A method and device for secure scanning of images

By disassembling the mirror layer tasks between the cluster management server and the business processing node and utilizing multi-threaded parallel scanning, the problem of slow traditional mirror scanning is solved, and more efficient mirror security scanning is achieved.

CN114065226BActive Publication Date: 2025-05-30BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111444777.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-05-30
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

The traditional container image scanning method is divided into multiple layers and contains a large number of files, resulting in slow scanning speed and low efficiency.

Method used

The cluster management server obtains the user's mirror security scan task and determines whether there is a scan result in the database. If it does not exist, the task is disassembled into multiple mirror layer scanning tasks, and these tasks are distributed to multiple business processing nodes, and security scans are performed in parallel using multiple threads.

Benefits of technology

By disassembling the mirror layer tasks and utilizing multi-threaded parallel scanning, the reading time of the mirror file is significantly shortened and the speed and efficiency of mirror scanning is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114065226B_ABST
    Figure CN114065226B_ABST
Patent Text Reader

Abstract

The present application provides a method and apparatus for secure scanning of images. The method is applied to a distributed cluster system, which includes multiple service processing nodes and a cluster management server that communicates with the multiple service processing nodes. The method includes the cluster management server obtaining a secure image scanning task, determining whether there is a corresponding scanning result for the target image in the image security scanning task in the database. If not, the image security scanning task is disassembled into multiple image layer scanning tasks in units of image layers, and the multiple image layer scanning tasks are sent to at least one target service processing node among the multiple service processing nodes. Each target service processing node reads the corresponding image layer scanning content according to the identification information of the image layer in the received image layer scanning task, disassembles it into multiple scanning subtasks, and performs parallel security scanning on the multiple scanning subtasks using multiple threads, thereby reducing the reading and scanning time of the image file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to a method and device for secure scanning of images. Background Art

[0002] In traditional deployment methods, applications rely on the environment in the operating system. To solve the problems brought about by the different requirements of multiple applications for the running environment, containerized deployment was introduced. Containers install the required environment for running, and developers are required to package their application programs and their required dependencies into container images. Containers are started based on the images, but in fact, the images are opaque. They are encapsulated and built based on the base image again and again. As the images are built more and more times, the content of the images becomes more and more complex. Therefore, more and more vulnerabilities will accumulate in the image files.

[0003] For the above reasons, the container image scanning function has become an essential function for container security. However, because the image is divided into multiple layers and may contain a large number of files, the traditional layer-by-layer scanning method has the problems of slow scanning speed and low efficiency. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a method and device for secure scanning of images to solve the above problems.

[0005] In a first aspect, the present invention provides a method for secure scanning of images, which is applied to a distributed cluster system. The distributed cluster system includes multiple service processing nodes and a cluster management server that communicates with the multiple service processing nodes. This method is executed by the cluster management server and includes: obtaining a mirror security scanning task selected by the user terminal, where the mirror security scanning task includes the mirror layer information of the target mirror; determining whether there is a corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database; if not, decomposing the mirror security scanning task into multiple mirror layer scanning tasks in units of mirror layers, where each mirror layer scanning task contains the identification information of at least one mirror layer of the target mirror, and the identification information of the mirror layers included in different mirror layer scanning tasks is different; and sending the multiple mirror layer scanning tasks to at least one target service processing node among the multiple service processing nodes, so that each target service processing node obtains the corresponding mirror layer scanning content according to the identification information of the mirror layer in the received mirror layer scanning task, and splits the obtained mirror layer scanning content into multiple scanning subtasks, thereby performing parallel security scanning on the multiple scanning subtasks using multiple threads.

[0006] In the above-described mirror security scanning method of the design, this solution uses a cluster management server to obtain a mirror security scanning task sent by a client. Then, based on the fact that there is no scanning result of the target mirror corresponding to the mirror security scanning task in the database, the mirror security scanning task is disassembled into multiple mirror layer scanning tasks in units of mirror layers. Each mirror layer scanning task includes at least one mirror layer identifier. Finally, the multiple mirror layer scanning tasks are sent to at least one target service processing node among multiple service processing nodes, so that each target service processing node obtains the mirror scanning content of the corresponding mirror layer identifier based on the received scanning task, then splits the mirror scanning content into multiple scanning subtasks, and uses multi-threading to perform security scanning on the multiple scanning subtasks in parallel, realizing the disassembly of the mirror security scanning tasks of multiple mirror layers, using the target service processing node to simultaneously read the disassembled mirror layer content, and splitting it into multiple scanning subtasks to perform scanning simultaneously, thereby greatly reducing the reading time of the mirror file and improving the speed of mirror scanning.

[0007] In an optional implementation manner of the first aspect, before sending the multiple mirror layer scanning tasks to at least one target service processing node among the multiple service processing nodes, the method further includes: obtaining the status information reported by each service processing node; determining the service processing nodes with the current status being idle according to the status information reported by each service processing node; and determining the target service processing node according to the service processing nodes with the current status being idle.

