A method and system for security analysis of a mirroring system

By extracting and analyzing the mirror system information, identifying the operating system, scanning, and generating formatted reports, the shortcomings of container mirroring security checks are solved, and efficient and accurate mirroring system security analysis is achieved.

CN114020411BActive Publication Date: 2025-07-25HARBIN ANTIY TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111293938.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-03
Publication Date
2025-07-25
Estimated Expiration
2041-11-03

AI Technical Summary

Technical Problem

In the prior art, the security inspection methods of container mirroring are insufficient, resulting in potential security risks when introducing mirroring, making it difficult to effectively identify and analyze the security of the mirroring system.

Method used

By extracting the mirror system information, generating file directories, using the operating system feature library to compare feature information, identifying the operating system and scanning and analysis, generating a formatted analysis report, and combining the package manager information and vulnerability database to judge the vulnerability of system components.

Benefits of technology

Provide efficient and accurate mirror system security analysis, improves the efficiency and accuracy of security inspections, generates easy-to-reference analysis reports, and helps optimize the security of mirror system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114020411B_ABST
    Figure CN114020411B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and system for security analysis of an image system, including: extracting image system information to generate an image system file directory; analyzing the files in the image system according to the image system file directory to extract feature information; comparing the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the image system; scanning and analyzing the files included in the image system file directory according to the specific operating system scanning strategy based on the specific operating system information; generating a formatted analysis report according to the format rules. In practical applications of the present invention, when a container image repository is deployed and large-scale container image security check scans need to be automatically performed regularly, it can provide highly efficient and accurate analyzable data. Finally, a formatted analysis report is generated for developers or users to reference, facilitating targeted optimization of the image system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a mirror system security analysis method and system. Background Art

[0002] Containers are a lightweight, portable, self-contained software packaging technology that allows applications to run in the same way almost anywhere. The container itself is also a lightweight operating system that contains all the code required for a software to run, as well as runtime dependencies and configuration files. The image is the basis for container operation. It is essentially a file system package consisting of a file system encapsulated by the layer and metadata describing the image. The image is composed of multiple file system layers. Each time some files or configurations are added to the base image, a read-write layer will be added on top of the original image layer. All modifications to the original image are based on this read-write layer. The base layer below can then be used to create other images and can be reused.

[0003] With the evolution of software development architecture, container technology has become an important supporting technology in the fields of DevOps and microservices due to its lightweight, agile, easy-to-expand features and strong community support. Containers contain all the required operating environments and configuration files for applications. Packaged containers can run in different environments, and different services will not affect each other. For these reasons, containerized deployment has become the most popular production method nowadays. Some of the images used by developers come from the official organization of the corresponding software in the image, and some come from third parties or even individuals. While introducing these images, potential security risks are also brought about. The security inspection methods for container images have become an issue that needs to be studied and solved urgently. Summary of the invention

[0004] In view of this, the present invention provides a method and system for analyzing the security of an image system, which extracts and analyzes the image system files to obtain the operating system information, configuration files, system component information and other data in the image, and provides a basis for version number comparison rules, thereby analyzing the security of the image system and finally generating a formatted analysis report for reference by developers or users, thereby at least partially solving the problems existing in the prior art.

[0005] The specific content of the invention is:

[0006] A mirror system security analysis method, comprising:

[0007] Extract the image system information and generate the image system file directory;

[0008] Analyze the files in the mirror system according to the mirror system file directory to extract feature information;

[0009] Compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the image system; in this process, according to the operating system feature rules, check whether there are feature files in the image system file directory and whether the content conforms to the feature rules, and based on the comprehensive inspection results, analyze the specific supported operating system distributions included in the image system (such as Debian series, RedHat series, alpine, photon, etc.);

[0010] According to the specific operating system information, scan and analyze the files included in the image system file directory according to the specific operating system scanning strategy;

[0011] Generate a formatted analysis report according to the format rules.

[0012] In practical applications, when a container image repository is deployed and large-scale container image security inspection scans need to be automatically performed regularly, the present invention can provide efficient and accurate analyzable data. Collecting and analyzing data information using the image system file directory is equivalent to decompressing the image to a temporary working directory, and the scanning program collects and analyzes the data in this working directory according to the corresponding feature library and scanning rules. The image itself is a complete operating system, containing all software running environments and configuration files. Therefore, the purpose of constructing the image system file directory is that after constructing a complete file path, the files at the specified path can be directly queried according to the rules without traversing these files, improving work efficiency. The way to identify the operating system is to check whether the operating system feature configuration file exists and is complete. For developers or users who do not have a particularly customized operating system, they will not and do not need to specifically modify these basic operating system dependency configuration features. Therefore, this method can be used to identify the specific operating system information included in the image.

