CICD platform safety assessment method
By static scanning and key field extraction of CICD platform configuration files, multi-level vulnerability and attack detection is solved, the problem of small coverage of CICD platform security assessment in the existing technology is solved, and comprehensive security detection of CICD platform workflow is achieved, and security and detection efficiency are improved.
Patent Information
- Application Number
- CN202510355974.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-27
AI Technical Summary
The existing CICD platform security assessment method has a small coverage and cannot effectively detect multiple risks in the CICD platform workflow, especially the security analysis effect of the entire life cycle of the container is poor.
By obtaining the configuration files of the CICD platform, statically scan and extracting key fields, and based on these fields, performing multi-level vulnerability detection and attack detection on the workflow of the CICD platform, including permission configuration detection, credential leakage detection, insecure dependency component version detection, as well as mining attacks, credential theft, and code injection detection.
It realizes multi-level security detection of the CICD platform, covering permission configuration, credential leakage, dependency component security and attack behavior, significantly improving the comprehensiveness and accuracy of platform security, reducing the complexity and resource consumption of security assessment.
Smart Images

Figure CN120217387A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network security technology, and more specifically, to a method for security assessment of a CICD platform. Background Art
[0002] Continuous Integration and Continuous Deployment (CICD) is a software development process that integrates the processes of code integration, building, testing, and deployment in an automated manner to improve software development efficiency.
[0003] GitHub Actions is a CICD platform provided by GitHub that allows developers to define and configure automated tasks, such as performing specific operations like building, testing, and deploying when events such as code commits and pull requests occur.
[0004] However, current CICD platform security assessment methods usually only focus on single - type security issues, such as detection of permissions, detection of plain - text secrets, or detection of code injection. The coverage is relatively small and cannot cover multiple risks in the CICD platform's workflow. Also, the security analysis effect for the full life cycle of containers is poor. Summary of the Invention
[0005] To solve the problem of the relatively small coverage of current CICD platform security assessment methods, the present invention provides a method for security assessment of a CICD platform, which can achieve multi - level security detection of the CICD platform and reduce the complexity and resource consumption of CICD platform security assessment.
[0006] To achieve the above object, the present invention provides a method for security assessment of a CICD platform, the method comprising:
[0007] Obtain the configuration file of the CICD platform;
[0008] Perform a static scan on the configuration file to extract key fields;
[0009] Based on the key fields, perform vulnerability detection on the workflow of the CICD platform;
[0010] According to the vulnerability detection results, locate the risk areas, and the vulnerability detection results include at least one of improper permission configuration, credential leakage, and use of insecure dependent components.
[0011] Further, the keyword fields include a permission field and a trigger field. Based on the keyword fields, vulnerability detection is performed on the workflow of the CICD platform, including detecting whether there is improper permission configuration in the workflow of the CICD platform when the permission scope corresponding to a specific permission field is not within the set permission scope or when a specific trigger field exists.
[0012] Further, the keyword fields include a first display environment variable field, a second display environment variable field, and a token field. Based on the keyword fields, vulnerability detection is performed on the workflow of the CICD platform, including matching at least one of the token field or the second display environment variable field in the output command when the keyword fields include the first display environment variable field to detect whether there is credential leakage in the workflow of the CICD platform.
[0013] Further, the keyword field includes the version number of a dependent component. Based on the keyword field, vulnerability detection is performed on the workflow of the CICD platform, including obtaining the version number of the dependent component and determining whether the version number is the specified version number to detect whether the workflow of the CICD platform uses an insecure dependent component.
[0014] Further, the above CICD platform security assessment method further includes performing a static scan on the configuration file to extract attack behavior characteristics; based on the attack behavior characteristics, performing attack detection on the workflow of the CICD platform; and based on the vulnerability detection results and the attack detection results, locating the risk area, where the attack detection results include at least one of a mining attack, credential theft, and code injection.
[0015] Further, the attack behavior characteristics include downloading and running mining software. Based on the attack behavior characteristics, attack detection is performed on the workflow of the CICD platform, including detecting whether there is behavior of installing and running mining software in the workflow of the CICD platform according to the download and execution commands in the configuration file; and when a workflow with the behavior of downloading and running mining software is detected, determining the probability of the workflow being attacked by a mining attack.
