Container Vulnerability Handling Method, Device, Storage Medium and Electronic Device
By obtaining the basic vulnerability information and configuration information of the container image, and generating detection data for risk detection, the problem of not being able to identify new vulnerabilities introduced by the container in the existing technology is solved, and the comprehensiveness and accuracy of vulnerability scanning are improved.
Patent Information
- Application Number
- CN202211435395.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-11-16
AI Technical Summary
The container vulnerability scanning method in the prior art cannot identify new vulnerabilities introduced.
By obtaining the basic vulnerability information of the container image and the configuration information of the container, differential configuration information are determined, and detection data is generated for risk detection to identify non-basic vulnerabilities.
New vulnerability identification of containers is realized, improving the comprehensiveness and accuracy of vulnerability scanning.
Smart Images

Figure CN115758377B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of electronic digital data processing, and in particular, to a method, device, storage medium, and electronic device for processing container vulnerabilities. Background Art
[0002] A "container" is an open-source application container engine in the technical field of electronic digital data processing. During the current use of containers, it is necessary to perform vulnerability scanning on the containers. The conventional vulnerability scanning queries based on the container version number and then identifies the vulnerabilities. However, during the use of the containers, the configuration content may change, thus introducing new vulnerabilities. At this time, the above scanning method will not be able to identify them. Summary of the Invention
[0003] The main purpose of the present application is to provide a method, device, storage medium, and electronic device for processing container vulnerabilities to solve the problem that the existing container vulnerability scanning method cannot identify the newly introduced vulnerabilities in the prior art.
[0004] To achieve the above object, according to one aspect of the present application, a method for processing container vulnerabilities is provided. The method includes: obtaining the version number of a container to be processed and obtaining the container image corresponding to the version number; determining basic vulnerability information according to the container image and performing basic vulnerability scanning on the container to be processed according to the basic vulnerability information; obtaining first configuration information and second configuration information, and determining differential configuration information according to the first configuration information and the second configuration information, where the first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image; generating detection data according to the differential configuration information and performing risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed.
[0005] Optionally, determining basic vulnerability information according to the container image and performing basic vulnerability scanning on the container to be processed according to the basic vulnerability information includes: obtaining the basic vulnerability information corresponding to the container image from a vulnerability database; determining vulnerability features according to the basic vulnerability information and performing the basic vulnerability scanning on the container to be processed according to the vulnerability features.
[0006] Optionally, determine vulnerability features based on the basic vulnerability information, and perform the basic vulnerability scanning on the container to be processed according to the vulnerability features, including: if all the vulnerability features of the preset basic vulnerability exist in the container to be processed, determine that the preset basic vulnerability exists in the container to be processed; if some of the vulnerability features of the preset basic vulnerability exist in the container to be processed, or the vulnerability features of the preset basic vulnerability do not exist in the container to be processed, determine that the preset basic vulnerability does not exist in the container to be processed.
[0007] Optionally, determine the differential configuration information according to the first configuration information and the second configuration information, including: generating a first configuration vector according to the first configuration information, where the elements in the first configuration vector correspond to the configuration data in the container to be processed; generating a second configuration vector according to the second configuration information, where the elements in the second configuration vector correspond to the configuration data in the container image; comparing the first configuration vector and the second configuration vector to obtain the differential configuration information, and the differential configuration information is used to represent the different elements in the first configuration vector and the second configuration vector.
[0008] Optionally, generate detection data according to the differential configuration information, including: combining the elements in the differential configuration information to obtain a plurality of differential element combinations; querying a preset vulnerability database according to each differential element combination to obtain a vulnerability set; generating the detection data according to the vulnerability set, and the detection data includes input detection data and output detection data.
[0009] Optionally, perform risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed, including: processing the input detection data using the container to be processed to obtain a processing result; matching the processing result with the output detection data to obtain a matching result; determining the non-basic vulnerability information of the container to be processed according to the matching result.
[0010] Optionally, the method further includes: determining that there are no non-basic vulnerabilities when the differential configuration information represents no difference; generating a vulnerability scan report when the differential configuration information represents a difference, and the vulnerability scan report includes error information that the non-basic vulnerabilities will cause.
