Edge container cloud mirror image processing method based on cloud edge collaborative scene
By implementing the edge container cloud mirroring processing method based on cloud edge collaborative scenarios on the edge side, the problem of low mirror accuracy due to manual processing is solved, and more efficient and stable mirror processing and security management are achieved.
Patent Information
- Application Number
- CN202510013985.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, mirror processing relies on manual operations and there are subjective factors, resulting in low processing accuracy, which in turn affects the operation stability of the mirror.
The edge container cloud image processing method based on cloud edge collaborative scenarios is adopted. By receiving the mirror whitelist, filtering candidate images, obtaining mirror information, performing feature extraction and detection, determining normal and abnormal images, performing repair and reinforcement processing, and finally encrypting sensitive data.
It improves the accuracy and stability of mirror processing, reduces subjective errors in manual intervention, and enhances the security and legality of mirroring.
Smart Images

Figure CN119938225A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, apparatus, computer device, computer-readable storage medium, and computer program product for processing edge container cloud images in a cloud-edge collaboration scenario. Background Art
[0002] At present, in order to ensure the operational stability of images (such as edge container cloud images), it is crucial to accurately process the images.
[0003] In traditional technology, manual processing is generally used in the process of processing images; however, this manual processing method has subjective factors and is prone to errors, resulting in low accuracy of image processing, which in turn causes low operating stability of the image. Summary of the invention
[0004] Based on this, it is necessary to provide an edge container cloud image processing method, device, computer equipment, computer-readable storage medium and computer program product based on a cloud-edge collaboration scenario, which can improve the operating stability of the image, in response to the above technical problems.
[0005] In a first aspect, the present application provides an edge container cloud image processing method based on a cloud-edge collaboration scenario, which is applied to the edge side, including:
[0006] Receive the image whitelist sent by the center;
[0007] From multiple candidate images, select a candidate image corresponding to the image whitelist as the image to be processed; the image to be processed refers to an edge container cloud image;
[0008] Obtaining image information of the image to be processed;
[0009] Performing feature extraction processing on the image information to obtain a feature vector corresponding to the image information, inputting the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed;
[0010] According to the target image detection result, determining a normal image and an abnormal image in each of the images to be processed;
[0011] Repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image;
[0012] The sensitive data in the target hardened image is encrypted to obtain an encrypted image.
[0013] In one of the embodiments, obtaining the image information of the image to be processed includes:
[0014] Obtain source information, version information, and modification record information of the image to be processed;
[0015] Preprocessing the source information, the version information and the modification record information to obtain preprocessed source information, preprocessed version information and preprocessed modification record information;
[0016] The preprocessed source information, the preprocessed version information and the preprocessed modification record information are combined and processed according to a preset combination method to obtain the mirror information.
[0017] In one embodiment, the repairing the abnormal image to obtain a repaired image includes:
[0018] Perform vulnerability scanning on the abnormal image through an image scanning tool to obtain target vulnerability information in the abnormal image;
[0019] According to the target vulnerability information, query the corresponding relationship between the vulnerability information and the repair instruction to obtain the target repair instruction corresponding to the abnormal image;
[0020] According to the target repair instruction, the abnormal image is repaired to obtain a repaired image.
[0021] In one embodiment, the step of performing reinforcement processing on the normal image and the repaired image to obtain a target reinforced image includes:
[0022] Determine a first image type corresponding to the normal image and a second image type corresponding to the repaired image;
[0023] Determine, according to the first image type, a first reinforcement tool corresponding to the normal image, and, according to the second image type, determine a second reinforcement tool corresponding to the repaired image;
[0024] Using the first reinforcement tool, the normal image is reinforced to obtain a first reinforced image, and using the second reinforcement tool, the repaired image is reinforced to obtain a second reinforced image;
[0025] The first reinforced image and the second reinforced image are both used as the target reinforced image.
[0026] In one of the embodiments, after selecting a candidate image corresponding to the image whitelist from a plurality of candidate images as the image to be processed, the method further includes:
[0027] Determine a target image from the multiple candidate images; the target image is used to represent an image other than the image to be processed among the multiple candidate images;
[0028] Determining a target computing unit corresponding to the target image according to an image identifier corresponding to the target image;
[0029] The target computing unit is deleted.
[0030] In one embodiment, the trained image detection model is trained in the following manner:
[0031] Get the sample image information of the sample image;
[0032] Performing feature extraction processing on the sample image information to obtain a sample feature vector corresponding to the sample image information, inputting the sample feature vector into the image detection model to be trained, and obtaining a predicted image detection result corresponding to the sample image;
[0033] An actual image detection result corresponding to the sample image is obtained, and according to a difference between the predicted image detection result and the actual image detection result, the image detection model to be trained is iteratively trained to obtain the trained image detection model.