[0013] Further, the extraction of the image system information and the generation of the image system file directory specifically include:

[0014] Extract the image system information and determine whether there is a storage driver. If so, construct the image system file directory according to the storage driver; otherwise, write the files of each layer in the image system into the image system file directory in sequence according to their addition, deletion, and modification flags. This process includes two steps:

[0015] One is that the scanning algorithm is based on the Docker bottom layer. First, obtain the Docker execution permission of the server, and then call the Docker daemon API to query the inspect information of the target image to obtain information such as the hash, storage driver, and layers of the target image, that is, the image system information;

[0016] The second is to determine whether there is a storage driver. If so, construct the image system file directory based on the storage driver. For example, if it is overlay2, and its overlay2 directory exists, the LowerDir, UpperDir, and WorkDir of the target image can be mounted as a file directory that is exactly the same as the image runtime (an example of why you need to check whether the overlay directory exists is that when installing Docker for Windows under Windows, the storage driver in the Docker container image inspect information is also overlay2, but the Docker data is stored in a volume and does not actually exist in the host directory); otherwise, merge the files of each layer in the image file into the working directory in turn according to their addition, deletion, and modification flags.

[0017] Further, the scanning and analyzing of the files contained in the image system file directory according to the specific operating system information and the specific operating system scanning strategy specifically includes:

[0018] According to the specific operating system information, the files contained in the image system file directory are scanned using the package manager feature rules used by the corresponding operating system to determine whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether other versions of the package manager are installed by itself; the scanning results are combined and analyzed to obtain the directory address and configuration information of the system components;

[0019] According to the directory address of the system component, combined with the corresponding rules of the corresponding package manager for archiving and saving the system component, the system component information is parsed, and the parsing result includes the component name, manufacturer, version number, and included file list;

[0020] The specific operating system information contained in the mirror system includes the specific operating system release name, version number, and related configuration information.

[0021] The general automated scanning process is: the developer uploads a container image and creates an automated scanning task. After the scan starts, the working directory of the image is constructed in the temp directory. By querying the operating system feature library rules and comparing them with the file features of the working directory, the inspection items include path comparison and file format. If a certain operating system feature is matched, the operating system information is extracted according to the rule. Once the operating system is known, the corresponding package management configuration rules can be known, and then the package manager configuration can be continued to be searched. According to the found configuration, the corresponding query rules are continued to be selected to obtain the system dependency package information and its version number. For example:

[0022] The system description file of the Ubuntu system is placed under / etc / lsb-release. As long as this file is found, it can be determined that the container image is built based on the Ubuntu system. At this time, the / var / lib / dpkg directory can be further checked to determine whether dpkg is used as the package manager for the container image. When dpkg manages the operating system software packages, it will record the dependency configuration in the / var / lib / dpkg / info / directory. By traversing this directory in sequence, it can be known which system components are installed on the current operating system and what their corresponding versions are.

[0023] Further, while scanning and analyzing the files contained in the mirror system file directory according to the specific operating system scanning strategy, it also includes:

[0024] Combined with the relevant configuration information of the specific operating system contained in the mirror system and the package manager information obtained by scanning, select the comparison rules that conform to the system components, compare the system component information with the feature data in the external vulnerability database, and judge whether there are vulnerabilities in the system components.

[0025] Further, judging whether there are vulnerabilities in the system components specifically includes:

[0026] Judge whether the system component information contains patch information. If it does, judge whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that the system component has a vulnerability. If it is not lower, it is determined that the system component does not have a vulnerability;

[0027] If the system component information does not contain patch information, judge whether the system component information contains common vulnerability disclosure entries. If it does, judge whether the version number of the system component is within the range disclosed in the common vulnerability disclosure (CVE) entries (within the range corresponding to the cpe). If it is within the range, it is determined that the system component has a vulnerability; if the system component information does not contain common vulnerability disclosure entries or the version number of the system component is not within the range disclosed in the common vulnerability disclosure entries, it is determined that the system component does not have a vulnerability.

[0028] The naming rules of system components are not all in accordance with the semver standard among different distributions, but each operating system maintains its own system security patches, and the distribution manufacturers have all published the open-source code of their package managers. Here, the version management module is abstracted as part of the version comparison rules. Using the official's own version comparison rules to compare with the vulnerability database, the result is more accurate and credible than using other comparison modules.

