A Docker Secure Usage Inspection System and Risk Detection and Repair Method
Through the Docker security use inspection system combining local and cloud resources, the timeliness and accuracy of Docker security inspections are solved, and the security detection and repair of the entire process is realized, which is suitable for lightweight deployment and real-time updates for individual users.
Patent Information
- Application Number
- CN202210586075.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-27
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-05-27
AI Technical Summary
The existing technology is difficult to check and repair Docker's security in a timely and dynamic manner, especially not suitable for the deployment and use of individual users. Traditional software models lead to the inability to update inspection rules in a timely manner, and the analysis accuracy and coverage are limited.
It provides a Docker security use inspection system, including CLI parsing module, security analysis module, feedback and processing module and execution module. Combined with local and cloud resources, it can realize security detection and repair throughout the whole process through Dockerfile analysis components, Docker image analysis components, cloud security database and cloud sandbox.
It realizes full coverage security detection and repair of Docker usage process, reduces the deployment cost of individual users, and combines cloud big data and local capabilities to provide real-time update risk analysis and repair suggestions, improving the accuracy and user experience of detection.
Smart Images

Figure CN115185629B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data risk detection, and particularly relates to a security usage inspection system for Docker, as well as a risk detection and repair method. Background Art
[0002] Docker is an open-source application container engine based on LXC. Due to its advantages such as lightweight, elastic scalability, rapid deployment, and portability, it is widely used in large Internet enterprises. At the same time, it also facilitates individual users to quickly build, deploy, and use development, services, etc. Docker can perfectly assist you in achieving rapid delivery throughout the entire development cycle. Docker allows developers to develop in local containers equipped with applications and services and can be directly integrated into the sustainable development process. With the development and popularization of Docker technology, the security issues it brings cannot be ignored. Container technology is a new type of technological revolution, which not only has traditional host security issues but also brings new security threats.
[0003] "A Method, Device, and Equipment for Security Inspection of Container Images" realizes a method, device, and equipment for security inspection of container images. The solution includes: obtaining the Dockerfile file of the container image, where the Dockerfile file includes the file text for building the container image; parsing the Dockerfile file to obtain a parsing result; and matching the parsing result with a security inspection database to obtain a security inspection list. The security analysis of the Dockerfile in this patent depends on the matching of various sub-databases. That is to say, the accuracy and coverage of its analysis depend on the data accuracy and data volume of the sub-databases. Moreover, this device is not suitable for individual users or deployment on personal terminals. The large data volume and inability to dynamically update the data of the sub-databases are the problems it has, and the deployment convenience for personal terminals is also its shortcoming. Its traditional software mode determines that it has problems such as the inability to update inspection rules in a timely and dynamic manner. Summary of the Invention
[0004] The purpose of the present invention is to provide a security usage inspection system for Docker, as well as a risk detection and repair method, so as to solve the problems raised in the above background art.
[0005] To achieve the above purpose, the present invention provides the following technical solutions:
[0006] A security usage inspection system for Docker, which includes a CLI parsing module, a security analysis module, a feedback and processing module, and an execution module. The CLI parsing module receives the user's input at the command line and parses it. The security analysis module mainly includes the following components: a Dockerfile analysis component, a Docker image analysis component, a Docker instruction analysis component, a cloud security database, a cloud sandbox, and an associated scheduling component.
[0007] Preferably, the cloud sandbox security analysis module includes cloud sandbox security detection for files and a corresponding data statistics database.
[0008] A method for detecting and repairing security risks in the safe use of Docker includes the following steps:
[0009] S1: The security usage inspection system for Docker determines what method to use to analyze the configuration content of the attributes according to the configuration item attributes of each configuration in the Dockerfile. First, it uses the configuration security detection rules for detection, mainly checking whether there are problems with the format and whether there are format problems such as unspecified tags.
[0010] S2: For security detection of images, etc., if it is not matched in the local library, the name and tag information of the image will be sent to the public cloud image security analysis module for analysis.
[0011] S3: After each analysis request is sent, it will first query whether there is matching data in the image analysis record database. If there is, the data in the database will be extracted and then formatted and returned. If not, it will be added to the background analysis component for analysis, and a task id will be returned to the query request. The user side will poll the analysis result within a certain period of time. If not, it will be marked as the image analysis not completed.
[0012] S4: To further detect whether it is safe and risk-free, if the current state is an online state, the analyzed data will be sent to the cloud analysis component. The architecture of the cloud system includes more complete and real-time updated risk analysis rules and an analysis record database, which can be used as reference data for users. If there is, the result and the historical matching times will be returned as reference data. If it is a new analysis, the analysis result will be added to the database to enrich the database data.
[0013] Preferably, in S3, the image analysis record database and the analysis of new images rely on the cloud image analysis service.