[0011] According to another aspect of the present application, a container vulnerability handling device is provided. The device includes a first acquisition unit, a scanning unit, a second acquisition unit, and a detection unit. The first acquisition unit is used to acquire the version number of the container to be processed and acquire the container image corresponding to the version number. The scanning unit is used to determine basic vulnerability information based on the container image and perform a basic vulnerability scan on the container to be processed according to the basic vulnerability information. The second acquisition unit is used to acquire first configuration information and second configuration information, and determine differential configuration information according to the first configuration information and the second configuration information. The first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image. The detection unit is used to generate detection data according to the differential configuration information and perform a risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed.
[0012] According to another aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above methods.
[0013] According to another aspect of the present application, an electronic device is provided, including: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include those for executing any one of the above methods.
[0014] Applying the technical solution of the present application, for the above container vulnerability handling method, first, the version number of the container to be processed is acquired, and the container image corresponding to the version number is acquired. Secondly, basic vulnerability information is determined based on the container image, and a basic vulnerability scan is performed on the container to be processed according to the basic vulnerability information. Then, first configuration information and second configuration information are acquired, and differential configuration information is determined according to the first configuration information and the second configuration information. The first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image. Finally, detection data is generated according to the differential configuration information, and a risk detection is performed on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed. The above method uses vulnerability scanning based on configuration information to achieve the identification of new vulnerabilities (i.e., non-basic vulnerability information) of the container to be processed, thereby avoiding the problem that the existing container vulnerability scanning method cannot identify newly introduced vulnerabilities, and improving the comprehensiveness and accuracy of container vulnerability scanning. Description of the Drawings
[0015] The accompanying drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0016] Figure 1 A schematic flowchart of a method for handling container vulnerabilities according to an embodiment of this application is shown;
[0017] Figure 2 A schematic flowchart of another method for handling container vulnerabilities according to an embodiment of this application is shown;
[0018] Figure 3 A schematic flowchart of yet another method for handling container vulnerabilities according to an embodiment of this application is shown;
[0019] Figure 4 A schematic diagram of a device for handling container vulnerabilities according to an embodiment of this application is shown;
[0020] Figure 5 A schematic diagram of another device for handling container vulnerabilities according to an embodiment of this application is shown. Detailed implementation manners
[0021] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments may be combined with each other. The following will describe this application in detail with reference to the drawings and in combination with the embodiments.
[0022] In order to enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of this application.
[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to describe the embodiments of this application here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0024] It should be understood that when an element (such as a layer, film, region, or substrate) is described as being "on" another element, the element can be directly on the other element, or there can also be intermediate elements. Moreover, in the specification and claims, when an element is described as being "connected" to another element, the element can be "directly connected" to the other element, or "connected" to the other element through a third element.
[0025] As introduced in the background art, the existing container vulnerability scanning method in the prior art cannot identify newly introduced vulnerabilities. To solve the problem that the existing container vulnerability scanning method in the prior art cannot identify newly introduced vulnerabilities, embodiments of the present application provide a container vulnerability processing method, apparatus, storage medium, and electronic device.
[0026] According to an embodiment of the present application, a container vulnerability processing method is provided. Figure 1 is a flowchart of a container vulnerability processing method according to an embodiment of the present application. As Figure 1 shown, the method includes the following steps:
[0027] Step S101, obtain the version number of the container to be processed, and obtain the container image corresponding to the above version number;
[0028] For the above step S101, in container technology, a container itself essentially contains software and the environment required by the software. During the version update process, each version has corresponding detected vulnerabilities. The container to be processed is formed based on the container image, and the container image is obtained by the developer's packaging and is only readable. When in use, a container to be processed is newly created based on the container image. When the container to be processed is initially formed, it can be regarded as a copy of the container image. When identifying the container to be processed, first identify the version number of the container to be processed to determine the container image corresponding to the version number. This is because when the container to be processed is used, the configuration information contained in it may change, while the container image is the most initial version of the container to be processed.
[0029] Step S102, determine the basic vulnerability information according to the above container image, and perform a basic vulnerability scan on the above container to be processed according to the above basic vulnerability information;
[0030] For the above step S102, since the content of the container image is only readable, the content of the container image corresponding to each version number is the same, and its vulnerabilities are also the same. Although the configuration of the container to be processed will change during use, its framework will not change. Therefore, when performing a basic vulnerability scan, the unchangeable framework in the container to be processed is detected to detect the vulnerabilities existing under this framework. The specific implementation process of the above step S102 is as follows, as Figure 2 shown:
[0031] Step S1021: Obtain the basic vulnerability information corresponding to the above container image from the vulnerability database. Specifically, in the vulnerability database, records are kept for each historical version of each container image, where the vulnerabilities corresponding to each historical version are recorded.