[0034] In the second aspect, the present application also provides an edge container cloud image processing device based on a cloud-edge collaboration scenario, which is applied to the edge side, including:
[0035] The list receiving module is used to receive the image whitelist sent by the center side;
[0036] An image screening module, used to screen out a candidate image corresponding to the image whitelist from a plurality of candidate images as an image to be processed; the image to be processed refers to an edge container cloud image;
[0037] An information acquisition module, used to acquire the image information of the image to be processed;
[0038] An image detection module is used to perform feature extraction processing on the image information to obtain a feature vector corresponding to the image information, and input the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed;
[0039] An image determination module, used to determine a normal image and an abnormal image in each of the images to be processed according to the target image detection result;
[0040] An image reinforcement module is used to repair the abnormal image to obtain a repaired image, and to reinforce the normal image and the repaired image to obtain a target reinforced image;
[0041] The image encryption module is used to encrypt the sensitive data in the target hardened image to obtain an encrypted image.
[0042] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0043] Receive the image whitelist sent by the center;
[0044] From multiple candidate images, select a candidate image corresponding to the image whitelist as the image to be processed; the image to be processed refers to an edge container cloud image;
[0045] Obtaining image information of the image to be processed;
[0046] Performing feature extraction processing on the image information to obtain a feature vector corresponding to the image information, inputting the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed;
[0047] According to the target image detection result, determining a normal image and an abnormal image in each of the images to be processed;
[0048] Repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image;
[0049] The sensitive data in the target hardened image is encrypted to obtain an encrypted image.
[0050] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0051] Receive the image whitelist sent by the center;
[0052] From multiple candidate images, select a candidate image corresponding to the image whitelist as the image to be processed; the image to be processed refers to an edge container cloud image;
[0053] Obtaining image information of the image to be processed;
[0054] Performing feature extraction processing on the image information to obtain a feature vector corresponding to the image information, inputting the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed;
[0055] According to the target image detection result, determining a normal image and an abnormal image in each of the images to be processed;
[0056] Repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image;
[0057] The sensitive data in the target hardened image is encrypted to obtain an encrypted image.
[0058] In a fifth aspect, the present application further provides a computer program product, including a computer program, which implements the following steps when executed by a processor:
[0059] Receive the image whitelist sent by the center;
[0060] From multiple candidate images, select a candidate image corresponding to the image whitelist as the image to be processed; the image to be processed refers to an edge container cloud image;
[0061] Obtaining image information of the image to be processed;
[0062] Performing feature extraction processing on the image information to obtain a feature vector corresponding to the image information, inputting the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed;
[0063] According to the target image detection result, determining a normal image and an abnormal image in each of the images to be processed;
[0064] Repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image;
[0065] The sensitive data in the target hardened image is encrypted to obtain an encrypted image.
[0066] The above-mentioned edge container cloud image processing method, device, computer equipment, storage medium and computer program product based on the cloud-edge collaboration scenario first receive the image whitelist sent by the center side, and screen out the candidate image corresponding to the image whitelist from multiple candidate images as the image to be processed, and then obtain the image information of the image to be processed, and then perform feature extraction processing on the image information to obtain the feature vector corresponding to the image information, and input the feature vector into the trained image detection model to obtain the target image detection result corresponding to the image to be processed, and determine the normal image and abnormal image in each image to be processed according to the target image detection result, and then repair the abnormal image to obtain the repaired image, and reinforce the normal image and the repaired image to obtain the target reinforced image, and finally, encrypt the sensitive data in the target reinforced image to obtain the encrypted image. In this way, in the process of processing the image, the image to be processed among multiple candidate images can be determined based on the image whitelist, and the normal image and the abnormal image in the image to be processed can be accurately determined through the trained image detection model, and the abnormal image can be repaired, and the normal image and the repaired image can be reinforced and encrypted, so that the corresponding image processing can be performed according to the image detection situation of the image to be processed, and the image can be processed more accurately, which is conducive to improving the accuracy of image processing and thus improving the operating stability of the image; moreover, the whole process does not require human intervention, avoiding the subjective factors in the manual processing method, which is prone to errors, resulting in low accuracy of image processing, and then causing the defect of low operating stability of the image, further improving the operating stability of the image. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0068] Figure 1 This is an application environment diagram of an edge container cloud image processing method based on a cloud-edge collaboration scenario in an embodiment;
[0069] Figure 2 It is a flowchart of an edge container cloud image processing method based on a cloud-edge collaboration scenario in an embodiment;
[0070] Figure 3 It is a schematic diagram of the architecture of a method for trusted and secure management and control of edge container cloud images in a cloud-edge collaboration scenario in one embodiment;
[0071] Figure 4 It is a flowchart of an edge container cloud image processing method based on a cloud-edge collaboration scenario in another embodiment;
[0072] Figure 5 It is a structural block diagram of an edge container cloud image processing device based on a cloud-edge collaboration scenario in an embodiment;
[0073] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0074] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0075] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0076] The edge container cloud image processing method based on the cloud-edge collaboration scenario provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown in FIG. 1 , the center side 102 communicates with the edge side 104 through a network. Specifically, refer to Figure 1 , the center side 102 sends the image whitelist to the edge side 104, and the edge side 104 selects the candidate image corresponding to the image whitelist from multiple candidate images as the image to be processed, obtains the image information of the image to be processed, performs feature extraction processing on the image information, obtains the feature vector corresponding to the image information, inputs the feature vector into the trained image detection model, obtains the target image detection result corresponding to the image to be processed, and determines the normal image and the abnormal image in each image to be processed according to the target image detection result, repairs the abnormal image to obtain the repaired image, reinforces the normal image and the repaired image to obtain the target reinforced image, and encrypts the sensitive data in the target reinforced image to obtain the encrypted image. Among them, the center side 102 is also called the cloud, which can be a terminal or a server; the edge side 104 is also called the edge device, which can be a terminal or a server. The terminal can be, but is not limited to, various personal computers, laptops, smart phones and tablets. The server can be implemented as an independent server or a server cluster composed of multiple servers.