[0029] A mirror system security analysis system, comprising:

[0030] A mirror data extraction module, configured to extract mirror system information and generate a mirror system file directory;

[0031] A configuration analysis module, configured to analyze the files in the mirror system according to the mirror system file directory, extract feature information; compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the mirror system; according to the specific operating system information, scan and analyze the files included in the mirror system file directory according to the specific operating system scanning strategy;

[0032] An information formatting module, configured to generate a formatted analysis report according to format rules.

[0033] In practical applications, when a container image repository is deployed and large-scale container image security checks and scans need to be automatically performed regularly, the present invention can provide efficient and accurate analyzable data. Collecting and analyzing data information using the mirror system file directory is equivalent to decompressing the mirror to a temporary working directory, and the scanning program collects and analyzes the data in this working directory according to the corresponding feature library and scanning rules. The mirror itself is a complete operating system, containing all software running environments and configuration files. Therefore, the purpose of constructing the mirror system file directory is that after constructing a complete file path, files at the specified path can be directly queried according to the rules without traversing these files, improving work efficiency. The way to identify the operating system is to check whether the operating system feature configuration file exists and is complete. For developers or users who do not have a specially customized operating system, they will not and do not need to specifically modify these basic operating system dependency configuration features. Therefore, this method can be used to identify the specific operating system information included in the mirror.

[0034] Further, the mirror data extraction module is specifically configured to:

[0035] Extract mirror system information, and determine whether there is a storage driver. If so, construct a mirror system file directory according to the storage driver; otherwise, write the files in each layer of the mirror system into the mirror system file directory in sequence according to their add, delete, and modify flags. This process includes two steps:

[0036] One is that the scanning algorithm is based on the Docker bottom layer. First, obtain the Docker execution permission of the server, and then call the Docker daemon API to query the inspect information of the target mirror to obtain information such as the hash, storage driver, and layers of the target mirror, that is, the mirror system information;

[0037] The second is to determine whether there is a storage driver. If so, construct the image system file directory based on the storage driver. For example, if it is overlay2, and its overlay2 directory exists, the LowerDir, UpperDir, and WorkDir of the target image can be mounted as a file directory that is exactly the same as the image runtime (an example of why you need to check whether the overlay directory exists is that when installing Docker for Windows under Windows, the storage driver in the Docker container image inspect information is also overlay2, but the Docker data is stored in a volume and does not actually exist in the host directory); otherwise, merge the files of each layer in the image file into the working directory in turn according to their addition, deletion, and modification flags.

[0038] Further, the scanning and analyzing of the files contained in the image system file directory according to the specific operating system information and the specific operating system scanning strategy specifically includes:

[0039] According to the specific operating system information, the files contained in the image system file directory are scanned using the package manager feature rules used by the corresponding operating system to determine whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether other versions of the package manager are installed by itself; the scanning results are combined and analyzed to obtain the directory address and configuration information of the system components;

[0040] According to the directory address of the system component, combined with the corresponding rules of the corresponding package manager for archiving and saving the system component, the system component information is parsed, and the parsing result includes the component name, manufacturer, version number, and included file list;

[0041] The specific operating system information contained in the mirror system includes the specific operating system release name, version number, and related configuration information.

[0042] The general automated scanning process is: the developer uploads a container image and creates an automated scanning task. After the scan starts, the working directory of the image is constructed in the temp directory. By querying the operating system feature library rules and comparing them with the file features of the working directory, the inspection items include path comparison and file format. If a certain operating system feature is matched, the operating system information is extracted according to the rule. Once the operating system is known, the corresponding package management configuration rules can be known, and then the package manager configuration can be continued to be searched. According to the found configuration, the corresponding query rules are continued to be selected to obtain the system dependency package information and its version number. For example:

[0043] The system description file of the Ubuntu system is placed under / etc / lsb-release. As long as this file is found, it can be determined that the container image is built based on the Ubuntu system. At this time, the / var / lib / dpkg directory can be further checked to determine whether dpkg is used as the package manager for the container image. When dpkg manages the operating system software packages, it will record the dependency configuration in the / var / lib / dpkg / info / directory. By traversing this directory in sequence, it can be known which system components are installed in the current operating system and what versions they correspond to.

[0044] Further, while scanning and analyzing the files contained in the mirror system file directory according to the specific operating system scanning strategy, the configuration analysis module is further used for:

[0045] Combined with the relevant configuration information of the specific operating system included in the mirror system and the package manager information obtained by scanning, select the comparison rules that conform to the system components, compare the system component information with the feature data in the external vulnerability database, and determine whether there are vulnerabilities in the system components.

