Container escape detection method, program product, electronic equipment and storage medium
By directly detecting file read and write operations in the kernel state, and using eBPF programs to judge the container process and file system, the performance overhead and real-time problems of container escape detection method in high concurrency and high performance scenarios are solved, and fast and accurate container escape risk identification is achieved.
Patent Information
- Application Number
- CN202510765109.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
The container escape detection method in the prior art has problems such as large system performance overhead and poor detection real-time performance in high concurrency and high performance scenarios, which is difficult to meet the needs.
The file read and write operations in the kernel state are directly detected, and file read and write events are captured through the eBPF program, and whether the main process belongs to the container process, and further determines whether the file system belongs to the host file system to determine whether there is a risk of container escaping.
It reduces system performance overhead, improves real-time and accuracy of detection, and can quickly identify container escape risks when file read and write operations occur, suitable for high-concurrency and high-performance scenarios.
Smart Images

Figure CN120277670A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer security technologies, and in particular, to a container escape detection method, a program product, an electronic device, and a storage medium. Background Art
[0002] Container technology is increasingly widely used in modern cloud computing environments. The core of container technology relies on the namespace mechanism of the Linux kernel of the operating system to achieve resource isolation. Container escape is a common security threat. Attackers access the host resources from inside the container through vulnerabilities or configuration errors, resulting in a serious threat to system security. The container escape detection methods in related technologies usually rely on user-space tools or file system checks, which have problems such as high system performance overhead and poor detection real-time performance, and are difficult to meet the requirements of high-concurrency and high-performance scenarios.
[0003] Obviously, how to reduce system performance overhead and improve detection real-time performance to better meet the requirements of high-concurrency and high-performance scenarios is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of the embodiments of this application is to provide a container escape detection method, a computer program product, an electronic device, and a computer-readable storage medium, which can detect container escape behaviors in the kernel state, is beneficial to reducing system performance overhead and improving detection real-time performance, and can better meet the requirements of high-concurrency and high-performance scenarios.
[0005] To solve the above technical problems, the embodiments of this application provide a container escape detection method, including: When a file read / write operation occurs in the system is detected in the kernel state, determine the main process of the currently operating file; When it is determined that the main process belongs to a container process, determine whether the currently operating file belongs to the container; When the currently operating file does not belong to the container, determine whether the file system to which the currently operating file belongs is a host file system; When it is determined that the file system to which the currently operating file belongs is a host file system, determine that there is a container escape risk in the operation behavior of the file read / write operation.
[0006] This application also provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the above container escape detection method are implemented.
[0007] This application also provides an electronic device, including: A memory for storing computer programs; A processor for executing a computer program to implement the steps of the container escape detection method as described above.
[0008] This application also provides a computer-readable storage medium with a computer program stored thereon. When the computer program is executed by a processor, it implements the steps of the container escape detection method as described above.
[0009] It can be seen from the above technical solutions that the beneficial effects of this application are as follows: This application provides a container escape detection method, including: when a file read / write operation occurs in the system is detected in the kernel mode, determining the main process of the currently operating file; when it is determined that the main process belongs to a container process, determining whether the currently operating file belongs to the container; when the currently operating file does not belong to the container, determining whether the file system to which the currently operating file belongs belongs to the host file system; when it is determined that the file system to which the currently operating file belongs belongs to the host file system, determining that there is a risk of container escape in the operation behavior of the file read / write operation.
[0010] Through this application, since in this application, the file read / write operation situation in the system is directly detected in the kernel mode, and when a file read / write operation occurs in the system is detected, the main process of the currently operating file is determined, and then it is further determined whether the main process belongs to a container process. When the main process does not belong to a container process, if the file system to which the currently operating file belongs belongs to the host file system, it can be determined that there is a risk of container escape in the operation behavior of the file read / write operation. By directly detecting the file read / write operation in the kernel mode, this application can reduce the system performance overhead, and can capture and analyze in real time when the file read / write operation occurs, and can quickly determine whether there is a risk of container escape, improving the detection real-time performance, which is beneficial to better meeting the requirements of high concurrency and high performance scenarios.
[0011] Therefore, it can solve the technical problems of large system performance overhead, poor detection real-time performance, and difficulty in meeting the requirements of high concurrency and high performance scenarios, and achieve the technical effects of reducing the system performance overhead, improving the detection real-time performance, and being beneficial to better meeting the requirements of high concurrency and high performance scenarios.
