Containerization-based zero-day vulnerability protection method and device and medium
By splitting network application services into different modules and leveraging containerized features for permission management and access control, the limitations of zero-day vulnerability protection are solved, and comprehensive protection and in-depth defense for web and non-web services are achieved.
Patent Information
- Application Number
- CN202510333452.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-18
AI Technical Summary
The existing technology is difficult to effectively protect against zero-day vulnerabilities, especially the lack of protection for vulnerabilities at non-web-type services and operating system levels, and the RASP technology lacks a deep defense mechanism, which is easily bypassed.
Split the network application service into an open service module, an external access module and an internal module. Permission management and access control are carried out through containerized features, unnecessary network interaction is prohibited, and alarms and repairs of container abnormal behavior are implemented.
It realizes comprehensive protection of web and non-web services, reduces underlying vulnerabilities and operating system risks, improves system security and stability, and can quickly deal with zero-day vulnerabilities.
Smart Images

Figure CN120337226A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a container-based zero-day vulnerability protection method, device and medium. Background Art
[0002] A zero-day vulnerability refers to a vulnerability that has not been known to software development manufacturers and the public and for which no security patch has been released, and is only mastered by a few attackers or researchers. Given the lack of ready-made patches for repairing such vulnerabilities and the difficulty of effectively detecting them based on signatures, this poses a major challenge in the field of network security attack and defense. Currently, in the field of zero-day vulnerability protection, the RASP (Runtime Application Self-Protection) technology is a quite effective and mature method. This technology deploys a RASP subsystem on a web server and sets hook points at preset critical call points for mounting. Whenever these hook points are triggered, the RASP subsystem uses a detection technology that integrates web server context information to identify and analyze potential attack behaviors.
[0003] However, the protection scope of the RASP technology is mainly limited to the web application level and it is difficult to provide effective protection for non-web type services. The types of vulnerabilities it can protect are limited, especially it cannot cover overflow vulnerabilities and security threats at the operating system level. In a Java environment, the implementation of RASP depends on the JVM level, so it lacks the ability to protect against lower-level overflow vulnerabilities and operating system-level vulnerabilities. In addition, the RASP technology lacks a depth defense mechanism. Once an attacker successfully obtains the permission to execute commands on the server, they can bypass the protection restrictions of RASP and then continue to carry out post-exploitation attacks. Summary of the Invention
[0004] The present invention provides a container-based zero-day vulnerability protection method, device and medium to solve the problem that various services including web and non-web services are difficult to effectively protect against zero-day vulnerabilities.
[0005] To achieve the above object, the present application provides a container-based zero-day vulnerability protection method, including:
[0006] Performing module splitting on various services of a network application to obtain a number of modules; wherein, the number of modules includes an open service module, an external access module and an internal module;
[0007] Performing container network permission management and access control on the various services, prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet;
[0008] Alarm and repair the abnormal container behaviors calibrated in the various services mentioned above.
[0009] In the present invention, since the various services of the network application include various types of services such as web and non-web services, by splitting the various services of the network application into different modules, such as an open service module, an external access module, and an internal module, more specific and detailed security policies can be formulated according to the characteristics and requirements of different modules. Moreover, since this method utilizes the containerization feature and is implemented at the container management level, it can effectively protect against underlying overflow vulnerabilities and operating system-level vulnerabilities. This splitting makes the functions of each module more clear, facilitating targeted security management and protection. Among them, prohibiting the open service module from actively initiating requests externally can prevent this module from being used as an attack springboard, further protecting the security of the internal network and system. Only allowing the external access module to actively access the preset Internet can limit its access scope and reduce the potential attack surface. Prohibiting the internal module from interacting with the Internet can completely isolate it from the external environment, thereby reducing the risk of being attacked externally. By alarming and repairing the abnormal container behaviors calibrated in the various services, measures can be taken promptly when a security incident occurs, thus effectively dealing with zero-day vulnerabilities.
[0010] Compared with the prior art, the present invention splits the various services of the network application into different modules and formulates security policies for each module by utilizing the containerization feature, which can effectively protect against underlying and zero-day vulnerabilities, clarify the module functions at the same time, reduce the risk of being attacked, and quickly respond to security incidents through alarming, so it can solve the problem that it is difficult to effectively protect zero-day vulnerabilities for various services including web and non-web services.
[0011] As a preferred solution, perform container network permission management and access control on the various services mentioned above, prohibit the open service module from actively initiating requests externally, control the external access module to actively access the preset Internet, and prohibit the internal module from interacting with the Internet. Specifically:
[0012] Restrict the container read and write permissions of the various services through container configuration; among them, the various services include web services and non-web services;
[0013] Perform proxy forwarding and access control on the network access requests of several containers in the various services, and perform vulnerability protection on the several modules according to the preset container network security policy; among them, the container network security policy includes prohibiting the open service module from actively initiating requests externally, controlling the external access module to actively access the preset Internet, and prohibiting the internal module from interacting with the Internet;
[0014] Perform network access control among the several modules.
[0015] This preferred solution can reduce system instability factors caused by misoperations or malicious behaviors through permission control, thus ensuring the continuity and reliability of services. Moreover, whether it is a web service or a non-web service, it can be managed and protected through unified container configuration and network security policies, which helps reduce the overall security risk of the system and simplifies the implementation and maintenance of security policies. Through proxy forwarding and access control, effective management and monitoring of network traffic can be achieved, preventing the intrusion and attack of malicious traffic. At the same time, the preset container network security policy can further reduce the risk of the system being attacked.
[0016] As a preferred solution, limit the container read and write permissions of various services through container configuration. Specifically:
[0017] Based on various services, mount the host directory to several containers in the principle of minimizing, control the container of the web service to mount the web directory in a read-only manner, and prohibit the writable mounting of preset sensitive directories.