[0077] In an exemplary embodiment, Figure 2 As shown, a method for processing edge container cloud images based on a cloud-edge collaboration scenario is provided. Figure 1 Taking the edge side in the example as an example, in this embodiment, the method includes the following steps:
[0078] Step S201, receiving the mirror whitelist sent by the center side.
[0079] The image whitelist refers to the list information used to filter out illegal images.
[0080] Exemplarily, the edge side obtains first location information of the edge side and second location information of the center side; then, the edge side establishes a network path between the edge side and the center side based on the first location information and the second location information; then, the edge side receives the mirror whitelist sent by the center side through the network path.
[0081] Step S202: Filter out a candidate image corresponding to the image whitelist from multiple candidate images as an image to be processed; the image to be processed refers to an edge container cloud image.
[0082] The candidate image refers to the image to be selected.
[0083] The image to be processed refers to the image that needs to be processed.
[0084] The edge container cloud image refers to the container cloud image that needs to be processed on the edge side. The container cloud image is used to represent a lightweight executable software package that packages the application and all its dependencies together.
[0085] Exemplarily, the edge side extracts the image identity information in the image whitelist; then, the edge side selects candidate images corresponding to the image identity information from multiple candidate images, and uses these candidate images as images to be processed.
[0086] For example, see Figure 3 If the image whitelist contains the image identity information of image 1 and image 2, it means that image 1 and image 2 are legal and can be used normally by the edge side as images to be processed; if the image whitelist does not contain the image identity information of image 3, it means that image 3 is illegal.
[0087] Step S203, obtaining image information of the image to be processed.
[0088] The image information includes the source information, version information and modification record information of the image to be processed.
[0089] Exemplarily, the edge side obtains the source information, version information and modification record information of the image to be processed; then, the edge side uses the source information, version information and modification record information of the image to be processed as the image information of the image to be processed.
[0090] Step S204, performing feature extraction processing on the mirror information to obtain a feature vector corresponding to the mirror information, inputting the feature vector into the trained mirror detection model to obtain a target mirror detection result corresponding to the mirror to be processed.
[0091] Among them, the feature vector is used to represent the characterization vector corresponding to the mirror information.
[0092] Among them, the image detection model refers to a network model that can use the feature vector corresponding to the image information of the image to be processed to obtain the target image detection result corresponding to the image to be processed, such as a convolutional neural network model and a recurrent neural network model.
[0093] The target image detection result is used to indicate the comprehensive detection status of the image to be processed.
[0094] Exemplarily, the edge side identifies the data type of the mirror information; then, the edge side queries the correspondence between the data type and the feature extraction model according to the data type of the mirror information, and obtains the feature extraction model corresponding to the data type of the mirror information as the feature extraction model corresponding to the mirror information; then, the edge side inputs the mirror information into the feature extraction model corresponding to the mirror information, performs feature extraction processing on the mirror information through the feature extraction model corresponding to the mirror information, and obtains the feature vector corresponding to the mirror information; then, the edge side inputs the feature vector into the trained mirror detection model to obtain the predicted probability of the image to be processed under each preset mirror detection result; then, the edge side screens out the preset mirror detection result with the largest predicted probability from each preset mirror detection result, and uses the preset mirror detection result as the target mirror detection result corresponding to the image to be processed.
[0095] Step S205: determining normal images and abnormal images in the images to be processed according to the target image detection result.
[0096] Among them, a normal image is also called a legal image.
[0097] Among them, abnormal images are also called illegal images.
[0098] Exemplarily, the edge side extracts indicator data from the target image detection result as indicator data of the image to be processed; then, the edge side determines the normal image and the abnormal image in each image to be processed based on the indicator data of the image to be processed; for example, if each indicator data satisfies a preset indicator data range, the image to be processed is judged to be a normal image; if there is one indicator data in each indicator data that does not satisfy the preset indicator data range, the image to be processed is judged to be an abnormal image.
[0099] Step S206, repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image.
[0100] The repaired image refers to the abnormal image after repair processing.
[0101] The target reinforced image includes a normal image after reinforcement processing and a repaired image after reinforcement processing.
[0102] Exemplarily, the edge side obtains vulnerability information in the abnormal image, and repairs the abnormal image according to the vulnerability information in the abnormal image to obtain a repaired image; then, the server uses a reinforcement tool to reinforce the normal image and the repaired image to obtain a target reinforced image.
[0103] Step S207, encrypting the sensitive data in the target hardened image to obtain an encrypted image.
[0104] Among them, sensitive data refers to data in the hardened image whose importance is greater than the preset importance.
[0105] The encrypted image refers to a hardened image obtained by encrypting sensitive data.