[0012] In addition, this application also provides corresponding computer program products, electronic devices and computer-readable storage media for the container escape detection method, further making the method more practical, and the computer program products, electronic devices and computer-readable storage media have corresponding advantages. Description of the Drawings
[0013] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0014] Figure 1 It is a flowchart of a container escape detection method provided by an embodiment of the present application; Figure 2 It is an architecture diagram of a container escape detection provided by an embodiment of the present application; Figure 3 It is a flowchart of another container escape detection method provided by an embodiment of the present application; Figure 4 It is a structural diagram of a container escape detection device provided by an embodiment of the present application. Specific embodiments
[0015] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0016] The terms "including" and "having" in the specification of the present application and the accompanying drawings above, and any variations related to "including" and "having", are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units not listed.
[0017] To enable those skilled in the art to better understand the solution of the present application, the following will further elaborate on the present application in conjunction with the accompanying drawings and specific embodiments.
[0018] Next, a container escape detection method provided by the embodiments of the present application will be introduced in detail. Figure 1 It is a flowchart of a container escape detection method provided by an embodiment of the present application, and this method includes the following contents from S110 to S140.
[0019] S110: When a file read / write operation occurs in the system is detected in the kernel mode, determine the main process of the currently operating file.
[0020] It should be noted that in this embodiment, the file read / write operations in the system can be directly captured in the kernel mode. If a file read / write operation occurs in the system, the main process of the currently operating file can be obtained.
[0021] In practical applications, an eBPF (Extended Berkeley Packet Filter) program can be used to directly capture file read and write events in the kernel space, avoiding the need to mount hooks in kernel modules and significantly improving detection efficiency and stability (such as Figure 2 the architecture diagram shown). For example, the lsm (Linux Security Module) hook type in eBPF technology can be used to detect and prevent container escape. An lsm file_open hook can be mounted in the eBPF program to monitor file read and write operations in the kernel space. When a file read and write event occurs in the system, the kernel triggers this hook and executes the eBPF program to perform the container escape detection process in this application.
[0022] S120: When it is determined that the main process belongs to a container process, determine whether the currently operating file belongs to the container.
[0023] It can be understood that only processes running in a container may experience container escape. Therefore, in this application, after determining the main process of the currently operating file, it can be further determined whether the main process belongs to a container process, that is, whether the main process is running in a container. When it is determined that the main process is running in a container, it can be further determined whether the currently operating file belongs to the container, that is, whether the currently operating file is in the container. Of course, if it is determined that the main process does not belong to a container process, it means that there is no container escape risk for this main process.
[0024] S130: When the currently operating file does not belong to the container, determine whether the file system to which the currently operating file belongs is the host file system.
[0025] It should be noted that in this application, when it is determined that the currently operating file does not belong to the container, in order to accurately detect whether there is a container escape risk in the operation behavior of the file read and write operation, it can be further determined whether the file system to which the currently operating file belongs is the host file system.
[0026] S140: When it is determined that the file system to which the currently operating file belongs is the host file system, determine that there is a container escape risk in the operation behavior of the file read and write operation.
[0027] That is, if the file system to which the currently operating file belongs is the host file system, it indicates that there is a container escape risk in the operation behavior of this file read and write operation, thus achieving fast and accurate detection of container escape.
[0028] It can be seen that in this application, the file read and write operation situation in the system is directly detected in the kernel state. When a file read and write operation occurs in the system, the main process of the currently operated file is determined. Then, it is further determined whether the main process belongs to a container process. When the main process does not belong to a container process, if the file system to which the currently operated file belongs is the host file system, it can be determined that there is a risk of container escape in the operation behavior of the file read and write operation. By directly detecting file read and write operations in the kernel state, this application can reduce the system performance overhead, and can capture and analyze in real time when file read and write operations occur, quickly determine whether there is a risk of container escape, improve the detection real-time performance, and is conducive to better meeting the requirements of high concurrency and high performance scenarios.
[0029] The technical solution will be further described and introduced below. Please refer to Figure 3 。
[0030] In one implementation, when it is determined in S120 that the main process belongs to a container process and before determining whether the currently operated file belongs to a container, the method may further include: Obtain the namespace information of the main process; Determine whether the namespace information is preset namespace information. If so, determine that the main process does not belong to a container process; if not, determine that the main process belongs to a container process.
