Mirror image file management method, device, storage medium and device

By performing security detection and encryption on the image files in the Docker container when receiving the file access instruction, the problem of high-risk vulnerability risks in existing image file management is solved, and the automated encryption processing of the image files is realized, which improves data security.

CN118296641BActive Publication Date: 2025-07-01BEIJING XIAOYOU NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410378433.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-07-01
Estimated Expiration
2044-03-29

AI Technical Summary

Technical Problem

Existing image file management has a high risk of vulnerabilities, resulting in poor data security.

Method used

When receiving the file access instruction, the image file in the Docker container is safely detected, and the image file in the detection result is determined whether to read the image file, and the unread image file is marked and encrypted.

Benefits of technology

By marking and encrypting the mirror files, automated encryption processing is achieved to prevent malicious access from causing data leakage and improve data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118296641B_ABST
    Figure CN118296641B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of cloud native technologies, and discloses a method, device, storage medium and apparatus for managing mirror files. When receiving a file access instruction, the present invention performs a security detection on the mirror files in a Docker container to obtain a security detection result; determines whether to read the mirror files according to the security detection result to obtain a determination result; marks the mirror files according to the determination result, and encrypts the marked mirror files to obtain encrypted mirror files. Compared with the traditional management of mirror files, there is a risk of high-risk vulnerabilities, resulting in poor data security. The present invention realizes automatic encryption processing of mirror files without a large number of configurations and without compilation and installation, prevents data leakage caused by malicious access, and improves data security by marking and encrypting the mirror files to obtain encrypted mirror files.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud native, and particularly to a method, device, storage medium and device for managing mirror files. Background Art

[0002] Currently, with the development of cloud computing, Docker containers are one of the widely used containers. To ensure file security, files are packaged into images, and data transmission security is achieved by managing mirror files. However, there are high-risk vulnerability risks in the existing mirror file management, resulting in poor data security. Summary of the Invention

[0003] The main objective of the present invention is to provide a method, device, storage medium and device for managing mirror files, aiming to solve the technical problem that traditional mirror file management has high-risk vulnerability risks, resulting in poor data security.

[0004] To achieve the above objective, the present invention provides a method for managing mirror files, which is applied to a cloud server. The method for managing mirror files includes the following steps:

[0005] When receiving a file access instruction, perform a security check on the mirror file in the Docker container to obtain a security check result;

[0006] Judge whether to read the mirror file according to the security check result to obtain a judgment result;

[0007] Mark the mirror file according to the judgment result, and encrypt the marked mirror file to obtain an encrypted mirror file.

[0008] Optionally, the step of when receiving a file access instruction, performing a security check on the mirror file in the Docker container to obtain a security check result includes:

[0009] When receiving a file access instruction, perform an anomaly detection on the Docker container to obtain a detection result;

[0010] Perform a security check on a preset mirror folder according to the detection result to obtain a security check result.

[0011] Optionally, the step of marking the mirror file according to the judgment result, and encrypting the marked mirror file to obtain an encrypted mirror file includes:

[0012] Mark the mirror file according to the judgment result, and determine mirror vulnerability information according to the security check result corresponding to the marked mirror file;

[0013] Remove the abnormal image file from the preset image folder according to the mirror vulnerability information, and encrypt the remaining image files.

[0014] Optionally, the step of performing anomaly detection on the Docker container when receiving a file access instruction to obtain a detection result includes:

[0015] When receiving a file access instruction, determine whether there is a to-be-accessed image file in the Docker container according to a preset language model for the to-be-accessed file information included in the file access instruction, and obtain an access judgment result;

[0016] Perform anomaly detection on the Docker container according to the access judgment result to obtain a detection result.

[0017] Optionally, the step of determining whether to read the image file according to the security detection result to obtain a judgment result includes:

[0018] When the security detection result is normal, determine to read the image file;

[0019] When the security detection result is abnormal, determine not to read the image file.