[0016] Further, the attack behavior characteristics include sending sensitive data to the outside. Based on the attack behavior characteristics, attack detection is performed on the workflow of the CICD platform, including detecting whether there is behavior of sending sensitive data to the outside in the workflow of the CICD platform according to the command of sending data to the outside in the configuration file; and when a workflow with the behavior of sending sensitive data to the outside is detected, determining whether there is credential theft in the workflow.
[0017] Furthermore, the attack behavior characteristics include injecting malicious commands. Based on the attack behavior characteristics, attack detection is performed on the workflows of the CICD platform, including detecting whether there are malicious command injections in the workflows of the CICD platform according to various event triggers in the configuration file; in the case of detecting a workflow with malicious command injection behavior, determining whether there is code injection in the workflow.
[0018] Furthermore, the above CICD platform security assessment method further includes obtaining the workflows of the CICD platform that execute containerized applications; performing security detection on the workflows of the CICD platform that execute containerized applications through container image security detection or container runtime configuration security detection; container image security detection includes obtaining the container images of the workflows of the CICD platform that execute containerized applications; parsing the build hierarchy of the container images and analyzing whether they contain known vulnerabilities or risk components; using a known vulnerability database to detect whether insecure dependent components are used in the container images; detecting whether there are uncleaned temporary files or redundant dependencies in the container images.
[0019] Furthermore, container runtime configuration security detection includes checking whether the privileged mode is enabled when the container starts, whether high-risk ports are bound, and whether limits are set for container resources.
[0020] Generally speaking, compared with the prior art, the above technical solutions conceived by the present invention can achieve the following beneficial effects:
[0021] (1) A CICD platform security assessment method provided by the present invention detects vulnerabilities in the workflows of GitHub Actions by statically analyzing the configuration file, without actually running the code. The vulnerability detection scope covers permission configuration detection, credential leakage detection, and detection of insecure dependent component versions, and can detect multiple security hazards in GitHub Actions. Compared with single-dimensional security detection, this comprehensiveness ensures the security of the platform, protects the development team from security risks such as malicious attacks, data leakage, and vulnerability exploitation, and greatly reduces the complexity and resource consumption of CICD platform security assessment; moreover, static scanning has high accuracy when locating risk areas.
[0022] (2) A CICD platform security assessment method provided by the present invention can not only detect vulnerabilities in the workflows of GitHub Actions, but also implement attack detections such as mining attack detection, credential stealing detection, and code injection detection. This multi-level detection overcomes the deficiencies of existing CICD platform security detection in attack behavior detection, can ensure the security of the workflows of the CICD platform in multiple aspects, and enables users to comprehensively control the risk status of the CICD platform.
[0023] (3) The CICD platform security assessment method provided by the present invention can also perform security analysis on containers for containerized applications in the workflow of the CICD platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0025] Figure 1 Schematic flowchart of a CICD platform security assessment method provided by an embodiment of the present application;
[0026] Figure 2 Schematic flowchart of a CICD platform security assessment method provided by another embodiment of the present application;
[0027] Figure 3 Schematic diagram of an analysis model adopted by a CICD platform security assessment method provided by an embodiment of the present application;
[0028] Figure 4 Schematic diagram of an analysis report generated by applying the CICD platform security assessment method provided by an embodiment of the present application;
[0029] Figure 5 Schematic diagram of the structure of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] In order to make the objectives, technical solutions and advantages of the present invention clearer, the following further elaborates on the present invention in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0031] The terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0032] Such as Figure 1As shown, a security assessment method for the CICD platform is provided. This method can be executed by a terminal or by a server that communicates with the terminal over a network. Among them, the terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, etc. The server can be an independent server or implemented using a server cluster composed of multiple servers. Taking the application of this method to the terminal as an example, the steps are as follows:
[0033] Step 101, obtain the configuration file of the CICD platform.