[0031] It should be noted that in order to accurately determine whether the main process of the currently operated file belongs to a container process, the preset namespace information defaultly allocated at kernel startup can be set in advance. During the container escape detection process, after determining the main process of the currently operated file, the namespace information of the main process can be obtained, and then it is further determined whether the namespace information is preset namespace information. For example, the preset namespace information defaultly allocated at kernel startup can be PROC_PID_INIT_INO. After obtaining the namespace information of the main process, the namespace information of the main process is compared with the preset namespace information. If the two are inconsistent, it means that the main process belongs to a container process. If the two are consistent, it means that the main process does not belong to a container process.
[0032] In one implementation, the process of obtaining the namespace information of the main process described above may include: Obtain the process structure information of the main process; Read the namespace information field from the process structure information; Obtain the namespace information of the main process from the namespace information field.
[0033] In practical applications, in order to accurately obtain the namespace information of the main process and improve the detection accuracy, the eBPF helper function bpf_get_current_task() can be used to obtain the process structure information (i.e., the task_struct structure) corresponding to the main process of the currently operating file, and the BPF_CORE_READ() helper function is used to read the namespace information field (i.e., the nsproxy field) in the process structure information task_struct, so as to obtain the namespace information of the process.
[0034] The namespace information is stored in the task_struct->nsproxy field, and the namespace information field nsproxy points to a field structure (i.e., the struct nsproxy structure). The field structure contains various types of namespaces (such as the PID namespace, network namespace, etc.). Among them, the PID namespace is the key information. Therefore, the PID namespace can be obtained from the namespace information field in practical applications.
[0035] That is, after obtaining the PID namespace, the PID namespace can be compared with the preset namespace information PROC_PID_INIT_INO. If the two are inconsistent, it means that the main process belongs to a container process, and subsequent judgments are made.
[0036] In one implementation, the process of determining whether the currently operating file belongs to a container in S120 may include: Obtain the root directory inode value of the main process; Obtain the root directory inode value of the currently operating file; Determine whether the root directory inode value of the main process is equal to the root directory inode value of the currently operating file; When the root directory inode value of the main process is equal to the root directory inode value of the currently operating file, determine that the currently operating file belongs to the container; When the root directory inode value of the main process is not equal to the root directory inode value of the currently operating file, determine that the currently operating file does not belong to the container.
[0037] It should be noted that in order to further accurately distinguish container-internal behavior from container-escape behavior, the root directory inode value of the main process (i.e., the inode value of the root directory of the main process) and the root directory inode value of the currently operating file (i.e., the inode value of the root directory of the currently operating file) can be obtained. Then, the inode value of the root directory of the main process is compared with the inode value of the root directory of the currently operating file. If the two are equal, it means that the currently operating file belongs to the container, that is, it is a container-internal behavior. At this time, the behavior detection of the currently operating file can be ended. If the inode value of the root directory of the main process is not equal to the inode value of the root directory of the currently operating file, it means that the currently operating file does not belong to the container, and it is initially determined that there may be a container-escape risk, and then subsequent detection can be further carried out.
[0038] In one implementation, the process of obtaining the root directory inode value of the main process includes: Determine whether the kernel has enabled the process file system function; When the kernel has enabled the process file system function, obtain the memory management structure information of the main process through the process structure information of the main process; Determine the file structure information according to the memory management structure information; Obtain the path information of the main process according to the file structure information; Determine the root directory of the main process according to the path information of the main process; When the kernel has not enabled the process file system function, obtain the memory mapping area linked list of the main process; Traverse the memory mapping area linked list to obtain the file information corresponding to the code segment of the main process; Determine the root directory of the main process according to the file information; After determining the root directory, obtain the corresponding root directory inode value according to the file tree structure of the root directory.
[0039] It can be understood that in this embodiment, in order to accurately obtain the root directory inode value of the main process, it is possible to first determine whether the kernel has enabled the process file system function. For example, it is possible to determine whether the kernel has enabled the process file system function (i.e., the PROC_FS function) by obtaining the process structure information (task_struct) of the main process. If the kernel has enabled the PROC_FS function, then the memory management structure information mm_struct of the process can be read through the process structure information. Since the exe_file field in mm_struct is a file structure (i.e., the file structure), the path information of the main process can be obtained through the exe_file field in the memory management structure information. After obtaining the path information, the root directory of the main process can be determined based on the path information, and the file tree structure corresponding to the root directory can be obtained, so that the root directory inode value corresponding to the root directory can be obtained through the file tree structure.