[0046] Further, determining whether there are vulnerabilities in the system components specifically includes:

[0047] Determine whether the system component information contains patch information. If it does, determine whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that the system component has a vulnerability. If it is not lower, it is determined that the system component does not have a vulnerability;

[0048] If the system component information does not contain patch information, determine whether the system component information contains a Common Vulnerabilities and Exposures (CVE) entry. If it does, determine whether the version number of the system component is within the range disclosed in the CVE entry (within the range corresponding to the cpe). If it is within the range, it is determined that the system component has a vulnerability; if the system component information does not contain a CVE entry or the version number of the system component is not within the range disclosed in the CVE entry, it is determined that the system component does not have a vulnerability.

[0049] The naming rules of system components are not all in accordance with the semver standard among different distributions, but each operating system maintains its own system security patches, and the distribution manufacturers have all published the open-source code of their package managers. Here, the version management module is abstracted as part of the version comparison rules. Using the official's own version comparison rules to compare with the vulnerability database, the result is more accurate and reliable than using other comparison modules.

[0050] The beneficial effects of the present invention are as follows:

[0051] In practical applications of the present invention, when a container image repository is deployed and large-scale container image security inspection scans need to be automatically performed regularly, it can provide highly efficient and accurate analyzable data. The present invention analyzes based on the specific operating system information included in the image system, with higher accuracy of the analysis results, and also enriches the application environment for security detection and analysis of the image system. The present invention constructs the file directory of the image system. When collecting and analyzing data information, it can directly query the files at the specified path according to the rules without traversing these files, improving work efficiency. The present invention finally generates a formatted analysis report for developers or users to refer to, facilitating targeted optimization of the image system. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0053] Figure 1 It is a flowchart of a method for security analysis of an image system according to an embodiment of the present invention;

[0054] Figure 2 It is a flowchart of another method for security analysis of an image system according to an embodiment of the present invention;

[0055] Figure 3 It is a structural diagram of a system for security analysis of an image system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] The following will describe the embodiments of the present invention in detail with reference to the drawings.

[0057] It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other; and, based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present disclosure.

[0058] It should be noted that the following description relates to various aspects of embodiments within the scope of the appended claims. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. In addition, this device can be implemented and this method can be practiced using other structures and / or functionality in addition to one or more of the aspects described herein.

[0059] The present invention provides an embodiment of a method for security analysis of an image system, as Figure 1 shown, including:

[0060] S11: Extract image system information to generate an image system file directory;

[0061] S12: Analyze the files in the image system according to the image system file directory to extract feature information;

[0062] S13: Compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the image system; in this process, according to the operating system feature rules, check whether there are feature files in the image system file directory and whether the content conforms to the feature rules, and comprehensively analyze the check results to analyze the specific operating system distributions (such as Debian series, RedHat series, alpine, photon, etc.) that can be supported and scanned in the image system;

[0063] S14: According to the specific operating system information, scan and analyze the files included in the image system file directory according to the specific operating system scanning strategy;

[0064] S15: Generate a formatted analysis report according to the format rules.

[0065] In practical applications, when a container image repository is deployed and large-scale container image security inspection and scanning needs to be automatically performed regularly, the present invention can provide efficient and accurate analyzable data. By using the mirror system file directory to collect and analyze data information, it is equivalent to decompressing the mirror into a temporary working directory, and the scanning program collects and analyzes the data in this working directory according to the corresponding feature library and scanning rules. The mirror itself is a complete operating system, containing all software running environments and configuration files. Therefore, the purpose of constructing the mirror system file directory is that after constructing the complete file path, the files at the specified path can be directly queried according to the rules without traversing these files, improving work efficiency. The way to identify the operating system is to check whether the operating system feature configuration file exists and is complete. For developers or users who do not have a specially customized operating system, they will not and do not need to specifically modify these basic dependency configuration features of the operating system. Therefore, this method can be used to identify the specific operating system information contained in the mirror.