[0020] Optionally, the step of marking the image file according to the judgment result and encrypting the marked image file to obtain an encrypted image file includes:

[0021] When determining not to read the image file, perform a sensitive file scan on the image file to determine sensitive image files;

[0022] Mark the sensitive image files to obtain marked image files;

[0023] Encrypt the marked image files to obtain encrypted image files.

[0024] Optionally, after the step of marking the image file according to the judgment result and encrypting the marked image file to obtain an encrypted image file, it further includes:

[0025] Perform partition processing on the encrypted image file and the local image file, and label different image folders to obtain a labeling result;

[0026] Perform formatting processing on the image folder according to the labeling result to obtain a processed image folder.

[0027] In addition, to achieve the above object, the present invention further provides a mirror file management device, which includes a memory, a processor, and a mirror file management program stored on the memory and executable on the processor. The mirror file management program is configured to implement the steps of mirror file management as described above.

[0028] In addition, to achieve the above object, the present invention further provides a storage medium on which a mirror file management program is stored. When the mirror file management program is executed by a processor, it implements the steps of the mirror file management method as described above.

[0029] In addition, to achieve the above object, the present invention further provides a mirror file management device, which includes:

[0030] A file detection module, configured to perform a security detection on the mirror file in the Docker container when receiving a file access instruction, and obtain a security detection result;

[0031] A reading judgment module, configured to judge whether to read the mirror file according to the security detection result, and obtain a judgment result;

[0032] A file encryption module, configured to mark the mirror file according to the judgment result, and encrypt the marked mirror file to obtain an encrypted mirror file.

[0033] The present invention performs a security detection on the mirror file in the Docker container when receiving a file access instruction to obtain a security detection result; judges whether to read the mirror file according to the security detection result to obtain a judgment result; marks the mirror file according to the judgment result, and encrypts the marked mirror file to obtain an encrypted mirror file. Compared with the traditional mirror file management, which has a high - risk vulnerability and poor data security, the present invention marks and encrypts the mirror file to obtain an encrypted mirror file. The present invention realizes automatic encryption processing of the mirror file without a large number of configurations and without compilation and installation, prevents data leakage caused by malicious access, and improves data security. Description of the Drawings

[0034] Figure 1 It is a schematic structural diagram of a mirror file management device in the hardware operating environment related to the embodiment solution of the present invention;

[0035] Figure 2 It is a schematic flow chart of the first embodiment of the mirror file management method of the present invention;

[0036] Figure 3 It is a schematic block diagram of the first embodiment of the mirror file management device of the present invention.

[0037] The realization, functional features, and advantages of the objectives of the present invention will be further described in conjunction with embodiments with reference to the accompanying drawings. Specific Embodiments

[0038] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0039] Refer to Figure 1 , Figure 1 which is a schematic structural diagram of an image file management device for the hardware operating environment involved in the embodiment solution of the present invention.

[0040] As Figure 1 shown, the image file management device may include: a processor 1001, such as a Central Processing Unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. For the wired interface of the user interface 1003, it may be a USB interface in the present invention. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed Random Access Memory (RAM) or a stable memory (Non-volatile Memory, NVM), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0041] Those skilled in the art can understand that Figure 1 the structure shown in

[0042] does not constitute a limitation on the image file management device and may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements. Figure 1 As

[0043] In Figure 1In the mirror file management device shown, the network interface 1004 is mainly used to connect to the background server and communicate with the background server for data; the user interface 1003 is mainly used to connect to user devices; the mirror file management device calls the mirror file management program stored in the memory 1005 through the processor 1001 and executes the mirror file management method provided by the embodiments of the present invention.

[0044] Based on the above hardware structure, embodiments of the mirror file management method of the present invention are proposed.

[0045] Refer to Figure 2 , Figure 2 which is a schematic flowchart of the first embodiment of the mirror file management method of the present invention, and the first embodiment of the mirror file management method of the present invention is proposed.