[0034] Among them, the CICD platform can be GitHub Actions, and the configuration file of the CICD platform can be a YAML file. The YAML file is used to define the workflow of GitHub Actions. YAML (YAML Ain't Markup Language) is a data serialization format used in scenarios such as configuration files and data exchange. Although the name contains "Markup Language", it is not actually a markup language but a structured data format, usually used in configuration files, such as software settings, automation processes, etc.
[0035] Exemplarily, the terminal obtains the YAML file of GitHub Actions.
[0036] Step 102, perform a static scan on the configuration file and extract key fields.
[0037] Among them, the key fields include permission fields (such as "permissions: write"), trigger fields (such as pull_request_target), the first display environment variable field, the second display environment variable field, token fields (such as echo$TOKEN), and the version numbers of dependent components. Among them, the first display environment variable field and the second display environment variable field are two different commands for displaying environment variables. For example, the first display environment variable field is echo$SECRET, and the second display environment variable field is printenv.
[0038] Exemplarily, the terminal uses regular expressions to analyze the YAML file line by line and extract the key fields in the file (such as "runs-on", "steps", "permissions", etc.) to quickly locate potential high-risk areas.
[0039] Step 103, based on the key fields, perform vulnerability detection on the workflow of the CICD platform.
[0040] Exemplarily, the terminal extracts key fields in the YAML file through a vulnerability analysis model, and identifies structural security issues based on the key fields, including improper permission configuration, credential leakage, using insecure dependency versions, etc. Through a set of rules for specific vulnerability types (such as permission declaration rules, dependency security rules, etc.), this model can efficiently detect common code vulnerabilities. For example, if a configuration such as "permissions: write" is detected, the model will further analyze whether the use of this permission is reasonable to determine whether there is a possibility of abuse. By matching specific key fields (such as "TOKEN", "SECRET") in the output command, in the case of potential credential leakage, a warning prompt is given to ensure the security of sensitive information.
[0041] Step 104, according to the vulnerability detection results, locate the risk areas, and the vulnerability detection results include at least one of improper permission configuration, credential leakage, and using insecure dependency components.
[0042] Exemplarily, the terminal locates the risk areas according to the vulnerability detection results; and classifies the risk levels of each risk area, and determines the corresponding repair suggestions according to the risk levels of each risk area.
[0043] In the above CICD platform security assessment method, through statically analyzing the configuration file, vulnerability detection is performed on the workflows of GitHub Actions without actually running the code. The vulnerability detection scope covers permission configuration detection, credential leakage detection, and insecure dependency component version detection, and can detect multiple security hazards in GitHub Actions. Compared with single-dimensional security detection, this comprehensiveness ensures the platform security and protects the development team from security risks such as malicious attacks, data leakage, and vulnerability exploitation, greatly reducing the complexity and resource consumption of the CICD platform security assessment; moreover, static scanning has high accuracy when locating the risk areas.
[0044] If there are extensive write permission fields or pull_request_target trigger fields in the workflows of the CICD platform, it may lead to abuse of permissions. Among them, extensive write permission fields may allow unauthorized users to access and modify sensitive data, resulting in data leakage; if the pull_request_target trigger is improperly configured, attackers can trigger the workflow by creating malicious pull requests, thereby deploying code without sufficient review.
[0045] In one embodiment, in step 103 above, vulnerability detection is performed on the workflow of the CICD platform based on key fields, including detecting whether there is improper permission configuration in the workflow of the CICD platform when the permission scope corresponding to a specific permission field is not within the set permission scope, or when a specific trigger field exists.
[0046] Among them, specific permission fields include a write permission field ("permissions:write"), a delete permission field ("permissions:delete"), a modify permission field ("permissions:modify"), etc. Specific trigger fields include a pull request target trigger field (pull_request_target), etc.
[0047] Exemplarily, the terminal analyzes the "permissions:write" field and a specific trigger (such as pull_request_target) in the YAML file to determine whether its use is reasonable. For example, in an automated deployment task, if unnecessary write permissions are found, they are marked as high-risk behaviors to prevent sensitive resources from being maliciously modified.