[0008] In an optional implementation manner of the first aspect, determining the target service processing node according to the service processing nodes with the current status being idle includes: obtaining the number of target service processing nodes and the number of scanning tasks; determining whether the number of target service processing nodes is less than the number of mirror layer scanning tasks; if not less, then assigning one mirror layer scanning task to one target service processing node.

[0009] In an optional implementation manner of the first aspect, after determining whether the number of target service processing nodes is less than the number of mirror layer scanning tasks, the method further includes: if the number of target service processing nodes is less than the number of mirror layer scanning tasks, then determining the number of mirror layer scanning tasks assigned to each target service processing node according to the number of mirror layer scanning tasks and the number of target service processing nodes.

[0010] In an optional implementation manner of the first aspect, after determining whether there is a corresponding scanning result of the target mirror corresponding to the mirror security scanning task in the database, the method further includes: if there is a corresponding scanning result of the target mirror corresponding to the security scanning task in the database, then returning the scanning result of the target mirror corresponding to the security scanning task to the client.

[0011] In an alternative embodiment of the first aspect, the mirror security scan person also includes a mirror identifier of the target mirror. Determining whether there is a corresponding scan result for the target mirror corresponding to the mirror security scan task in the database includes: determining whether a scan result with the mirror identifier of the target mirror is found in the database.

[0012] In a second aspect, the present invention provides a mirror security scanning device applied to a distributed cluster system. The distributed cluster system includes a plurality of service processing nodes and a cluster management server communicating with the plurality of service processing nodes. The device is disposed in the cluster management server and includes: an acquisition module for acquiring a mirror security scan task selected by a user terminal, where the mirror security scan task includes mirror layer information of a target mirror; a judgment module for judging whether there is a corresponding scan result for the target mirror corresponding to the mirror security scan task in the database; a decomposition module for, after there is no corresponding scan result in the database, decomposing the mirror security scan task into a plurality of mirror layer scan tasks in units of mirror layers, where each mirror layer scan task includes identification information of at least one mirror layer of the target mirror, and the identification information of the mirror layers included in different mirror layer scan tasks is different; and a sending module for sending the plurality of mirror layer scan tasks to at least one target service processing node among the plurality of service processing nodes, so that each target service processing node obtains corresponding mirror layer scan content according to the identification information of the mirror layer in the received mirror layer scan task, and splits the obtained mirror layer scan content into a plurality of scan subtasks, thereby performing security scanning on the plurality of scan subtasks in parallel using multiple threads.

[0013] In the mirror security scanning device designed above, this solution uses the cluster management server to obtain the mirror security scan task sent by the user terminal, and then, based on the fact that there is no scan result for the target mirror corresponding to the mirror security scan task in the database, decomposes the mirror security scan task into a plurality of mirror layer scan tasks in units of mirror layers. Each mirror layer scan task includes at least one mirror layer identifier. Finally, the plurality of mirror layer scan tasks are sent to at least one target service processing node among the plurality of service processing nodes, so that each target service processing node obtains the mirror scan content corresponding to the mirror layer identifier based on the received scan task, then splits the mirror scan content into a plurality of scan subtasks, and performs security scanning on the plurality of scan subtasks in parallel using multiple threads, realizing the decomposition of the mirror security scan task of multiple mirror layers, using the target service processing node to simultaneously read the decomposed mirror layer content, and splitting it into a plurality of scan subtasks to perform scanning simultaneously, thereby greatly reducing the reading time of the mirror file and improving the speed of mirror scanning.

[0014] In an alternative embodiment of the second aspect, the obtaining module is further configured to obtain the status information reported by each service processing node; the apparatus further includes a determining module, configured to determine, according to the status information reported by each service processing node, the service processing nodes whose current status is idle; and determine the target service processing node according to the service processing nodes whose current status is idle.

[0015] In an alternative embodiment of the second aspect, the determining module is specifically configured to obtain the number of target service processing nodes and the number of scanning tasks; determine whether the number of target service processing nodes is less than the number of image layer scanning tasks; if not less, assign one image layer scanning task to one target service processing node.

[0016] In an alternative embodiment of the second aspect, the determining module is further specifically configured to, if the number of target service processing nodes is less than the number of image layer scanning tasks, determine the number of image layer scanning tasks assigned to each target service processing node according to the number of image layer scanning tasks and the number of target service processing nodes.

[0017] In an alternative embodiment of the second aspect, the sending module is further configured to, after determining that the scanning result corresponding to the target image of the security scanning task exists in the database, return the scanning result of the target image corresponding to the security scanning task to the client.

[0018] In an alternative embodiment of the second aspect, the image security scanning task further includes the image identifier of the target image, and the determining module is specifically configured to determine whether a scanning result with the image identifier of the target image is found in the database.

[0019] In a third aspect, the present invention provides a method for security scanning of an image, which is applied to a distributed cluster system. The distributed cluster system includes a plurality of service processing nodes and a cluster management server communicating with the plurality of service processing nodes. The method is executed by the service processing node and includes: receiving at least one image layer scanning task sent by the cluster management server, where each image layer scanning task includes the identification information of at least one image layer, and the image layer scanning task is obtained by the cluster management server decomposing the selected image security scanning task in units of image layers when the scanning result corresponding to the target image of the image security scanning task does not exist in the database; obtaining the corresponding image layer scanning content according to the identification information of the image layer of each image layer scanning task; splitting each image layer scanning content into corresponding multiple scanning subtasks; and performing parallel security scanning on the multiple scanning subtasks by using the created multiple threads.

