Kubernetes-based Web Vulnerability Scanning Method, Device, Electronic Device and Medium
By embedding vulnerability scanner and detection coordinator in Kubernetes Pod, using the shared Network Namespace mechanism, directly accessing web applications locally for vulnerability detection, solving the problem of vulnerability scanning in the existing technology that occupies the bandwidth of cluster entry and ensuring the stability of business operations.
Patent Information
- Application Number
- CN202111386434.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-11-22
AI Technical Summary
When the existing technology scans vulnerability for web applications running on Kubernetes, it will occupy the cluster ingress bandwidth, squeeze the cluster business traffic, and affect the stability of the business operation.
By embedding the vulnerability scanner and detection coordinator in the running unit Pod, using the shared Network Namespace mechanism, the vulnerability scanner detection traffic can be directly accessed from the web application locally for vulnerability detection, avoiding passing through the cluster entrance.
Localization of vulnerability detection traffic is realized, avoiding the use of cluster inlet bandwidth and not affecting the stability of other service operating units.
Smart Images

Figure CN114036530B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of network security technology, and in particular, to a web vulnerability scanning method, device, electronic device and medium based on Kubernetes. Background Art
[0002] Software applications with a microservices technology architecture have been widely used with the popularization of container technology and the container orchestration platform Kubernetes. Compared with the traditional technology architecture, the microservices technology architecture will cause a sharp increase in the number of service units, that is, the number of Web applications. With the prevalence of the agile development concept, the demand for continuous delivery of software products has increased, the release frequency has been greatly improved, and the frequency of vulnerability security scanning before product delivery has increased sharply.
[0003] When the existing technology scans for vulnerabilities in Web applications running on Kubernetes, a vulnerability detection engine is deployed at the edge of the Kubernetes cluster according to the network deployment conditions of the detected Web application, and a unified entry address is opened outside the Kubernetes cluster through the Kubernetes Ingress mechanism. The vulnerability detection software accesses the entry address to scan for vulnerabilities in the Web application. Although this method can achieve large-scale concurrent detection by deploying multiple vulnerability detection engines, the vulnerability detection traffic centrally scans for vulnerabilities in the Web application through the cluster entry, which will occupy the cluster entry bandwidth, squeeze the cluster service traffic, and affect the stability of business operations. Summary of the Invention
[0004] The embodiments of the present application provide a web vulnerability scanning method, device, electronic device and medium based on Kubernetes, which can enable the detection traffic of the vulnerability detection engine to directly access the Web application locally for vulnerability detection, without occupying the cluster entry bandwidth and without affecting other business operation units.
[0005] In one embodiment, the embodiments of the present application provide a web vulnerability scanning method based on Kubernetes. The method is executed by a detection coordinator, and the detection coordinator, the vulnerability scanner, and the Web application are in a running unit Kubernetes Pod. The method includes:
[0006] If a vulnerability scanning trigger event is detected, a vulnerability scanning task creation request is sent to the vulnerability detection software control center;
[0007] After the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters;
[0008] According to the scanning parameters, control the vulnerability scanner to scan for vulnerabilities in the Web application.
[0009] In one embodiment, the embodiment of the present application provides a web vulnerability scanning device based on Kubernetes, and the device is configured in a detection coordinator; the detection coordinator, a vulnerability scanner, and a Web application are in a running unit, i.e., a Kubernetes Pod. The device includes:
[0010] A task creation module, configured to send a vulnerability scanning task creation request to a vulnerability detection software management center if a vulnerability scanning trigger event is detected;
[0011] A parameter acquisition module, configured to, after the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software management center to obtain scanning parameters;
[0012] A vulnerability scanning module, configured to control the vulnerability scanner to perform vulnerability scanning on the Web application according to the scanning parameters.
[0013] In one embodiment, the embodiment of the present application provides an electronic device, characterized in that the electronic device includes:
[0014] One or more processors;
[0015] A memory, configured to store one or more programs;
[0016] When the one or more programs are executed by the one or more processors, the one or more processors implement the Kubernetes-based web vulnerability scanning method according to any embodiment of the present application.