[0046] In this embodiment, the mirror file management method is applied to a cloud server, and the mirror file management method includes the following steps:

[0047] Step S10: When a file access instruction is received, perform a security check on the mirror file in the Docker container to obtain a security check result.

[0048] It should be noted that the execution subject in this embodiment may be a device including a mirror file management system, and the device may be a mobile phone, a computer, a tablet. In this embodiment and the following embodiments, the computer is taken as an example to illustrate the mirror file management method of the present invention.

[0049] It can be understood that when a file access instruction is received, a security check is performed on the mirror file in the Docker container. In fact, the security check is divided into static detection and dynamic detection. Through static detection, the mirror file in the container can be scanned to obtain a scan result. According to the scan duration in the scan result, it is judged whether there is repeated scanning resulting in slow speed. If the scan duration exceeds the preset duration, it is determined that there is an abnormality, and the mirror file with the abnormality is determined according to the address information included in the abnormality result. The dynamic detection refers to the dynamic abnormality detection of the network and the host, which can detect behavior vulnerabilities. This solution uses HIDS to detect intrusion behaviors to achieve high accuracy of abnormality detection, so as to judge whether there is an abnormality in the mirror file in the Docker container and obtain a security check result. Mirror files can be created and processed through various tools and software, such as ImgBurn, UltraISO, PowerISO, etc. These tools can read the data on the disk or optical disc and convert it into the mirror file format. At the same time, they can also perform operations such as editing, encrypting, and decompressing the mirror file. Mirror files can also be mounted or opened through various operating systems or virtual machine software to access the data therein.

[0050] It should be understood that the security detection results include static anomaly detection results and dynamic anomaly detection results.

[0051] In a specific implementation, when a file access instruction is received, security detection is performed on the image files in the Docker container to obtain static anomaly detection results and dynamic anomaly detection results.

[0052] Furthermore, step S10 includes: when a file access instruction is received, performing anomaly detection on the Docker container to obtain a detection result; and performing security detection on a preset image folder according to the detection result to obtain security detection results.

[0053] It should be noted that the detection results include static anomaly detection results and dynamic anomaly detection results. When a file access instruction is received, static anomaly detection and dynamic anomaly detection are performed on the Docker container to obtain static anomaly detection results and dynamic anomaly detection results.

[0054] It can be understood that security detection is performed on a preset image folder according to the static anomaly detection results and dynamic anomaly detection results to obtain security detection results. The preset image folder refers to a folder that is preset for storing various types of image files.

[0055] It should be understood that if at least one of the static anomaly detection results and dynamic anomaly detection results is abnormal, secondary security detection is performed on the preset image folder to obtain security detection results.

[0056] In a specific implementation, when performing security detection on the preset image folder, the file name to be accessed carried in the file access instruction is compared with the image files stored in the preset image folder to obtain a comparison result, and whether the access is secure is determined according to the comparison result to obtain security detection results.

[0057] Step S20: Determine whether to read the image file according to the security detection results to obtain a determination result.

[0058] It should be noted that the security detection results include two results: successful match and failed match. When the match is successful, the security detection result is determined to be normal; if the match fails, the security detection result is determined to be abnormal.

[0059] Furthermore, step S20 further includes: when the security detection result is normal, determining to read the image file; when the security detection result is abnormal, determining not to read the image file.

[0060] It can be understood that when the security detection result is normal, it is determined to read the image file; when the security detection result is abnormal, it is determined not to read the image file.

[0061] Step S30: Mark the mirror file according to the judgment result, and encrypt the marked mirror file to obtain an encrypted mirror file.

[0062] It should be noted that when the judgment result is to read the mirror file, the mirror file is read normally. When the judgment result is not to read the mirror file, the files with the similarity between the name of the file to be accessed in the file access instruction and the name of the mirror file exceeding the preset threshold are marked, and the marked mirror file is encrypted to obtain an encrypted mirror file.

