the image file. When running multiple program containers using the image file, each program container is implemented as an independently running process, so the program containers are isolated from each other and do not interfere with each other.

[0067] Optionally, the first application corresponds to one or more image files, wherein, if the first application corresponds to multiple image files, the multiple image files correspond to different operating requirements respectively, for example: the first application corresponds to two image files, namely image file a and image file b, image file a is used to run the program container in the basic environment, thereby simulating the operation of the first application in the process of running the program container in the basic environment, and image file b is used to simulate the operation of the first application in the process of running the program container in the optimized environment, for verifying the optimization performance of the application, wherein image file b includes optimization parameters and configuration parameters corresponding to the program container.

[0068] In an optional embodiment, when the first application corresponds to multiple image files, each image file is marked with an environment tag, and the environment tag is used to indicate the environment type corresponding to the image file, so that according to the environment operation requirements of the first application, a target environment tag that matches the environment operation requirements is determined from the multiple environment tags, and the image file corresponding to the target environment tag is used as the target image file corresponding to the first application. That is, by marking the environment tag, When the same application corresponds to multiple different image files, it can quickly locate the one that meets the needs according to actual needs. Image files, which improves the efficiency of obtaining image files .

[0069] Optionally, the image file is compiled by the designer according to the first application; or, the image file is downloaded from a public container open platform with authorization.

[0070] Step 220: Analyze the image file to obtain attribute data in the image file that indicates the program container during operation.

[0071] The attribute data includes first attribute data.

[0072] In some embodiments, attribute data is used to describe the file attributes corresponding to the image file, thereby defining the configuration and container attributes of the program container at runtime. Therefore, attribute data can also be called metadata in the image file.

[0073] Optionally, the attribute data includes at least one of the following data contents:

[0074] 1. Entrypoint data: defines the command or executable file that is executed by default when the program container starts;

[0075] 2. Command line parameters (Command, Cmd): additional parameters passed to the entry point or application;

[0076] 3. Environment Variables: Defines the runtime environment settings of the application container. Environment variable data can be used by the first application in the application container.

[0077] 4. Architecture Information: describes the hardware architecture type supported by the image file, such as x86, ARM, etc.

[0078] 5. System Information: This includes the operating system, kernel version, and other system environment information when the program container is running.

[0079] It is worth noting that the above-mentioned attribute data is only an illustrative example and is not limited to this embodiment of the present application.

[0080] Optionally, the data analysis method includes at least one of the following methods:

[0081] 1. The image file is compiled with data extraction instructions during the compilation process. By executing the data extraction instructions, the attribute data in the image file is read according to the data extraction instructions and the attribute data is obtained according to the result of the data extraction instructions.

[0082] 2. Traverse all the data in the image file. Different types of data are marked with different data tags. According to the traversal results of all the data in the image file, the key point tags corresponding to the attribute data are determined from the multiple data tags. Then, the traversal results are filtered according to the key point tags to obtain the attribute data corresponding to the key point tags. That is, by marking the data tags, when traversing all the data in the image file, Filter by data label to The method of obtaining attribute data can ensure that no data is missed, and improve the comprehensiveness and accuracy of attribute data acquisition ;

[0083] 3. Traverse all the data in the image file one by one. If the data is attribute data, keep the data. If the data does not belong to attribute data, discard the data. By mirroring the data in the files one by one, the properties can be improved. The accuracy of data acquisition ensures the accuracy of the data analysis process .

[0084] It is worth noting that the above data analysis method is only an illustrative example and is not limited to this embodiment of the present application.

[0085] In this embodiment, the first attribute data refers to at least one of the above-mentioned multiple attribute data.

[0086] Step 230: Generate second attribute data corresponding to the first attribute data.

[0087] The second attribute data is used to simulate the first attribute data to run the program container under safe conditions.

[0088] In some embodiments, the second attribute data is of the same data type as the first attribute data, but is data that ensures safe operation of the program container. For example, if the first attribute data is image entry data, the second attribute data is also image entry data; or if the first attribute data is environment variable data, the second attribute data is also environment variable data.

[0089] Illustratively, the security condition means that during the execution of the second attribute data, the program container will not generate any offensive behavior against the server. The offensive behavior includes at least one of the following types of behavior: exceeding authority, stealing data, destroying data, hijacking network traffic data, and the like.

[0090] Optionally, the second attribute data is generated in at least one of the following ways:

[0091] 1. Pre-generate a database that stores security data files of different data types, and select a target data file corresponding to the data type of the first attribute data from the database as the second attribute data;

[0092] 2. The first attribute data consists of multiple field contents. By manually adjusting the field contents at the specified position, the adjusted attribute data is used as the second attribute data. For example, the first attribute data includes sub-data corresponding to three fields. Sub-data 1 corresponding to the second field is modified to data 2, thereby obtaining the second attribute data. pass Adjusting the data content of the specified field position can simplify the data adjustment process and improve the efficiency of obtaining the second attribute data. ;

[0093] 3. Different data adjustment templates are pre-set for different data types. According to the data type corresponding to the first attribute data, a target adjustment template matching its data type is selected, and the first attribute data is adjusted using the target adjustment template to obtain the second attribute data. That is, by setting the data adjustment template, Able to Automatically adjust the first attribute data according to the adjustment template, improving the efficiency of data adjustment .

[0094] It is worth noting that the above-mentioned method for generating the second attribute data is only an illustrative example and is not limited to this embodiment of the present application.

[0095] Step 240: configure the second attribute data into the image file, and run the program container based on the second attribute data to obtain the container running result.

[0096] The container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

[0097] In some embodiments, configuring the second attribute data into the image file refers to adding the second attribute data into the file content corresponding to the image file.

[0098] Optionally, in the process of configuring the second attribute data to the image file, the first attribute data will be overwritten, that is, the current image file only contains the second attribute data; or, in the process of configuring the second attribute data to the image file, the first attribute data will not be overwritten, that is, the image file contains both the first attribute data and the second attribute data.

[0099] Schematically, in the process of executing the program container based on the second attribute data, that is, the running process of the program container is realized according to the program running path corresponding to the second attribute data, so that the running result of the program container for the program running path of the second attribute data is used as the container running result.