[0066] Preferably, the extraction of mirror system information to generate a mirror system file directory specifically includes:

[0067] Extract the mirror system information and determine whether there is a storage driver. If so, construct the mirror system file directory according to the storage driver; otherwise, write the files of each layer in the mirror system into the mirror system file directory in sequence according to their addition, deletion, and modification flags. This process includes two steps:

[0068] One is that the scanning algorithm is based on the Docker bottom layer. First, obtain the Docker execution permission of the server, and then call the Docker daemon API to query the inspect information of the target mirror to obtain information such as the hash, storage driver, and layers of the target mirror, that is, the mirror system information;

[0069] The second is to determine whether there is a storage driver. If so, construct the mirror system file directory according to the storage driver. For example: if it is overlay2 and its overlay2 directory exists, the LowerDir, UpperDir, and WorkDir of the target mirror can be mounted into a file directory exactly the same as when the mirror runs (an example of why it is necessary to check whether the overlay directory exists is that when installing Docker for Windows on Windows, although the storage driver in the Docker container image inspect information is also overlay2, the Docker data exists in a volume and does not actually exist in the host directory); otherwise, merge the files of each layer of the mirror file into the working directory in sequence according to their addition, deletion, and modification flags.

[0070] Preferably, scanning and analyzing the files contained in the image system file directory according to the specific operating system information and the specific operating system scanning strategy specifically includes:

[0071] According to the specific operating system information, the files contained in the image system file directory are scanned using the package manager feature rules used by the corresponding operating system to determine whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether other versions of the package manager are installed by itself; the scanning results are combined and analyzed to obtain the directory address and configuration information of the system components;

[0072] According to the directory address of the system component, combined with the corresponding rules of the corresponding package manager for archiving and saving the system component, the system component information is parsed, and the parsing result includes the component name, manufacturer, version number, and included file list;

[0073] The specific operating system information contained in the mirror system includes the specific operating system release name, version number, and related configuration information.

[0074] The general automated scanning process is: the developer uploads a container image and creates an automated scanning task. After the scan starts, the working directory of the image is constructed in the temp directory. By querying the operating system feature library rules and comparing them with the file features of the working directory, the inspection items include path comparison and file format. If a certain operating system feature is matched, the operating system information is extracted according to the rule. Once the operating system is known, the corresponding package management configuration rules can be known, and then the package manager configuration can be continued to be searched. According to the found configuration, the corresponding query rules are continued to be selected to obtain the system dependency package information and its version number. For example:

[0075] The system description file of the Ubuntu system is placed in / etc / lsb-release. Once this file is found, it can be determined that the container image is built based on the Ubuntu system. At this time, you can further check the / var / lib / dpkg directory to determine whether the container image uses dpkg as the package manager. When managing operating system software packages, dpkg will record the dependency configuration in the / var / lib / dpkg / info / directory. By traversing this directory in turn, you can know which system components are installed in the current operating system and what their corresponding versions are.

[0076] Preferably, while scanning and analyzing the files contained in the image system file directory according to the specific operating system scanning strategy, it also includes:

[0077] Based on the relevant configuration information of the specific operating system included in the mirror system and the package manager information obtained by scanning, select the comparison rules that conform to the system components, compare the system component information with the feature data in the external vulnerability database, and determine whether there are vulnerabilities in the system components.

[0078] Preferably, the determination of whether there are vulnerabilities in the system components specifically includes:

[0079] Determine whether the system component information contains patch information. If it does, determine whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that there is a vulnerability in the system component. If it is not lower, it is determined that there is no vulnerability in the system component;

[0080] If the system component information does not contain patch information, determine whether the system component information contains a Common Vulnerabilities and Exposures (CVE) entry. If it does, determine whether the version number of the system component is within the range disclosed in the CVE entry (within the range corresponding to the CPE). If it is within the range, it is determined that there is a vulnerability in the system component; if the system component information does not contain a CVE entry or the version number of the system component is not within the range disclosed in the CVE entry, it is determined that there is no vulnerability in the system component.

[0081] The naming rules of system components between different distributions do not all follow the semver standard, but each operating system maintains its own system security patches, and the distribution vendors have also published the open-source code of their package managers. Here, the version management module is extracted as part of the version comparison rules. Using the official's own version comparison rules to compare with the vulnerability database, the result is more accurate and reliable than using other comparison modules.

[0082] To further illustrate the method of the present invention, in combination with the above preferred solution, another embodiment of the mirror system security analysis method is provided, as Figure 2 shown, including:

[0083] S21: Extract mirror system information;

[0084] S22: Determine whether there is a storage driver. If so, construct the mirror system file directory according to the storage driver; otherwise, write the files of each layer in the mirror system into the mirror system file directory in sequence according to their add / delete / modify flags;

[0085] S23: Analyze the files in the mirror system according to the mirror system file directory and extract feature information;

[0086] S24: Compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the image system;

[0087] S25: According to the specific operating system information, use the feature rules of the package manager used by the corresponding operating system to scan the files included in the file directory of the image system, and determine whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether it has installed other versions of the package manager by itself; Subsequently, execute S26 - S27, S28 - S210 respectively, and finally execute S211;