[0048] In this embodiment, by analyzing the rationality of permission configuration, especially detecting specific triggers such as pull_request_target, permission abuse can be effectively prevented.
[0049] Credential leakage or exposure means that when an individual or organization uses various services, their authentication information (such as username, password, API key, access token, etc.) is obtained or leaked by an unauthorized third party. In the YAML file, if there are commands such as echo$SECRET, it is very likely to cause credential leakage.
[0050] In one embodiment, in step 103 above, vulnerability detection is performed on the workflow of the CICD platform based on key fields, including matching at least one of a token field (such as echo$TOKEN) or a second display environment variable field (such as printenv) in the output command when the key field includes a first display environment variable field (such as echo$SECRET) to detect whether there is credential leakage in the workflow of the CICD platform.
[0051] Exemplarily, when the terminal extracts echo$SECRET, it matches all possible output commands that may contain credentials (such as printenv, echo$TOKEN, etc.) to detect whether there is a risk of direct or indirect credential leakage.
[0052] In software development, the management of dependent component versions is a very important aspect. In the workflow of the CICD platform, insecure dependent component versions (such as referencing third-party actions of v1 or latest) may introduce known vulnerabilities. To address this issue, the existing solution is to detect whether there are dependencies on non-specific versions by parsing the reference format of dependencies. This approach avoids compatibility issues caused by dependency updates but increases security risks.
[0053] In one embodiment, in step 103 above, vulnerability detection is performed on the workflow of the CICD platform based on key fields, including obtaining the version number of the dependent component and determining whether the version number is the specified version number to detect whether the workflow of the CICD platform uses insecure dependent components.
[0054] In this embodiment, by analyzing whether the version number of the dependent component is the specified version number, the use of dependent components containing vulnerabilities is avoided, and by regularly updating the security database of key components, the compatibility issues caused by dependency updates are avoided, ensuring the accuracy of the detection results.
[0055] In one embodiment, as Figure 2 shown, the CICD platform security assessment method further includes the following steps:
[0056] Step 201, perform a static scan on the configuration file to extract attack behavior characteristics.
[0057] Among them, the attack behavior characteristics include downloading and running mining software, sending sensitive data to the outside, and injecting malicious commands.
[0058] Step 202, based on the attack behavior characteristics, perform attack detection on the workflow of the CICD platform.
[0059] Exemplarily, the terminal extracts the attack behavior characteristics in the YAML file through an attack detection model, and based on the attack behavior characteristics, identifies possible malicious behavior configurations, including malicious mining, stealing Tokens, running malicious code, etc. Through the preset attack behavior characteristics, the attack detection model can identify YAML files that conform to specific attack behavior characteristics. In particular, sending data commands to the outside (such as using the curl command to send data to an external server) will be judged as a high-risk operation by the attack detection model, thus effectively preventing the execution of malicious behaviors.
[0060] Step 203, according to the vulnerability detection results and the attack detection results, locate the risk areas, and the attack detection results include at least one of mining attacks, credential stealing, and code injection.
[0061] In this embodiment, by extracting attack behavior characteristics, malicious behaviors such as mining attacks, credential theft, and code injection can be identified. This multi-level detection overcomes the deficiencies of existing CICD platform security detection in terms of attack behavior detection, and can ensure the security of the CICD platform's workflow in multiple aspects, enabling users to comprehensively control the risk situation of the CICD platform.
[0062] Malicious mining behaviors utilize free server resources and run mining commands by downloading miner tools. Mining attack detection is mainly achieved through traffic analysis.
[0063] In one embodiment, the attack behavior characteristics include downloading and running mining software. In step 202 above, based on the attack behavior characteristics, attack detection is performed on the CICD platform's workflow, including detecting whether there is a behavior of installing and running mining software in the CICD platform's workflow according to the download and execution commands in the configuration file; in the case of detecting a workflow with the behavior of downloading and running mining software, determining the probability of the workflow being attacked by mining.
[0064] Exemplarily, the terminal detects the download and execution commands (such as wget <mining tool>) in the YAML file and further analyzes whether there is a behavior of installing and running mining software. When detecting a workflow with a specific tool combination such as downloading and running mining software, a high-risk warning is immediately given to prompt the user to check whether the operation is reasonable, thereby effectively preventing resource abuse.