[0100] Optionally, the container running result includes at least one of the following result conditions:

[0101] 1. The container run result is used to indicate whether there is risky content in the image file. If so, the run result is "1", and if not, the run result is "0";

[0102] 2. The container operation results include risk warning results. For example, if the image file contains risky content, a corresponding risk warning result will be generated. If the image file does not contain risky content, no risk warning result will be generated.

[0103] 3. The container running result includes the location of the risk content in the image file. For example, if there is risk content in the image file and the risk content is located at the 24th line of code in the image file, the container running result includes: 24-1, which is used to indicate that the 24th line of code in the current image file is risky content.

[0104] It is worth noting that the above content regarding the container operation results is only an illustrative example and is not limited to this embodiment of the present application.

[0105] In summary, the method provided by the present application obtains an image file corresponding to a first application, and when the image file includes multiple running data for simulating the running of the first application in a program container, performs data analysis on the image file to obtain attribute data in the image file for representing the program container during operation, including first attribute data, generates second attribute data corresponding to the program container for simulating the first attribute data under safe conditions, thereby configuring the second attribute data into the image file, and running the program container according to the second attribute data to obtain the container running result, and obtains the program security after the program container executes the program running path corresponding to the second attribute data according to the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, it is possible to avoid constructing a separate isolated environment to run the program container, thereby ensuring the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security.

[0106] In some embodiments, the container operation results are described in detail. Figure 3 This is a flowchart of a program running method provided by an exemplary embodiment of the present application, that is, step 240 also includes steps 241 and 242, and the method includes the following steps.

[0107] Step 220: Analyze the image file to obtain attribute data in the image file that indicates the program container during operation.

[0108] The attribute data is used to indicate attribute data of the program container during its operation, and the attribute data includes first attribute data.

[0109] In this embodiment, the data extraction command docker inspect is executed to output the data extraction result, and the data extraction result is parsed into structured data.

[0110] Here, structured data refers to data constructed using a specified data structure, for example, represented by a two-dimensional table structure.

[0111] In this embodiment, the attribute data includes entry point data, command line parameters, environment variable data, architecture information, system information, and other data. When the structured data corresponding to the data extraction result contains the data type as described above, the structured data is recorded, and finally the recorded structured data is integrated and output in the specified data format as the attribute data in the image file.

[0112] Optionally, the specified data format includes at least one of JSON format, tree structure format (Extensible Markup Language, XML), spreadsheet format (Excel), and other format types.

[0113] In this embodiment, taking the JSON format as an example, the structured data is integrated to obtain the attribute data as follows:

[0114]

[0115]

[0116] For illustration, please refer to Figure 4 , which shows a data analysis process flow chart provided by an exemplary embodiment of the present application, such as Figure 4 As shown, the method includes the following steps.

[0117] Step 410: Execute the data extraction instruction.

[0118] Optionally, the data extraction instruction is an instruction stored in the mirror file, that is, the data extraction instruction is automatically executed during the process of executing the mirror file line by line; or, the data extraction instruction is independently stored in a specified file, and there is an association between the specified file and the mirror file. When the mirror file is running, the specified file is run synchronously, so the data extraction result corresponding to the mirror file extracted by the data extraction instruction is executed.

[0119] By executing the docker inspect${risk-image} command pre-stored in the image file, the data extraction result corresponding to the image file is read.

[0120] Optionally, the data extraction result includes data of one data type; or, includes data of multiple different data types.

[0121] Step 420: parse the data extraction results.

[0122] After obtaining the data extraction result, data analysis is performed on the data extraction result to obtain structured data corresponding to the data extraction result, wherein the structured data refers to data constructed using a specified data structure.

[0123] In this embodiment, different data structures are set for data of different data types in the data extraction result, so that the data in the data extraction result is generated into corresponding structured data according to the matching data structure.

[0124] Optionally, the structured data is the entire data, and the structured data includes structured data corresponding to multiple data of different data types stored in series; or, the structured data is implemented as multiple independent data, each data corresponding to a data type.

[0125] Step 430: Record entry point data.

[0126] After obtaining structured data by analyzing the data extraction results, the attribute data in the image file is analyzed. If there is attribute data defined as entry point data in the image file, the structured data corresponding to the entry point data is selected from the structured data for recording. If no entry point data is defined, it is not recorded.

[0127] Step 440: Record command line parameters.

[0128] After obtaining structured data by analyzing the data extraction results, the attribute data in the image file is analyzed. If there is attribute data defined as command line parameters in the image file, the structured data corresponding to the command line parameters is selected from the structured data for recording. If no command line parameters are defined, no record is made.

[0129] Step 450: Record environmental variable data.

[0130] After obtaining structured data by analyzing the data extraction results, the attribute data in the image file is analyzed. If there is attribute data defined as environment variable data in the image file, the structured data corresponding to the environment variable data is selected from the structured data for recording. If no environment variable data is defined, it is not recorded.

[0131] Step 460: Record system information.

[0132] After obtaining structured data by analyzing the data extraction results, the attribute data in the image file is analyzed. If there is attribute data defined as system information in the image file, the structured data corresponding to the system information is selected from the structured data for recording. If no system information is defined, it is not recorded.

[0133] Step 470: Record the architecture information.

[0134] After obtaining structured data by analyzing the data extraction results, the attribute data in the image file is analyzed. If there is attribute data defined as architecture information in the image file, the structured data corresponding to the architecture information is selected from the structured data for recording. If no architecture information is defined, it is not recorded.

[0135] Step 480: Generate a key information list.

[0136] Integrate all the structured data recorded in the above steps, organize all the structured data in JSON format, and obtain a key information list, wherein the key information list includes multiple attribute data defined in the image file.

[0137] Step 241: configure the second attribute data into the image file to obtain a file configuration result.

[0138] Illustratively, the file configuration result refers to a configured image file obtained after configuring the second attribute data to the image file, that is, the configured image file.

[0139] The following describes two different configuration methods in detail.

[0140] In some embodiments, the second attribute data replaces the first attribute data in the image file to obtain a file configuration result.