[0032] Step S1022: Determine the vulnerability features based on the above basic vulnerability information, and perform the above basic vulnerability scanning on the to-be-processed container according to the above vulnerability features. Specifically, different vulnerabilities are determined by different features. Therefore, for each vulnerability, it can be judged according to the features.
[0033] In the actual operation process, the specific implementation of the above Step S1022 is as follows:
[0034] Step S201: If all the vulnerability features of the preset basic vulnerability exist in the to-be-processed container, it is determined that the preset basic vulnerability exists in the to-be-processed container.
[0035] Step S202: If some of the vulnerability features of the preset basic vulnerability exist in the to-be-processed container, or the vulnerability features of the preset basic vulnerability do not exist in the to-be-processed container, it is determined that the preset basic vulnerability does not exist in the to-be-processed container.
[0036] Specifically, judge one by one whether the features corresponding to each vulnerability appear in the to-be-processed container at the same time. For example, if a vulnerability contains three features, namely Feature A, Feature B, and Feature C, when Feature A, Feature B, and Feature C exist in the to-be-processed container at the same time, it is regarded that the to-be-processed container has this vulnerability.
[0037] Step S103: Obtain the first configuration information and the second configuration information, and determine the differential configuration information according to the above first configuration information and the above second configuration information. The above first configuration information refers to the configuration information in the to-be-processed container, and the above second configuration information refers to the configuration information in the container image.
[0038] For the above Step S103, the above first configuration information is the configuration changed during long-term use. Since the container image is not writable, the configuration information it contains is fixed. As long as the version numbers are the same, the configuration information corresponding to the container image is the same. Compare the configuration information of the to-be-processed container with the corresponding configuration information of the container image one by one, judge the changed configuration data, and record the changed configuration data to obtain the differential configuration information. Among them, the specific implementation steps of determining the differential configuration information according to the above first configuration information and the above second configuration information are as follows, for example Figure 3 as shown:
[0039] Step S1031: Generate a first configuration vector according to the above first configuration information. The elements in the first configuration vector correspond to the configuration data items in the to-be-processed container.
[0040] Step S1032: Generate a second configuration vector according to the above second configuration information. The elements in the second configuration vector correspond to the configuration data items in the container image. Among them, the configuration data items in the container image are the original configuration data of the to-be-processed container, and during subsequent use, this configuration data may change.
[0041] Step S1033: Compare the first configuration vector and the second configuration vector to obtain the above differential configuration information. The differential configuration information is used to represent the different elements in the first configuration vector and the second configuration vector. Among them, during the generation of the first configuration vector and the second configuration vector, the arrangement order of each element is the same, that is, when reading the configuration information, it is carried out in a preset order. Through comparison, it can be judged which configuration data has changed, and use it as differential configuration. It is precisely because of these configuration changes that new vulnerabilities may be caused.
[0042] Step S104: Generate detection data according to the above differential configuration information, and use the detection data to perform risk detection on the to-be-processed container to obtain the non-basic vulnerability information of the to-be-processed container.
[0043] For the above step S104, under different configuration data, there may be different vulnerabilities. At this time, perform risk detection according to the differential configuration information, so as to generate test data according to different risks. The test data is used to test the to-be-processed container, and use the test result to judge whether there is such a risk. If it exists, it is regarded as having a vulnerability. In this way, determine the non-basic vulnerability information. Among them, generating detection data according to the above differential configuration information includes the following steps:
[0044] Step S301: Combine the elements in the above differential configuration information to obtain multiple differential element combinations. Specifically, because between different configuration information, different vulnerabilities may be generated. For example, if there are ten elements in the differential configuration, the combination of three of these elements will generate a vulnerability, and different combinations correspond to different vulnerabilities. Therefore, combine each element to obtain differential element combinations.
[0045] Step S302: Query a preset vulnerability database according to each of the above differential element combinations to obtain a vulnerability set.
[0046] Step S303: Generate the above-mentioned detection data according to the above-mentioned vulnerability set. The above-mentioned detection data includes input detection data and output detection data. Specifically, the above-mentioned vulnerability database contains vulnerabilities corresponding to various configuration combinations in different software, and records the risks that will be caused. According to the query results, the vulnerability set is obtained, and the corresponding test data is generated accordingly. Based on the risks recorded in the vulnerability database, the test input data and test output data are generated.