[0063] It can be understood that when encrypting the mirror file, the mirror file to be encrypted can be downloaded to the local mirror repository, and the encryption step can be completed. In this solution, the local mirror file can be encrypted by the hash encryption algorithm and measured by the storage reference value. To avoid malicious access, it is necessary to encrypt the suspected mirror file to be read corresponding to the content to be accessed in the file access instruction, so as to avoid data leakage.

[0064] It should be understood that the hash encryption algorithm has high security and short time consumption. In this solution, the local mirror file is encrypted by using the hash encryption algorithm to ensure the encryption speed. The hash encryption algorithm can be obtained by using a 64-bit identifier for the plaintext length and appending 448 bits of plaintext to get a multiple of 512 in length, so as to obtain a partition and a message digest, and then realize encryption. Mark the mirror file according to the judgment result, and encrypt the marked mirror file to obtain an encrypted mirror file.

[0065] Further, step S30 further includes: marking the mirror file according to the judgment result, and determining mirror vulnerability information according to the security detection result corresponding to the marked mirror file; removing the abnormal mirror file from the preset mirror folder according to the mirror vulnerability information, and encrypting the remaining mirror files.

[0066] It should be noted that the mirror file is marked according to the judgment result, and the mirror vulnerability information is determined according to the security detection result corresponding to the marked mirror file. In this solution, the vulnerability metadata is obtained, and the mirror files in the preprocessed mirror repository are mirror-matched. The mirror matching can determine the mirror vulnerability information by matching the mirror features with the vulnerability database metadata, and match the associated mirror files with the mirror vulnerability data for secondary scanning, so as to determine the mirror vulnerability information.

[0067] It can be understood that the mirror file with vulnerabilities is removed from the preset mirror folder as an abnormal mirror file according to the mirror vulnerability information, and the remaining mirror files are encrypted, so as to ensure the data security of the remaining normal mirror files.

[0068] In this embodiment, when a file access instruction is received, security detection is performed on the image file in the Docker container to obtain a security detection result; it is determined whether to read the image file according to the security detection result to obtain a determination result; the image file is marked according to the determination result, and the marked image file is encrypted to obtain an encrypted image file. Compared with the traditional image file management, there is a risk of high-risk vulnerabilities, resulting in poor data security. In this embodiment, by marking and encrypting the image file, an encrypted image file is obtained. The present invention realizes automatic encryption processing of the image file without a large number of configurations and without compilation and installation, prevents data leakage caused by malicious access, and improves data security.

[0069] Based on the above Figure 2 The second embodiment of the image file management method of the present invention is proposed based on the first embodiment shown above.

[0070] In this embodiment, the step of performing anomaly detection on the Docker container when a file access instruction is received to obtain a detection result includes: when a file access instruction is received, it is determined whether there is a to-be-accessed image file in the Docker container according to a preset language model for the to-be-accessed file information included in the file access instruction to obtain an access determination result; anomaly detection is performed on the Docker container according to the access determination result to obtain a detection result.

[0071] It should be noted that the preset language model can be a language classification model constructed based on the LSTM model. Among them, the LSTM language model can capture the to-be-accessed file information included in the file access instruction through a time series call function, and determine whether there is a to-be-accessed image file in the Docker container according to the to-be-accessed file name in the to-be-accessed file information to obtain an access determination result. Compared with the traditional model, the LSTM language model can update the parameters of the model through the gradient descent method, thereby improving the performance of the model.

[0072] It can be understood that when there is no to-be-accessed file, the access is determined to be abnormal, and when there is a to-be-accessed file, the access is determined to be normal.

[0073] It should be understood that when the access is determined to be abnormal, static anomaly detection and dynamic anomaly detection are performed on the Docker container to obtain a static detection result and a dynamic detection result.