[0018] This preferred solution can limit the access scope of the container to the host by mounting the host directory in the principle of minimizing, reducing security risks such as container escape. Mounting necessary directories can ensure the supply of resources required for the normal operation of the container, while avoiding unnecessary resource occupation, which helps achieve refined management and efficient utilization of resources. Prohibiting the writable mounting of sensitive directories can prevent illegal access and modification of sensitive data inside the container, effectively reducing the risk of data leakage.
[0019] As a preferred solution, perform proxy forwarding and access control on the network access requests of each container in various services. Specifically:
[0020] Control the open service module to provide services externally only through port mapping;
[0021] Prohibit the internal module from accessing the Internet;
[0022] Allow the external access module to send Internet network requests, and limit the network protocol type and destination address used by the external access module when initiating requests.
[0023] In this preferred solution, by means of port mapping of the open service module, external users can only access specific service ports and cannot directly access other parts of the container or the host machine, which reduces the potential security attack surface and improves the overall security of the system. Prohibiting internal modules from accessing the Internet can reduce the risk of the internal network being attacked from the outside and help protect the security of internal data and services. Allowing the external access module to send Internet network requests while restricting the types of network protocols and destination addresses it uses not only ensures the flexibility of the system but also realizes controllability over external access.
[0024] As a preferred solution, network access control is performed between the several modules, specifically:
[0025] Compare the requests and access control lists between several containers among the several modules, and intercept predefined illegal requests according to the comparison results; wherein, the access control list is established according to the access relationships between the several modules.
[0026] By establishing an access control list in this preferred solution, it can be clear which requests are legal and which are illegal, which helps to intercept illegal requests in a timely manner and prevent potential security threats.
[0027] As a preferred solution, prohibit the open service module from actively initiating requests to the outside, control the external access module to actively access the preset Internet, and prohibit the internal module from interacting with the Internet, specifically:
[0028] Prohibit the open service module from actively initiating communication requests to the outside, and control the open service module to open the preset external services to the Internet through port mapping;
[0029] Prohibit the external access module from providing service interfaces to the outside, but retain the active access permission of the external access module to the preset Internet;
[0030] Prohibit any form of data inflow or outflow between the internal module and the Internet.
[0031] By prohibiting the open service module from actively initiating communication requests to the outside in this preferred solution, it can effectively prevent this module from being maliciously used as an attack source or leaking internal sensitive information. Retaining the active access permission of the external access module to the preset Internet while prohibiting it from providing service interfaces to the outside can reduce the risk of data leakage. By prohibiting data exchange between the internal module and the Internet, a closed and secure internal network environment can be constructed, which helps prevent external attackers from penetrating the internal network and stealing or destroying sensitive data.
[0032] As a preferred solution, various services of the network application are split into modules, obtaining several modules; among them, the several modules include an open service module, an external access module, and an internal module, specifically:
[0033] According to the characteristics and functions of the application software, various services of the network application are split into modules, obtaining several modules including the open service module, the external access module, and the internal module;
[0034] Among them, the open service module is a module that is open to the outside and provides services; the external access module is a module that actively initiates network requests to the outside; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules.
[0035] This preferred solution splits the network application into multiple modules, and each module undertakes specific functions and responsibilities, which makes the structure of the system clearer and easier to understand and maintain. The open service module is open to the outside and provides services, enabling the system to interact and integrate with other systems. The external access module can actively initiate network requests to the outside, obtain external resources or data, and provide rich information support for the system. The internal module has no interaction with the external network and only communicates and exchanges data with other internal modules, thus ensuring the security and privacy of internal data.
[0036] This application also provides a zero-day vulnerability protection device based on containerization, including a splitting module, a management module, and an alarm module;
[0037] Among them, the splitting module is used to split various services of the network application into modules, obtaining several modules; among them, the several modules include an open service module, an external access module, and an internal module;
[0038] The management module is used to manage container network permissions and access control for the various services, prohibit the open service module from actively initiating requests to the outside, control the external access module to actively access the preset Internet, and prohibit the internal module from interacting with the Internet;
[0039] The alarm module is used to alarm and repair the marked container abnormal behaviors in the various services.
[0040] As a preferred solution, the management module includes a permission unit, a protection unit, and an access unit;
[0041] Among them, the permission unit is used to restrict the container read and write permissions of the various services through container configuration; among them, the various services include web services and non-web services;
[0042] The protection unit is used to proxy-forward and access-control network access requests of several containers in the various services, and perform vulnerability protection on the several modules according to a preset container network security policy; wherein, the container network security policy includes prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet;
[0043] The access unit is used to perform network access control among the several modules.
[0044] As a preferred solution, the permission unit is specifically:
[0045] Based on the various services, mount the host directory to several containers according to the principle of minimization, control the container for the web service to be mounted with the web directory in read-only mode, and prohibit writable mounting of a preset sensitive directory.
[0046] As a preferred solution, the protection unit includes a permission subunit, an access subunit, and a request subunit;
[0047] Among them, the permission subunit is used to control the open service module to provide services to the outside only through port mapping;
[0048] The access subunit is used to prohibit the internal module from accessing the Internet;
[0049] The request subunit is used to allow the external access module to send Internet network requests, and restrict the network protocol type and destination address used by the external access module when initiating requests.
[0050] As a preferred solution, the access unit is specifically:
[0051] Compare the requests and access control lists among several containers in the several modules, and intercept predefined illegal requests according to the comparison results; wherein, the access control list is established according to the access relationships among the several modules.