[0014] Preferably, the data analyzed and recorded in the database in S4 includes the corresponding rules, risk levels, and the number of matches for each analysis. Each analysis request will query whether there is the same historical record in the historical analysis record database.
[0015] Compared with the prior art, the beneficial effects of the present invention are:
[0016] 1. The security usage inspection system for Docker, as well as the risk detection and repair method, can perform security detection, risk analysis, and feedback repair suggestions to users for various instruction operations during the user's use of Docker and the entire process of compilation and operation of Docker Containers, covering the entire process of Docker use, including the dockerfile stage, the build stage, and the running and using stage, and also paying extra attention to the security issues of external resources introduced during the use process.
[0017] 2. The security usage inspection system for Docker, as well as the risk detection and repair method, simplifies the deployment and usage costs of the user side by combining the capabilities of local devices and cloud big data, and has the ability of continuous evolution and upgrade. In this way, the balance between the usage experience and the detection ability is achieved. In the user offline mode, most of the risk analysis can be completed relying on the detection rules on the user side, while the analysis ability of the cloud provides comprehensive detection and protection functions such as big data statistical analysis, cloud sandbox running detection, and repair suggestions.
[0018] 3. The security usage inspection system for Docker, as well as the risk detection and repair method, detects the downloaded files for the download behavior in the Dockerfile, adds a cloud sandbox for running detection, and after each detection, the file will record the hash and synchronize the hash and various data of the detection results to the cloud database to form a detection record database. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 It is the overall module composition structure diagram of the inspection system in the embodiment of the present invention;
[0021] Figure 2 It is the product side - user side flowchart of the inspection method in the embodiment of the present invention;
[0022] Figure 3It is the overall technical architecture diagram of the inspection method according to the embodiment of the present invention;
[0023] Figure 4 It is the CLI parsing flowchart of the inspection method according to the embodiment of the present invention;
[0024] Figure 5 It is the Dockerfile analysis flowchart of the inspection method according to the embodiment of the present invention;
[0025] Figure 6 It is the Dockerfile security analysis module diagram of the inspection method according to the embodiment of the present invention;
[0026] Figure 7 It is the working flowchart of the image analysis component of the inspection method according to the embodiment of the present invention;
[0027] Figure 8 It is the architecture diagram of the image analysis component of the inspection method according to the embodiment of the present invention;
[0028] Figure 9 It is the working flowchart of the cloud sandbox analysis component of the inspection method according to the embodiment of the present invention. Detailed implementation manners
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0030] Embodiment
[0031] Please refer to Figures 1-9 , the Docker secure usage inspection system provided by the present invention includes a CLI parsing module, a security analysis module, a feedback and processing module, and an execution module. The CLI parsing module receives the input of the user at the command line and parses it. The security analysis module mainly includes the following components: a Dockerfile analysis component, a Docker image analysis component, a Docker instruction analysis component, a cloud security database, a cloud sandbox, and a linkage scheduling component. The cloud sandbox security analysis module includes cloud sandbox security detection for files and a corresponding data statistics database.
[0032] CLI parsing module: When users use it, they will input various commands and their parameters according to their needs. The job of the CLI parsing module is to tell the program what the user wants to do. The CLI parsing module receives the user's input on the command line and parses it. During the parsing stage, the text passed into the application through the command line is processed. The processing process will be carried out according to the rules defined in the implementation of the parser. The result of the CLI parsing will determine which analysis modules the security analysis calls to work.
[0033] If the user performs an operation on the Dockerfile, then the user's instructions and the Dockerfile file operated by the user will be processed by the parsing module, and the content in the file will be converted into a data format containing instructions and arrays and passed to the Dockerfile security analysis module for further analysis. The input of this system is the data after the parsing module processes the Dockerfile.
[0034] A method for detecting and repairing security risks in Docker, which includes the following steps:
[0035] S1: The Docker security usage inspection system decides what method to use to analyze the configuration content of the attributes according to the configuration item attributes of each item in the Dockerfile. First, it uses the configuration security detection rules for detection, mainly checking whether there are problems with the format and whether there are format problems such as unassigned tags.
[0036] S2: For security detection of images, etc., if it is the case that there is no match in the local library, the name and tag information of the image will be sent to the public cloud image security analysis module for analysis.
[0037] S3: After each analysis request is sent, it will first query the image analysis record database to see if there is matching data. If there is, the data in the database will be extracted and then formatted and returned. If not, it will be added to the background analysis component for analysis, and a task id will be returned to the query request. The user side will poll to query the analysis result within a certain period of time. If not, it will be marked as the Image analysis is not completed. The Image analysis record database and the analysis of the new image rely on the cloud image analysis service.