[0141] In this embodiment, when configuring the second attribute data to the image file, the second attribute data completely overwrites the first attribute data in the image file, and the image file containing the second attribute data is used as the file configuration result. By directly overwriting, it can be ensured that only the second attribute data can be run in the final image file, ensuring the operation of the image file. Row Security .

[0142] In some embodiments, the first attribute data corresponds to a first execution path; in configuring the second attribute data to the image file, the first execution path is adjusted to a second execution path corresponding to the second attribute data; and a file configuration result is obtained based on the second execution path.

[0143] In this embodiment, in the image file, the first attribute data corresponds to the first running path. The first running path means that during the process of running the program container according to the first attribute data, the running process of the program container is executed according to the first running path.

[0144] In this embodiment, when configuring the second attribute data to the image file, the first attribute data is not overwritten, but the first running path in the image file is adjusted to the second running path corresponding to the second attribute data, thereby obtaining the configured image file as the file configuration result.

[0145] Optionally, the running path adjustment method includes at least one of the following adjustment methods:

[0146] 1. Directly overwrite the first running path with the second running path, that is, the file configuration result only contains the second running path corresponding to the second attribute data;

[0147] 2. Add the second running path to the image file and execute a disable instruction on the first running path. The disable instruction is used to indicate that during the current running process of the program container, the first running path is not executed, but the second running path is executed.

[0148] It is worth noting that the above-mentioned adjustment method of the running path is only an illustrative example and is not limited to this embodiment of the present application.

[0149] That is, By changing the running path instead of directly overwriting, the original data in the image file can be guaranteed to be The data content is not changed, which improves the accuracy of subsequent program container security detection .

[0150] Step 242: Run the program container based on the file configuration result to obtain the container running result.

[0151] In this embodiment, the program container is run according to the configured image file, so that the program container executes the second running path and obtains the container running result corresponding to the second running path.

[0152] In summary, the method provided by the present application obtains an image file corresponding to a first application, and when the image file includes multiple running data for simulating the running of the first application in a program container, performs data analysis on the image file to obtain attribute data in the image file for representing the program container during operation, including first attribute data, generates second attribute data corresponding to the program container for simulating the first attribute data under safe conditions, thereby configuring the second attribute data into the image file, and running the program container according to the second attribute data to obtain the container running result, and obtains the program security after the program container executes the program running path corresponding to the second attribute data according to the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, it is possible to avoid constructing a separate isolated environment to run the program container, thereby ensuring the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security.

[0153] In this embodiment, by configuring the second attribute data into the image file and running the program container according to the file configuration result, the security of the program container operation can be guaranteed, thereby improving the accuracy of security detection.

[0154] In some embodiments, the generation process of the second attribute data is described in detail. Figure 5 , which shows a flowchart of a program running method provided by an exemplary embodiment of the present application, that is, step 230 also includes steps 231 to 232, such as Figure 5 As shown, the method includes the following steps.

[0155] Step 231: Acquire a preset database.

[0156] The database includes a plurality of candidate attribute data, and the candidate attribute data is used to indicate running data when the program container is run under safe conditions.

[0157] Illustratively, a database is pre-generated, wherein the database includes a plurality of candidate attribute data, wherein the candidate attribute data can ensure that the program container runs under safe conditions.

[0158] Step 232: Match the first attribute data with the database, and obtain second attribute data corresponding to the first attribute data from a plurality of candidate attribute data.

[0159] In this embodiment, after obtaining the first attribute data, second attribute data matching the data type corresponding to the first attribute data is obtained from the database. For example, if the first attribute data is architecture information, the second attribute data is also architecture information.

[0160] In some embodiments, the first attribute data includes image entry data, which refers to the running data used to start the program container; the entry tag corresponding to the image entry data is obtained, the entry tag is used to indicate the data acquisition source of the first attribute data, and the entry tag corresponds to the first entry name; the first attribute data is matched with the database, and the target attribute data corresponding to the first attribute data is obtained from multiple candidate attribute data; the data name corresponding to the target attribute data is adjusted to the first entry name to obtain attribute data with the same name; the attribute data with the same name is mounted with parameter processing to obtain second attribute data corresponding to the attribute data with the same name.

[0161] In this embodiment, attribute data can be divided into two categories: entry data and system instruction data. Entry data refers to the instruction data executed when the program container is started, and system instruction data refers to the instruction data executed when the program container implements the program function during operation.

[0162] In this embodiment, when the first attribute data belongs to mirrored entry data, an entry tag corresponding to the mirrored entry data is obtained, thereby determining a data source corresponding to the mirrored entry data.

[0163] If the first attribute data includes an image entry point (Entrypoint), the value corresponding to the field where the image entry point is located is used as the entry label. If the first attribute data does not include an image entry point, it means that the image entry data comes from the command line parameter (Cmd). Therefore, the first parameter of the Cmd field is used as the entry label. That is, when the image entry data belongs to the image entry point, the first field at the first position in the image entry data is used as the entry label; or, when the image entry data belongs to the command line parameter, the second field at the second position in the image entry data is used as the entry label. In this embodiment, different entry labels are determined according to the different data sources of the image entry data, which can improve the authenticity of the final generated second attribute data in simulating the first attribute data, thereby improving the accuracy of the container operation results.

[0164] In this embodiment, after determining the entry tag corresponding to the mirror entry data, the entry tag is used as the first entry name, and target attribute data matching the attribute type of the first attribute data is retrieved from a pre-set database. The data name of the target attribute data is adjusted to the first entry name, thereby obtaining attribute data with the same name as the entry tag. Specifically, if the mirror entry data includes a mirror entry point, the target attribute data is renamed to data with the same name as the value corresponding to the field where the mirror entry point is located. If the mirror entry data uses a command line parameter as the mirror entry point, the target attribute data is renamed to data with the same name as the first element in the command line parameter.

[0165] In this embodiment, after the attribute data with the same name is obtained, the attribute data with the same name is subjected to mounting parameter processing to obtain the second attribute data corresponding to the first attribute data.

[0166] That is, by renaming the data to obtain the second attribute data, it can be ensured that during the process of running the program container through the second attribute data, the program container can be safely run through the second attribute data.