[0052] As a preferred solution, the management module includes a communication unit, an interface unit, and an interaction unit;
[0053] Among them, the communication unit is used to prohibit the open service module from actively initiating communication requests to the outside, and control the open service module to open a preset external service to the Internet through port mapping;
[0054] The interface unit is used to prohibit the external access module from providing service interfaces to the outside, but retain the active access permission of the external access module to a preset Internet;
[0055] The interaction unit is used to prohibit any form of data inflow or outflow between the internal module and the Internet.
[0056] As a preferred solution, the splitting module is specifically:
[0057] The various services of the network application are split into several modules according to the characteristics and functions of the application software, and the obtained modules include the open service module, the external access module, and the internal module;
[0058] Among them, the open service module is a module that is open to the outside and provides services; the external access module is a module that actively initiates network requests to the outside; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules.
[0059] This application also provides a storage medium, on which a computer program is stored. The computer program is called and executed by a computer to implement the above-mentioned zero-day vulnerability protection method based on containerization. Description of the Drawings
[0060] Figure 1 is a schematic flowchart of a zero-day vulnerability protection method based on containerization provided by an embodiment of this application;
[0061] Figure 2 is an access control diagram provided by an embodiment of this application;
[0062] Figure 3 is a schematic structural diagram of a zero-day vulnerability protection device based on containerization provided by an embodiment of this application. Detailed Embodiments
[0063] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0064] In the description of this application, unless otherwise specified, "several" means two or more.
[0065] A zero-day vulnerability protection method based on containerization provided by an embodiment of this application is mainly applied to the situation where various types of services, including web and non-web services, need to be protected, and effective protection is provided for underlying overflow vulnerabilities, operating system-level vulnerabilities, or high-risk 0day vulnerabilities (also known as zero-day vulnerabilities).
[0066] Embodiment 1:
[0067] Please refer to Figure 1 , the embodiments of the present application provide a containerized zero-day vulnerability protection method, including S1 to S3, and the specific implementation steps are as follows:
[0068] S1. Split various services of the network application into several modules; among them, the several modules include an open service module, an external access module, and an internal module.
[0069] Step S1 of the embodiments of the present application is specifically:
[0070] According to the characteristics and functions of the application software, split various services of the network application into several modules including an open service module, an external access module, and an internal module; among them, various services include web services and non-web services. Web services refer to containers that provide services through web protocols such as HTTP (HyperText Transfer Protocol) and HTTPS (HyperText Transfer Protocol Secure), and non-web services refer to containers that do not provide web protocol services;
[0071] Among them, the open service module is a module that is open to the outside and provides services, such as a web service module, an smtp service module; the external access module is a module that actively initiates network requests to the outside, such as a module that needs to perform DNS resolution requests, a module for updating the IP library and virus library, etc.; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules; and the same module cannot be both an open service module and an external access module at the same time. The smtp service module refers to a software component specifically used to implement the SMTP (Simple Mail Transfer Protocol) function, and the DNS resolution request (DNS Resolution Request) refers to the process of converting a domain name into a corresponding IP address.
[0072] The main purpose of S1 in this embodiment is in two aspects: First, it realizes the detailed splitting of application functions, which provides convenience for subsequent security management and control of each container; second, by deploying different modules to run in different containers, it achieves security isolation between containers and between containers and the host. In this way, even if a container is attacked by a vulnerability, its impact will be effectively limited within the container, thus greatly reducing the potential threat to the host and other containers, and realizing a more in-depth protection strategy, that is, defense in depth;
[0073] Moreover, by splitting the network application into multiple modules, each module undertakes specific functions and responsibilities, which makes the system structure clearer and easier to understand and maintain. The open service module is open to the outside and provides services, enabling the system to interact and integrate with other systems. The external access module can actively initiate network requests to the outside, obtain external resources or data, and provide rich information support for the system. The internal module has no interaction with the external network and only communicates and exchanges data with other internal modules, thus ensuring the security and privacy of internal data.
[0074] S2. Manage the container network permissions and access control for various services, prohibit the open service module from actively initiating requests to the outside, control the external access module to actively access the preset Internet, and prohibit the internal module from interacting with the Internet.
[0075] Step S2 of the embodiment of the present application includes S2.1 to S2.4, specifically:
[0076] S2.1. Restrict the container read and write permissions of various services through container configuration, that is, utilize the container namespace mechanism (namespace mechanism) to make the directory mounts of each container follow the following rules:
[0077] ① When mounting the host directory to the container, the principle of minimization should be followed. That is, only mount the directories necessary for the container to run, and try to reduce the number and permissions of the mounted directories; moreover, for the mounted directories, the read, write, and execution permissions need to be minimized.
[0078] ② For the container providing the web service, its web directory should be mounted in read-only mode;
[0079] ③ Prohibit writable mounts of preset sensitive directories; among them, the preset sensitive directories include directories such as host tools and cron jobs.
[0080] In this embodiment, the restriction of directory access in S2.1 is achieved through container directory mount permissions. Therefore, compared with the RASP (Runtime Application Self-Protection) method for protecting file uploads, the protection effect is more thorough and there is no possibility of bypassing. At the same time, based on the minimized directory mounts, the vulnerability of cross-directory unauthorized file reading can be effectively protected;
[0081] Moreover, by mounting the host directory according to the minimization principle, the access scope of the container to the host can be restricted, reducing security risks such as container escape. Mounting necessary directories can ensure the supply of resources required for the normal operation of the container, while avoiding unnecessary resource occupation, which helps to achieve refined management and efficient utilization of resources. Prohibiting writable mounting of sensitive directories can prevent illegal access and modification of sensitive data inside the container, effectively reducing the risk of data leakage.
[0082] S2.2. Develop and deploy a dedicated network proxy module to proxy the network access requests of each container and perform access control at the same time. Among them, the network proxy module manages network access in the following ways:
[0083] ① Control the open service module not to access the Internet externally, and only provide services externally through port mapping. Moreover, this operation can be achieved by precisely configuring the port mapping rules of the container, that is, mapping the port occupied by the internal service of the container to a specific port of the host. Thus, external users only need to access the corresponding port of the host to successfully access and utilize the services provided inside the container.