[0040] Of course, if the kernel has not enabled the PROC_FS function, then the mapping table (mmap) pointer can be determined from the memory management structure information mm_struct of the process. The mapping table pointer points to the linked list of the memory mapping areas of the process. Therefore, the linked list of the memory mapping areas can be obtained through the mapping table pointer. Then, by traversing the linked list of the memory mapping areas, the file corresponding to the code segment (VM_EXECUTABLE) of the main process can be determined, and further, the root directory of the main process can be determined by gradually going up through the file tree structure dentry of the file. After determining the root directory, the inode value of the root directory can be further obtained through the file tree structure dentry of the root directory, that is, by calling BPF_CORE_READ(dentry, d_inode, i_ino).
[0041] In one implementation, the process of obtaining the root directory inode value of the currently operating file may include: Obtaining the context file structure information corresponding to the currently operating file; Reading the file tree information of the currently operating file through the context file structure information; Determining the root directory of the currently operating file according to the file tree information; Obtaining the root directory inode value corresponding to the currently operating file according to the root directory of the currently operating file.
[0042] It can be understood that in order to accurately obtain the root directory index node value of the current operation file in this application, the file tree information dentry of the current operation file can be read according to the context file structure information (that is, the context struct file) corresponding to the current operation file, and then the root directory of the current operation file can be determined in a step-by-step manner, and then BPF_CORE_READ(dentry, d_inode, i_ino) can be called to read the inode value of the root directory.
[0043] In one implementation, the process of determining whether the file system to which the currently operated file belongs belongs to the host file system in S130 may include: Get the root directory index node value of the host; Determine whether the root directory index node value of the current operation file is equal to the root directory index node value of the host machine; When the root directory index node value of the current operation file is equal to the root directory index node value of the host machine, it is determined that the file system to which the current operation file belongs belongs to the host machine file system.
[0044] It should be noted that in this embodiment, in order to accurately identify whether the file system to which the current operation file belongs belongs to the host file system, the root directory index node value of the host can be further obtained. For example, when the file_open hook of LSM detects that a file read and write operation occurs in the system in the kernel state, the kernel triggers the hook and executes the eBPF program (that is, when the program starts) to obtain the root directory index node value of the host. Then compare the root directory index node value of the current operation file with the root directory index node value of the host. If the root directory index node value of the current operation file is equal to the root directory index node value of the host, it means that the file system to which the current operation file belongs belongs to the host file system, and it can be determined that the container has escaped. In this application, by comparing the root directory index node value of the current operation file with the root directory index node value of the host, it can be accurately determined whether the file system to which the current operation file belongs belongs to the host file system, which is conducive to improving the detection accuracy.
[0045] In one embodiment, the method may further include: If the root directory index node value of the current operation file is not equal to the root directory index node value of the host machine, determine whether the root directory index node value of the current operation file is equal to 1; When the root directory index node value of the current operation file is equal to 1, obtain the device number of the file system to which the current operation file belongs; Get the device number information of all file systems on the host; Match the device number of the file system to which the current operation file belongs with the device number information of all file systems on the host machine; If there is a device number in the device number information of all file systems on the host machine that is the same as the device number of the file system to which the current operation file belongs, determine that the file system to which the current operation file belongs belongs to the host machine file system.
[0046] It can be understood that in this application, when it is determined that the root directory inode value of the current operation file is not equal to the root directory inode value of the host machine, it can be further determined whether the root directory inode value of the current operation file is equal to 1. If the root directory inode value of the current operation file is equal to 1, it can be preliminarily determined that the root directory of the current operation file belongs to a sub-file system, and it is necessary to further determine whether the root directory of the current operation file belongs to a container. The device number of the file system to which the current operation file belongs can be obtained. Among them, the context file structure information corresponding to the current operation file (that is, the context struct file structure) can be obtained first, and then the mount point information (struct vfsmount) of the current operation file can be read from the context file structure information corresponding to the current operation file. The root mount point information can also be obtained according to the mount point information (struct vfsmount), and the super block information (struct super_block) can be obtained according to the mount point information (struct vfsmount), so as to determine the device number of the file system to which the current operation file belongs according to the super block information.