[0167] In some embodiments, when the image entry data belongs to the image entry point, a mount path parameter is obtained, and the mount path parameter is used to indicate the location of the second attribute data in the image file; a specified entry parameter is generated based on the mount path parameter, and the specified entry parameter is used as the second attribute data.

[0168] In this embodiment, first, the mount path parameter is obtained to indicate that the image entry data is mounted to the location in the image file, for example: -v entry: / tmp / safe / entry. When the entry label is obtained through the image entry point, the specified entry parameter is directly generated according to the mount path parameter as the second attribute data, for example: --entrypoint= / tmp / safe / entry.

[0169] That is, when the image entry data comes from the image entry point, directly generating the specified entry parameters can ensure that the image point entry corresponding to the second attribute data is consistent with the first attribute data, thereby improving the accuracy of program container operation.

[0170] In some embodiments, when the image entry data belongs to a command line parameter, a mount path parameter is obtained, and the mount path parameter is used to indicate the location of the second attribute data in the image file; a specified entry parameter is generated based on the mount path parameter; the entry tag is removed from the command line parameter to obtain an adjusted command line parameter; and the specified entry parameter and the adjusted command line parameter are used as the second attribute data.

[0171] In this embodiment, when obtaining mount path parameters, if the entry tag is obtained via command line parameters, then based on the mount path parameters and the generation of the specified entry parameters, the entry tag is removed from the command line parameters to obtain the adjusted command parameters, and the specified entry parameters and the adjusted command line parameters are used as the second attribute data. For example, if the command line parameters are [" / foo-risk", "-s", "8080"], where " / foo-risk" is used to represent the entry tag, after obtaining the specified entry parameter -entrypoint=" / tmp / safe / foo-risk", " / foo-risk" is removed from the command line parameters, and the obtained adjusted command line parameters are appended together with the specified entry parameters as the second attribute data. That is, by aligning the data content of the second attribute data with the command line parameters, it is ensured that the first attribute data can be fully simulated, thereby improving the running accuracy of the program container.

[0172] In some embodiments, the first attribute data includes environment variable data, which is used to determine the running environment when running the program container; obtain backup parameters corresponding to the environment variable parameters; and generate adjustment variable parameters corresponding to the environment variable parameters based on the backup parameters as second attribute data.

[0173] In this embodiment, if the first attribute data belongs to environment variable data, the backup parameter corresponding to the environment variable data is obtained, for example: --env="PATH_BAK=${IMAGE_PATH_ENV}", so as to generate the adjustment variable parameter corresponding to the environment variable parameter according to the backup parameter, for example: --env=

[0174] "PATH = / tmp / safe; / tmp / safe / system-tools / bin; / tmp / safe / system-tools / sbin" is used as the second attribute data corresponding to the first attribute data. In other words, by generating backup parameters, the consistency of the adjusted environment variable parameters with the original parameters can be improved, ensuring that the program container can run in a safe and correct environment, thereby improving the security and accuracy of operation.

[0175] For illustration, please refer to Figure 6 , which shows a flow chart of a method for generating second attribute data provided by an exemplary embodiment of the present application, such as Figure 6 As shown, the method includes the following contents.

[0176] Step 600: Mark the image entry point as an entry tag.

[0177] In this embodiment, the image file includes field contents corresponding to multiple attribute data. By traversing the multiple attribute data of the image file, it is checked whether the entry point data field is included. If the entry point data field is included, it indicates that the source of the entry label can be realized by the entry point data, so the entry label is marked as the value of the field corresponding to the entry point data; otherwise, execute step 610.

[0178] In this embodiment, multiple attribute data in the image file are respectively annotated with data category tags to indicate attribute data of different data types, for example, entry point data is labeled 1, and environment variable data is labeled 2. By traversing the data category tags corresponding to the multiple attribute data in the image file, if there is a data category tag corresponding to the entry point data, the entry tag is annotated as the value of the corresponding field of the entry point data.

[0179] Optionally, the value of the entire field of the entry point data is used as the entry label, or the value corresponding to a specified character position in the field of the entry point data is used as the entry label.

[0180] Step 610: Mark the first parameter of the command line parameter as an entry label.

[0181] Optionally, the parameter at a specified field position in the command line parameters is used as an entry label; or, the parameter at a random field position in the command line parameters is used as an entry label.

[0182] In this embodiment, if the attribute data does not include a field corresponding to the entry point data, the first parameter in the field corresponding to the command line parameter obtained through traversal is used as the entry tag during the process of traversing the image file.

[0183] Optionally, in the process of traversing the field contents corresponding to multiple attribute data in the image file, if the command line parameters are obtained, the field contents corresponding to the command line parameters are first recorded. When the entry point data is traversed again, the value corresponding to the field content of the entry point data is used as the entry label. Otherwise, the first parameter in the field corresponding to the command line parameter is used as the entry label.

[0184] Step 620: Generate attribute data with the same name according to the entry tag.

[0185] In this embodiment, based on the marked entry tag, the entry tag is used as the attribute name, thereby generating attribute data with the same name as the entry tag as the attribute data with the same name.

[0186] Step 630: Generate mount path parameters.

[0187] In this embodiment, a parameter library is pre-set, which includes multiple candidate mount parameters, from which a target mount parameter matching the entry label is selected as the mount path parameter, for example: -v entry: / tmp / safe / entry.

[0188] Step 640: Generate second attribute data according to the mount path parameters.

[0189] After obtaining the mount path parameters, the second attribute data is generated according to the mount path corresponding to the mount parameters. There are two situations:

[0190] 1. When the entry tag comes from the entry point data, directly generate the specified entry parameter: --entrypoint= / tmp / safe / entry as the second attribute data;

[0191] 2. When the entry tag comes from the command line parameters, in addition to generating the specified entry parameters, the adjustment command line parameters are also generated:

[0192] For example, if the command line parameters in the image file are ["entry", "-", "80"], the following two parameters will be generated:

[0193] a. Specify the entry point parameter: --entrypoint= / tmp / safe / entry;

[0194] b. Remove the entry label from the mount path parameter to adjust the command line parameter: -s 80.

[0195] Therefore, the entry parameters and the adjustment command line parameters are specified as the second attribute data.