[0106] Exemplarily, the edge side obtains the data to be analyzed in the target reinforced image; then, the edge side inputs the data to be analyzed into the trained importance prediction model to obtain the importance of each data to be analyzed; then, the edge side filters out the data to be analyzed whose importance is greater than the preset importance from each data to be analyzed, as the sensitive data in the target reinforced image; then, the edge side encrypts the sensitive data in the target reinforced image to obtain the encrypted image.
[0107] In the above-mentioned edge container cloud image processing method based on the cloud-edge collaboration scenario, the image whitelist sent by the center side is first received, and the candidate image corresponding to the image whitelist is screened out from multiple candidate images as the image to be processed, and then the image information of the image to be processed is obtained. Next, feature extraction processing is performed on the image information to obtain a feature vector corresponding to the image information, and the feature vector is input into the trained image detection model to obtain the target image detection result corresponding to the image to be processed, and according to the target image detection result, the normal image and the abnormal image in each image to be processed are determined, and then, the abnormal image is repaired to obtain the repaired image, and the normal image and the repaired image are reinforced to obtain the target reinforced image. Finally, the sensitive data in the target reinforced image is encrypted to obtain the encrypted image. In this way, in the process of processing the image, the image to be processed among multiple candidate images can be determined based on the image whitelist, and the normal image and the abnormal image in the image to be processed can be accurately determined through the trained image detection model, and the abnormal image can be repaired, and the normal image and the repaired image can be reinforced and encrypted, so that the corresponding image processing can be performed according to the image detection situation of the image to be processed, and the image can be processed more accurately, which is conducive to improving the accuracy of image processing and thus improving the operating stability of the image; moreover, the whole process does not require human intervention, avoiding the subjective factors in the manual processing method, which is prone to errors, resulting in low accuracy of image processing, and then causing the defect of low operating stability of the image, further improving the operating stability of the image.
[0108] In an exemplary embodiment, the above step S203, obtaining the image information of the image to be processed, specifically includes the following contents: obtaining the source information, version information and modification record information of the image to be processed; preprocessing the source information, version information and modification record information to obtain preprocessed source information, preprocessed version information and preprocessed modification record information; combining the preprocessed source information, preprocessed version information and preprocessed modification record information according to a preset combination method to obtain the image information.
[0109] The source information is used to indicate the creation location of the image to be processed.
[0110] The version information is used to indicate the version number of the image to be processed.
[0111] The modification record information is used to indicate the changes of the image to be processed, including the modification time, modification personnel, and modification specific content.
[0112] The preprocessed source information refers to the source information after preprocessing.
[0113] The preprocessed version information refers to the version information after preprocessing.
[0114] The post-preprocessing modification record information refers to the modification record information after preprocessing.
[0115] The preset combination mode refers to a preset combination mode, which may be a combination mode from left to right. It should be noted that the preset combination mode depends on the situation.
[0116] Exemplarily, the edge side obtains the image identity information of the image to be processed, and determines the source information, version information and modification record information corresponding to the image identity information according to the image identity information of the image to be processed, as the source information, version information and modification record information of the image to be processed respectively; then, the edge side identifies the abnormal information in the source information, version information and modification record information, and deletes the abnormal information in the source information, version information and modification record information to obtain the pre-processed source information, pre-processed version information and pre-processed modification record information; then, the edge side combines the pre-processed source information, pre-processed version information and pre-processed modification record information according to a preset combination method to obtain the combined information as the image information.
[0117] In this embodiment, by obtaining multi-dimensional information of the image to be processed, and performing preprocessing and combination processing, the image information of the image to be processed is made more comprehensive, which is conducive to improving the accuracy of determining the image information of the image to be processed and provides a more accurate data basis for subsequent data analysis.
[0118] In an exemplary embodiment, the above step S206, repairing the abnormal image to obtain a repaired image, specifically includes the following contents: performing vulnerability scanning on the abnormal image through an image scanning tool to obtain target vulnerability information in the abnormal image; according to the target vulnerability information, querying the correspondence between the vulnerability information and the repair instruction to obtain the target repair instruction corresponding to the abnormal image; according to the target repair instruction, repairing the abnormal image to obtain the repaired image.
[0119] Among them, image scanning tools refer to tools used to perform vulnerability scanning and security detection on images, such as Clair (a container security scanning tool), Trivy (a container security scanning tool), etc.
[0120] The target vulnerability information refers to the vulnerability information in the abnormal image.
[0121] The corresponding relationship between vulnerability information and repair instructions is used to indicate the association information between vulnerability information and repair instructions. For example, vulnerability information A corresponds to repair instruction a, vulnerability information B corresponds to repair instruction b, and vulnerability information C corresponds to repair instruction c.
[0122] The target repair instruction refers to the repair instruction corresponding to the abnormal image.
[0123] Exemplarily, the edge side performs vulnerability scanning on the abnormal image through an image scanning tool to obtain vulnerability information in the abnormal image as target vulnerability information; then, the edge side extracts key vulnerability information (such as vulnerability type) in the target vulnerability information; then, the edge side queries the correspondence between the vulnerability information and the repair instruction based on the key vulnerability information, and obtains the repair instruction corresponding to the key vulnerability information as the target repair instruction corresponding to the abnormal image; then, the edge side performs integrity check on the target repair instruction to obtain the integrity check result corresponding to the target repair instruction; when the integrity check result corresponding to the target repair instruction is passed, the edge side repairs the abnormal image according to the target repair instruction to obtain the repaired image.