[0084] ② Prohibit internal modules from accessing the Internet.
[0085] ③ Allow the external access module to send Internet network requests, and minimize the control of both the network protocol type and the destination address used by the external access module when initiating requests. Moreover, this operation can be achieved through protocol control or destination address control. Specifically, protocol control involves configuring the network proxy module to ensure that only requests conforming to specific protocols are allowed to pass; destination address control is to strictly limit the access permissions to specific Internet addresses or domain names by setting up white lists or black lists.
[0086] It should be noted that several modules are functional units of application software (various types of web and non-web services), and they are split according to the requirements and characteristics of the application software; while the container is the running environment of the module, which provides the infrastructure and isolation mechanism required for the module to run;
[0087] Moreover, the above steps can effectively protect various command execution vulnerabilities, whether they are overflow vulnerabilities, deserialization vulnerabilities, or command injection vulnerabilities. However, when the command execution vulnerabilities are not effectively protected, attackers may attempt to use these vulnerabilities to execute malicious commands. During the vulnerability exploitation process, since the command execution results may not be directly echoed to the attacker due to reasons such as output being restricted, redirected, or filtered, the attacker needs to adopt other strategies to indirectly obtain the execution results or achieve their attack goals. These strategies include but are not limited to:
[0088] (a) Perform a reverse shell through command execution, enabling the server to actively connect to the attacker's remote control server, allowing the attacker to complete interactive operations on the target server on the remote control server. Among them, the reverse shell is a network attack technique that allows attackers to execute commands on remote systems;
[0089] (b) Download from the Internet side through command execution;
[0090] (c) Write a webshell through command execution. Among them, the webshell is a malicious software hidden on the web server;
[0091] (d) Tamper with system files through command execution, such as SSH keys, cron job files, etc. Among them, the SSH key is an authentication method for remote login and secure file transfer.
[0092] To apply the embodiments of the present application, please refer to Figure 2 , Figure 2 is the access control diagram provided by the embodiments of the present application, which shows the process of access control of the open service module, external access module, and internal module through the network proxy module.
[0093] In this embodiment, S2.2 uses the port mapping method of the open service module to enable external users to only access specific service ports and not directly access other parts of the container or host, which reduces the potential security attack surface and improves the overall security of the system. Prohibiting the internal module from accessing the Internet can reduce the risk of the internal network being attacked externally and help protect the security of internal data and services. Allowing the external access module to send Internet network requests while restricting the network protocol types and destination addresses it uses not only ensures the flexibility of the system but also realizes the controllability of external access.
[0094] S2.3. Perform vulnerability protection on several modules according to the preset container network security policy, specifically:
[0095] ① The container network security policy of the open service module is "only incoming and no outgoing", that is, it prohibits the open service module from actively initiating communication requests to the outside and controls the open service module to open the preset external services to the Internet through port mapping. Among them, the "preset external services" refer to services designed to receive requests from the Internet (such as HTTP, HTTPS requests, etc.), such as web servers, API services, etc. In addition, the API service refers to the service that provides these interfaces, which allows different software applications to access and interact with each other's data or functions.
[0096] Moreover, when an attacker attacks the open service module, since the container network of such a module cannot initiate requests externally, the two most common attack operations (a) and (b) used by attackers in command execution vulnerabilities cannot be implemented. At the same time, since step S2.1 strictly restricts directory mounting, the attacker cannot write a webshell, nor can they modify system files such as SSH keys and cron tasks, that is, the two operations (c) and (d) cannot be implemented.
[0097] ② The container network security policy of the external access module is "out only, no in", that is, it prohibits the external access module from providing service interfaces externally, but retains the external access module's active access permission to the preset Internet; among them, the preset Internet is a limited Internet, and its "limitation" can be reflected in the following aspects: protocol limitation, traffic limitation, destination address limitation, and time limitation.
[0098] Moreover, external access restricts the addresses, ports, and services it can access based on the principle of minimization. The internal module cannot be directly accessed, so the attacker cannot directly attack it. Even if an internal vulnerability is triggered through an inter-module interface call, due to the access target address limitation, it is difficult to interact with the attacker's remote control end.
[0099] ③ The container network security policy of the internal module is "no in and no out", that is, it prohibits any form of data inflow or outflow between the internal module and the Internet.
[0100] Moreover, due to the access restrictions set for the internal module, the attacker cannot directly launch an attack on it. Even if the attacker attempts to trigger potential internal vulnerabilities through an inter-module interface call, they will be unable to further exploit these vulnerabilities to execute malicious commands due to the lack of a network connection (similar to the case of the external access module). Such a design effectively blocks the path for attackers to use command execution vulnerabilities for destruction.
[0101] It should be noted that "(a), (b), (c), and (d)" in this embodiment S2.3 refer to the strategies mentioned in embodiment S2.2 where the attacker needs to adopt other strategies to indirectly obtain the execution result or achieve their attack goal.
[0102] In this embodiment S2.3, by prohibiting the open service module from actively initiating communication requests to the outside, it can effectively prevent this module from being maliciously used as an attack source or leaking internal sensitive information. Retaining the external access module's active access permission to the preset Internet while prohibiting it from providing service interfaces externally can reduce the risk of data leakage. By prohibiting data exchange between the internal module and the Internet, a closed and secure internal network environment can be constructed, which helps prevent external attackers from infiltrating the internal network and stealing or destroying sensitive data;
[0103] Therefore, after the above steps are completed in this embodiment S2.3, all three types of modules can effectively protect against attacks on command execution vulnerabilities, and attackers cannot exploit command execution vulnerabilities.