[0047] In an optional embodiment, the above-mentioned detection data is used to perform a risk detection on the above-mentioned container to be processed to obtain the non-basic vulnerability information of the above-mentioned container to be processed, including:
[0048] Step S401: Use the above-mentioned container to be processed to process the above-mentioned input detection data to obtain a processing result;
[0049] Step S402: Match the above-mentioned processing result with the above-mentioned output detection data to obtain a matching result;
[0050] Step S403: Determine the above-mentioned non-basic vulnerability information of the above-mentioned container to be processed according to the above-mentioned matching result.
[0051] To avoid affecting the original container to be processed, exemplarily, a copy of the container to be processed can be made in an isolated environment first, and it is used as a substitute for the original container to be processed for detection. The test input data is input into it, and the processing is performed through the copied container to be processed to obtain a processing result. If the processing result is consistent with the test output data, it indicates that in the current container to be processed, the existing combination of different elements does cause the corresponding vulnerability to occur, and the non-basic vulnerability information is generated.
[0052] Specifically, the above method further includes: when the above-mentioned difference configuration information indicates no difference, it is determined that there are no non-basic vulnerabilities; when the above-mentioned difference configuration information indicates a difference, a vulnerability scan report is generated, and the above-mentioned vulnerability scan report includes the error information that the above-mentioned non-basic vulnerabilities will cause.
[0053] In the above-mentioned container vulnerability handling method of the present application, first, the version number of the container to be processed is obtained, and the container image corresponding to the above version number is obtained; secondly, the basic vulnerability information is determined according to the above container image, and the above container to be processed is scanned for basic vulnerabilities according to the above basic vulnerability information; then, the first configuration information and the second configuration information are obtained, and the differential configuration information is determined according to the above first configuration information and the above second configuration information, where the above first configuration information refers to the configuration information in the above container to be processed, and the above second configuration information refers to the configuration information in the above container image; finally, detection data is generated according to the above differential configuration information, and the above container to be processed is detected for risks using the above detection data to obtain the non-basic vulnerability information of the above container to be processed. The above method uses vulnerability scanning based on configuration information to achieve the identification of new vulnerabilities (i.e., non-basic vulnerability information) of the container to be processed, thereby avoiding the problem in the prior art that the container vulnerability scanning method cannot identify the newly introduced vulnerabilities, and improving the comprehensiveness and accuracy of container vulnerability scanning.
[0054] According to an embodiment of the present application, a container vulnerability handling device is provided, as Figure 4 shown. The above device includes a first acquisition unit 01, a scanning unit 02, a second acquisition unit 03, and a detection unit 04. The above first acquisition unit 01 is used to obtain the version number of the container to be processed and obtain the container image corresponding to the above version number; in container technology, a container itself essentially includes software and the environment required by the software. During the version update process, each version has corresponding detected vulnerabilities. The container to be processed is formed based on the container image, and the container image is packaged by the developer and is only readable. When in use, a container to be processed is newly created based on the container image. When the container to be processed is initially formed, it can be regarded as a copy of the container image. When identifying the container to be processed, first identify the version number of the container to be processed to determine the container image corresponding to the version number. This is because when the container to be processed is used, the configuration information contained in it may change, while the container image is the most initial version of the container to be processed.
[0055] The above scanning unit 02 is used to determine the basic vulnerability information according to the above container image and scan the above container to be processed for basic vulnerabilities according to the above basic vulnerability information; since the content of the container image is only readable and the content of the container image corresponding to each version number is the same, and its vulnerabilities are also the same. Although the configuration of the container to be processed will change during use, its framework will not change. Therefore, when performing basic vulnerability scanning, the unchangeable framework in the container to be processed is detected to detect the vulnerabilities existing under this framework.
[0056] The second obtaining unit 03 is used to obtain the first configuration information and the second configuration information, and determine the differential configuration information according to the first configuration information and the second configuration information. The first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image. The first configuration information is the configuration changed during long-term use. Since the container image is not writable, the configuration information it contains is fixed. As long as the version numbers are the same, the corresponding configuration information of the container image is the same. Compare the configuration information of the container to be processed with that of the container image one by one, judge the changed configuration data, and record the changed configuration data to obtain the differential configuration.