[0017] In one embodiment, the embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the Kubernetes-based web vulnerability scanning method according to any embodiment of the present application. Description of the Drawings
[0018] Figure 1 is a flowchart of the Kubernetes-based web vulnerability scanning method provided by an embodiment of the present application;
[0019] Figure 2 is a flowchart of the Kubernetes-based web vulnerability scanning method provided by another embodiment of the present application;
[0020] Figure 3 is a block diagram of the structure of the Kubernetes-based web vulnerability scanning device provided by an embodiment of the present application;
[0021] Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0022] The following further elaborates on this application in embodiments in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are merely for explaining this application and not for limiting this application. Additionally, it should be noted that for ease of description, only parts related to this application rather than all structures are shown in the drawings.
[0023] Figure 1 It is a flowchart of a web vulnerability scanning method based on Kubernetes provided by an embodiment of this application. This embodiment is applicable to the scenario of web application vulnerability scanning running on Kubernetes. This method can be executed by the web vulnerability scanning device based on Kubernetes provided by the embodiments of this application. This device is configured in the detection coordinator, and the detection coordinator, the vulnerability scanner, and the web application are in a running unit Kubernetes Pod. This device can be implemented in software and / or hardware and can be integrated into an electronic device.
[0024] As Figure 1 shown, the web vulnerability scanning method based on Kubernetes provided in the embodiments of this application may include the following steps:
[0025] S110. If a vulnerability scanning trigger event is detected, a vulnerability scanning task creation request is sent to the vulnerability detection software control center.
[0026] Among them, the vulnerability scanning trigger event refers to the event that the web application starts successfully. In the embodiments of this application, the detection coordinator continuously monitors the startup status of the web application. If it detects that the web application starts successfully, a vulnerability scanning task creation request is sent to the vulnerability detection software control center.
[0027] Monitoring the startup status of the web application means determining whether the process from the image to the service is normally started. If it is normally started, it indicates that the web application starts successfully.
[0028] After receiving the vulnerability scanning task creation request, the vulnerability detection software control center creates a vulnerability scanning task in the form of an API.
[0029] S120. After the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters.
[0030] After the vulnerability scanning task is successfully created, the detection coordinator controls the vulnerability scanner to register with the vulnerability detection software control center and receives the scanning parameters issued by the vulnerability detection software control center.
[0031] Scan parameters refer to the parameters used to guide a vulnerability scanner during scanning. In the embodiments of the present application, the scan parameters may be an API-KEY and a scan target.
[0032] S130. According to the scan parameters, control the vulnerability scanner to perform a vulnerability scan on the Web application.
[0033] After the detection coordinator receives the scan parameters issued by the vulnerability detection software control center, based on the scan parameters, control the vulnerability scanner to perform a vulnerability scan on the Web application.
[0034] In the embodiments of the present application, the vulnerability scanner may be an AWVS scanner, and the content of the vulnerability scan on the Web application is limited to the scope supported by the AWVS scanner.
[0035] In the embodiments of the present application, after controlling the vulnerability scanner to perform a vulnerability scan on the Web application according to the scan parameters, the method further includes:
[0036] Report the vulnerability scan results to the vulnerability detection software control center through the vulnerability scanner.
[0037] Among them, the vulnerability scan results may include the id of the scan target, the form of the vulnerability scan, vulnerability information, and suggestions on how to repair the vulnerabilities.
[0038] In the embodiments of the present application, the vulnerability scan of the Web application running on Kubernetes is completed through the following method. The method includes: if a vulnerability scan trigger event is detected, send a vulnerability scan task creation request to the vulnerability detection software control center; after the vulnerability scan task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scan parameters; according to the scan parameters, control the vulnerability scanner to perform a vulnerability scan on the Web application. In the embodiments of the present application, by embedding "sidecar containers" such as a vulnerability scanner and a detection coordinator in the running unit Pod, the containers within the Pod can use the shared Network Namespace mechanism, enabling the vulnerability scanner to directly access the Web application locally to detect vulnerabilities in the Web application, without occupying the Kubernetes cluster ingress bandwidth and without affecting the stability of other business running units (Kubernetes Pods).