[0047] Furthermore, after obtaining the device number of the file system to which the current operation file belongs, the device number information of all file systems on the host machine can be further obtained. For example, the system can be restarted, and when the system restarts, the eBPF program is used to execute commands in the user state (such as findmnt -o TARGET,SOURCE,FSTYPE,MAJ:MIN) to collect the device number information of all file systems on the host machine and record it in the eBPF map. In the kernel state, it can be queried through the eBPF map whether the device number of the file system to which the current operation file belongs matches the device number information of all file systems on the host machine, that is, whether there is a device number in the device number information of all file systems on the host machine that is the same as the device number of the file system to which the current operation file belongs. If there is a device number in the device number information of all file systems on the host machine that is the same as the device number of the file system to which the current operation file belongs, it can be determined that the file system to which the current operation file belongs belongs to the host machine file system, that is, it can be determined that there is a risk of container escape in the operation behavior of the file read and write operation.
[0048] In one implementation, after determining that there is a risk of container escape in the operation behavior of a file read / write operation, the method may further include: Determine the target risk level to which the relevant directory of the operation behavior belongs according to the different risk levels of the host directory set in advance.
[0049] It should be noted that in order to reduce the false alarm rate, the host directories can be classified in advance according to the severity of escape, and risk levels can be set for the classified host directories. Thus, when it is determined that there is a risk of container escape in the operation behavior of the file read / write operation, the target risk level corresponding to the relevant directory of the operation behavior can be further determined, so as to determine whether to intercept the operation behavior according to the target risk level. In practical applications, after determining that there is a risk of container escape in the operation behavior of a file read / write operation, the operation behavior with a risk of container escape can also be intercepted.
[0050] Furthermore, the operation behavior with a risk of container escape can be intercepted when the target risk level reaches a preset interception level.
[0051] That is to say, when it is determined that there is a risk of container escape in the operation behavior corresponding to a file read / write operation, it can be further determined whether the target risk level of the corresponding relevant directory has reached the preset interception level, or whether the risk coefficient corresponding to the target risk level has reached the preset risk coefficient, and then the hook mechanism of LSM is used to intercept the relevant operations to prevent the container escape behavior from threatening the system security.
[0052] In other words, in this application, the hook mechanism of LSM is used to intercept the behavior with an escape risk, which can effectively prevent the container escape behavior from threatening the system security, and through the direct interception in the kernel state, the risk that the user-mode tool may be bypassed or tampered with is avoided.
[0053] In one implementation, the different risk levels of the host directory may include a risk-free level, a low-risk level, a medium-risk level, and a high-risk level, and the method for determining the risk level of the host directory can be divided according to the following method.
[0054] In practical applications, the risk level of the internal file system of the container can be set to a risk-free level; the risk level of the directory corresponding to the critical system configuration file, critical device file, or critical kernel information can be set to a high-risk level; the risk level of the directory containing user data, temporary files, or service data can be set to a medium-risk level; the risk level of the directory used to store applications, library files, or installed software can be set to a low-risk directory. Additionally, corresponding risk factors can be set for different risk levels. For example, the risk factor for the risk-free level is 0%, the risk factor for the high-risk directory is >80%, the risk factor for the medium-risk directory is >50%, and the risk factor for the low-risk directory is >20%.
[0055] That is to say, part of the internal file system of the container can be set as a whitelist with a risk level of risk-free and a risk factor of 0%. Since part of the internal file system of the container shares the same file system with the host machine, a file system whitelist can be added to the eBPF map, such as / etc / hosts inside the container, so as to filter out false alarms.
[0056] The risk level of the directory related to critical system configuration files, device files, or kernel information, etc., can be set to a high-risk directory with a risk factor of >80%, such as directories like / etc, / boot, / dev, etc. If such directories are maliciously exploited, it may lead to system crashes, data leaks, or complete out-of-control, so they are set as high-risk directories.
[0057] The risk level of the directory containing user data, temporary files, or service data can be set to a medium-risk directory with a risk factor of >50%, such as directories like / home, / root, / var, etc. If such directories are maliciously exploited, it may lead to data leaks or service interruptions, but it has a relatively small impact on the overall stability of the system, so such directories are set as medium-risk directories.
[0058] The risk level of the directory used to store applications, library files, or installed software can be set to a low-risk directory with a risk factor of >20%, such as directories like / usr, / opt, etc. Such directories have a relatively small impact on the system stability, but if maliciously exploited, it may cause the application to fail to run properly.