[0057] The detection unit 04 is used to generate detection data according to the differential configuration information, and perform risk detection on the container to be processed using the detection data to obtain the non-basic vulnerability information of the container to be processed. Under different configuration data, there may be different vulnerabilities. At this time, risk assessment is carried out according to the differential configuration, and thus inspection data is generated according to different risks. The inspection data is used to test the container to be processed, and the test results are used to judge whether such a risk actually exists. If it exists, it is regarded as having a vulnerability. In this way, the non-basic vulnerability information is determined.
[0058] In an alternative embodiment, the scanning unit includes an obtaining module and a scanning module. The obtaining module is used to obtain the basic vulnerability information corresponding to the container image from the vulnerability database. Specifically, in the database, the historical versions of each container image are recorded, and the vulnerabilities corresponding to each historical version are recorded.
[0059] The scanning module is used to determine the vulnerability characteristics according to the basic vulnerability information, and perform the basic vulnerability scanning on the container to be processed according to the vulnerability characteristics. Specifically, different vulnerabilities are determined by different characteristics. Therefore, for each vulnerability, it can be judged according to the characteristics.
[0060] Exemplarily, such as Figure 5As shown, the above first scanning module includes a first determination module 11 and a second determination module 12: the first determination module 11 is used to determine that the preset basic vulnerability exists in the to-be-processed container if all the vulnerability features of the preset basic vulnerability exist in the to-be-processed container; the second determination module 12 is used to determine that the preset basic vulnerability does not exist in the to-be-processed container if some of the vulnerability features of the preset basic vulnerability exist in the to-be-processed container, or if the vulnerability features of the preset basic vulnerability do not exist in the to-be-processed container. It is possible to more accurately determine whether the preset basic vulnerability exists in the to-be-processed container. Specifically, it is judged one by one whether the features corresponding to each vulnerability appear in the to-be-processed container at the same time. For example, if a vulnerability contains three features, namely feature A, feature B, and feature C, when feature A, feature B, and feature C exist in the to-be-processed container at the same time, it is considered that the to-be-processed container has this vulnerability.
[0061] In another optional example, the above second acquisition unit further includes a first generation unit, a second generation unit, and a comparison unit. The first generation unit is used to generate a first configuration vector according to the above first configuration information, and the elements in the first configuration vector correspond to the configuration data in the to-be-processed container; the second generation unit is used to generate a second configuration vector according to the above second configuration information, and the elements in the second configuration vector correspond to the configuration data in the container image; the comparison unit is used to compare the first configuration vector and the second configuration vector to obtain the difference configuration information, and the difference configuration information is used to represent the different elements in the first configuration vector and the second configuration vector. Among them, during the generation process of the first configuration vector and the second configuration vector, the arrangement order of each element is the same, that is, when reading the configuration information, it is carried out in a preset order. Specifically, through comparison, it can be judged which configuration data has changed and use it as the difference configuration. It is precisely because of these configuration changes that new vulnerabilities may be generated.
[0062] Exemplarily, the above detection unit includes a combination unit, a query unit, and a third generation unit. The combination unit is used to combine the elements in the difference configuration information to obtain a plurality of difference element combinations; specifically, because different vulnerabilities may be generated between different configuration information. For example, there are ten elements in the difference configuration, and the combination of three of these elements will generate a vulnerability, and different combinations correspond to different vulnerabilities. Therefore, each element is combined to obtain the difference element combination.
[0063] The above query unit is used to query a preset vulnerability database according to each of the above difference element combinations to obtain a set of vulnerabilities; the above third generation unit is used to generate the above detection data according to the above set of vulnerabilities, and the above detection data includes input detection data and output detection data. Specifically, the above vulnerability database contains vulnerabilities corresponding to various configuration combinations in different software, and records the risks that will be caused. According to the query results, a set of vulnerabilities is obtained, and corresponding test data is generated accordingly. Based on the risks recorded in the vulnerability database, test input data and test output data are generated, and the results are more accurate.