[0065] In one embodiment, the attack behavior characteristics include sending sensitive data to the outside. In step 202 above, based on the attack behavior characteristics, attack detection is performed on the CICD platform's workflow, including detecting whether there is a behavior of sending sensitive data to the outside in the CICD platform's workflow according to the command of sending data to the outside in the configuration file; in the case of detecting a workflow with the behavior of sending sensitive data to the outside, determining whether there is credential theft in the workflow.
[0066] Due to the high risk of credential theft, attackers may send sensitive data to external servers through methods such as HTTP requests. In this embodiment, the terminal determines whether there may be a behavior of credential theft by detecting the command of sending data to the outside (such as using curl <external URL> to post data to an external website) in the YAML file.
[0067] In one embodiment, the attack behavior characteristics include injecting malicious commands. In step 202 above, based on the attack behavior characteristics, attack detection is performed on the workflow of the CICD platform, including detecting whether there are malicious command injections in the workflow of the CICD platform according to various event triggers in the configuration file; in the case of detecting a workflow with malicious command injection behavior, determining whether there is code injection in the workflow.
[0068] Exemplarily, code injection and command execution are common attack means. An attacker can manipulate tasks by injecting commands in the PR title or event trigger. In this embodiment, the terminal analyzes whether various event triggers (such as "PR title", "event name", etc.) in the YAML file contain malicious input, and filters and determines whether there may be code injection through feature extraction and regular expressions.
[0069] In one embodiment, as Figure 3 shown, a CICD platform security assessment method adopts an analysis model that combines pattern matching and feature extraction. This model identifies specific patterns and keyword fields in the YAML file through a predefined vulnerability and attack feature matching library, and then outputs an analysis result to prompt the security risks of GitHub Actions.
[0070] Referring to Table 1, the vulnerability feature matching library contains a set of rules for common vulnerabilities, and stores the rule name, keyword field name, matching condition (such as regular expression), risk level, and repair suggestion for each vulnerability type in tabular form.
[0071] Table 1
[0072]
[0073] Referring to Table 2, the attack feature matching library contains the attack name, behavior characteristics, matching pattern, and potential risks of possible malicious behaviors. Examples of behavior characteristics include downloading and running mining software, sending sensitive data to the outside, injecting malicious commands, etc.
[0074] Table 2
[0075]
[0076] To further enhance the comprehensiveness of the CICD platform security assessment, the above CICD platform security assessment method also employs a static analysis module for the entire codebase. The static analysis module is used to analyze the relationships between code files. Specifically, by constructing a code dependency graph, parsing the call relationships between modules, and discovering potential high-risk paths. For example, identifying whether high-privilege modules call unvalidated external code. The static analysis module is also used to identify key functional modules, that is, to locate key functional modules, divide them by security priority, and increase the detection intensity for key functional modules. The static analysis module is also used to combine the code structure with the YAML configuration file to confirm whether there are potential contradictions or security risks between the code implementation and the configuration.
[0077] In this embodiment, by statically analyzing the YAML configuration file of GitHub Actions and matching it according to the preset possible vulnerability types, exploitable vulnerabilities that may exist in the workflow of GitHub Actions can be obtained, and possible attack behaviors can also be detected to obtain analysis results and risk warnings. This method not only covers common code security issues but also extends to complex security risks such as configuration errors, credential leaks, and privilege abuse. At the same time, combined with the static analysis of the entire codebase, it further enhances the comprehensiveness of detection. Since this method can quickly locate potential risk areas, such as identifying high-risk privilege settings, misconfigured dependencies, etc., it greatly improves the detection efficiency and is therefore suitable for large-scale CICD environments.
[0078] Compared with traditional methods that rely on dynamic analysis or manual detection, which usually require actual code execution, this not only increases the detection complexity but also may delay security feedback. This embodiment uses static analysis. Through regular expressions and feature matching, risks can be quickly identified without code execution, improving the security detection efficiency of the CICD platform, reducing the resource consumption of detection, and ensuring the real-time nature of detection.