[0059] In practical applications, users can set each monitoring directory, the corresponding risk level and the corresponding risk coefficient according to actual needs, which can greatly improve the detection efficiency and effectively reduce the false alarm rate. It should be noted that by combining the eBPF technology and the LSM hook mechanism, the present application can be more efficient, accurate and real-time when performing container escape detection, and can also reduce the system overhead during the detection process. Its flexibility and comprehensiveness can be applied to a variety of application scenarios, effectively improving the security of the system while reducing the impact on performance.
[0060] In other words, in the present application, by directly capturing file read and write events in the kernel state through the eBPF technology, the context switch between the user state and the kernel state can be effectively avoided, significantly reducing the performance overhead. And by processing events in the kernel state, container escape detection can be efficiently completed, which is more suitable for high-concurrency and high-performance scenarios. The present application can capture and analyze in real time when file read and write events occur, quickly determine whether there is a container escape risk. Through real-time detection, it can effectively respond to the dynamically changing container environment, timely discover and intercept potential escape behaviors. And by combining the namespace information of the main process, the inode value of the root directory and the file system device number, etc. during the detection process, it can accurately distinguish container-internal behaviors from container escape behaviors. Through multi-level detection, misjudgment or omission caused by a single judgment condition can be effectively avoided.
[0061] In addition, it should also be noted that the operation of the eBPF program has little impact on the system performance and is suitable for resource-constrained environments. By working together in the user state and the kernel state, the data collection and processing burden in the kernel state is reduced, further reducing the system overhead. It also supports dynamic loading and unloading of eBPF programs, and can flexibly adjust the detection strategy according to actual needs. By storing the host file system information through the eBPF map, it supports dynamic update and expansion, which is beneficial to adapting to complex file system environments. During the use of the present application, it can not only detect container escape behaviors (such as accessing the host file system), but also identify abnormal operations of the sub-file system inside the container. Through a multi-level analysis mechanism, it covers a variety of possible container escape scenarios, improving the comprehensiveness of detection.
[0062] In practical applications, the detection method in the present application can be combined with other security mechanisms (such as auditing, intrusion detection systems) to further improve the security of the system. Thus, based on the flexible programming ability of eBPF, it can be extended to support more detection scenarios and security policies.
[0063] It should also be noted that in actual applications, the eBPF program can be dynamically loaded into the running kernel without restarting the system or modifying the kernel code, which reduces the complexity of deployment and maintenance. The cooperative working mode between the user space and the kernel space makes the system configuration more convenient and is suitable for large-scale distributed environments.
[0064] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0065] The embodiments of the present application also provide a container escape detection device. Refer to Figure 4 , Figure 4 which is a structural diagram of a container escape detection device provided by the present application. The device may include: The first determination module 11 is configured to determine the main process of the currently operating file when a file read / write operation occurs in the system in the kernel state; The first judgment module 12 is configured to judge whether the currently operating file belongs to a container when it is determined that the main process belongs to a container process; The second judgment module 13 is configured to judge whether the file system to which the currently operating file belongs is a host file system when the currently operating file does not belong to a container; The second determination module 14 is configured to determine that there is a risk of container escape in the operation behavior of the file read / write operation when it is determined that the file system to which the currently operating file belongs is a host file system.
[0066] In one embodiment, it includes: An acquisition module is configured to acquire the namespace information of the main process; A third judgment module is configured to judge whether the namespace information is preset namespace information. If so, it triggers the third determination module; if not, it triggers the fourth determination module; The third determination module is configured to determine that the main process does not belong to a container process; The fourth determination module is configured to determine that the main process belongs to a container process.
[0067] In one embodiment, the acquisition module includes: The first acquisition unit is configured to acquire the process structure information of the main process; The second acquisition unit is configured to read the namespace information field from the process structure information; The third acquisition unit is configured to acquire the namespace information of the main process from the namespace information field.
[0068] In one embodiment, the first determination module 12 includes: A fourth acquisition unit for acquiring the root directory inode value of the main process; A fifth acquisition unit for acquiring the root directory inode value of the currently operating file; A first determination unit for determining whether the root directory inode value of the main process is equal to the root directory inode value of the currently operating file; A first determination unit for determining that the currently operating file belongs to a container when the root directory inode value of the main process is equal to the root directory inode value of the currently operating file; A second determination unit for determining that the currently operating file does not belong to a container when the root directory inode value of the main process is not equal to the root directory inode value of the currently operating file.