[0064] In an optional example, the above detection unit includes a processing module, a matching module, and a third determination module: the above processing module is used to process the above input detection data by using the above container to be processed to obtain a processing result; the above matching module is used to match the above processing result with the above output detection data to obtain a matching result; the above third determination module is used to determine the above non-basic vulnerability information of the above container to be processed according to the above matching result. Specifically, in order to avoid affecting the original container to be processed, exemplarily, a copy of the container to be processed can be made in an isolated environment first, and it can be used as a substitute for the original container to be processed for detection. The test input data is input into it, and the processing result is obtained through the container to be processed obtained by replication. If the processing result is consistent with the test output data, it means that in the current container to be processed, the combination of difference elements that exists has indeed caused the corresponding vulnerability to occur, and non-basic vulnerability information is generated.
[0065] In other embodiments, the above device includes a fourth determination module and a fourth generation module. The above fourth determination module is used to determine that there are no non-basic vulnerabilities when the above difference configuration information indicates no difference; the above fourth generation module is used to generate a vulnerability scan report when the above difference configuration information indicates a difference, and the above vulnerability scan report includes error information that the above non-basic vulnerabilities will cause. The problem that the existing container vulnerability scanning method cannot identify newly introduced vulnerabilities can be avoided.
[0066] The container vulnerability handling device of the present application includes a first acquisition unit, a scanning unit, a second acquisition unit, and a detection unit. The first acquisition unit is used to acquire the version number of the container to be processed and obtain the container image corresponding to the version number. The scanning unit is used to determine basic vulnerability information based on the container image and perform a basic vulnerability scan on the container to be processed according to the basic vulnerability information. The second acquisition unit is used to acquire first configuration information and second configuration information, and determine differential configuration information based on the first configuration information and the second configuration information. The first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image. The detection unit is used to generate detection data based on the differential configuration information and perform a risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed. The device adopts vulnerability scanning based on configuration information, realizes the identification of new vulnerabilities (i.e., non-basic vulnerability information) of the container to be processed, and thus avoids the problem that the existing container vulnerability scanning method cannot identify the introduced new vulnerabilities, improving the comprehensiveness and accuracy of container vulnerability scanning.
[0067] According to an embodiment of the present application, there is provided a computer-readable storage medium, where the computer-readable storage medium includes a stored program, and when the program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above methods.
[0068] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0069] According to an embodiment of the present application, there is provided an electronic device, including: one or more processors, a memory, and one or more programs, where the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include those for executing any one of the above methods.
[0070] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0071] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general purpose computers, special purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in the flow Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in a block or multiple blocks.
[0072] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in the flow Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in a block or multiple blocks.
[0073] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the flow Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in a block or multiple blocks.
[0074] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0075] A computer-readable medium includes permanent and non-permanent, removable and non-removable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0076] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0077] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0078] 1) In the above container vulnerability handling method of the present application, first, the version number of the container to be processed is obtained, and the container image corresponding to the version number is obtained; secondly, the basic vulnerability information is determined according to the container image, and the basic vulnerability scan is performed on the container to be processed according to the basic vulnerability information; then, the first configuration information and the second configuration information are obtained, and the differential configuration information is determined according to the first configuration information and the second configuration information, where the first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image; finally, the detection data is generated according to the differential configuration information, and the risk detection is performed on the container to be processed using the detection data to obtain the non-basic vulnerability information of the container to be processed. The above method uses vulnerability scanning based on configuration information to identify new vulnerabilities (i.e., non-basic vulnerability information) of the container to be processed, thereby avoiding the problem that the container vulnerability scanning method in the prior art cannot identify newly introduced vulnerabilities, and improving the comprehensiveness and accuracy of container vulnerability scanning.
[0079] 2) The container vulnerability handling device of the present application includes a first acquisition unit, a scanning unit, a second acquisition unit, and a detection unit. The first acquisition unit is used to acquire the version number of the container to be processed and the container image corresponding to the version number. The scanning unit is used to determine basic vulnerability information based on the container image and perform a basic vulnerability scan on the container to be processed according to the basic vulnerability information. The second acquisition unit is used to acquire first configuration information and second configuration information, and determine differential configuration information based on the first configuration information and the second configuration information. The first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image. The detection unit is used to generate detection data based on the differential configuration information and perform risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed. The device uses vulnerability scanning based on configuration information to identify new vulnerabilities (i.e., non-basic vulnerability information) of the container to be processed, thereby avoiding the problem that the existing container vulnerability scanning method cannot identify newly introduced vulnerabilities, and improving the comprehensiveness and accuracy of container vulnerability scanning.