[0104] S2.4. Sort out the access relationships between several modules, establish an access control list (ACL), and clarify the source module, destination module, destination port, and protocol.
[0105] Use the network proxy module to perform network access control between modules through the access control list to defend against SSRF (Server-Side Request Forgery) vulnerabilities and abnormal mutual effects between modules, that is, compare the requests between several containers in several modules with the access control list through the network proxy module, and intercept predefined illegal requests according to the comparison results.
[0106] Among them, the predefined illegal requests include unauthorized access, potential SSRF attacks, illegal protocols, and abnormal interactions between modules, etc.
[0107] The purpose of this embodiment S2.4 is: the primary goal is to prevent SSRF vulnerabilities from being exploited to detect and illegally call internal services, thereby ensuring the security of internal services; the secondary goal is to prevent an attacker from launching a lateral attack on other internal containers using the foothold after infiltrating and controlling a container, so as to enhance the depth defense ability of the entire system and ensure that the overall security of the system is not violated.
[0108] Moreover, by establishing an access control list, it can be clarified which requests are legal and which are illegal, which helps to intercept illegal requests in a timely manner and prevent potential security threats.
[0109] In this embodiment S2, permission control can reduce system instability factors caused by misoperations or malicious behaviors, thereby ensuring the continuity and reliability of services; moreover, whether it is a web service or a non-web service, it can be managed and protected through unified container configuration and network security policies, which helps to reduce the overall security risk of the system and simplify the implementation and maintenance of security policies. Through proxy forwarding and access control, effective management and monitoring of network traffic can be achieved, and the intrusion and attack of malicious traffic can be prevented. At the same time, the preset container network security policy can further reduce the risk of the system being attacked.
[0110] S3. Alarm and repair the abnormal behaviors of the containers marked in various services.
[0111] The specific steps of step S3 in the embodiment of the present application are as follows:
[0112] Monitor the abnormal behavior of the container, record and save relevant logs, and send alarms via text messages or emails. After receiving the alarm, the administrator will take corresponding repair measures according to the information in the logs and the nature of the abnormal behavior;
[0113] Among them, monitoring the abnormal behavior of the container includes:
[0114] ① Monitor read and write operations that violate the container directory access restrictions. Moreover, this method can be achieved by monitoring the error messages generated in the container due to attempts to perform illegal read and write operations. These error messages usually indicate that the container attempts to access or modify directories or files that it has no right to access.
[0115] ② Monitor events that violate the container network security rules. Moreover, this method can be implemented by the network proxy module. As a bridge for the container to communicate with the external network, the network proxy module can monitor and record the network access behavior of the container. When it is found that the access behavior of the container violates the security rules (such as accessing a prohibited website, using a disabled protocol, etc.), an alarm is triggered through the network proxy module.
[0116] ③ Monitor events that violate the access control list between containers. Moreover, this method can be implemented by the network proxy module. The network proxy module can monitor and record the communication behavior between containers and judge whether these behaviors are compliant according to the access control list. When a violation of communication behavior is found, an alarm is triggered through the network proxy module.
[0117] In the present embodiment S3, since the module splitting has been carried out, the user can quickly locate the module where the abnormality occurs, further analyze the zero-day vulnerability, and thus perform vulnerability repair.
[0118] Overall, the present embodiment has the following beneficial effects:
[0119] In this application, since various services of network applications include various types of services such as web and non-web services, by splitting various services of network applications into different modules, such as an open service module, an external access module, and an internal module, more specific and detailed security policies can be formulated according to the characteristics and requirements of different modules; moreover, since this method utilizes containerization characteristics and is implemented at the container management level, it can effectively protect against underlying overflow vulnerabilities and operating system-level vulnerabilities. This splitting makes the functions of each module more clear, facilitating targeted security management and protection. Among them, prohibiting the open service module from initiating requests externally can prevent this module from being used as an attack springboard, further protecting the security of the internal network and system; only allowing the external access module to actively access the preset Internet can limit its access scope and reduce the potential attack surface; prohibiting the internal module from interacting with the Internet can completely isolate it from the external environment, thereby reducing the risk of being attacked externally. By warning and repairing the abnormal container behaviors marked in various services, measures can be taken promptly when security incidents occur, thus effectively dealing with zero-day vulnerabilities;
[0120] In addition, with the secure features of containerization, this application can achieve protection against several types of high-risk zero-day vulnerabilities such as file upload, file read / write, command execution, and SSRF through strict control of module splitting, read / write permissions, and network access permissions. Compared with RASP, this application can protect non-web services and effectively protect against overflow vulnerabilities; compared with signature-based protection technologies such as WAF (Web Application Firewall), IDS (Intrusion Detection System), and traffic analysis, this application is not based on vulnerability exploitation signatures, so it can provide a more effective protection effect for zero-day vulnerabilities with unknown signatures. At the same time, due to the adoption of containerization and the isolation characteristics of containers, when this application encounters a zero-day vulnerability attack, the impact scope can be limited within the container, thereby protecting other containers and the host, achieving a depth defense.
[0121] Embodiment 2:
[0122] Please refer to Figure 3 , the embodiment of this application provides a zero-day vulnerability protection device based on containerization, including a splitting module 10, a management module 20, and an alarm module 30;
[0123] Among them, the splitting module 10 is used to split various services of network applications into several modules; among them, the several modules include an open service module, an external access module, and an internal module;
[0124] The management module 20 is used to manage container network permissions and access control for various services, prohibit the open service module from actively initiating requests to the outside, control the external access module to actively access the preset Internet, and prohibit the internal module from interacting with the Internet;
[0125] The alarm module 30 is used to alarm and repair the marked container abnormal behaviors in various services.