[0196] That is, depending on the image entry point, there may be two forms:

[0197] 1. When the image entry is entry point data, the second attribute data can be implemented as: docker run -v entry: / tmp / safe / entry -v system-tools / linux / amd64: / tmp / safe / system-tools --env="PATH_BAK=${IMAGE_PATH_ENV}" --env="PATH= / tmp / safe; / tmp / safe / system-tools / bin; / tmp / safe / system-tools / sbin" --entrypoint= / tmp / safe / entry${risk-image}

[0198] When the image entry point is a command line parameter, the second attribute data can be implemented as: docker run -v entry: / tmp / safe / entry -v system-tools / linux / amd64: / tmp / safe / system-tools --env="PATH_BAK=${IMAGE_PATH_ENV}" --env="PATH= / tmp / safe; / tmp / safe / system-tools / bin; / tmp / safe / system-tools / sbin" --entrypoint= / tmp / safe / entry${risk-image} -s 80

[0199] Step 650: Find a matching system tool set in the database based on the system information and architecture information.

[0200] In this embodiment, when the data type corresponding to the first attribute data is implemented as a system information type or an architecture information type, candidate attribute data matching the system information type is obtained from the database as system information, or candidate attribute data matching the architecture information type is obtained from the database as architecture information, for example: system-tools / linux / amd64.

[0201] Step 660: Generate system command mount path parameters.

[0202] According to the corresponding system information or architecture information in the database determined in step 650, the mount path parameters corresponding to the system information or the mount path parameters corresponding to the architecture information are generated, for example: -v system-tools / linux / amd64: / tmp / safe / system-tools. Since the system information and the architecture information both belong to the system commands corresponding to the program container, the mount path parameters corresponding to the system information and the mount path parameters corresponding to the architecture information belong to system class command mount path parameters.

[0203] Taking the mount path parameters corresponding to the system information as an example, a mount parameter template library is generated in advance, a mount parameter template is selected from the mount parameter template library, and the system information is substituted into the mount parameter template to generate the mount path parameters corresponding to the system information.

[0204] Step 670: Generate backup parameters.

[0205] In this embodiment, by traversing multiple attribute data in the image file, it is checked whether there is environment variable data in the image file. If there is environment variable data, a backup parameter corresponding to the environment variable data is generated, for example: --env="PATH_BAK=${IMAGE_PATH_ENV}".

[0206] Among them, the backup parameters are used to simulate environmental variable data under safe conditions.

[0207] Step 680: Generate adjustment variable data.

[0208] In this embodiment, adjustment variable data corresponding to the environment variable data is generated according to the backup parameters, for example: --env="PATH= / tmp / safe; / tmp / safe / system-tools / bin; / tmp / safe / system-tools / sbin".

[0209] Parameters are rewritten through backup parameters to generate adjustment variable data corresponding to the environment variable data, wherein the adjustment variable data includes operating parameters under safe conditions, for example: / tmp / safe / system.

[0210] Step 690: Assemble the generated second attribute data and splice them into a start command.

[0211] According to the image name corresponding to the image file and the second attribute data corresponding to the generated different data types, a complete container startup command under safe conditions is constructed.

[0212] In the process of constructing the container startup command, the data sorting order is obtained, and the data sorting order is used to represent the arrangement order of different data types. According to the data sorting order, the second attribute data of multiple different data types are sequentially spliced ​​together to generate the container startup command.

[0213] For illustration, please refer to Figure 7 , which shows a flow chart of a method for generating attribute data of the same name provided by an exemplary embodiment of the present application, such as Figure 7 As shown, the method includes the following steps.

[0214] Step 710: Print program startup log.

[0215] In this embodiment, in the process of generating attribute data with the same name, the program startup log in the image file is first printed, such as: Start simulating entry point program execution.

[0216] The program startup log is used to record the historical log content corresponding to the startup of the program container, such as the running status, running parameters, data output results, data input results, and running results of the program container within the historical time period.

[0217] Step 720: Print command line parameters.

[0218] After the program startup log is printed, the program startup log is checked to see whether command line parameters are entered within the historical time period. If command line parameters are entered, the command line parameters are printed.

[0219] Step 730: Call the Sleep instruction to wait for exit.

[0220] By calling the Sleep instruction in the image file, the original first attribute data in the image file enters a sleep state, waiting for the external termination of the program container, thereby realizing running the program container under safe conditions according to the second attribute data.

[0221] The program also uses system commands such as echo and sleep. However, since the environment variable data during container runtime is modified, the program actually executes system commands under safe conditions in / tmp / safe / system-tools, so it does not cause security issues.

[0222] In some embodiments, the attribute data includes multiple first attribute data corresponding to different data types; extracting the first shared field from the multiple first attribute data, the first shared field refers to the field content shared by the multiple first attribute data; obtaining the field adjustment content; adjusting the first shared field to the field adjustment content, and obtaining the second attribute data corresponding to the multiple first attribute data.

[0223] In this embodiment, if the attribute data includes multiple first attribute data of different data types, the common field content among the multiple first attribute data is extracted as the first shared field. After the field adjustment content is generated, the field adjustment content is used to replace the first shared field, thereby obtaining the second attribute data corresponding to the multiple first attribute data. In other words, if there are shared fields among different first attribute data, they are adjusted uniformly, thereby improving the efficiency of generating the second attribute data.

[0224] In summary, the method provided by the present application obtains an image file corresponding to a first application, and when the image file includes multiple running data for simulating the running of the first application in a program container, performs data analysis on the image file to obtain attribute data in the image file for representing the program container during operation, including first attribute data, generates second attribute data corresponding to the program container for simulating the first attribute data under safe conditions, thereby configuring the second attribute data into the image file, and running the program container according to the second attribute data to obtain the container running result, and obtains the program security after the program container executes the program running path corresponding to the second attribute data according to the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, it is possible to avoid constructing a separate isolated environment to run the program container, thereby ensuring the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security.

[0225] In this embodiment, by pre-generating a database and selecting the second attribute data therefrom, the efficiency of obtaining the second attribute data can be improved.