[0079] In one embodiment, as Figure 4As shown, after the detection is completed, the terminal generates an analysis report based on all vulnerability detection results and attack detection results. The analysis report not only covers specific vulnerability types and attack behaviors, but also includes their risk levels and corresponding repair suggestions. For example, for the risk of credential leakage, the terminal not only prompts the risk, but also suggests replacing it with a more secure reference method; for the risk of using insecure dependent components, the corresponding risk level is high, and the corresponding repair suggestion is to use a hash value to determine the specified version number; for the risk of privilege abuse, the corresponding risk level is medium, and the corresponding repair suggestion is to reduce unnecessary permission configurations. Also, the terminal will issue a warning when the risk level exceeds the set level to promptly prompt the user of the potential risks existing in the CICD platform. In addition, the terminal also provides a risk level ranking to help users prioritize high-risk issues.
[0080] In this embodiment, by outputting the analysis report, it can ensure that users can understand the potential risks existing in the CICD platform in real time, comprehensively and deeply. And users can quickly solve high-risk problems according to the priority. This operable risk grading mechanism effectively improves the practicality of the CICD platform security assessment method and helps to quickly eliminate the key security hazards of the CICD platform.
[0081] In one embodiment, for the containerized applications in the CICD process, the above CICD platform security assessment method also adopts a container analysis module that covers the entire container life cycle. The container analysis module is used to detect the security of the container image, that is, by parsing the build hierarchy of the container image, analyze whether it contains known vulnerabilities or risk components; use a known vulnerability database (such as Common Vulnerabilities and Exposures, abbreviated as CVE) to detect whether there are security hazards in the dependent versions used in the container image; at the same time, scan whether there are uncleared temporary files or redundant dependencies in the image to avoid potential attack risks.
[0082] The container analysis module is also used for the security analysis of the container runtime configuration, that is, mainly check the security configuration when the container starts, including whether the privileged mode is enabled, whether high-risk ports are bound, and whether reasonable limits are set for container resources (such as CPU and memory). For communication behaviors using unencrypted protocols, the system will directly mark them as high-risk and provide suggestions for encryption improvement.
[0083] The container analysis module is also used for sensitive file protection, that is, scan the internal file system of the container to locate possible exposed keys, configuration files or database credentials. By analyzing the access permissions and distributions of these files, ensure compliance with the principle of minimizing access to avoid accidental leakage or illegal access of sensitive data.
[0084] The container analysis module is also used for container - to - container communication security, that is, it monitors the network traffic between containers in real - time and analyzes whether there is unauthorized cross - container communication or unencrypted data transmission. The system can identify abnormal high - frequency requests or other suspicious behaviors and propose isolation and encryption suggestions to prevent data leakage and the spread of attacks.
[0085] The container analysis module is also used for resource abuse prevention. That is, for resource abuse scenarios such as malicious mining and DDoS, the system collects the CPU, memory, and disk usage of containers in real - time and combines historical data to analyze whether there are abnormal high - load behaviors. Once malicious behaviors are detected, the system can automatically adjust resource allocation or terminate relevant processes to ensure the stability and security of the container environment.
[0086] This application also provides a computer device. The internal structure diagram of the computer device can be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non - volatile storage medium and an internal memory. The non - volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non - volatile storage medium. The input / output interface of the computer device is used for the processor to exchange information with external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a CICD platform security assessment method.
[0087] Those skilled in the art can understand that Figure 5 the structure shown in
[0088] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0088] As Figure 5 shown, this application also provides a computer device, which includes a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the steps in the above - mentioned method embodiments.
[0089] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the foregoing method embodiments are implemented. Among them, the computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, DVDs, CD-ROMs, microdrives, and magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.
[0090] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps in the foregoing method embodiments are implemented.