[0020] In the above-described mirror security scanning method of the design, this solution uses the target processing node to obtain the mirror layer scanning content according to the mirror layer identification information in the received mirror layer scanning task, then splits the mirror layer scanning content into multiple scanning subtasks, and then uses multiple threads to perform parallel security scanning on the multiple scanning subtasks, achieving parallel reading of each mirror layer in the target mirror of the mirror security scanning task, and splitting the scanning content of each mirror layer into multiple scanning subtasks for parallel security scanning, thereby greatly reducing the reading time of the mirror file and improving the speed of mirror scanning.

[0021] In an alternative implementation manner of the third aspect, after using the created multiple threads to perform parallel security scanning on the multiple scanning subtasks, the method further includes: obtaining the scanning results completed by each thread; integrating the scanning results of all threads to obtain the scanning result of the corresponding mirror layer scanning task; and reporting the scanning result of the corresponding mirror layer scanning task to the cluster management server.

[0022] In a fourth aspect, the present invention provides a mirror security scanning device applied to a distributed cluster system. The distributed cluster system includes multiple service processing nodes and a cluster management server communicating with the multiple service processing nodes. The device is disposed on the service processing node and includes: a receiving module, configured to receive at least one mirror layer scanning task sent by the cluster management server, where each mirror layer scanning task includes identification information of at least one mirror layer, and the mirror layer scanning task is obtained by the cluster management server decomposing the selected mirror security scanning task in units of mirror layers when there is no corresponding scanning result in the database for the target mirror corresponding to the mirror security scanning task; a second obtaining module, configured to obtain the corresponding mirror layer scanning content according to the identification information of the mirror layer of each mirror layer scanning task; a splitting module, configured to split the scanning content of each mirror layer into corresponding multiple scanning subtasks; and a scanning module, configured to use the created multiple threads to perform parallel security scanning on the multiple scanning subtasks.

[0023] In the above-described mirror security scanning device of the design, this solution uses the target processing node to obtain the mirror layer scanning content according to the mirror layer identification information in the received mirror layer scanning task, then splits the mirror layer scanning content into multiple scanning subtasks, and then uses multiple threads to perform parallel security scanning on the multiple scanning subtasks, achieving parallel reading of each mirror layer in the target mirror of the mirror security scanning task, and splitting the scanning content of each mirror layer into multiple scanning subtasks for parallel security scanning, thereby greatly reducing the reading time of the mirror file and improving the speed of mirror scanning.

[0024] In an alternative implementation of the fourth aspect, the second acquisition module is further configured to acquire the scanning results of each thread after the scanning is completed; the integration module is configured to integrate the scanning results of all threads to obtain the scanning results of the corresponding image layer scanning task; and the reporting module is configured to report the scanning results of the corresponding image layer scanning task to the cluster management server.

[0025] In a fifth aspect, the present application provides an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it executes the method in the first aspect, any optional implementation manner of the first aspect, or the third aspect, any optional implementation manner of the third aspect.

[0026] In a sixth aspect, the present application provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, it executes the method in the first aspect, any optional implementation manner of the first aspect, or the third aspect, any optional implementation manner of the third aspect.

[0027] In a seventh aspect, the present application provides a computer program product. When the computer program product runs on a computer, it causes the computer to execute the method in the first aspect, any optional implementation manner of the first aspect, or the third aspect, any optional implementation manner of the third aspect. Description of the Drawings

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0029] Figure 1 It is an example structure diagram of a distributed cluster system provided by an embodiment of the present application;

[0030] Figure 2 It is the first flowchart of the security scanning method for an image provided by an embodiment of the present application;

[0031] Figure 3 It is the second flowchart of the security scanning method for an image provided by an embodiment of the present application;

[0032] Figure 4 It is the third flowchart of the security scanning method for an image provided by an embodiment of the present application;

[0033] Figure 5 It is the fourth flowchart of the security scanning method for an image provided by an embodiment of the present application;

[0034] Figure 6 Schematic structural diagram of the first security scanning device for images provided by an embodiment of the present application;

[0035] Figure 7 Schematic structural diagram of the second security scanning device for images provided by an embodiment of the present application;

[0036] Figure 8 Schematic structural diagram of an electronic device provided by an embodiment of the present application.

[0037] Icons: 10 - Cluster management server; 20 - Service processing node; 30 - Client; 40 - Database; 500 - Acquisition module; 510 - Judgment module; 520 - Decomposition module; 530 - Sending module; 540 - Determination module; 600 - Receiving module; 610 - Second acquisition module; 620 - Splitting module; 630 - Scanning module; 640 - Integration module; 650 - Reporting module; 7 - Electronic device; 701 - Processor; 702 - Memory; 703 - Communication bus. Detailed implementation manners

[0038] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the accompanying drawings in the embodiments of the present application.