[0226] For illustration, please refer to Figure 8 , which shows a schematic diagram of a program running method provided by an exemplary embodiment of the present application, such as Figure 8As shown, first, the control scheduler 810 extracts the specified image information from the image analysis component 811, which then returns the extracted image information. Second, the instruction generator 812 generates a startup instruction for the image file under safety conditions, and the instruction generator 812 returns the startup command under safety conditions. Instruction generator 812 queries the image file system's dataset through the safety system database 813, which then returns the image file system's dataset. Finally, the control scheduler 810 launches the container launcher 814 under safety conditions to launch the program container 815.

[0227] For illustration, please refer to Figure 9 , which shows an interactive diagram of a program running method provided by an exemplary embodiment of the present application, such as Figure 9 As shown, the method includes the following contents.

[0228] 1. The scheduling controller 901 sends the name of the image containing risky content to the image analysis component 902.

[0229] Among them, the scheduling controller 901 is used to coordinate the workflow of each component, receive relevant instructions sent by the component, forward the instructions to the corresponding component, complete the work content corresponding to the instruction, obtain the output result, and forward the output result to the corresponding component after receiving it to complete the interactive process of the program operation.

[0230] In this embodiment, the scheduling controller 901 sends the image name corresponding to the image file to the image analysis component 902 , wherein the image file includes risky content that may attack the server. Therefore, the image file is implemented as a risky Docker image 903 .

[0231] 2. The image analysis component 902 analyzes risky image metadata through the risky Docker image 903.

[0232] After receiving the image name, the image analysis component 902 obtains the risk Docker image 903 corresponding to the image name from the image library, and performs data analysis on the image to obtain risk image metadata.

[0233] 3. The image analysis component 902 returns the image attribute information to the scheduling controller 901.

[0234] After the image analysis component 902 obtains the risk image metadata, it processes the data to obtain structured data, from which the structured data corresponding to different data types are recorded, thereby generating corresponding attribute data.

[0235] That is, the mirroring attribute information is returned to the scheduling controller 901 for mirroring attribute information corresponding to different data types.

[0236] 4. The scheduling controller 901 sends the image name and attribute information to the container startup command generator 904.

[0237] After receiving the image attribute information, the scheduling controller 901 forwards the image name and image attribute information corresponding to the image file to the container startup command generator 904 .

[0238] The container startup command generator 904 is used to generate a container startup instruction, thereby running the program container corresponding to the image file according to the container startup instruction.

[0239] 5. The container startup command generator 904 searches for candidate attribute data from the database 905 based on the image system and architecture information.

[0240] After receiving the image name and image attribute information corresponding to the image file, the container startup command generator 904 searches the database 905 for candidate attribute data corresponding to the system information and candidate attribute data corresponding to the architecture information in the image attribute information.

[0241] 6. The container startup command generator 904 generates an image program under safe conditions according to the image entry instruction.

[0242] When the container command generator 904 generates an image entry instruction according to the entry tag and entry point data generated in the above embodiment, the corresponding second attribute data under the security condition is generated according to the image entry instruction as the image program under the security condition.

[0243] 7. The container startup command generator 904 generates a container startup instruction.

[0244] The container startup command generator 904 splices the plurality of second attribute data to generate a container startup instruction under security conditions corresponding to the image file.

[0245] 8. The container startup command generator 904 returns the container startup instruction to the scheduling controller 901.

[0246] After the container startup command generator 904 generates the container startup instruction, it sends the container startup instruction to the scheduling controller 901 .

[0247] 9. The scheduling controller 901 sends a container start instruction to the container launcher 906.

[0248] After receiving the container start instruction, the scheduling controller 901 sends the container start instruction to the container launcher 906 to start the program container corresponding to the image file.

[0249] 10. The container launcher 906 launches the program container based on the risk image and the container launch instruction.

[0250] The container launcher 906 starts and runs the program container corresponding to the image file under safe conditions based on the image file containing risky content and the corresponding container startup instruction under safe conditions.

[0251] For illustration, please refer to Figure 10 , which shows a schematic diagram of a second attribute data generation method provided by an exemplary embodiment of the present application, such as Figure 10 As shown, the method includes the following contents.

[0252] First, execute step 1010 to extract the image key information. By executing the data extraction command, attribute data from the image file is extracted and used as the image key information. Next, execute step 1020 to generate second attribute data. If the image key information includes the first attribute data, second attribute data corresponding to the first attribute data under security conditions is generated. Finally, execute step 1030 to securely launch the program container.

[0253] The program running method provided in this embodiment runs the image file under safe conditions during the application process when it is known that there is risky content in the image file. At this time, the security capabilities related to the program container can identify that a risky image file is being run, and relevant alarms and blocking actions will be generated.

[0254] In another application process, for example, image scanning products will first run the image file and then scan the files in the running program container to see if there are any risks. This solution can ensure that no security risks are caused when running the image.

[0255] In summary, the method provided by the present application obtains an image file corresponding to a first application, and when the image file includes multiple running data for simulating the running of the first application in a program container, performs data analysis on the image file to obtain attribute data in the image file for representing the program container during operation, including first attribute data, generates second attribute data corresponding to the program container for simulating the first attribute data under safe conditions, thereby configuring the second attribute data into the image file, and running the program container according to the second attribute data to obtain the container running result, and obtains the program security after the program container executes the program running path corresponding to the second attribute data according to the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, it is possible to avoid constructing a separate isolated environment to run the program container, thereby ensuring the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security.

[0256] The method provided in this embodiment has the following effects:

[0257] By obtaining the first attribute data in the image file, the corresponding second attribute data is generated to simulate the first attribute data running under safe conditions, and then configured into the image file to safely run the program container, which can avoid the problem of not being able to directly simulate the execution of risky images in the related art. Moreover, because the simulated second attribute data is run under safe conditions, the problem of possible attacks due to the default trust in the image file system commands in the related art is solved. The program running method provided by the embodiment of the present application can safely run the program container without establishing a separate and isolated program container corresponding to the running image file, which not only reduces the cost of verifying the effectiveness of the container image security capabilities, but also improves the efficiency of verifying the effectiveness of the container image security capabilities.

[0258] Figure 11 This is a structural block diagram of a program running device provided by an exemplary embodiment of the present application. Figure 11 As shown, the device includes the following parts.