[0080] The foregoing are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for handling container vulnerabilities, characterized in that, Including: Obtaining the version number of the container to be processed, and obtaining the container image corresponding to the version number; Determining basic vulnerability information based on the container image, and performing a basic vulnerability scan on the container to be processed according to the basic vulnerability information; Obtaining first configuration information and second configuration information, and determining differential configuration information according to the first configuration information and the second configuration information, where the first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image; Generating detection data according to the differential configuration information, and performing risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed; Generating detection data according to the differential configuration information, including: Combining elements in the differential configuration information to obtain a plurality of differential element combinations; Querying a preset vulnerability database according to each differential element combination to obtain a set of vulnerabilities; Generating the detection data according to the set of vulnerabilities, where the detection data includes input detection data and output detection data; Performing risk detection on the container to be processed using the detection data to obtain non-basic vulnerability information of the container to be processed, including: Using the container to be processed to process the input detection data to obtain a processing result; Matching the processing result with the output detection data to obtain a matching result; Determining the non-basic vulnerability information of the container to be processed according to the matching result.
2. The method according to claim 1, wherein Determining basic vulnerability information based on the container image, and performing a basic vulnerability scan on the container to be processed according to the basic vulnerability information, including: Obtaining basic vulnerability information corresponding to the container image from a vulnerability database; Determining vulnerability characteristics according to the basic vulnerability information, and performing the basic vulnerability scan on the container to be processed according to the vulnerability characteristics.
3. The method according to claim 2, wherein Determining vulnerability characteristics according to the basic vulnerability information, and performing the basic vulnerability scan on the container to be processed according to the vulnerability characteristics, including: If all vulnerability characteristics of a preset basic vulnerability exist in the container to be processed, determining that the preset basic vulnerability exists in the container to be processed; If some vulnerability characteristics of a preset basic vulnerability exist in the container to be processed, or if the vulnerability characteristics of the preset basic vulnerability do not exist in the container to be processed, determining that the preset basic vulnerability does not exist in the container to be processed.
4. The method according to claim 1, characterized in that, Determining differential configuration information according to the first configuration information and the second configuration information, including: Generating a first configuration vector according to the first configuration information, where the elements in the first configuration vector correspond to the configuration data in the container to be processed; Generating a second configuration vector according to the second configuration information, where the elements in the second configuration vector correspond to the configuration data in the container image; Comparing the first configuration vector and the second configuration vector to obtain the differential configuration information, where the differential configuration information is used to represent the different elements in the first configuration vector and the second configuration vector.
5. The method according to any one of claims 1 to 4, characterized in that The method further includes: When the differential configuration information indicates no difference, determining that there are no non-basic vulnerabilities; When the difference configuration information indicates a difference, a vulnerability scanning report is generated, and the vulnerability scanning report includes error information that the non - basic vulnerabilities will cause.
6. A container vulnerability handling device, characterized in that Including: A first acquisition unit, configured to acquire the version number of a container to be processed, and acquire the container image corresponding to the version number; A scanning unit, configured to determine basic vulnerability information according to the container image, and perform a basic vulnerability scan on the container to be processed according to the basic vulnerability information; A second acquisition unit, configured to acquire first configuration information and second configuration information, and determine difference configuration information according to the first configuration information and the second configuration information, where the first configuration information refers to the configuration information in the container to be processed, and the second configuration information refers to the configuration information in the container image; A detection unit, configured to generate detection data according to the difference configuration information, and perform a risk detection on the container to be processed by using the detection data to obtain non - basic vulnerability information of the container to be processed; The detection unit includes: A combination unit, configured to combine elements in the difference configuration information to obtain a plurality of difference element combinations; A query unit, configured to query a preset vulnerability database according to each of the difference element combinations to obtain a vulnerability set; A third generation unit, configured to generate the detection data according to the vulnerability set, where the detection data includes input detection data and output detection data; The detection unit includes: A processing module, configured to process the input detection data by using the container to be processed to obtain a processing result; A matching module, configured to match the processing result with the output detection data to obtain a matching result; A third determination module, configured to determine the non - basic vulnerability information of the container to be processed according to the matching result.
7. A computer-readable storage medium, characterized in that, The computer - readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer - readable storage medium is located to execute the method according to any one of claims 1 to 5.
8. An electronic device, characterized in that, Including: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include programs for executing the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Container cluster deployment platform
CN114138402A
Container vulnerability scanning method and device
CN114444082A