[0039] An embodiment of the present application provides a distributed cluster system, as Figure 1 shown. The distributed cluster system includes a cluster management server 10, multiple service processing nodes 20, a client 30, and a database 40. The cluster management server 10 can communicate with the client 30, multiple service processing nodes 20, and the database 40. Among them, the client 30 is used for user operations. For example, a user can select a target image that needs to be scanned for security on the client 30, thereby generating and sending an image security scanning task to the cluster management server 10. The cluster management server performs a security scan on the target image selected by the user and returns the scan result to the client 30. The multiple service processing nodes 20 can scan the obtained scanning tasks using the configured solution. For example, the service processing node 20 can perform a parallel security scan on multiple scanned subtasks after splitting the scanning task in a multi-threaded manner. Among them, the security scan refers to scanning and checking for security risks in the image file. The database 40 stores the scan results of the images that have been scanned and completed. The cluster management server 10 can determine whether a corresponding scan result can be found for the target image in the database. Among them, the security image scanning task includes the name of the target image, the image ID that serves as the unique identifier of the target image, and the image layer information of the target image, etc. The cluster management server can distinguish different images according to the unique identifier of the image. It should be noted here that the foregoing image is a form of file storage and is a type of redundancy. A complete copy of the data on one disk exists on another disk, which is the image.

[0040] Based on the above-designed distributed cluster system, an embodiment of the present application provides a method for secure scanning of images. This method for secure scanning of images can accelerate the scanning of images, thereby improving the efficiency of image scanning. As Figure 2 shown, the method for secure scanning of images includes:

[0041] Step S100: The cluster management server obtains the image security scanning task selected by the user.

[0042] Step S110: The cluster management server determines whether there is a corresponding scanning result for the target image corresponding to the image security scanning task in the database. If so, go to step S170; if not, go to step S120.

[0043] Step S120: The cluster management server decomposes the image security scanning task into multiple image layer scanning tasks in units of image layers.

[0044] Step S130: The cluster management server sends multiple image layer scanning tasks to at least one target business processing node among multiple business processing nodes.

[0045] Step S140: Each target business processing node obtains the corresponding image layer scanning content according to the identification information of the image layer in the received image layer scanning task.

[0046] Step S150: Each target business processing node splits the obtained image layer scanning content into multiple scanning subtasks.

[0047] Step S160: Each target business processing node performs parallel security scanning on the multiple split scanning subtasks by using multiple created threads.

[0048] Step S170: Return the scanning result corresponding to the target image to the client.

[0049] In step S100, the user can select the target image to be scanned on the client, thereby sending an image security scanning task to the cluster management server. As mentioned above, the image security scanning task contains the unique identifier of the target image, i.e., the target image ID, the name of the target image, and the image layer information of the target image, etc.

[0050] Based on the above, the cluster management server can obtain the mirror security scanning task selected by the client, and then execute step S110. The cluster management server determines whether there is a corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database. If there is a corresponding scanning result for the target mirror in the database, then step S170 is executed to directly return the scanning result corresponding to the target mirror to the client; if there is no corresponding scanning result for the target mirror in the database, then step S120 is executed.

[0051] As a possible implementation, the cluster management server can search in the database according to the mirror identifier of the target mirror to check whether there is a scanning result with this mirror identifier. If found, it means that there is a corresponding scanning result for the target mirror in the database; if not found, it means that there is no corresponding scanning result for the target mirror in the database.

[0052] In S120, the mirror security scanning task obtained as described above includes the mirror layer information of the target mirror, which may include the number of mirror layers of the target mirror and each mirror layer has a corresponding mirror layer identifier. Based on this, the cluster management server decomposes the mirror security scanning task into multiple mirror layer scanning tasks in units of mirror layers. Specifically, the cluster management server can create a mirror layer scanning task for each mirror layer identifier; as another possible implementation, the cluster management server can also create a mirror layer scanning task with a certain number of mirror layer identifiers. For example, create a mirror layer scanning task with two mirror layer identifiers, etc.

[0053] Among them, the number of mirror layer identifiers of the mirror layer in each mirror layer scanning task of the solution of this application can be specifically set according to the situation. For example, in the case where the number of mirror layers of the mirror is small, this solution can set that each mirror layer scanning task includes one mirror layer identifier; when the number of mirror layers of the mirror is large (such as more than one hundred but not more than 127 layers, where the upper limit of the number of mirror layers is 127), this solution can set that each mirror layer scanning task includes multiple (such as 5) mirror layer identifiers. Among them, the above specific numerical examples are only for the convenience of understanding this solution and are not specific limitations on this solution.

[0054] Based on the cluster management server obtaining multiple mirror layer scanning tasks, the cluster management server can send the multiple mirror layer scanning tasks to at least one target service processing node among multiple service processing nodes.

[0055] Among them, before sending, as a possible implementation, as Figure 3 shown, the cluster management server can determine the target service processing node among multiple service processing nodes in the following manner, including:

[0056] Step S200: The cluster management server obtains the status information reported by each business processing node.

[0057] Step S210: The cluster management server determines the business processing nodes with the current status being idle based on the status information reported by each business processing node.