[0126] In one embodiment, the splitting module 10 is specifically:
[0127] According to the characteristics and functions of the application software, various services of the network application are split into several modules including an open service module, an external access module, and an internal module; among them, various services include web services and non-web services. A web service refers to a container that provides services through web protocols such as HTTP (HyperText Transfer Protocol) and HTTPS (HyperText Transfer Protocol Secure), and a non-web service refers to a container that does not provide web protocol services;
[0128] Among them, the open service module is a module that is open to the outside and provides services, such as a web service module and an smtp service module; the external access module is a module that actively initiates network requests to the outside, such as a module that needs to perform DNS resolution requests, update IP libraries and virus libraries, etc.; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules; and the same module cannot be both an open service module and an external access module at the same time. The smtp service module refers to a software component specifically used to implement the SMTP (Simple Mail Transfer Protocol) function, and the DNS resolution request refers to the request process of converting a domain name into a corresponding IP address.
[0129] The main purpose of the splitting module 10 in this embodiment lies in two aspects: First, it realizes the detailed splitting of application functions, which provides convenience for subsequent security management and control of each container; second, by deploying different modules to run in different containers, it achieves security isolation between containers and between containers and the host. In this way, even if a certain container is attacked by a vulnerability, its impact will be effectively limited within the container, thereby greatly reducing the potential threats to the host and other containers, and realizing a more in-depth protection strategy, that is, defense in depth;
[0130] Moreover, by splitting the network application into multiple modules, each module undertakes specific functions and responsibilities, which makes the system structure clearer and easier to understand and maintain. The open service module is open to the outside and provides services, enabling the system to interact and integrate with other systems. The external access module can actively initiate network requests to the outside, obtain external resources or data, and provide rich information support for the system. The internal module has no interaction with the external network and only communicates and exchanges data with other internal modules, thus ensuring the security and privacy of internal data.
[0131] In one embodiment, the management module 20 includes a permission unit, a protection unit, a communication-interface-interaction unit, and an access unit, specifically as follows:
[0132] Among them, the permission unit is used to restrict the container read and write permissions of various services through container configuration, that is, by using the container namespace mechanism (namespace mechanism), the directory mounts of each container follow the following rules:
[0133] ① When mounting the host directory to the container, the principle of minimization should be followed. That is, only mount the directories necessary for the container to run, and try to reduce the number and permissions of the mounted directories; moreover, for the mounted directories, the read, write, and execution permissions need to be minimized.
[0134] ② For the container providing web services, its web directory should be mounted in read-only mode;
[0135] ③ Prohibit writable mounts of preset sensitive directories; among them, the preset sensitive directories include directories such as host tools and cron jobs.
[0136] In this embodiment, the restriction of directory access in the permission unit is achieved through container directory mount permissions. Therefore, compared with the protection method of file upload by RASP (Runtime Application Self-Protection), the protection effect is more thorough and there is no possibility of bypassing. At the same time, based on the minimized directory mounts, it can effectively protect against the vulnerability of cross-directory unauthorized file reading;
[0137] Moreover, by mounting the host directory according to the principle of minimization, the access scope of the container to the host can be restricted, reducing security risks such as container escape. Mounting the necessary directories can ensure the supply of resources required for the normal operation of the container, while avoiding unnecessary resource occupation, which helps to achieve refined management and efficient utilization of resources. Prohibiting writable mounts of sensitive directories can prevent illegal access and modification of sensitive data inside the container, effectively reducing the risk of data leakage.
[0138] The protection unit is used to develop and deploy a dedicated network proxy module to proxy the network access requests of each container and perform access control at the same time. Among them, the network proxy module manages network access in the following ways:
[0139] ① Control the open service module not to access the Internet externally, and only provide services externally through port mapping. And this operation can be achieved by precisely configuring the port mapping rules of the container, that is, mapping the port occupied by the internal service of the container to a specific port of the host machine. Thus, external users only need to access the corresponding port of the host machine to successfully access and utilize the services provided inside the container.
[0140] ② Prohibit internal modules from accessing the Internet.
[0141] ③ Allow the external access module to send Internet network requests, and minimize the control of the network protocol type and destination address used by the external access module when initiating requests. And this operation can be achieved through protocol control or destination address control. Specifically, protocol control involves configuring the network proxy module to ensure that only requests conforming to specific protocols are allowed to pass. Destination address control is to strictly limit the access rights to specific Internet addresses or domain names by setting up a whitelist or blacklist.
[0142] It should be noted that several modules are functional units of application software (various types of web and non-web services), and they are obtained by splitting according to the requirements and characteristics of the application software. And the container is the running environment of the module, which provides the infrastructure and isolation mechanism required for the module to run;
[0143] And the above steps can effectively protect various command execution vulnerabilities, whether they are overflow vulnerabilities, deserialization vulnerabilities, or command injection vulnerabilities. However, when the command execution vulnerabilities are not effectively protected, attackers may try to use these vulnerabilities to execute malicious commands. During the vulnerability exploitation process, since the command execution results may not be directly displayed to the attacker due to reasons such as output being restricted, redirected, or filtered, the attacker needs to adopt other strategies to indirectly obtain the execution results or achieve their attack goals. These strategies include but are not limited to:
[0144] (a) Perform a reverse shell through command execution to make the server actively connect to the attacker's remote control server, enabling the attacker to complete interactive operations on the target server on the remote control server. Among them, the reverse shell is a network attack technique that allows attackers to execute commands on a remote system;
[0145] (b) Download from the Internet side through command execution;
[0146] (c) Writing a webshell through command execution; where the webshell is a malicious software hidden on the web server;
[0147] (d) Tampering with system files through command execution, such as SSH keys, cron job files, etc.; where the SSH key is an authentication method for remote login and secure file transfer.