[0074] In specific implementation, this solution performs vulnerability scanning by scanning the image folder, stores the scanning result in a database, and determines whether encryption storage is required according to a reference value. If so, abnormal image files are determined according to the vulnerability information, and whether the image is trustworthy is determined, and then encrypted storage is realized.

[0075] In this embodiment, the step S30 further includes: when it is determined not to read the mirror file, performing a sensitive file scan on the mirror file to determine sensitive mirror files; marking the sensitive mirror files to obtain marked mirror files; and encrypting the marked mirror files to obtain encrypted mirror files.

[0076] It should be noted that when it is determined not to read the mirror file, a sensitive file scan is performed on the mirror file to determine sensitive mirror files; a sensitive file refers to a file with sensitive data, and the sensitive mirror files are marked to obtain marked mirror files; the marking process can be to mark with characters, label the sensitive files to obtain marked sensitive files, and encrypt the marked mirror files to obtain encrypted mirror files.

[0077] In specific implementation, when it is determined not to read the mirror file, a sensitive file scan is performed on the mirror file to determine sensitive mirror files; the sensitive mirror files are marked to obtain marked mirror files; and the marked mirror files are encrypted to obtain encrypted mirror files.

[0078] In this embodiment, after the step S30, it further includes: performing a partition process on the encrypted mirror file and the local mirror file, and marking different mirror folders to obtain a marking result; and performing a formatting process on the mirror folders according to the marking result to obtain processed mirror folders.

[0079] It should be noted that a partition process is performed on the encrypted mirror file and the local mirror file, and different mirror folders are marked to obtain a marking result; the marking process can be to distinguish by characters or numbers to obtain the marking result.

[0080] It can be understood that according to the marking result, a formatting process is performed on the mirror folders to obtain processed mirror folders, and the processed mirror folders are further formatted to obtain mirror folders with a unified format. The mirror file format is a file format that copies all data on storage media such as disks or optical discs into a single file. In this way, the content of an entire disk or optical disc can be saved in a single file for backup, cloning, transmission, or installation. Mirror file formats include ISO, BIN, DMG, IMG, etc. Among them, ISO is a common optical disc image file format widely used for operations such as CD and DVD optical disc backup, cloning, and burning; BIN is the default image file format of CDRWin software and is also used for optical disc backup and cloning; DMG is a disk image file format on Apple computers used to store and transfer Mac OS X operating systems and applications, etc.; IMG is a common disk image file format that can store various types of disk data.

[0081] In a specific implementation, in this solution, the encrypted image file and the local image file are partitioned, and different image folders are labeled to obtain a labeling result; the image folders are formatted according to the labeling result to obtain processed image folders.

[0082] In this embodiment, when a file access instruction is received, a security check is performed on the image file in the Docker container to obtain a security check result; it is determined whether to read the image file according to the security check result to obtain a determination result; the image file is marked according to the determination result, and the marked image file is encrypted to obtain an encrypted image file. Compared with the traditional image file management, there is a risk of high-risk vulnerabilities, resulting in poor data security. In this embodiment, by marking and encrypting the image file, an encrypted image file is obtained. The present invention realizes automatic encryption processing of the image file without a large number of configurations and without compilation and installation, prevents data leakage caused by malicious access, and improves data security.

[0083] In addition, to achieve the above object, the present invention also proposes a storage medium, on which an image file management program is stored, and when the image file management program is executed by a processor, the steps of the image file management method as described above are implemented.

[0084] Refer to Figure 3 , Figure 3 which is the structural block diagram of the first embodiment of the image file management device of the present invention.

[0085] As Figure 3 shown, the image file management device proposed in the embodiment of the present invention includes:

[0086] A file detection module 10, configured to perform a security check on the image file in the Docker container when a file access instruction is received to obtain a security check result;

[0087] A reading judgment module 20, configured to determine whether to read the image file according to the security check result to obtain a determination result;

[0088] A file encryption module 30, configured to mark the image file according to the determination result and encrypt the marked image file to obtain an encrypted image file.