[0069] In one embodiment, the fourth acquisition unit includes: A first determination subunit for determining whether the kernel has enabled the process file system function; A first acquisition subunit for acquiring the memory management structure information of the main process through the process structure information of the main process when the kernel has enabled the process file system function; A first determination subunit for determining the file structure information according to the memory management structure information; A second acquisition subunit for acquiring the path information of the main process according to the file structure information; A second determination subunit for determining the root directory of the main process according to the path information of the main process; A third acquisition subunit for acquiring the memory mapping area linked list of the main process when the kernel has not enabled the process file system function; A fourth acquisition subunit for acquiring the file information corresponding to the code segment of the main process by traversing the memory mapping area linked list; A third determination subunit for determining the root directory of the main process according to the file information; A fifth acquisition subunit for acquiring the corresponding root directory inode value according to the file tree structure of the root directory after determining the root directory.
[0070] In one embodiment, the fifth acquisition unit includes: A sixth acquisition subunit for acquiring the context file structure information corresponding to the currently operating file; A seventh acquisition subunit for reading the file tree information of the currently operating file through the context file structure information; A fourth determination subunit for determining the root directory of the currently operating file according to the file tree information; An eighth acquisition subunit, configured to acquire an inode value corresponding to the current operating file according to the root directory of the current operating file.
[0071] In one embodiment, the second determination module 13 includes: A sixth acquisition unit, configured to acquire the inode value of the root directory of the host; A second determination unit, configured to determine whether the inode value of the root directory of the current operating file is equal to the inode value of the root directory of the host; A third determination unit, configured to determine that the file system to which the current operating file belongs belongs to the host file system when the inode value of the root directory of the current operating file is equal to the inode value of the root directory of the host.
[0072] In one embodiment, the apparatus may further include: A third determination unit, configured to determine whether the inode value of the root directory of the current operating file is equal to 1 when the inode value of the root directory of the current operating file is not equal to the inode value of the root directory of the host; A seventh acquisition unit, configured to acquire the device number of the file system to which the current operating file belongs when the inode value of the root directory of the current operating file is equal to 1; An eighth acquisition unit, configured to acquire the device number information of all file systems on the host; A matching unit, configured to match the device number of the file system to which the current operating file belongs with the device number information of all file systems on the host; A fourth determination unit, configured to determine that the file system to which the current operating file belongs belongs to the host file system when there is a device number in the device number information of all file systems on the host that is the same as the device number of the file system to which the current operating file belongs.
[0073] In one embodiment, the seventh acquisition unit includes: A ninth acquisition subunit, configured to acquire context file structure information corresponding to the current operating file; A tenth acquisition subunit, configured to read the mount point information of the current operating file from the context file structure information corresponding to the current operating file; An eleventh acquisition subunit, configured to acquire superblock information according to the mount point information; A fifth determination subunit, configured to determine the device number of the file system to which the current operating file belongs according to the superblock information.
[0074] In one embodiment, the apparatus further includes: A fifth determination module, configured to determine the target risk level to which the relevant directory of the operation behavior belongs according to different risk levels of the pre-set host directories.
[0075] In one embodiment, the apparatus further comprises: An interception module, configured to intercept an operation behavior with a risk of container escape when the target risk level reaches a preset interception level.
[0076] In one embodiment, the different risk levels of the host directory include a risk-free level, a low-risk level, a medium-risk level, and a high-risk level.
[0077] For the description of the features in the corresponding embodiments of the container escape detection apparatus in this application, reference may be made to the relevant descriptions in the corresponding embodiments of the container escape detection method, which will not be elaborated herein one by one.
[0078] An embodiment of this application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above embodiments of the container escape detection method.
[0079] An embodiment of this application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any one of the above embodiments of the container escape detection method when running.
[0080] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.
[0081] An embodiment of this application further provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any one of the above embodiments of the container escape detection method are implemented.
[0082] An embodiment of this application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any one of the above embodiments of the container escape detection method are implemented.
[0083] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0084] The above has introduced in detail a container escape detection method, computer program product, electronic device, and computer-readable storage medium provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for detecting container escape, characterized in that, including: When a file read / write operation occurs in the kernel mode, determining the main process of the currently operating file; When it is determined that the main process belongs to a container process, determining whether the currently operating file belongs to the container; When the currently operating file does not belong to the container, determining whether the file system to which the currently operating file belongs is a host file system; When it is determined that the file system to which the currently operating file belongs is the host file system, determining that there is a risk of container escape in the operation behavior of the file read / write operation.