[0124] In this embodiment, by using an image scanning tool to perform vulnerability scanning on the abnormal image, the target vulnerability information in the abnormal image can be accurately obtained, and through the corresponding relationship, the target repair instructions that match the abnormal image can be more accurately determined, which is beneficial to improving the repair effect of the abnormal image.
[0125] In an exemplary embodiment, the above step S206, which performs reinforcement processing on the normal image and the repaired image to obtain a target reinforced image, specifically includes the following contents: determining a first image type corresponding to the normal image, and a second image type corresponding to the repaired image; determining a first reinforcement tool corresponding to the normal image according to the first image type, and determining a second reinforcement tool corresponding to the repaired image according to the second image type; reinforcing the normal image by the first reinforcement tool to obtain a first reinforced image, and reinforcing the repaired image by the second reinforcement tool to obtain a second reinforced image; using the first reinforced image and the second reinforced image as the target reinforced image.
[0126] The first image type refers to an image type corresponding to a normal image.
[0127] The second image type refers to the image type corresponding to the repaired image.
[0128] The first reinforcement tool refers to the reinforcement tool corresponding to the normal image.
[0129] Among them, the hardening tools include Docker Bench Security (an image hardening tool).
[0130] The second reinforcement tool refers to the reinforcement tool corresponding to the repaired image.
[0131] The first reinforced image refers to a normal image after reinforcement.
[0132] The second reinforced image refers to a repaired image after reinforcement processing.
[0133] Exemplarily, the edge side extracts the first metadata corresponding to the normal image and the second metadata corresponding to the repaired image respectively; then, the edge side determines the first image type corresponding to the normal image based on the first metadata, and determines the second image type corresponding to the repaired image based on the second metadata; then, the edge side queries the correspondence between the image type and the reinforcement tool based on the first image type to obtain the first reinforcement tool corresponding to the normal image, and queries the correspondence between the image type and the reinforcement tool based on the second image type to obtain the second reinforcement tool corresponding to the repaired image; then, the edge side reinforces the normal image through the first reinforcement tool to obtain the first reinforced image, and reinforces the repaired image through the second reinforcement tool to obtain the second reinforced image; then, the edge side uses the first reinforced image and the second reinforced image as the target reinforced images.
[0134] In this embodiment, the types of the normal image and the repaired image are first determined, and then the corresponding reinforcement tools are selected accordingly, thereby achieving accurate adaptation of the reinforcement tools and the image, so that the advantages of different reinforcement tools can be fully utilized, thereby improving the reinforcement effect of the image, and facilitating the stability of the image reinforcement quality.
[0135] In an exemplary embodiment, the above step S202, after screening out a candidate image corresponding to the image whitelist from multiple candidate images as the image to be processed, specifically includes the following contents: determining a target image from multiple candidate images; the target image is used to represent an image other than the image to be processed in the multiple candidate images; determining a target computing unit corresponding to the target image according to an image identifier corresponding to the target image; and deleting the target computing unit.
[0136] The target image is used to represent images other than the image to be processed among multiple candidate images, also known as illegal images.
[0137] The image identifier refers to identification information that uniquely distinguishes an image, such as an image number.
[0138] The target computing unit refers to the Pod (the smallest deployable computing unit) corresponding to the target image.
[0139] Exemplarily, the edge side determines, from among multiple candidate images, an image other than the image to be processed as the target image; then, the edge side determines, based on the image identifier corresponding to the target image, a computing unit corresponding to the image identifier as the target computing unit corresponding to the target image; then, the edge side generates a computing unit deletion instruction corresponding to the target computing unit, and deletes the target computing unit according to the computing unit deletion instruction.
[0140] For example, see Figure 3 If the image whitelist does not contain the image identity information of image 3, it means that image 3 is illegal, and the computing unit using image 3 is stopped and deleted.
[0141] In this embodiment, by accurately locating and deleting target computing units that are not related to the image to be processed, the attack surface of the system can be directly reduced, and the possibility of external malicious attacks can be reduced, thereby ensuring the security and legality of the edge-side cloud image, and then effectively responding to security issues, which is conducive to ensuring the safe operation of the edge container cloud.
[0142] In an exemplary embodiment, the edge container cloud image processing method based on the cloud-edge collaboration scenario provided by the present application also includes a training step of a trained image detection model, which specifically includes the following contents: obtaining sample image information of a sample image; performing feature extraction processing on the sample image information to obtain a sample feature vector corresponding to the sample image information, and inputting the sample feature vector into the image detection model to be trained to obtain a predicted image detection result corresponding to the sample image; obtaining the actual image detection result corresponding to the sample image, and iteratively training the image detection model to be trained based on the difference between the predicted image detection result and the actual image detection result to obtain a trained image detection model.
[0143] The sample image refers to an image used to train the image detection model to be trained.
[0144] The sample image information refers to the image information of the sample image.
[0145] The sample feature vector refers to the feature vector corresponding to the sample mirror information.
[0146] The predicted image detection result refers to the predicted value corresponding to the image detection result of the sample image.
[0147] The actual image detection result refers to the actual value corresponding to the image detection result of the sample image.