[0058] Step S220: The cluster management server determines the target business processing nodes based on the business processing nodes with the current status being idle.

[0059] In the above embodiment, each business processing node can automatically report its own status information to the cluster management server. Among them, the status information of the business processing node can be idle or busy. In such a case, the cluster management server can know the current status of each business processing node, so as to determine all the business processing nodes with the current status being idle as the target business processing nodes.

[0060] Based on the above determination of the target business processing nodes, as a possible implementation manner, the following method can be used to determine the number of scanning tasks required to be processed by each target business processing node, as Figure 4 shown, including:

[0061] Step S300: The cluster management server obtains the number of target business processing nodes and the number of image layer scanning tasks.

[0062] Step S310: The cluster management server determines whether the number of target business processing nodes is less than the number of image layer scanning tasks. If so, go to Step S320; if not, go to Step S330.

[0063] Step S320: The cluster management server determines the number of image layer scanning tasks assigned to each target business processing node according to the number of image layer scanning tasks and the number of target business processing nodes.

[0064] Step S330: The cluster management server assigns one image layer scanning task to one target business processing node.

[0065] In the above embodiments, the cluster management server first obtains the number of target service processing nodes and the number of image layer scanning tasks. If the number of target service processing nodes is greater than or equal to the number of image layer scanning tasks, it means that there are sufficient target service processing nodes to handle the image layer scanning tasks. In such a case, the cluster management server assigns one image layer scanning task to one target service processing node, so that each target service processing node gets an image layer scanning task for security scanning. If the number of target service processing nodes is less than the number of image layer scanning tasks, the cluster management server can determine the number of image layer scanning tasks assigned to each target service processing node in the following multiple ways.

[0066] As a possible implementation, when the number of image layer scanning tasks is an integer multiple of the number of target service processing nodes, the cluster management server can evenly divide the multiple image layer scanning tasks, so that each target service processing node gets the same number of image layer scanning tasks. For example, if the number of split image layer scanning tasks is 6 and the number of idle service processing nodes, i.e., the number of target service processing nodes, is 3 at this time, then the 6 image layer scanning tasks are evenly distributed to the target service processing nodes, so that each target service processing node scans 2 image layer scanning tasks.

[0067] As another possible implementation, regardless of whether the number of image layer scanning tasks is an integer multiple of the number of target service processing nodes, the cluster management server can obtain the processing capabilities of each target service processing node, such as CPU, GPU performance, etc., and then allocate the number of image layer scanning tasks according to the processing capabilities of each target service processing node. The target service processing node with stronger processing capabilities gets more image layer scanning tasks. For example, if the number of split image layer scanning tasks is 6 and the number of idle service processing nodes, i.e., the number of target service processing nodes, is 3 at this time, which are the target service processing node A1, the target service processing node A2, and the target service processing node A3 respectively, and the processing capability of the target service processing node A1 is the strongest, followed by the target service processing node A3, and finally the target service processing node A2. Then, in this solution, 3 image layer scanning tasks can be assigned to the target service processing node A1, 2 image layer scanning tasks can be assigned to the target service processing node A3, and 1 image layer scanning task can be assigned to the target service processing node A2, thus completing the allocation of the image layer scanning tasks.

[0068] After the aforementioned cluster management server sends the image layer scanning task to the target service processing node, each target service processing node executes steps S140 to S160. That is, each target service processing node obtains the corresponding image layer scanning content according to the image layer identifier in the received image layer scanning task. For example, target service processing node A3 receives an image layer scanning task, and the image layer identifier in this image layer scanning task is L1. Then target service processing node A3 reads the image layer scanning content corresponding to image layer identifier L1 according to image layer identifier L1. Among them, the image scanning content can be stored in the cloud or other storage devices, and the target service processing node can obtain it by reading through the network method.

[0069] On the above basis, the target service processing node splits the obtained image layer scanning content into multiple image layer scanning subtasks. Specifically, each target service processing node splits the read image layer scanning content according to the set block size to form scanning subtasks of the block size, and assigns the unique identifier of the image layer corresponding to the image layer scanning content to each scanning subtask of the block size, so that the scanning result can be corresponding to the image layer. For example, target service processing node A3 receives an image layer scanning task, and the two image layer identifiers in this image layer scanning task are L1 and L2 respectively. Target service processing node A3 reads the image layer scanning content corresponding to image layer identifier L1 and the image layer scanning content corresponding to image layer identifier L2 respectively. Then target service processing node A3 splits both image layer scanning contents to form multiple scanning subtasks of the block size. Among them, multiple scanning subtasks corresponding to image layer identifier L1 are all assigned the L1 identifier, and multiple scanning subtasks corresponding to image layer identifier L2 are all assigned the L2 identifier for distinction.

[0070] On the basis of forming multiple scanning subtasks after the above splitting, each target service processing node creates multiple threads on its own node, and uses the created multiple threads to perform parallel and secure scanning on the formed multiple scanning subtasks. Among them, the number of created threads can be the same as or different from the number of splits of the scanning subtasks, and it can be specifically determined according to the actual application.