[0039] Figure 2 It is a flowchart of a Kubernetes-based web vulnerability scanning method provided by another embodiment of the present application. This embodiment is optimized based on the above embodiment, and the specific optimizations are as follows:
[0040] S210. Obtain the runtime metadata of the running unit where it is located and the runtime metadata of the running unit where the Web application is located to achieve communication with the Web application.
[0041] The detection coordinator automatically reads the runtime metadata of its running unit from the environment variables by using the Kubernetes Downward API mechanism. Here, the running unit where it is located refers to the Kubernetes Pod where the detection coordinator is located. The runtime metadata of the running unit can be the Pod name, IP, and Namespace.
[0042] The containers within the Pod can communicate by sharing the Network Namespace. The detection coordinator determines whether it and the Web application are in the same Pod by obtaining the Namespace of the Pod where it is located and the Namespace of the Pod where the Web application is located. If the two obtained Namespaces are the same, the detection coordinator and the Web application are in the same Pod. At this time, the detection coordinator and the Web application can communicate, and then the detection coordinator can continuously detect whether the Web application has started and control the vulnerability scanner to perform vulnerability scanning on the Web application.
[0043] The Pod IP address is also the IP address of the Web application within the Pod. After the detection coordinator and the Web application achieve communication, the detection coordinator can control the vulnerability scanner to access the Web application and perform vulnerability scanning based on the Pod IP.
[0044] S220. If a vulnerability scanning trigger event is detected, send a vulnerability scanning task creation request to the vulnerability detection software control center.
[0045] S230. After the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters.
[0046] S240. Control the vulnerability scanner to perform vulnerability scanning on the Web application according to the scanning parameters.
[0047] In the embodiment of the present application, the vulnerability scanning of the Web application running on Kubernetes is completed through the following method. The method includes: obtaining the running metadata of the running unit where it is located and the running metadata of the running unit where the Web application is located to realize communication with the Web application; if a vulnerability scanning trigger event is detected, sending a vulnerability scanning task creation request to the vulnerability detection software control center; after the vulnerability scanning task is successfully created, controlling the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters; and according to the scanning parameters, controlling the vulnerability scanner to perform vulnerability scanning on the Web application. Through the above technical solution, the running metadata of the Kubernetes Pod and the parameters required for vulnerability scanning can be automatically obtained, avoiding the limitations of manual query and configuration. At the same time, through the mechanism of sharing the Network Namespace by the containers in the Pod, the traffic detected by the vulnerability scanner can directly access the Web application locally to perform vulnerability detection on the Web application, without occupying the Kubernetes cluster entry bandwidth and without affecting the stability of other business running units (Kubernetes Pods).
[0048] The following is the code provided by the embodiment of the present application. The code includes processes such as reading the targets in the environment variables, determining whether the Web application is started, vulnerability scanning, and returning the scanning results. The code is as follows:
[0049]
[0050]
[0051]
[0052]
[0053]
[0054]
[0055] Figure 3 It is a structural block diagram of a Web vulnerability scanning device based on Kubernetes provided by an embodiment of the present application. The device can execute the Web vulnerability scanning method based on Kubernetes provided by any embodiment of the present application, and has corresponding functional modules and beneficial effects for executing the method. As Figure 3 shown, the device may include:
[0056] A task creation module 310, configured to send a vulnerability scanning task creation request to the vulnerability detection software control center if a vulnerability scanning trigger event is detected.
[0057] A parameter acquisition module 320, configured to control a vulnerability scanner to register with a vulnerability detection software management center after a vulnerability scanning task is successfully created, so as to obtain scanning parameters.
[0058] A vulnerability scanning module 330, configured to control a vulnerability scanner to perform vulnerability scanning on a Web application according to the scanning parameters.
[0059] In an embodiment of the present application, the device further includes:
[0060] A communication establishment module, configured to obtain runtime metadata of the operating unit where it is located and runtime metadata of the operating unit where the Web application is located, so as to establish communication with the Web application.
[0061] In an embodiment of the present application, the runtime metadata of the operating unit where it is located includes the name, IP, and Namespace of the operating unit where it is located.