[0148] Exemplarily, the edge side obtains sample image information of the sample image from the database in response to a model training instruction for the image detection model to be trained; then, the edge side performs feature extraction processing on the sample image information to obtain a sample feature vector corresponding to the sample image information, and inputs the sample feature vector into the image detection model to be trained to obtain a predicted image detection result corresponding to the sample image; then, the edge side obtains the actual image detection result corresponding to the sample image, and obtains a loss value based on the difference between the predicted image detection result and the actual image detection result; then, the edge side adjusts the model parameters of the image detection model to be trained based on the loss value; then, the edge side re-trains the image detection model after the model parameters are adjusted until the loss value obtained by the trained image detection model is less than the loss value threshold, then stops the training, and uses the trained image detection model as the trained image detection model.
[0149] In this embodiment, by pre-training the image detection model, it is convenient in actual application to predict the target image detection result corresponding to the image to be processed after obtaining the image information of the image to be processed; moreover, the image detection model receives new data in each round of iteration, and performs internal model improvement and optimization, so as to be able to make predictions more effectively, which is beneficial to improving the prediction accuracy of the image detection model.
[0150] In an exemplary embodiment, Figure 4 As shown, another edge container cloud image processing method based on a cloud-edge collaboration scenario is provided, and the method is applied to a server as an example for explanation, including the following steps:
[0151] Step S401, receiving the mirror whitelist sent by the center side.
[0152] Step S402: Filter out a candidate image corresponding to the image whitelist from multiple candidate images as an image to be processed; the image to be processed refers to an edge container cloud image.
[0153] Step S403, obtaining source information, version information and modification record information of the image to be processed; preprocessing the source information, version information and modification record information to obtain preprocessed source information, preprocessed version information and preprocessed modification record information.
[0154] Step S404: combining the preprocessed source information, the preprocessed version information and the preprocessed modification record information in accordance with a preset combination method to obtain mirror information.
[0155] Step S405, performing feature extraction processing on the mirror information to obtain a feature vector corresponding to the mirror information, inputting the feature vector into the trained mirror detection model to obtain a target mirror detection result corresponding to the mirror to be processed.
[0156] Step S406: determining normal images and abnormal images in the images to be processed according to the target image detection result.
[0157] Step S407: perform vulnerability scanning on the abnormal image using an image scanning tool to obtain target vulnerability information in the abnormal image.
[0158] Step S408, according to the target vulnerability information, query the corresponding relationship between the vulnerability information and the repair instruction, and obtain the target repair instruction corresponding to the abnormal image; according to the target repair instruction, repair the abnormal image to obtain a repaired image.
[0159] Step S409, determining a first image type corresponding to the normal image and a second image type corresponding to the repaired image; determining a first reinforcement tool corresponding to the normal image according to the first image type, and determining a second reinforcement tool corresponding to the repaired image according to the second image type.
[0160] Step S410, using a first reinforcement tool to reinforce the normal image to obtain a first reinforced image, and using a second reinforcement tool to reinforce the repaired image to obtain a second reinforced image; the first reinforced image and the second reinforced image are both used as target reinforced images.
[0161] Step S411, encrypting the sensitive data in the target hardened image to obtain an encrypted image.
[0162] In the above-mentioned edge container cloud image processing method based on the cloud-edge collaboration scenario, in the process of processing the image, the image to be processed among multiple candidate images can be determined based on the image whitelist, and the trained image detection model can accurately determine the normal image and the abnormal image in the image to be processed, and repair the abnormal image, as well as reinforce and encrypt the normal image and the repaired image, so that the corresponding image processing can be performed according to the image detection situation of the image to be processed, and the image can be processed more accurately, which is conducive to improving the accuracy of image processing, and thus improving the operating stability of the image; moreover, the entire process does not require human intervention, avoiding the subjective factors in the manual processing method, which is prone to errors, resulting in low accuracy of image processing, and then causing the defect of low operating stability of the image, further improving the operating stability of the image.
[0163] In an exemplary embodiment, in order to more clearly illustrate the edge container cloud image processing method based on the cloud-edge collaboration scenario provided by the embodiment of the present application, the edge container cloud image processing method based on the cloud-edge collaboration scenario is specifically described below with a specific embodiment. Figure 2 As shown, the present application also provides a method for trusted security management of edge container cloud images based on a cloud-edge collaborative scenario. In the process of processing the image, the image whitelist sent by the center is first received, and the candidate image corresponding to the image whitelist is screened out from multiple candidate images as the image to be processed, and then the image information of the image to be processed is obtained. Then, the image information is subjected to feature extraction processing to obtain the feature vector corresponding to the image information, and the feature vector is input into the trained image detection model to obtain the target image detection result corresponding to the image to be processed, and according to the target image detection result, the normal image and the abnormal image in each image to be processed are determined, and then the abnormal image is repaired to obtain the repaired image, and the normal image and the repaired image are reinforced to obtain the target reinforced image, and finally, the sensitive data in the target reinforced image is encrypted to obtain the encrypted image. Specifically including the following contents:
[0164] The center sends out a whitelist of images, and the edge uses the image ID (identity) to filter illegal images according to the whitelist. If they are legal, they are allowed to be used normally. Otherwise, the Pod using this image is deleted or stopped. This ensures the security and legality of the cloud images on the edge, effectively responds to security issues, and ensures the safe operation of the edge container cloud.