[0089] In this embodiment, when a file access instruction is received, a security check is performed on the image file in the Docker container to obtain a security check result; it is determined whether to read the image file according to the security check result to obtain a determination result; the image file is marked according to the determination result, and the marked image file is encrypted to obtain an encrypted image file. Compared with the traditional image file management which has a high - risk vulnerability risk, resulting in poor data security, in this embodiment, by marking and encrypting the image file, an encrypted image file is obtained. The present invention realizes automatic encryption processing of the image file without a large number of configurations and without compilation and installation, prevents data leakage caused by malicious access, and improves data security.

[0090] Further, the file detection module 10 is further configured to, when a file access instruction is received, perform an anomaly detection on the Docker container to obtain a detection result; perform a security check on a preset image folder according to the detection result to obtain a security check result.

[0091] Further, the file encryption module 30 is further configured to mark the image file according to the determination result, and determine image vulnerability information according to the security check result corresponding to the marked image file; remove the abnormal image file from the preset image folder according to the image vulnerability information, and encrypt the remaining image files.

[0092] Further, the file detection module 10 is further configured to, when a file access instruction is received, determine whether there is a to - be - accessed image file in the Docker container according to a preset language model for the to - be - accessed file information included in the file access instruction to obtain an access determination result; perform an anomaly detection on the Docker container according to the access determination result to obtain a detection result.

[0093] Further, the file detection module 10 is further configured to determine to read the image file when the security check result is normal; determine not to read the image file when the security check result is abnormal.

[0094] Further, the file encryption module 30 is further configured to, when it is determined not to read the image file, perform a sensitive file scan on the image file to determine sensitive image files; mark the sensitive image files to obtain a marked image file; encrypt the marked image file to obtain an encrypted image file.

[0095] Further, the file encryption module 30 is further configured to perform partition processing on the encrypted image file and the local image file, and label different image folders to obtain a labeling result; perform formatting processing on the image folder according to the labeling result to obtain a processed image folder.

[0096] It should be understood that the above is only for illustration and does not constitute any limitation to the technical solution of the present invention. In specific applications, those skilled in the art can set it according to needs, and the present invention does not make any restrictions in this regard.

[0097] It should be noted that the above-described work process is only illustrative and does not limit the protection scope of the present invention. In actual applications, those skilled in the art can select some or all of them according to actual needs to achieve the purpose of the solution of this embodiment, and no restrictions are made here.

[0098] In addition, for the technical details not described in detail in this embodiment, reference can be made to the mirror file management method provided in any embodiment of the present invention, and details will not be repeated here.

[0099] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or system including that element.

[0100] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments. Among the several apparatus unit claims listing several apparatuses, several of these apparatuses may be embodied by the same hardware item. The use of the terms first, second, and third, etc. does not denote any order, and these terms can be interpreted as names.

[0101] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as a Read Only Memory image (ROM) / Random Access Memory (RAM), magnetic disk, optical disk), and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0102] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present invention.

Claims

1. A method for managing an image file, characterized in that: The image file management method comprises the following steps: When receiving a file access instruction, perform a security check on the image file in the Docker container to obtain a security check result; Determine whether to read the image file according to the security detection result, and obtain a determination result; Marking the image file according to the judgment result, and encrypting the marked image file by a hash encryption algorithm to obtain an encrypted image file; When receiving a file access instruction, a function is called according to a time series of a preset language model to determine whether there is an image file to be accessed in the Docker container based on the file information to be accessed contained in the file access instruction, and an access judgment result is obtained, wherein the preset language model is a language classification model built based on the LSTM model; Perform an abnormality detection on the Docker container according to the access judgment result to obtain a detection result; Perform static detection and dynamic detection on the image file in the Docker container according to the detection result to obtain a security detection result; The security detection result includes a static anomaly detection result and a dynamic anomaly detection result. The step of performing static detection and dynamic detection on the image file in the Docker container according to the detection result to obtain the security detection result includes: Based on the detection result, the image file in the Docker container is scanned to obtain a scanning result, and whether repeated scanning causes slow speed is determined according to the scanning time of the scanning result and the preset time, so as to obtain a static anomaly detection result; The HIDS detects intrusion behavior and determines whether the image file in the Docker container is abnormal, thereby obtaining a dynamic anomaly detection result.