[0259] An acquisition module 1110 is configured to acquire an image file corresponding to a first application program, wherein the image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application program in a program container;

[0260] An analysis module 1120 is configured to perform data analysis on the image file to obtain attribute data in the image file that indicates the running process of the program container, wherein the attribute data includes first attribute data;

[0261] A generating module 1130 is configured to generate second attribute data corresponding to the first attribute data, wherein the second attribute data is used to simulate the first attribute data to run the program container under a safe condition;

[0262] The running module 1140 is used to configure the second attribute data into the image file, and run the program container based on the second attribute data to obtain a container running result, and the container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

[0263] In some embodiments, the running module 1140 is used to configure the second attribute data into the image file to obtain a file configuration result; and run the program container based on the file configuration result to obtain the container running result.

[0264] In some embodiments, the running module 1140 is configured to replace the first attribute data in the image file with the second attribute data to obtain the file configuration result.

[0265] In some embodiments, the first attribute data corresponds to a first operation path;

[0266] The running module 1140 is configured to adjust the first running path to a second running path corresponding to the second attribute data during configuration of the second attribute data to the image file; and obtain the file configuration result based on the second running path.

[0267] In some embodiments, the generation module 1130 is used to obtain a pre-set database, which includes multiple candidate attribute data, and the candidate attribute data is used to indicate the running data when the program container is running under the security conditions; match the first attribute data with the database, and obtain the second attribute data corresponding to the first attribute data from the multiple candidate attribute data.

[0268] In some embodiments, the first attribute data includes image entry data, where the image entry data refers to running data used to start the program container;

[0269] The generation module 1130 is used to obtain the entry label corresponding to the image entry data, the entry label is used to indicate the data acquisition source of the first attribute data, and the entry label corresponds to the first entry name; match the first attribute data with the database, and obtain target attribute data corresponding to the first attribute data from the multiple candidate attribute data; adjust the data name corresponding to the target attribute data to the first entry name to obtain attribute data with the same name; perform mounting parameter processing on the attribute data with the same name to obtain the second attribute data corresponding to the attribute data with the same name.

[0270] In some embodiments, the generation module 1130 is used to use the first field at the first position in the mirror entry data as the entry label when the mirror entry data belongs to a mirror entry point; or, when the mirror entry data belongs to a command line parameter, use the second field at the second position in the mirror entry data as the entry label.

[0271] In some embodiments, the mirror entry data belongs to a mirror entry point;

[0272] The generating module 1130 is configured to obtain a mount path parameter, where the mount path parameter is used to indicate a location of the second attribute data in the image file;

[0273] A designated entry parameter is generated based on the mount path parameter, and the designated entry parameter is used as the second attribute data.

[0274] In some embodiments, the image entry data is a command line parameter;

[0275] The generating module 1130 is configured to obtain a mount path parameter, where the mount path parameter is used to indicate a location of the second attribute data in the image file;

[0276] Generate specified entry parameters based on the mount path parameters;

[0277] Removing the entry tag from the command line parameter to obtain an adjusted command line parameter;

[0278] The designated entry parameter and the adjusted command line parameter are used as the second attribute data.

[0279] In some embodiments, the first attribute data includes environment variable data, and the environment variable data is used to determine the operating environment when running the program container;

[0280] The generating module 1130 is configured to obtain backup parameters corresponding to the environment variable parameters;

[0281] An adjustment variable parameter corresponding to the environment variable parameter is generated based on the backup parameter as the second attribute data.

[0282] In some embodiments, the attribute data includes first attribute data corresponding to a plurality of different data types;

[0283] The generation module 1130 is used to extract the first shared field from multiple first attribute data, where the first shared field refers to the field content shared by the multiple first attribute data; obtain field adjustment content; adjust the first shared field to the field adjustment content, and obtain the second attribute data corresponding to the multiple first attribute data respectively.

[0284] In summary, the program running device provided by the present application obtains an image file corresponding to a first application program, and when the image file includes multiple running data for simulating the running of the first application program in a program container, performs data analysis on the image file to obtain attribute data in the image file for representing the program container during operation, including first attribute data, generates second attribute data corresponding to the program container for simulating the first attribute data under safe conditions, thereby configuring the second attribute data into the image file, and running the program container according to the second attribute data to obtain the container running result, and obtains the program security after the program container executes the program running path corresponding to the second attribute data according to the container running result. That is, by constructing security data corresponding to the attribute data in the image file, using the security data to run the program container, and replacing the original attribute data with the independently constructed security data, it avoids the construction of a separate isolated environment to run the program container, ensuring the safe operation of the program container while reducing the overhead of computing resources, thereby improving the verification efficiency of program security.

[0285] It should be noted that the program execution apparatus provided in the above embodiment is merely exemplified by the division of the aforementioned functional modules. In actual applications, the aforementioned functions can be assigned to different functional modules as needed, i.e., the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the program execution apparatus provided in the above embodiment and the program execution method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0286] Figure 12 The following is a block diagram of a computer device 1200 according to an exemplary embodiment of the present application. Computer device 1200 may be a smartphone, tablet computer, MP3 player (Moving Picture Experts Group Audio Layer III), MP4 player (Moving Picture Experts Group Audio Layer IV), laptop computer, or desktop computer. Computer device 1200 may also be referred to as user equipment, portable terminal, laptop terminal, desktop terminal, or other similar names.

[0287] Typically, the computer device 1200 includes a processor 1201 and a memory 1202 .

[0288] The processor 1201 may include one or more processing cores, such as a 4-core processor, a 12-core processor, etc. The processor 1201 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 1201 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 1201 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 1201 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0289] The memory 1202 may include one or more computer-readable storage media, which may be non-transitory. The memory 1202 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 1202 is used to store at least one instruction, which is executed by the processor 1201 to implement the program execution method provided in the method embodiment of the present application.

[0290] In some embodiments, the computer device 1200 further includes other components, which can be understood by those skilled in the art. Figure 12 The structure shown in the figure does not constitute a limitation on the computer device 1200, and the computer device 1200 may include more or fewer components than shown in the figure, or combine some components, or adopt a different component arrangement.