[0088] S26: Combine and analyze the scan results to obtain the directory address and configuration information of the system components;

[0089] S27: According to the directory address of the system components, combine the corresponding rules for archiving and saving system components by the corresponding package manager to parse the system component information; The parsing results include component name, manufacturer, version number, and included file list;

[0090] S28: Combine the relevant configuration information of the specific operating system included in the image system and the scanned package manager information, select the comparison rules that conform to the system components, and compare the system component information with the feature data in the external vulnerability database;

[0091] S29: Determine whether the system component information contains patch information. If it does, determine whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that the system component has a vulnerability. If it is not lower, it is determined that the system component does not have a vulnerability; If the system component information does not contain patch information, enter S210;

[0092] S210: Determine whether the system component information contains a Common Vulnerabilities and Exposures (CVE) entry. If it does, determine whether the version number of the system component is within the range disclosed in the CVE entry. If it is within the range, it is determined that the system component has a vulnerability; If the system component information does not contain a CVE entry or the version number of the system component is not within the range disclosed in the CVE entry, it is determined that the system component does not have a vulnerability;

[0093] S211: Summarize all scan analysis and judgment results, and output a formatted readable report to feedback to the developer or user.

[0094] This embodiment can effectively reduce the time and labor required for collecting and scanning data, and improve the analysis efficiency. At the same time, it adapts the version number recognition and discrimination algorithms for multiple scenarios, which can improve the scanning accuracy and reduce false alarms. Using the official own version comparison rules to compare with the vulnerability database, the results are more accurate and reliable than using other comparison modules.

[0095] The present invention provides an embodiment of a mirror system security analysis system, as Figure 3 shown, including:

[0096] A mirror data extraction module 31, configured to extract mirror system information and generate a mirror system file directory;

[0097] A configuration analysis module 32, configured to analyze the files in the mirror system according to the mirror system file directory, extract feature information; compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the mirror system; according to the specific operating system information, scan and analyze the files included in the mirror system file directory according to the specific operating system scanning strategy;

[0098] An information formatting module 33, configured to generate a formatted analysis report according to the format rules.

[0099] In practical applications, when a container image repository is deployed and large-scale container image security checks and scans need to be performed automatically on a regular basis, the present invention can provide highly efficient and accurate analyzable data. Using the mirror system file directory to collect and analyze data information is equivalent to decompressing the mirror to a temporary working directory, and the scanning program collects and analyzes the data in this working directory according to the corresponding feature library and scanning rules. The mirror itself is a complete operating system, containing all software running environments and configuration files. Therefore, the purpose of constructing the mirror system file directory is that after constructing the complete file path, files at the specified path can be directly queried according to the rules, without having to traverse these files, improving work efficiency. The way to identify the operating system is to check whether the operating system feature configuration file exists and is complete. For developers or users who do not have a particularly customized operating system, they will not and do not need to specifically modify these basic operating system dependency configuration features. Therefore, this method can be used to identify the specific operating system information included in the mirror.

[0100] Preferably, the mirror data extraction module 32 is specifically configured to:

[0101] Extract mirror system information, and determine whether there is a storage driver. If so, construct a mirror system file directory according to the storage driver; otherwise, write the files in each layer of the mirror system into the mirror system file directory in sequence according to their add, delete, and modify flags. This process includes two steps:

[0102] First, the scanning algorithm is based on the Docker underlying layer. First, obtain the Docker execution permission of the server, and then call the Docker daemon API to query the inspect information of the target image to obtain information such as the hash, storage driver, and layers of the target image, that is, the image system information;

[0103] Second, determine whether there is a storage driver. If so, construct the image system file directory according to the storage driver. For example: if it is overlay2 and its overlay2 directory exists, the LowerDir, UpperDir, and WorkDir of the target image can be mounted into a file directory exactly the same as when the image runs (an example of why it is necessary to check whether the overlay directory exists is that when installing Docker for Windows on Windows, although the storage driver in the Docker container image inspect information is also overlay2, the Docker data exists in a volume and does not actually exist in the host directory); otherwise, the files in each layer of the image file are merged into the working directory in turn according to their add, delete, and modify flags.

[0104] Preferably, scanning and analyzing the files included in the image system file directory according to the specific operating system scanning policy according to the specific operating system information specifically includes:

[0105] According to the specific operating system information, scan the files included in the image system file directory using the feature rules of the package manager used by the corresponding operating system, and judge whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether other versions of the package manager are installed by itself; merge and analyze the scanning results to obtain the directory address and configuration information of the system components;

[0106] According to the directory address of the system components, combine the corresponding rules for archiving and saving system components by the corresponding package manager to parse the system component information, and the parsing results include component name, manufacturer, version number, and included file list;

[0107] The specific operating system information included in the image system includes the specific operating system distribution name, version number, and related configuration information.