[0071] In an alternative implementation manner of this embodiment, after the target service processing node uses the created multiple threads to perform secure scanning on the formed multiple scanning subtasks, as Figure 5 shown, the scanning result can be processed in the following manner:

[0072] Step S400: The target service processing node obtains the scanning result of each scanning subtask.

[0073] Step S410: The target service processing node aggregates the scanning results of all scanning subtasks to obtain the scanning result of the corresponding image layer scanning task.

[0074] Step S420: The target service processing node reports the scanning result of the corresponding image layer scanning task obtained by aggregation to the cluster management server.

[0075] Through the implementation method designed above, the cluster management server can obtain the scanning results of each image layer reported by all target service processing nodes, and then aggregate them to obtain the scanning result corresponding to the target image. On this basis, the cluster management server can store the scanning result corresponding to the target image in the database with the target image identifier as the primary key. When the user initiates the same image scanning next time, the scanning result in the database can be directly called, thus avoiding repeated scanning of the same image; in addition, after the cluster management server aggregates the scanning result corresponding to the target image, it can send the scanning result to the user side for display, so that the user can know the scanning result of the target image from the user side.

[0076] In the above-designed image security scanning method, this solution uses the cluster management server to obtain the image security scanning task sent by the user side. Then, based on the fact that there is no scanning result of the target image corresponding to the image security scanning task in the database, the image security scanning task is disassembled into multiple image layer scanning tasks in units of image layers. Each image layer scanning task includes at least one image layer identifier. Finally, the multiple image layer scanning tasks are sent to at least one target service processing node among multiple service processing nodes, so that each target service processing node obtains the image scanning content corresponding to the image layer identifier based on the received scanning task, then splits the image scanning content into multiple scanning subtasks, and uses multi-threading to perform security scanning on the multiple scanning subtasks in parallel, realizing the disassembly of the image security scanning task of multiple image layers, using the target service processing node to simultaneously read the disassembled image layer content, and splitting it into multiple scanning subtasks to perform scanning simultaneously, thus greatly reducing the reading time of the image file and improving the speed of image scanning.

[0077] Figure 6 The schematic structural block diagram of a kind of image security scanning device provided by this application is shown. It should be understood that this device is the same as the above Figures 2 to 5The method embodiment executed by the cluster management server in the embodiment corresponds to the method embodiment executed by the cluster management server, and the steps involved in the method executed by the cluster management server can be executed. The specific functions of the device can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. The device includes at least one software function module that can be stored in the memory in the form of software or firmware or fixed in the operating system (OS) of the device. Specifically, the device includes: an acquisition module 500, which is used to acquire an image security scanning task selected by a user end, and the image security scanning task includes image layer information of a target image; a judgment module 510, which is used to judge whether the target image corresponding to the image security scanning task has a corresponding scanning result in a database; a decomposition module 520, which is used to decompose the image security scanning task into multiple image layer scanning tasks in units of image layers when there is no corresponding scanning result in the database, wherein each image layer scanning task contains identification information of at least one image layer of the target image, and different image layer scanning tasks contain different identification information of the image layers; and a sending module 530, which is used to send the multiple image layer scanning tasks to at least one target business processing node among the multiple business processing nodes, so that each target business processing node obtains the corresponding image layer scanning content according to the identification information of the image layer in the received image layer scanning task, and splits the obtained image layer scanning content into multiple scanning subtasks, thereby using multi-threading to perform security scanning on the multiple scanning subtasks in parallel.

[0078] In the image security scanning device designed above, this scheme uses a cluster management server to obtain an image security scanning task sent by a user terminal, and then, based on the scanning results of the target image that does not correspond to the image security scanning task in the database, the image security scanning task is disassembled into multiple image layer scanning tasks in units of image layers, each image layer scanning task includes at least one image layer identifier, and finally the multiple image layer scanning tasks are sent to at least one target business processing node among multiple business processing nodes, so that each target business processing node obtains the image scanning content corresponding to the image layer identifier based on the received scanning task, and then the image scanning content is split into multiple scanning subtasks, and multiple scanning subtasks are security scanned in parallel using multi-threading, so as to realize the disassembly of image security scanning tasks of multiple image layers, and the target business processing node is used to read the disassembled image layer content at the same time, and split it into multiple scanning subtasks for simultaneous scanning, thereby greatly reducing the reading time of the image file and improving the speed of image scanning.

[0079] In an alternative implementation of this embodiment, the obtaining module 500 is further configured to obtain the status information reported by each service processing node; the apparatus further includes a determining module 540, configured to determine, according to the status information reported by each service processing node, the service processing nodes whose current status is idle; and determine the target service processing nodes according to the service processing nodes whose current status is idle.

[0080] In an alternative implementation of this embodiment, the determining module 540 is specifically configured to obtain the number of target service processing nodes and the number of scanning tasks; determine whether the number of target service processing nodes is less than the number of mirror layer scanning tasks; if not less than, assign one mirror layer scanning task to one target service processing node.

[0081] In an alternative implementation of this embodiment, the determining module 540 is further specifically configured to, if the number of target service processing nodes is less than the number of mirror layer scanning tasks, determine the number of mirror layer scanning tasks assigned to each target service processing node according to the number of mirror layer scanning tasks and the number of target service processing nodes.