[0038] S4: To further detect whether it is safe and risk-free, if the current state is an online state, the analyzed data will be sent to the cloud analysis component. The architecture of the cloud system includes more complete and real-time updated risk analysis rules and an analysis record database, which can be used as reference data for users. If there is a match, the result and the historical matching times will be returned as reference data. If it is a new analysis, the analysis result will be added to the database to enrich the database data. The analysis record database records the data of each analysis, including the corresponding rules, risk levels, and matching times. Each analysis request will query whether there is the same historical record in the historical analysis record database.
[0039] The workflow and principle of the Dockerfile analysis component on the client side are as follows. The system determines what method to use to analyze the configuration content of the attributes based on the attribute of each configuration item in the Dockerfile. For the basic FROM configuration item, which specifies the base image used by the Dockerfile, for this configuration item, first, the configuration security detection rules are used for detection, mainly checking whether there are problems with the format and whether there are format problems such as the tag not being specified. Then comes the security detection of the image, etc. The detection of the docker image will read the name and tag of the used docker image and query the user-side image security database. The security database only records the security image information that has passed the security detection and the images that have passed the official security certification. This database can be updated regularly by synchronizing information from the cloud. If it is not matched in the local library, the name and tag information of the image will be sent to the public cloud image security analysis module for analysis. To ensure speed, the cloud image security analysis module will have an image analysis record database, which records the information of the analyzed images, including the name, tag, whether there are risks, risk levels, the number of analysis times, etc. Each time an analysis request is sent, it will first query whether there is matching data in the image analysis record database. If so, the data in the database will be extracted and then formatted and returned. If not, it will be added to the background analysis component for analysis, and a task ID will be returned to the query request. The client side will poll to query the analysis result within a certain period of time. If not, it will be marked as the Image analysis is not completed. The image analysis record database and the analysis of new images rely on the cloud image analysis service. The image analysis service uses the Anchore engine to analyze the images and further processes the results, and combines task scheduling and management functions. When there are no new user-side tasks, the image analysis service will capture the images with higher popularity for analysis to populate the image analysis record database. For other configuration items, according to the attribute of the configuration item, the corresponding detection rules are selected for security detection. Different configuration items have different specifications and security requirements, and there are different security risks, so it is necessary to select the corresponding detection rules according to the configuration item to analyze and detect the attribute configuration content of the configuration item.The application of cloud capabilities is reflected in that for each piece of configuration information, if there is no matching record detected locally, that is, the local threat detection rules are not hit. To further detect whether it is safe and risk-free, if the current state is an online state, the analyzed data will be sent to the cloud analysis component. The architecture of the cloud system includes more complete and real-time updated risk analysis rules and an analysis record database. The analysis record database records the data of each analysis, including the corresponding rules, risk levels, and the number of matches, which can be used as reference data for users. Each analysis request will query whether there is the same historical record in the historical analysis record database. If there is, the result and the historical number of matches will be returned as reference data. If it is a new analysis, the analysis result will be added to the database to enrich the database data.
[0040] For operations such as downloading executable files and ADD / COPY in the Dockerfile, in order to ensure the security of executable files, the present invention sets up a cloud sandbox security analysis module. The cloud sandbox security analysis module includes cloud sandbox security detection for files and a corresponding data statistics database. This analysis cannot be completed on the user side. If the user-side terminal is executed in an online environment, the file address downloaded from the cloud and the files operated locally will be uploaded to the cloud sandbox system for analysis. For each file, its sha256 hash value will be calculated first, and then it will be queried whether there is a matching record in the data statistics database. If there is a matching record, it means that the same file has been analyzed before, so the analysis time can be saved and the data in the database can be directly returned to the user side. If it is a brand-new file that has not been analyzed, the file will be detected by anti-virus software and handed over to the cloud sandbox for analysis at the same time. The cloud sandbox system will run the file in the sandbox environment to detect the file security and record the behavior of the file, and then judge the security risk of the file. The detection result will be stored in the data statistics database together with various data.
[0041] For other Docker operations, such as the use of docker exec, check the executed instructions and parameters. For operations that are not standardized or pose risks, inform the user of the risks before execution. For example, if docker exec uses the --privileged option during execution, using the privileged option in docker exec can provide extended Linux capabilities for the command. Using the privileged option may cause an insecure situation. When it is detected that the user has performed such a risky operation, the user-side program will inform the user and recommend not using the --privileged option in the docker exec command. Another example is that using the --user option to execute docker exec may also introduce security risks. Using the --user option in docker exec to execute the command within the container as that user may cause an insecure situation. For example, assume your container is running as the tomcat user (or any other non-root user), then you can use the user=root option to run the command as the root user, which is very dangerous. There is also the mapping of privileged ports. TCP / IP port numbers below 1024 are considered privileged ports. Due to various security reasons, ordinary users and processes are not allowed to use them. By default, if the user does not explicitly declare a container port for host port mapping, Docker will automatically map the container port to a port in the range of 49153 - 65535 on the host. However, if the user explicitly declares it, Docker can map the container port to a privileged port on the host. This is because the container uses the NET_BIND_SERVICE Linux kernel feature that does not restrict privileged port mapping to execute. Privileged ports receive and send various sensitive and privileged data. Allowing docker to use them may have serious consequences, so it will be detected whether the user's operation involves mapping of privileged ports.