[0108] The conventional automated scanning process is as follows: The developer uploads a container image and creates an automated scanning task. After the scanning starts, the working directory of the image is constructed in the temp directory. By querying the rules of the operating system feature library and comparing with the file features of this working directory, the inspection items include path comparison and file format. If a certain operating system feature is matched, the operating system information is extracted according to this rule. Once the operating system is known, the corresponding package management configuration rules can be known, and then continue to search for the package manager configuration. According to the found configuration, continue to select the corresponding query rules to obtain the information of the system dependent packages and their version numbers. For example:

[0109] For the Ubuntu system, the system description file is placed under / etc / lsb-release. As long as this file is found, it can be determined that the container image is built based on the Ubuntu system. At this time, the / var / lib / dpkg directory can be further checked to determine whether dpkg is used as the package manager for this container image. When dpkg manages the operating system software packages, it will record the dependency configuration in the / var / lib / dpkg / info / directory. By traversing this directory in sequence, it can be known which system components are installed in the current operating system and what their corresponding versions are.

[0110] Preferably, while scanning and analyzing the files included in the mirror system file directory according to the specific operating system scanning strategy, the configuration analysis module 32 is further configured to:

[0111] Combined with the relevant configuration information of the specific operating system included in the mirror system and the package manager information obtained by scanning, select the comparison rules that conform to the system components, compare the system component information with the feature data in the external vulnerability database, and determine whether there are vulnerabilities in the system components.

[0112] Preferably, determining whether there are vulnerabilities in the system components specifically includes:

[0113] Judge whether the system component information contains patch information. If it does, judge whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that there is a vulnerability in the system component. If it is not lower, it is determined that there is no vulnerability in the system component;

[0114] If the system component information does not contain patch information, then determine whether the system component information contains Common Vulnerability Exposure (CVE) entries. If it does, then determine whether the version number of the system component is within the range disclosed in the CVE entries (within the range corresponding to the CPE). If it is within the range, then determine that the system component has a vulnerability; if the system component information does not contain CVE entries or the version number of the system component is not within the range disclosed in the CVE entries, then determine that the system component does not have a vulnerability.

[0115] The naming rules of system components are not all in accordance with the semver standard among different distributions. However, each operating system maintains its own system security patches, and the distribution vendors have also published the open-source code of their package managers. Here, the version management module is extracted as part of the version comparison rules. Using the official's own version comparison rules to compare with the vulnerability database, the results are more accurate and reliable than using other comparison modules.

[0116] The process of the system embodiment of the present invention is similar to that of the method embodiment. The description of the system embodiment is relatively simple. For the corresponding part, please refer to the method embodiment.

[0117] In practical applications of the present invention, when a container image repository is deployed and large-scale container image security checks and scans need to be performed automatically on a regular basis, it can provide highly efficient and accurate analyzable data. The present invention analyzes based on the specific operating system information included in the image system, and the analysis results are more accurate. At the same time, it also enriches the application environment for security detection and analysis of the image system. The present invention constructs the file directory of the image system. When collecting and analyzing data information, it can directly query the files at the specified path according to the rules, without having to traverse these files, improving work efficiency. The present invention finally generates a formatted analysis report for developers or users to refer to, facilitating targeted optimization of the image system.

[0118] As described above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for security analysis of a mirroring system, characterized in that, Including: Extract the mirror system information and generate a mirror system file directory; Analyze the files in the mirror system according to the mirror system file directory and extract feature information; Compare the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the mirror system; According to the specific operating system information, scan and analyze the files included in the mirror system file directory according to the specific operating system scanning strategy; Generate a formatted analysis report according to the format rules; Among them, the extraction of the mirror system information includes: querying the inspect information of the mirror system to obtain the mirror system information; the mirror system information includes: the hash of the mirror system, storage driver information, and layer information; The generation of the mirror system file directory includes: judging whether there is a storage driver according to the mirror system information, if so, constructing a mirror system file directory according to the storage driver; otherwise, writing the files of each layer in the mirror system into the mirror system file directory in turn according to their add / delete / modify flags.