2. The container escape detection method according to claim 1, wherein Before determining whether the currently operating file belongs to the container when it is determined that the main process belongs to a container process, it further includes: Obtaining the namespace information of the main process; Determining whether the namespace information is preset namespace information. If so, determining that the main process does not belong to a container process; if not, determining that the main process belongs to a container process.
3. The container escape detection method according to claim 2, wherein Obtaining the namespace information of the main process includes: Obtaining the process structure information of the main process; Reading the namespace information field from the process structure information; Obtaining the namespace information of the main process from the namespace information field.
4. The container escape detection method according to claim 1, characterized in that, Determining whether the currently operating file belongs to the container includes: Obtaining the root directory inode value of the main process; Obtaining the root directory inode value of the currently operating file; Determining whether the root directory inode value of the main process is equal to the root directory inode value of the currently operating file; When the root directory inode value of the main process is equal to the root directory inode value of the currently operating file, determining that the currently operating file belongs to the container; When the root directory inode value of the main process is not equal to the root directory inode value of the currently operating file, determining that the currently operating file does not belong to the container.
5. The container escape detection method according to claim 4, characterized in that, Obtaining the root directory inode value of the main process includes: Determining whether the kernel has enabled the process file system function; When the kernel has enabled the process file system function, obtaining the memory management structure information of the main process through the process structure information of the main process; Determining the file structure information according to the memory management structure information; Obtaining the path information of the main process according to the file structure information; Determining the root directory of the main process according to the path information of the main process; When the kernel has not enabled the process file system function, obtaining the memory mapping area linked list of the main process; Traversing the memory mapping area linked list to obtain the file information corresponding to the code segment of the main process; Determining the root directory of the main process according to the file information; After determining the root directory, obtaining the corresponding root directory inode value according to the file tree structure of the root directory.
6. The container escape detection method according to claim 4, wherein, Obtaining the root directory inode value of the currently operating file includes: Obtaining the context file structure information corresponding to the currently operating file; Reading the file tree information of the currently operating file through the context file structure information; Determining the root directory of the currently operating file according to the file tree information; Obtain the root directory inode value corresponding to the current operating file according to the root directory of the current operating file.
7. The container escape detection method according to claim 4, wherein Determine whether the file system to which the current operating file belongs belongs to the host file system, including: Obtain the root directory inode value of the host; Determine whether the root directory inode value of the current operating file is equal to the root directory inode value of the host; When the root directory inode value of the current operating file is equal to the root directory inode value of the host, determine that the file system to which the current operating file belongs belongs to the host file system.
8. The container escape detection method according to claim 7, wherein, It further includes: When the root directory inode value of the current operating file is not equal to the root directory inode value of the host, determine whether the root directory inode value of the current operating file is equal to 1; When the root directory inode value of the current operating file is equal to 1, obtain the device number of the file system to which the current operating file belongs; Obtain the device number information of all file systems on the host; Match the device number of the file system to which the current operating file belongs with the device number information of all file systems on the host; When there is a device number in the device number information of all file systems on the host that is the same as the device number of the file system to which the current operating file belongs, determine that the file system to which the current operating file belongs belongs to the host file system.
9. The container escape detection method according to claim 8, wherein Obtain the device number of the file system to which the current operating file belongs, including: Obtain the context file structure information corresponding to the current operating file; Read the mount point information of the current operating file from the context file structure information corresponding to the current operating file; Obtain the superblock information according to the mount point information; Determine the device number of the file system to which the current operating file belongs according to the superblock information.
10. The container escape detection method according to any one of claims 1 to 9, characterized in that, After determining that there is a risk of container escape in the operation behavior of the file read and write operation, it further includes: Determine the target risk level to which the relevant directory of the operation behavior belongs according to different risk levels of the pre-set host directory.
11. The container escape detection method according to claim 10, wherein It further includes: When the target risk level reaches the preset interception level, intercept the operation behavior with the risk of container escape.
12. The container escape detection method according to claim 10, wherein The different risk levels of the host directory include no risk level, low risk level, medium risk level and high risk level.
13. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the container escape detection method described in any one of claims 1 to 12 are implemented.
14. An electronic device, characterized in that, It includes: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the container escape detection method described in any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the container escape detection method described in any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Container escape protection method and device, computer equipment and storage medium
CN113886835A
Container escape detection and blocking method, device and equipment and storage medium
CN114676424A
Fanotify-based container escape detection method and system
CN116820668A
Container escape detection method and device
CN119577739A
Method and apparatus for processing security events in container virtualization environment
US20230376591A1