[0291] Optionally, the computer-readable storage medium may include: a read-only memory (ROM), a random access memory (RAM), a solid-state drive (SSD), or an optical disk. Among them, the random access memory may include a resistance random access memory (ReRAM) and a dynamic random access memory (DRAM). The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0292] An embodiment of the present application also provides a computer device, which includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the program running method as described in any of the above embodiments of the present application.

[0293] An embodiment of the present application also provides a computer-readable storage medium, in which at least one instruction, at least one program, a code set, or an instruction set is stored. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement a program running method as described in any of the above embodiments of the present application.

[0294] The present application also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to execute the program execution method described in any of the above embodiments.

[0295] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0296] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A program running method, characterized in that: The method comprises: Obtaining an image file corresponding to a first application, where the image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application in a program container; Performing data analysis on the image file to obtain attribute data in the image file for indicating the program container during operation, wherein the attribute data includes first attribute data; generating second attribute data corresponding to the first attribute data, where the second attribute data is used to simulate running the program container under a safe condition according to the first attribute data; The second attribute data is configured into the image file, and the program container is run based on the second attribute data to obtain a container running result, where the container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

2. The method according to claim 1, characterized in that The configuring the second attribute data into the image file, and running the program container based on the second attribute data to obtain a container running result includes: configuring the second attribute data into the image file to obtain a file configuration result; The program container is run based on the file configuration result to obtain the container running result.

3. The method according to claim 2, characterized in that The configuring the second attribute data into the image file to obtain a file configuration result includes: The first attribute data in the image file is replaced by the second attribute data to obtain the file configuration result.

4. The method according to claim 2, characterized in that The first attribute data corresponds to a first running path; The configuring the second attribute data into the image file to obtain a file configuration result includes: In the process of configuring the second attribute data into the image file, adjusting the first running path to a second running path corresponding to the second attribute data; The file configuration result is obtained based on the second execution path.

5. The method according to any one of claims 1 to 4, characterized in that: The generating of second attribute data corresponding to the first attribute data includes: Obtaining a preset database, wherein the database includes a plurality of candidate attribute data, wherein the candidate attribute data is used to indicate operation data when the program container is operated under the security condition; The first attribute data is matched with the database, and the second attribute data corresponding to the first attribute data is acquired from the plurality of candidate attribute data.

6. The method according to claim 5, characterized in that The first attribute data includes image entry data, where the image entry data refers to running data used to start the program container; The matching of the first attribute data with the database and obtaining the second attribute data corresponding to the first attribute data from the plurality of candidate attribute data includes: Obtain an entry tag corresponding to the mirror entry data, where the entry tag is used to indicate a data acquisition source of the first attribute data, and the entry tag corresponds to a first entry name; Matching the first attribute data with the database, and acquiring target attribute data corresponding to the first attribute data from the plurality of candidate attribute data; Adjusting the data name corresponding to the target attribute data to the first entry name to obtain attribute data with the same name; Perform mounting parameter processing on the attribute data with the same name to obtain the second attribute data corresponding to the attribute data with the same name.

7. The method according to claim 6, characterized in that The acquiring of the entry label based on the mirrored entry data includes: In the case where the mirror entry data belongs to a mirror entry point, the first field at the first position in the mirror entry data is used as the entry tag; or In a case where the mirror entry data belongs to a command line parameter, the second field at the second position in the mirror entry data is used as the entry tag.

8. The method according to claim 7, characterized in that The mirror entry data belongs to the mirror entry point; The performing mounting parameter processing on the attribute data of the same name to obtain the second attribute data corresponding to the attribute data of the same name includes: Obtaining a mount path parameter, where the mount path parameter is used to indicate a location of the second attribute data in the image file; A designated entry parameter is generated based on the mount path parameter, and the designated entry parameter is used as the second attribute data.

9. The method according to claim 7, characterized in that The image entry data belongs to the command line parameters; The performing mounting parameter processing on the attribute data of the same name to obtain the second attribute data corresponding to the attribute data of the same name includes: Obtaining a mount path parameter, where the mount path parameter is used to indicate a location of the second attribute data in the image file; Generate specified entry parameters based on the mount path parameters; Removing the entry tag from the command line parameter to obtain an adjusted command line parameter; The designated entry parameter and the adjusted command line parameter are used as the second attribute data.

10. The method according to any one of claims 1 to 4, characterized in that: The first attribute data includes environment variable data, and the environment variable data is used to determine the operating environment when running the program container; Generating second attribute data corresponding to the first attribute data based on the attribute data includes: Obtaining backup parameters corresponding to the environment variable parameters; An adjustment variable parameter corresponding to the environment variable parameter is generated based on the backup parameter as the second attribute data.

11. The method according to any one of claims 1 to 4, characterized in that: The attribute data includes a plurality of first attribute data corresponding to different data types respectively; The generating of second attribute data corresponding to the first attribute data includes: Extracting a first shared field from a plurality of first attribute data, where the first shared field refers to field content shared by the plurality of first attribute data; Get the field adjustment content; The first shared field is adjusted to the field adjustment content to obtain second attribute data corresponding to the plurality of first attribute data respectively.

12. A program running device, characterized in that: The device comprises: an acquisition module, configured to acquire an image file corresponding to a first application, wherein the image file includes a plurality of running data, and the running data in the image file is used to simulate running the first application in a program container; an analysis module, configured to perform data analysis on the image file to obtain attribute data in the image file for indicating the program container during operation, wherein the attribute data includes first attribute data; a generating module, configured to generate second attribute data corresponding to the first attribute data, wherein the second attribute data is used to simulate the first attribute data and run the program container under a safe condition; A running module is used to configure the second attribute data into the image file, and run the program container based on the second attribute data to obtain a container running result, wherein the container running result is used to indicate the program security of the program container after the program container executes the program running path corresponding to the second attribute data.

13. A computer device, characterized in that: The computer device includes a processor and a memory, wherein the memory stores at least one program, and the at least one program is loaded and executed by the processor to implement the program running method according to any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that The storage medium stores at least one program segment, and the at least one program segment is loaded and executed by the processor to implement the program running method according to any one of claims 1 to 11.

15. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the program running method according to any one of claims 1 to 11.