[0091] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0092] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0093] The above are only exemplary embodiments of the present disclosure, and the scope of the present disclosure cannot be limited thereby. That is, any equivalent changes and modifications made according to the teachings of the present disclosure still fall within the scope covered by the present disclosure. Those skilled in the art will easily think of the implementation schemes of the present disclosure after considering the specification and practicing the present disclosure. The present application aims to cover any variations, uses, or adaptive changes of the present disclosure, and these variations, uses, or adaptive changes follow the general principles of the present disclosure and include the common general knowledge or conventional technical means in the technical field not recorded in the present disclosure. The specification and embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
[0094] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered that the scope described in this specification is covered.
[0095] Those skilled in the art can easily understand that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A CICD platform security assessment method, characterized in that: include: Get the configuration file of the CICD platform; Performing static scanning on the configuration file to extract key fields; Based on the key fields, performing vulnerability detection on the workflow of the CICD platform; The risk area is located according to the vulnerability detection result, wherein the vulnerability detection result includes at least one of improper permission configuration, credential leakage, and use of unsafe dependent components.
2. The method according to claim 1, characterized in that The key fields include a permission field and a trigger field. Based on the key fields, vulnerability detection is performed on the workflow of the CICD platform, including: When the permission range corresponding to the specific permission field is not within the set permission range, or the specific trigger field exists, it is detected whether the workflow of the CICD platform has improper permission configuration.
3. The method according to claim 1, characterized in that The key fields include a first display environment variable field, a second display environment variable field, and a token field. Based on the key fields, vulnerability detection is performed on the workflow of the CICD platform, including: In a case where the key field includes a first display environment variable field, at least one of a token field or a second display environment variable field in an output command is matched to detect whether there is credential leakage in the workflow of the CICD platform.
4. The method according to claim 1, characterized in that The key field includes a version number of a dependent component, and based on the key field, vulnerability detection is performed on the workflow of the CICD platform, including: Obtain a version number of a dependent component and determine whether the version number is a specified version number to detect whether the workflow of the CICD platform uses an unsafe dependent component.
5. The method according to claim 1, characterized in that The method further comprises: Performing static scanning on the configuration file to extract attack behavior features; Based on the attack behavior characteristics, attack detection is performed on the workflow of the CICD platform; The risk area is located according to the vulnerability detection result and the attack detection result, wherein the attack detection result includes at least one of a mining attack, credential theft, and code injection.
6. The method according to claim 5, characterized in that The attack behavior characteristics include downloading and running mining software, and the attack detection on the workflow of the CICD platform based on the attack behavior characteristics includes: According to the download and execution commands in the configuration file, detecting whether the workflow of the CICD platform has the behavior of installing and running the mining software; When a workflow with the behavior of downloading and running mining software is detected, the probability of the workflow being attacked by mining software is determined.
7. The method according to claim 5, characterized in that The attack behavior feature includes sending sensitive data to the outside, and the attack detection on the workflow of the CICD platform based on the attack behavior feature includes: According to the command to send data to the outside in the configuration file, detecting whether the workflow of the CICD platform sends sensitive data to the outside; When a workflow that sends sensitive data to the outside is detected, it is determined whether credential theft occurs in the workflow.
8. The method according to claim 5, characterized in that The attack behavior feature includes injecting malicious commands, and the attack detection on the workflow of the CICD platform based on the attack behavior feature includes: According to various event triggers in the configuration file, detect whether there is malicious command injection in the workflow of the CICD platform; When a workflow having a malicious command injection behavior is detected, it is determined whether code injection exists in the workflow.
9. The method according to claim 1, characterized in that The method further comprises: Obtaining a workflow of the CICD platform for executing containerized applications; Perform security checks on the workflow of the CICD platform that executes the containerized application through container image security checks or container runtime configuration security checks; The container image security detection includes obtaining the container image of the workflow of the CICD platform that executes the containerized application; parsing the build hierarchy of the container image to analyze whether it contains known vulnerabilities or risky components; using a known vulnerability database to detect whether unsafe dependent components are used in the container image; and detecting whether there are uncleaned temporary files or redundant dependencies in the container image.
10. The method according to claim 9, characterized in that The container runtime configuration security detection includes checking whether the privileged mode is enabled when the container is started, whether high-risk ports are bound, and whether restrictions are set for container resources.