[0165] 1. Image scanning and auditing:
[0166] Use image scanning tools, such as Clair and Trivy, to perform vulnerability scans and security checks on images.
[0167] Establish an audit log recording system to monitor the source, version, modification record and other information of the image to detect abnormal situations in a timely manner.
[0168] 2. Security reinforcement and encryption:
[0169] Use container image security hardening tools, such as Docker Bench Security, to perform security assessment and hardening of container images.
[0170] Encrypt sensitive data in container images to ensure data security during transmission and storage.
[0171] 3. Access control and permission management:
[0172] Use identity authentication and authorization mechanisms to ensure that only authorized users can access and operate images.
[0173] Configure permission control when the container is running, use the principle of least privilege, and limit the container's access to host resources.
[0174] 4. Continuous monitoring and automated processing:
[0175] Integrate security information and event management systems to achieve real-time monitoring of edge container cloud images and security incident response.
[0176] Introduce automated security tools, such as container security operation and maintenance platforms, to achieve automatic repair of security vulnerabilities and emergency response.
[0177] In the above embodiment, in the process of processing the image, the image to be processed among multiple candidate images can be determined based on the image whitelist, and the normal image and abnormal image in the image to be processed can be accurately determined through the trained image detection model, and the abnormal image can be repaired, and the normal image and the repaired image can be reinforced and encrypted, so that the corresponding image processing can be performed according to the image detection situation of the image to be processed, and the image can be processed more accurately, which is conducive to improving the accuracy of image processing and thus improving the running stability of the image; moreover, the whole process does not require manual intervention, avoiding the subjective factors in the manual processing method, which is prone to errors, resulting in low accuracy of image processing, and then causing the defect of low running stability of the image, further improving the running stability of the image. At the same time, through the application of the above innovative points, the security of the edge container cloud image can be enhanced, security issues can be effectively addressed, the safe operation of the edge container cloud can be guaranteed, the security management level of the edge container cloud image can be effectively improved, potential security risks can be reduced, and the stable and safe operation of the edge container cloud system can be ensured.
[0178] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0179] Based on the same inventive concept, the embodiment of the present application also provides an edge container cloud image processing device based on a cloud-edge collaborative scenario for implementing the edge container cloud image processing method based on a cloud-edge collaborative scenario involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more embodiments of the edge container cloud image processing device based on a cloud-edge collaborative scenario provided below can be found in the above limitations on the edge container cloud image processing method based on a cloud-edge collaborative scenario, and will not be repeated here.
[0180] In an exemplary embodiment, Figure 5 As shown, an edge container cloud image processing device based on a cloud-edge collaboration scenario is provided, including: a list receiving module 501, an image screening module 502, an information acquisition module 503, an image detection module 504, an image determination module 505, an image reinforcement module 506 and an image encryption module 507, wherein:
[0181] The list receiving module 501 is used to receive the mirror whitelist sent by the center side.
[0182] The image screening module 502 is used to screen out a candidate image corresponding to the image whitelist from multiple candidate images as an image to be processed; the image to be processed refers to an edge container cloud image.
[0183] The information acquisition module 503 is used to acquire the image information of the image to be processed.
[0184] The mirror image detection module 504 is used to perform feature extraction processing on the mirror image information to obtain a feature vector corresponding to the mirror image information, and input the feature vector into the trained mirror image detection model to obtain a target mirror image detection result corresponding to the mirror image to be processed.
[0185] The image determination module 505 is used to determine the normal image and the abnormal image in each image to be processed according to the target image detection result.
[0186] The image reinforcement module 506 is used to repair the abnormal image to obtain a repaired image, and to reinforce the normal image and the repaired image to obtain a target reinforced image.
[0187] The image encryption module 507 is used to encrypt the sensitive data in the target hardened image to obtain an encrypted image.
[0188] In an exemplary embodiment, the information acquisition module 503 is also used to obtain the source information, version information and modification record information of the image to be processed; pre-process the source information, version information and modification record information to obtain pre-processed source information, pre-processed version information and pre-processed modification record information; and combine the pre-processed source information, pre-processed version information and pre-processed modification record information according to a preset combination method to obtain the image information.
[0189] In an exemplary embodiment, the image hardening module 506 is also used to perform vulnerability scanning on the abnormal image through an image scanning tool to obtain target vulnerability information in the abnormal image; based on the target vulnerability information, query the correspondence between the vulnerability information and the repair instructions to obtain the target repair instructions corresponding to the abnormal image; based on the target repair instructions, repair the abnormal image to obtain a repaired image.
[0190] In an exemplary embodiment, the image reinforcement module 506 is also used to determine a first image type corresponding to a normal image and a second image type corresponding to a repaired image; determine a first reinforcement tool corresponding to the normal image according to the first image type, and determine a second reinforcement tool corresponding to the repaired image according to the second image type; reinforce the normal image by the first reinforcement tool to obtain a first reinforced image, and reinforce the repaired image by the second reinforcement tool to obtain a second reinforced image; use the first reinforced image and the second reinforced image as target reinforced images.