[0042] The Docker Image analysis component in the cloud. This system consists of an analysis program and an analysis record database. The input of the system includes two parts. One part is the user's input, that is, the image information that the user needs to detect. The other part is that when the system is idle, it will search the public Docker register and automatically obtain the latest image for analysis.
[0043] The analysis record system in the cloud will analyze and process all detection requests from the user side, store the historical analysis results in the system's record database, improve the analysis processing speed and detection ability with the help of a large number of analysis results, and feedback the historical analysis and judgment as well as the proportion of the user's choices as analysis data to the user to assist the user in judging risks.
[0044] The Dockerfile analysis component consists of two main parts: Dockerfile parsing and instruction analysis. Dockerfile parsing extracts different instructions through our parser, processes them into dictionary-style JSON data, and stores and analyzes the data. The parsed data is checked for risks according to the analysis rules, and the results of the check are also stored in the database in the form of dictionary-style JSON data.
[0045] It is more user-friendly for individual users, covering all scenarios of Docker use more comprehensively, making it more seamless for users to use and reducing the learning cost for users. It combines local rules and cloud capabilities for Dockerfile security detection. It has the characteristics of being lightweight and supporting synchronization, and uses the real-time updated multi-dimensional detection rules in the cloud to achieve the speed and accuracy of detection. Moreover, with a large amount of data accumulation, it can give users targeted security suggestions for each detected security risk and provide users with statistical data obtained from cloud data for reference. With this solution, users can reduce the security risks brought by using Docker without increasing the usage cost. After all, individual users are not professional users, and there will inevitably be non-standard or insecure operations during use, which may introduce security risks and lead to potential security problems. This solution comprehensively guarantees the security of users using Docker through multi-system security detection and a combination of local and cloud detection methods.
[0046] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for detecting and fixing security risks in the safe use of Docker, characterized in that: A security usage inspection system for Docker, including a CLI parsing module, a security analysis module, a feedback and processing module, and an execution module. The CLI parsing module receives the user's input at the command line and parses it. The security analysis module includes the following components: a Dockerfile analysis component, a Docker image analysis component, a Docker instruction analysis component, a cloud security database, a cloud sandbox, and a linkage scheduling component. Among them, in the cloud sandbox of the security analysis module, there is a cloud sandbox security detection for files and a corresponding data statistics database. The security analysis module also includes a cloud image analysis service. Including the following steps: S1: The security usage inspection system of Docker analyzes the configuration content of each attribute according to the attribute of each configuration item in the Dockerfile, uses the configuration security detection rules for detection, checks whether there are problems with the format, and whether there is an unspecified tag format problem. S2: Perform a security detection on the docker image. The detection of the docker image will read the name and tag of the used docker image, query the image security database on the user side. If it is not matched in the local library, the name and tag information of the image will be sent to the public cloud image security analysis module for analysis. S3: After receiving the analysis request, the cloud image security analysis module queries whether there is matching data in the image analysis record database. If so, the data in the database will be extracted, formatted, and then returned. If not, it will be added to the background analysis component for analysis, and a task id will be returned to the analysis request. The user side will poll and query the analysis result within a certain period of time. If not, it will be marked as the Image analysis is not completed. S4: If the current state is an online state, the linkage scheduling component will send the analyzed data to the cloud analysis component. The architecture of the cloud system includes risk analysis rules and an analysis record database that are updated in real time. Each analysis request will query whether there is the same historical record in the historical analysis record database. If so, the result and the historical matching times will be returned as reference data. If it is a new analysis, the analysis result will be added to the database.
2. The method for detecting and repairing security usage risks of Docker according to claim 1, characterized in that: In S3, the Image analysis record database and the analysis of the new image rely on the cloud image analysis service.
3. The method for detecting and repairing security usage risks of Docker according to claim 2, characterized in that: In S4, the analysis record database records the data of each analysis, including the corresponding rules, risk levels, and matching times. Each analysis request will query whether there is the same historical record in the historical analysis record database.
Citation Information
Patent Citations
White list based container operation safety verification processing method and system
CN106487815A
Intelligent Docker container malicious file detection method and device
CN110210225A