[0062] In an embodiment of the present application, the task creation module 310 is specifically configured to:
[0063] Continuously monitor the startup status of the web application. If it is detected that the web application has started successfully, a vulnerability scanning task creation request is sent to the vulnerability detection software management center.
[0064] In an embodiment of the present application, the scanning parameters include an API-KEY and a scanning target.
[0065] In an embodiment of the present application, the device further includes:
[0066] A result reporting module, configured to report the vulnerability scanning result to the vulnerability detection software management center through the vulnerability scanner.
[0067] The above product can execute the Kubernetes-based web vulnerability scanning method provided by the embodiments of the present application, and has function modules and beneficial effects corresponding to the execution of the method.
[0068] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Figure 4 The block diagram of an exemplary electronic device 412 suitable for implementing the embodiments of the present application is shown. Figure 4 The shown electronic device 412 is only an example, and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0069] As Figure 4As shown, the electronic device 412 may include: one or more processors 416; a memory 428 for storing one or more programs, which when executed by the one or more processors 416 cause the one or more processors 416 to implement the Kubernetes-based Web vulnerability scanning method provided by the embodiments of the present application, including:
[0070] If a vulnerability scanning trigger event is detected, a vulnerability scanning task creation request is sent to the vulnerability detection software control center;
[0071] After the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters;
[0072] According to the scanning parameters, control the vulnerability scanner to perform a vulnerability scan on the Web application.
[0073] The components of the electronic device 412 may include, but are not limited to: one or more processors 416, a memory 428, and a bus 418 connecting different device components (including the memory 428 and the processor 416).
[0074] The bus 418 represents one or more of several types of bus architectures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus architectures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Processor ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0075] The electronic device 412 typically includes a variety of computer device-readable storage media. These storage media can be any available storage media accessible to the electronic device 412, including volatile and non-volatile storage media, removable and non-removable storage media.
[0076] The memory 428 may include computer device-readable storage media in the form of volatile memory, such as random access memory (RAM) 430 and / or cache memory 432. The electronic device 412 may further include other removable / non-removable, volatile / non-volatile computer device storage media. By way of example only, the storage system 434 may be used for reading and writing non-removable, non-volatile magnetic storage media ( Figure 4 not shown, commonly referred to as a "hard disk drive"). Although Figure 4Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical storage medium) may be provided. In these cases, each drive may be connected to the bus 418 through one or more data storage medium interfaces. The memory 428 may include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present application.
[0077] A program / utilities 440 having a set (at least one) of program modules 442 may be stored, for example, in the memory 428. Such program modules 442 include, but are not limited to, an operating device, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 442 generally perform the functions and / or methods in the embodiments described in the present application.
[0078] The electronic device 412 may also communicate with one or more external devices 414 and / or a display 424, etc., and may also communicate with one or more devices that enable a user to interact with the electronic device 412, and / or communicate with any device that enables the electronic device 412 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 422. Moreover, the electronic device 412 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN) and / or a public network, such as the Internet) through a network adapter 420. As Figure 4 shown, the network adapter 420 communicates with other modules of the electronic device 412 through the bus 418. It should be understood that although Figure 4 not shown in the figure, other hardware and / or software modules may be used in combination with the electronic device 412, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID devices, tape drives, and data backup storage devices, etc.
[0079] The processor 416 executes various functional applications and data processing by running at least one of multiple programs stored in the memory 428, for example, implementing the Kubernetes-based Web vulnerability scanning method provided by the embodiments of the present application.
[0080] An embodiment of the present application provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute the Kubernetes-based Web vulnerability scanning method provided by the embodiments of the present application when executed by a computer processor, including:
[0081] If a vulnerability scanning trigger event is detected, a request for creating a vulnerability scanning task is sent to the vulnerability detection software control center;
[0082] After the vulnerability scanning task is successfully created, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters;
[0083] According to the scanning parameters, control the vulnerability scanner to perform vulnerability scanning on the Web application.