2. The method according to claim 1, wherein The scanning and analyzing of the files included in the mirror system file directory according to the specific operating system scanning strategy specifically includes: According to the specific operating system information, scan the files included in the mirror system file directory using the feature rules of the package manager used by the corresponding operating system, and judge whether the specific operating system included in the mirror system uses the default package manager of the corresponding operating system and whether it has installed other versions of the package manager by itself; merge and analyze the scanning results to obtain the directory address and configuration information of the system components; According to the directory address of the system components, combine the corresponding rules for archiving and saving system components by the corresponding package manager to parse the system component information, and the parsing results include component name, manufacturer, version number, and included file list; The specific operating system information included in the mirror system includes the specific operating system distribution name, version number, and related configuration information.

3. The method according to claim 2, wherein While scanning and analyzing the files included in the mirror system file directory according to the specific operating system scanning strategy, the method further includes: Combining the relevant configuration information of the specific operating system included in the mirror system and the scanned package manager information, select the comparison rules that meet the system components, compare the system component information with the feature data in the external vulnerability database, and judge whether the system components have vulnerabilities.

4. The method according to claim 3, characterized in that, The judgment of whether the system components have vulnerabilities specifically includes: Judge whether the system component information contains patch information. If it does, judge whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that the system component has a vulnerability. If it is not lower, it is determined that the system component does not have a vulnerability; If the system component information does not contain patch information, determine whether the system component information contains a Common Vulnerability Disclosure (CVD) entry. If it does, determine whether the version number of the system component is within the range disclosed in the CVD entry. If it is within the range, determine that the system component has a vulnerability. If the system component information does not contain a CVD entry or the version number of the system component is not within the range disclosed in the CVD entry, determine that the system component does not have a vulnerability.

5. A mirror system security analysis system, characterized in that, Including: An image data extraction module for extracting image system information and generating an image system file directory; A configuration analysis module for analyzing the files in the image system according to the image system file directory, extracting feature information; comparing the feature information with the feature rules in the operating system feature library to obtain the specific operating system information included in the image system; scanning and analyzing the files included in the image system file directory according to the specific operating system scanning strategy based on the specific operating system information; An information formatting module for generating a formatted analysis report according to the format rules; Among them, the extraction of the image system information includes: querying the inspect information of the image system to obtain the image system information; the image system information includes: the hash of the image system, storage driver information, and layer information; The generation of the image system file directory includes: determining whether there is a storage driver according to the image system information. If so, constructing the image system file directory according to the storage driver; otherwise, sequentially writing the files of each layer in the image system into the image system file directory according to their add, delete, and modify flags.

6. The system according to claim 5, wherein The scanning and analyzing of the files included in the image system file directory according to the specific operating system scanning strategy based on the specific operating system information specifically includes: Scanning the files included in the image system file directory using the feature rules of the package manager used by the corresponding operating system according to the specific operating system information, determining whether the specific operating system included in the image system uses the default package manager of the corresponding operating system and whether other versions of the package manager are installed by itself; combining and analyzing the scanning results to obtain the directory address and configuration information of the system components; Parsing the system component information according to the directory address of the system components, in combination with the corresponding rules for archiving and storing system components by the corresponding package manager. The parsing results include component name, manufacturer, version number, and included file list; The specific operating system information included in the image system includes the specific operating system distribution name, version number, and related configuration information.

7. The system according to claim 6, wherein, While scanning and analyzing the files included in the image system file directory according to the specific operating system scanning strategy, the configuration analysis module is also used for: Based on the relevant configuration information of the specific operating system included in the mirroring system and the package manager information obtained by scanning, select the comparison rules that match the system components, and compare the system component information with the signature data in the external vulnerability database to determine whether there are vulnerabilities in the system components.

8. The system according to claim 7, wherein The determination of whether there are vulnerabilities in the system components specifically includes: Determine whether the system component information contains patch information. If it does, determine whether the version of the corresponding patch is lower than the version of the corresponding patch in the external vulnerability database. If it is lower, it is determined that there are vulnerabilities in the system component; if it is not lower, it is determined that there are no vulnerabilities in the system component; If the system component information does not contain patch information, determine whether the system component information contains a Common Vulnerabilities and Exposures (CVE) entry. If it does, determine whether the version number of the system component is within the range disclosed in the CVE entry. If it is within the range, it is determined that there are vulnerabilities in the system component; if the system component information does not contain a CVE entry or the version number of the system component is not within the range disclosed in the CVE entry, it is determined that there are no vulnerabilities in the system component.

Citation Information

Patent Citations

  • Method and device for processing software information

    CN106874366A

  • Safe mirror image scanning method based on Clair

    CN112084496A

  • Method and device for carrying out security scanning on service container mirror image

    CN112395042A