[0148] To apply the embodiments of the present application, please refer to Figure 2 , Figure 2 which is the access control diagram provided by the embodiments of the present application, showing the process of access control over the open service module, external access module, and internal module through the network proxy module.
[0149] In this embodiment, the protection unit uses the port mapping method of the open service module, enabling external users to only access specific service ports and preventing direct access to other parts of the container or the host. This reduces the potential security attack surface and improves the overall security of the system. Prohibiting the internal module from accessing the Internet can reduce the risk of external attacks on the internal network and help protect the security of internal data and services. Allowing the external access module to send Internet network requests while restricting the types of network protocols and destination addresses used ensures both the flexibility of the system and the controllability of external access.
[0150] The communication-interface-interaction unit is used to perform vulnerability protection on several modules according to the preset container network security policy, specifically:
[0151] ① The container network security policy of the open service module is "only incoming, no outgoing", that is, prohibiting the open service module from actively initiating communication requests to the outside, and controlling the open service module to open the preset external services to the Internet through port mapping; where the "preset external services" refer to services designed to receive requests from the Internet (such as HTTP, HTTPS requests, etc.), such as web servers, API services, etc.; in addition, the API service refers to the service that provides these interfaces, which allows different software applications to access and interact with data or functions with each other.
[0152] Moreover, when an attacker attacks the open service module, since the container network of such a module cannot actively initiate requests to the outside, the two types of attack operations (a) and (b) most commonly used by attackers in command execution type vulnerabilities cannot be implemented. At the same time, due to the strict restriction of directory mounting by the permission unit, the attacker cannot write a webshell or modify system files such as SSH keys and cron jobs, that is, the two types of operations (c) and (d) cannot be implemented.
[0153] ② The container network security policy of the external access module is "only outgoing, no incoming", that is, it prohibits the external access module from providing service interfaces externally, but retains the active access permission of the external access module to the preset Internet; among them, the preset Internet is a limited Internet, and its "limitation" can be reflected in the following aspects: protocol limitation, traffic limitation, destination address limitation, and time limitation.
[0154] Moreover, the external access is restricted according to the principle of minimizing the addresses, ports, and services it can access. The internal module cannot be directly accessed, so attackers cannot directly attack it. Even if its internal vulnerabilities are triggered through the interface call between modules, due to the access destination address limitation, it is difficult to interact with the attacker's remote control end.
[0155] ③ The container network security policy of the internal module is "no incoming and no outgoing", that is, it prohibits any form of data inflow or outflow between the internal module and the Internet.
[0156] Moreover, due to the access restrictions set for the internal module, attackers cannot directly launch an attack on it. Even if an attacker attempts to trigger its potential internal vulnerabilities through the interface call between modules, they will not be able to further exploit these vulnerabilities to execute malicious commands due to the lack of network connection (similar to the case of the external access module). Such a design effectively blocks the path for attackers to use command execution vulnerabilities for destruction.
[0157] It should be noted that "(a), (b), (c), and (d)" in the communication-interface-interaction unit of this embodiment refer to the strategies mentioned in the protection unit of the embodiment, which means that attackers need to adopt other strategies to indirectly obtain the execution results or achieve their attack goals.
[0158] In this embodiment, the communication-interface-interaction unit can effectively prevent the open service module from actively initiating communication requests to the outside, which can effectively prevent this module from being maliciously used as an attack source or leaking internal sensitive information. Retaining the active access permission of the external access module to the preset Internet while prohibiting it from providing service interfaces externally can reduce the risk of data leakage. By prohibiting data exchange between the internal module and the Internet, a closed and secure internal network environment can be constructed, which helps prevent external attackers from penetrating the internal network and stealing or destroying sensitive data;
[0159] Therefore, after the communication-interface-interaction unit of this embodiment completes the above steps, all three types of modules can effectively protect against attacks of command execution type vulnerabilities, and attackers cannot complete the exploitation of command execution type vulnerabilities.
[0160] An access unit is used to sort out the access relationships between several modules, establish an access control list (ACL), and clarify the source module, destination module, destination port, and protocol;
[0161] The access unit is also used to perform inter-module network access control through an access control list using the network proxy module, to defend against vulnerabilities of the SSRF (Server-Side Request Forgery) type and abnormal inter-module interactions, that is, to compare requests between several containers in several modules with the access control list through the network proxy module, and intercept predefined illegal requests according to the comparison results;
[0162] Among them, the predefined illegal requests include unauthorized access, potential SSRF attacks, illegal protocols, and abnormal inter-module interactions, etc.
[0163] The purpose of the access unit in this embodiment is: The primary goal is to prevent the SSRF vulnerability from being exploited to detect and illegally call internal services, thereby ensuring the security of internal services; the secondary goal is to prevent an attacker from launching a lateral attack on other internal containers using the foothold in the case where the attacker has penetrated and controlled a container, so as to enhance the depth defense ability of the entire system and ensure that the overall security of the system is not violated;
[0164] Moreover, by establishing an access control list, it can be clarified which requests are legal and which are illegal, which helps to intercept illegal requests in a timely manner and prevent potential security threats.
[0165] In this embodiment, the management module 20 can reduce system instability factors caused by misoperations or malicious behaviors through permission control, thereby ensuring the continuity and reliability of services; moreover, whether it is a web service or a non-web service, it can be managed and protected through unified container configuration and network security policies, which helps to reduce the overall security risk of the system and simplify the implementation and maintenance of security policies. Through proxy forwarding and access control, effective management and monitoring of network traffic can be achieved, preventing the intrusion and attack of malicious traffic. At the same time, the preset container network security policy can further reduce the risk of the system being attacked.