[0082] In an alternative implementation of this embodiment, the sending module 530 is further configured to, after determining that the target mirror corresponding to the security scanning task has a corresponding scanning result in the database, return the scanning result of the target mirror corresponding to the security scanning task to the client.

[0083] In an alternative implementation of this embodiment, the mirror security scanning task further includes the mirror identifier of the target mirror, and the determining module 510 is specifically configured to determine whether a scanning result with the mirror identifier of the target mirror is found in the database.

[0084] Figure 7 A schematic structural diagram of another mirror security scanning apparatus provided by the present application is shown. It should be understood that this apparatus is the same as the above Figures 2 to 5The method embodiment executed by the target business processing node in the embodiment corresponds to the method embodiment executed by the target business processing node, and the steps involved in the method executed by the target business processing node can be executed. The specific functions of the device can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. The device includes at least one software function module that can be stored in the memory in the form of software or firmware or solidified in the operating system (OS) of the device. Specifically, the device includes: a receiving module 600, which is used to receive at least one image layer scanning task sent by the cluster management server, wherein each image layer scanning task contains identification information of at least one image layer, and each image layer scanning task is obtained by the cluster management server by decomposing the image security scanning task; a second acquisition module 610, which is used to obtain the corresponding image layer scanning content according to the identification information of the image layer of each image layer scanning task; a splitting module 620, which is used to split each image layer scanning content into corresponding multiple scanning subtasks; and a scanning module 630, which is used to perform parallel security scanning on multiple scanning subtasks using multiple threads created.

[0085] In the image security scanning device designed above, this scheme uses the target processing node to obtain the image layer scanning content according to the image layer identification information in the received image layer scanning task, and then splits the image layer scanning content into multiple scanning subtasks, and then uses multi-threading to perform parallel security scanning on the multiple scanning subtasks, so as to realize parallel reading of each image layer in the target image of the image security scanning task, and disassemble each image layer scanning content into multiple scanning subtasks for parallel security scanning, thereby greatly reducing the reading time of the image file and improving the speed of image scanning.

[0086] In an optional implementation of this embodiment, the second acquisition module 610 is used to obtain the scanning results of each thread scanning; the integration module 640 is used to integrate the scanning results of all threads to obtain the scanning results of the corresponding image layer scanning task; the reporting module 650 is used to report the scanning results of the corresponding image layer scanning task to the cluster management server.

[0087] like Figure 8As shown in the figure, the present application provides an electronic device 7, including: a processor 701 and a memory 702. The processor 701 and the memory 702 are interconnected and communicate with each other through a communication bus 703 and / or other forms of connection mechanisms (not shown). The memory 702 stores a computer program executable by the processor 701. When the computing device runs, the processor 701 executes the computer program to execute the method performed by the cluster management server in any optional implementation manner, such as steps S100 to S130: The cluster management server obtains the mirror security scanning task selected by the user; The cluster management server checks whether there is a corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database. If not, the cluster management server decomposes the mirror security scanning task into multiple mirror layer scanning tasks in units of mirror layers; The cluster management server sends the multiple mirror layer scanning tasks to at least one target service processing node among the multiple service processing nodes.

[0088] Or when executing, execute the method performed by the target service processing node in any optional implementation manner, such as steps S130 to S140: Obtain the corresponding mirror layer scanning content according to the identification information of the mirror layer in the received mirror layer scanning task; Split the obtained mirror layer scanning content into multiple scanning subtasks; Use the created multiple threads to perform parallel security scanning on the split multiple scanning subtasks.

[0089] The present application provides a storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the method performed by the cluster management server or the method performed by the target service processing node in any of the foregoing optional implementation manners.

[0090] Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (abbreviated as SRAM), electrically erasable programmable read-only memory (abbreviated as EEPROM), erasable programmable read-only memory (abbreviated as EPROM), programmable read-only memory (abbreviated as PROM), read-only memory (abbreviated as ROM), magnetic memory, flash memory, a magnetic disk or an optical disc.

[0091] The present application provides a computer program product. When the computer program product runs on a computer, it causes the computer to execute the methods performed by the terminal device or the cloud server in any optional implementation manner.

[0092] In the embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.

[0093] In addition, the units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0094] Furthermore, in each embodiment of the present application, the various functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0095] It should be noted that if the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0096] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.

[0097] The above are only the embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for secure scanning of images, characterized in that, it is applied to a distributed cluster system, the distributed cluster system includes multiple service processing nodes and a cluster management server communicating with the multiple service processing nodes, and the method is executed by the cluster management server, including: Obtain the image security scanning task selected by the client, and the image security scanning task includes the image layer information of the target image; Judge whether the target image corresponding to the image security scanning task has a corresponding scanning result in the database; If not, decompose the image security scanning task into multiple image layer scanning tasks in units of image layers, where each image layer scanning task contains the identification information of at least one image layer of the target image, and the identification information of the image layers contained in different image layer scanning tasks is different; and Send the multiple image layer scanning tasks to at least one target service processing node among the multiple service processing nodes, so that each target service processing node obtains the corresponding image layer scanning content according to the identification information of the image layer in the received image layer scanning task, and splits the obtained image layer scanning content into multiple scanning subtasks, thereby performing security scanning on the multiple scanning subtasks in parallel using multiple threads.