2. The image file management method according to claim 1, characterized in that: The step of performing a security check on the image file in the Docker container upon receiving the file access instruction and obtaining a security check result comprises: When receiving a file access instruction, perform anomaly detection on the Docker container and obtain the detection result; A security check is performed on the preset mirror folder according to the detection result to obtain a security check result.

3. The image file management method according to claim 2, characterized in that: The step of marking the image file according to the judgment result, and encrypting the marked image file by a hash encryption algorithm to obtain the encrypted image file includes: Marking the image file according to the judgment result, and determining the image vulnerability information according to the security detection result corresponding to the marked image file; According to the image vulnerability information, abnormal image files are removed from the preset image folder, and the remaining image files are encrypted by a hash encryption algorithm.

4. The image file management method according to claim 1, characterized in that: The step of determining whether to read the image file according to the security detection result and obtaining the determination result comprises: When the security detection result is normal, determining to read the image file; When the security detection result is abnormal, it is determined not to read the image file.

5. The image file management method according to claim 1, characterized in that: The step of marking the image file according to the judgment result, and encrypting the marked image file by a hash encryption algorithm to obtain the encrypted image file includes: When it is determined that the image file is not to be read, performing a sensitive file scan on the image file to determine a sensitive image file; Marking the sensitive image file to obtain a marked image file; The marked image file is encrypted by a hash encryption algorithm to obtain an encrypted image file.

6. The image file management method according to claim 5, characterized in that: After the step of marking the image file according to the judgment result, and encrypting the marked image file by a hash encryption algorithm to obtain the encrypted image file, the method further includes: Partition the encrypted image file and the local image file, and mark different image folders to obtain the marking results; The mirror folder is formatted according to the marking result to obtain a processed mirror folder.

7. An image file management device, characterized in that: The image file management device comprises: a memory, a processor, and an image file management program stored in the memory and executable on the processor, wherein the image file management program implements the image file management method according to any one of claims 1 to 6 when executed by the processor.

8. A storage medium, characterized in that: The storage medium stores an image file management program, and when the image file management program is executed by the processor, the image file management method according to any one of claims 1 to 6 is implemented.

9. A mirror file management device, characterized in that: The image file management device comprises: The file detection module is used to perform security detection on the image file in the Docker container and obtain security detection results when receiving a file access instruction; A reading judgment module, used to judge whether to read the image file according to the security detection result, and obtain a judgment result; A file encryption module, used to mark the image file according to the judgment result, and encrypt the marked image file through a hash encryption algorithm to obtain an encrypted image file; The file detection module is further used to, when receiving a file access instruction, determine whether there is a to-be-accessed image file in the Docker container according to the time series of a preset language model to the to-be-accessed file information contained in the file access instruction, and obtain an access judgment result, wherein the preset language model is a language classification model built based on the LSTM model; perform anomaly detection on the Docker container according to the access judgment result to obtain a detection result; perform static detection and dynamic detection on the image file in the Docker container according to the detection result to obtain a security detection result; The file detection module is also used to scan the image file in the Docker container based on the detection result to obtain the scanning result, and determine whether there is repeated scanning resulting in slow speed according to the scanning time of the scanning result and the preset time to obtain the static anomaly detection result; and determine whether there is an anomaly in the image file in the Docker container by detecting the intrusion behavior through HIDS to obtain the dynamic anomaly detection result.

Citation Information

Patent Citations

  • Encryption and decryption method and device for mirror image verification, and medium

    CN111125725A

  • Docker mirror image security detection method

    CN113268739A