[0191] In an exemplary embodiment, the edge container cloud image processing device based on the cloud-edge collaboration scenario also includes a unit deletion module, which is used to determine a target image from multiple candidate images; the target image is used to represent images other than the image to be processed in the multiple candidate images; according to the image identifier corresponding to the target image, the target computing unit corresponding to the target image is determined; and the target computing unit is deleted.
[0192] In an exemplary embodiment, the edge container cloud image processing device based on the cloud-edge collaboration scenario also includes a model training module, which is used to obtain sample image information of a sample image; perform feature extraction processing on the sample image information to obtain a sample feature vector corresponding to the sample image information, and input the sample feature vector into the image detection model to be trained to obtain a predicted image detection result corresponding to the sample image; obtain the actual image detection result corresponding to the sample image, and iteratively train the image detection model to be trained based on the difference between the predicted image detection result and the actual image detection result to obtain a trained image detection model.
[0193] Each module in the edge container cloud image processing device based on the cloud-edge collaboration scenario can be implemented in whole or in part by software, hardware, and a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0194] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as image whitelists and image information. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a cloud image processing method for edge containers based on a cloud-edge collaboration scenario is implemented.
[0195] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0196] In an exemplary embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.
[0197] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0198] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0199] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0200] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0201] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A method for processing edge container cloud images based on a cloud-edge collaboration scenario, characterized in that: Applied to the edge side, the method includes: Receive the image whitelist sent by the center; From multiple candidate images, select a candidate image corresponding to the image whitelist as the image to be processed; the image to be processed refers to an edge container cloud image; Obtaining image information of the image to be processed; Performing feature extraction processing on the image information to obtain a feature vector corresponding to the image information, inputting the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed; According to the target image detection result, determining a normal image and an abnormal image in each of the images to be processed; Repairing the abnormal image to obtain a repaired image, and reinforcing the normal image and the repaired image to obtain a target reinforced image; The sensitive data in the target hardened image is encrypted to obtain an encrypted image.
2. The method according to claim 1, characterized in that The obtaining the image information of the image to be processed includes: Obtain source information, version information, and modification record information of the image to be processed; Preprocessing the source information, the version information and the modification record information to obtain preprocessed source information, preprocessed version information and preprocessed modification record information; The preprocessed source information, the preprocessed version information and the preprocessed modification record information are combined and processed according to a preset combination method to obtain the mirror information.
3. The method according to claim 1, characterized in that The repairing process of the abnormal image to obtain a repaired image includes: Perform vulnerability scanning on the abnormal image through an image scanning tool to obtain target vulnerability information in the abnormal image; According to the target vulnerability information, query the corresponding relationship between the vulnerability information and the repair instruction to obtain the target repair instruction corresponding to the abnormal image; According to the target repair instruction, the abnormal image is repaired to obtain a repaired image.
4. The method according to claim 1, characterized in that: The step of performing reinforcement processing on the normal image and the repaired image to obtain a target reinforced image includes: Determine a first image type corresponding to the normal image and a second image type corresponding to the repaired image; Determine, according to the first image type, a first reinforcement tool corresponding to the normal image, and, according to the second image type, determine a second reinforcement tool corresponding to the repaired image; Using the first reinforcement tool, the normal image is reinforced to obtain a first reinforced image, and using the second reinforcement tool, the repaired image is reinforced to obtain a second reinforced image; The first reinforced image and the second reinforced image are both used as the target reinforced image.
5. The method according to claim 1, characterized in that After selecting a candidate image corresponding to the image whitelist from a plurality of candidate images as the image to be processed, the method further includes: Determine a target image from the multiple candidate images; the target image is used to represent an image other than the image to be processed among the multiple candidate images; Determining a target computing unit corresponding to the target image according to an image identifier corresponding to the target image; The target computing unit is deleted.
6. The method according to any one of claims 1 to 5, characterized in that: The trained mirror detection model is trained in the following way: Get the sample image information of the sample image; Performing feature extraction processing on the sample image information to obtain a sample feature vector corresponding to the sample image information, inputting the sample feature vector into the image detection model to be trained, and obtaining a predicted image detection result corresponding to the sample image; An actual image detection result corresponding to the sample image is obtained, and according to a difference between the predicted image detection result and the actual image detection result, the image detection model to be trained is iteratively trained to obtain the trained image detection model.
7. An edge container cloud image processing device based on a cloud-edge collaboration scenario, characterized in that: Applied to the edge side, the device comprises: The list receiving module is used to receive the image whitelist sent by the center side; An image screening module, used to screen out a candidate image corresponding to the image whitelist from a plurality of candidate images as an image to be processed; the image to be processed refers to an edge container cloud image; An information acquisition module, used to acquire the image information of the image to be processed; An image detection module is used to perform feature extraction processing on the image information to obtain a feature vector corresponding to the image information, and input the feature vector into a trained image detection model to obtain a target image detection result corresponding to the image to be processed; An image determination module, used to determine a normal image and an abnormal image in each of the images to be processed according to the target image detection result; An image reinforcement module is used to repair the abnormal image to obtain a repaired image, and to reinforce the normal image and the repaired image to obtain a target reinforced image; The image encryption module is used to encrypt the sensitive data in the target hardened image to obtain an encrypted image.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.