2. The method according to claim 1, characterized in that, before sending the multiple image layer scanning tasks to at least one target service processing node among the multiple service processing nodes, the method further includes: Obtain the status information reported by each service processing node; Determine the service processing nodes with the current status being idle according to the status information reported by each service processing node; and Determine the target service processing nodes according to the service processing nodes with the current status being idle.

3. The method according to claim 2, characterized in that, determining the target service processing nodes according to the service processing nodes with the current status being idle includes: Obtain the number of target service processing nodes and the number of scanning tasks; Judge whether the number of target service processing nodes is less than the number of image layer scanning tasks; If not less, assign one image layer scanning task to one target service processing node.

4. The method according to claim 3, characterized in that, after judging whether the number of target service processing nodes is less than the number of image layer scanning tasks, the method further includes: If the number of target service processing nodes is less than the number of image layer scanning tasks, determine the number of image layer scanning tasks assigned to each target service processing node according to the number of image layer scanning tasks and the number of target service processing nodes.

5. The method according to claim 1, characterized in that, after judging whether the target image corresponding to the image security scanning task has a corresponding scanning result in the database, the method further includes: If the target image corresponding to the security scanning task has a corresponding scanning result in the database, return the scanning result of the target image corresponding to the security scanning task to the client.

6. The method according to claim 5, characterized in that, The mirror security scanning task further includes the mirror identifier of the target mirror. The step of determining whether there is a corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database includes: Determining whether a scanning result with the mirror identifier of the target mirror is found in the database.

7. A security scanning device for a mirror, characterized in that, it is applied to a distributed cluster system, the distributed cluster system includes a plurality of service processing nodes and a cluster management server communicating with the plurality of service processing nodes, and the device is arranged in the cluster management server, and includes: An acquisition module, configured to acquire a mirror security scanning task selected by a client, where the mirror security scanning task includes mirror layer information of a target mirror; A judgment module, configured to judge whether there is a corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database; A decomposition module, configured to, after there is no corresponding scanning result in the database, decompose the mirror security scanning task into a plurality of mirror layer scanning tasks in units of mirror layers, where each mirror layer scanning task includes identification information of at least one mirror layer of the target mirror, and the identification information of the mirror layers included in different mirror layer scanning tasks is different; and A sending module, configured to send the plurality of mirror layer scanning tasks to at least one target service processing node among the plurality of service processing nodes, so that each target service processing node obtains corresponding mirror layer scanning content according to the identification information of the mirror layer in the received mirror layer scanning task, and splits the obtained mirror layer scanning content into a plurality of scanning subtasks, thereby performing parallel security scanning on the plurality of scanning subtasks by using multiple threads.

8. A security scanning method for a mirror, characterized in that, it is applied to a distributed cluster system, the distributed cluster system includes a plurality of service processing nodes and a cluster management server communicating with the plurality of service processing nodes, and the method is executed by the service processing node, and includes: Receiving at least one mirror layer scanning task sent by the cluster management server, where each mirror layer scanning task includes identification information of at least one mirror layer, and the mirror layer scanning task is obtained by the cluster management server decomposing the mirror security scanning task selected by the user in units of mirror layers when there is no corresponding scanning result for the target mirror corresponding to the mirror security scanning task in the database; Obtaining corresponding mirror layer scanning content according to the identification information of the mirror layer of each mirror layer scanning task; Splitting each mirror layer scanning content into corresponding multiple scanning subtasks; and Performing parallel security scanning on the multiple scanning subtasks by using multiple created threads.

9. The method according to claim 8, characterized in that, after performing parallel security scanning on the multiple scanning subtasks by using multiple created threads, the method further includes: Obtaining the scanning result of each thread after scanning is completed; Integrating the scanning results of all threads to obtain the scanning result of the corresponding mirror layer scanning task; and Reporting the scanning result of the corresponding mirror layer scanning task to the cluster management server.

10. A security scanning device for images, characterized in that, it is applied to a distributed cluster system, the distributed cluster system includes multiple service processing nodes and a cluster management server communicating with the multiple service processing nodes, and the device is arranged on the service processing node and includes: a receiving module, configured to receive at least one image layer scanning task sent by the cluster management server, wherein each image layer scanning task contains identification information of at least one image layer, and the image layer scanning task is obtained by the cluster management server decomposing the selected image security scanning task in units of image layers when there is no corresponding scanning result in the database for the target image corresponding to the image security scanning task; a second obtaining module, configured to obtain corresponding image layer scanning content according to the identification information of the image layer of each image layer scanning task; a splitting module, configured to split each image layer scanning content into corresponding multiple scanning subtasks; and a scanning module, configured to perform parallel security scanning on the multiple scanning subtasks by using multiple created threads.

Citation Information

Patent Citations

  • Mirror image scanning method and device, equipment and storage medium

    CN119271355A