[0084] The computer storage medium of the embodiments of the present application may adopt any combination of one or more computer-readable storage media. The computer-readable storage medium may be a computer-readable signal storage medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device, apparatus, or component, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiments of the present application, the computer-readable storage medium may be any tangible storage medium that contains or stores a program, and the program may be used by or in combination with an instruction execution device, apparatus, or component.
[0085] The computer-readable signal storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal storage medium may also be any computer-readable storage medium other than the computer-readable storage medium, and the computer-readable storage medium may send, propagate, or transmit a program for use by or in combination with an instruction execution device, apparatus, or component.
[0086] The program code contained on the computer-readable storage medium may be transmitted using any appropriate storage medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0087] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or device. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0088] Note that the above is only the preferred embodiment of this application and the technical principles applied. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein. Various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of this application. Therefore, although this application has been described in more detail through the above embodiments, this application is not limited to the above embodiments. Without departing from the concept of this application, more other equivalent embodiments can be included, and the scope of this application is determined by the scope of the appended claims.
Claims
1. A Web vulnerability scanning method based on Kubernetes, characterized in that, the method is executed by a detection coordinator, and the detection coordinator, the vulnerability scanner, and the Web application are in a running unit Kubernetes Pod; the method includes: Obtain the running state metadata of the running unit where it is located, and the running state metadata of the running unit where the Web application is located. Among them, the running state metadata of the running unit where it is located includes the name, IP, and Namespace of the running unit where it is located, and obtain the Namespace of the running unit where it is located and the Namespace of the running unit where the Web application is located. If the two obtained Namespaces are the same, it is determined that it is in the same running unit as the Web application to achieve communication with the Web application; If a vulnerability scanning trigger event is detected, send a vulnerability scanning task creation request to the vulnerability detection software control center; After the vulnerability scanning task creation is successful, control the vulnerability scanner to register with the vulnerability detection software control center to obtain scanning parameters; According to the scanning parameters, control the vulnerability scanner to perform a vulnerability scan on the Web application.
2. The method according to claim 1, characterized in that, the step of if a vulnerability scanning trigger event is detected, send a vulnerability scanning task creation request to the vulnerability detection software control center, includes: Continuously monitor the startup status of the web application. If it is detected that the web application has started successfully, send a vulnerability scanning task creation request to the vulnerability detection software control center.
3. The method according to claim 1, characterized in that, the scanning parameters include API-KEY and the scanning target.
4. The method according to claim 1, characterized in that, after controlling the vulnerability scanner to perform a vulnerability scan on the Web application according to the scanning parameters, the method further includes: Report the vulnerability scanning results to the vulnerability detection software control center through the vulnerability scanner.
5. A Web vulnerability scanning device based on Kubernetes, characterized in that, the device is configured in a detection coordinator; the detection coordinator, the vulnerability scanner, and the Web application are in a running unit Kubernetes Pod; the device includes: A communication establishment module, which is used to obtain the running state metadata of the running unit where it is located, and the running state metadata of the running unit where the Web application is located. Among them, the running state metadata of the running unit where it is located includes the name, IP, and Namespace of the running unit where it is located, and obtain the Namespace of the running unit where it is located and the Namespace of the running unit where the Web application is located. If the two obtained Namespaces are the same, it is determined that it is in the same running unit as the Web application to achieve communication with the Web application; A task creation module, which is used to send a vulnerability scanning task creation request to the vulnerability detection software control center if a vulnerability scanning trigger event is detected; A parameter acquisition module, which is used to control the vulnerability scanner to register with the vulnerability detection software control center after the vulnerability scanning task is successfully created, so as to obtain scanning parameters; A vulnerability scanning module, which is used to control the vulnerability scanner to perform vulnerability scanning on the Web application according to the scanning parameters.
6. An electronic device, characterized in that, the electronic device includes: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the Kubernetes-based Web vulnerability scanning method according to any one of claims 1-4.
7. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the program is executed by a processor, it implements the Kubernetes-based Web vulnerability scanning method according to any one of claims 1-4.
Citation Information
Patent Citations
Method for realizing flow control of Pod network in Kubernetes
CN111371696A
Method for capturing network flow and Kubernetes cluster
CN111901203A