[0166] In one embodiment, the alarm module 30 is specifically:
[0167] Monitor the abnormal behaviors of containers, record and save relevant logs, and give alarms via text messages or emails. After receiving the alarm, the administrator will take corresponding repair measures according to the information in the logs and the nature of the abnormal behaviors;
[0168] Among them, monitoring the abnormal behaviors of containers includes:
[0169] ① Monitor read and write operations that violate the container directory access restrictions, and this method can be implemented by monitoring error messages generated in the container due to attempts to perform illegal read and write operations. These error messages usually indicate that the container attempts to access or modify directories or files that it has no right to access.
[0170] ②Monitor events that violate container network security rules, and this method can be implemented by the network proxy module. As a bridge for container communication with the external network, the network proxy module can monitor and record the network access behavior of containers. When it is found that the access behavior of a container violates the security rules (such as accessing a prohibited website, using a disabled protocol, etc.), an alarm is triggered through the network proxy module.
[0171] ③Monitor events that violate the access control list between containers, and this method can be implemented by the network proxy module. The network proxy module can monitor and record the communication behavior between containers, and determine whether these behaviors are compliant according to the access control list. When a violation communication behavior is found, an alarm is triggered through the network proxy module.
[0172] In the alarm module 30 of this embodiment, since the module has been split, users can quickly locate the abnormal module and further analyze the zero-day vulnerability for vulnerability repair.
[0173] Generally speaking, this embodiment has the following beneficial effects:
[0174] In this application, since various services of the network application include various types of services such as web and non-web, by splitting various services of the network application into different modules, such as an open service module, an external access module, and an internal module, more specific and detailed security policies can be formulated according to the characteristics and requirements of different modules; and because this method utilizes containerization characteristics and is implemented at the container management level, it can effectively protect against underlying overflow vulnerabilities and operating system-level vulnerabilities. This split makes the functions of each module more clear, facilitating targeted security management and protection. Among them, prohibiting the open service module from initiating requests to the outside actively can prevent this module from being used as an attack springboard and further protect the security of the internal network and system; only allowing the external access module to actively access the preset Internet can limit its access range and reduce the potential attack surface; prohibiting the internal module from interacting with the Internet can completely isolate it from the external environment, thereby reducing the risk of being attacked externally. By alarming and repairing the abnormal behaviors of containers marked in various services, measures can be taken promptly when a security event occurs, thus effectively dealing with zero-day vulnerabilities;
[0175] In addition, with the containerized security features of the present application, through strict control of module splitting, read / write permissions, and network access permissions, it is possible to achieve protection against several types of high-risk zero-day vulnerabilities such as file upload, file read / write, command execution, and SSRF. Compared with RASP, the present application can protect non-web services and effectively protect against overflow vulnerabilities; compared with feature-based protection technologies such as WAF (Web Application Firewall), IDS (Intrusion Detection System), and traffic analysis, the present application is not based on vulnerability exploitation features, so it can provide a more effective protection effect for zero-day vulnerabilities with unknown features. At the same time, due to the use of containerization and the isolation characteristics of containers, when the present application encounters a zero-day vulnerability attack, the impact scope can be limited within the container, thereby protecting other containers and the host machine, achieving in-depth defense.
[0176] Embodiment Three:
[0177] The embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the described zero-day vulnerability protection method based on containerization;
[0178] Among them, for the described zero-day vulnerability protection method based on containerization, if it is implemented in the form of a software functional unit and used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above various method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0179] The above are the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and refinements can still be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A zero-day vulnerability protection method based on containerization, characterized in that, Including: Splitting various services of a network application into several modules; among them, the several modules include an open service module, an external access module, and an internal module; Performing container network permission management and access control on the various services, prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet; Warning and repairing the container abnormal behaviors marked in the various services.
2. The zero-day vulnerability protection method based on containerization according to claim 1, wherein Performing container network permission management and access control on the various services, prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet, specifically: Restricting the container read and write permissions of the various services through container configuration; among them, the various services include web services and non-web services; Performing proxy forwarding and access control on the network access requests of several containers in the various services, and performing vulnerability protection on the several modules according to a preset container network security policy; among them, the container network security policy includes prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet; Performing network access control among the several modules.
3. The zero-day vulnerability protection method based on containerization according to claim 2, characterized in that Restricting the container read and write permissions of the various services through container configuration, specifically: Based on the various services, mounting the host directory to several containers according to the principle of minimization, controlling the containers of the web service to be mounted with the web directory in a read-only manner, and prohibiting the writable mounting of a preset sensitive directory.
4. A containerization-based zero-day vulnerability protection method according to claim 2, characterized in that Performing proxy forwarding and access control on the network access requests of each container in the various services, specifically: Controlling the open service module to provide services to the outside only through port mapping; Prohibiting the internal module from accessing the Internet; Allowing the external access module to send Internet network requests, and restricting the network protocol type and destination address used by the external access module when initiating requests.
5. The zero-day vulnerability protection method based on containerization according to claim 2, characterized in that, Performing network access control among the several modules, specifically: Comparing the request and access control lists among several containers in the several modules, and intercepting predefined illegal requests according to the comparison result; among them, the access control list is established according to the access relationship among the several modules.
6. The zero-day vulnerability protection method based on containerization according to claim 1, characterized in that, Prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet, specifically: Prohibiting the open service module from actively initiating communication requests to the outside, and controlling the open service module to open preset external services to the Internet through port mapping; Prohibiting the external access module from providing service interfaces to the outside, but retaining the active access permission of the external access module to the preset Internet; Prohibiting any form of data inflow or outflow between the internal module and the Internet.
7. A zero-day vulnerability protection method based on containerization according to claim 1, characterized in that, The various services of the network application are split into several modules; among them, the several modules include an open service module, an external access module, and an internal module, specifically: According to the characteristics and functions of the application software, the various services of the network application are split into several modules including the open service module, the external access module, and the internal module; Among them, the open service module is a module that is open to the outside and provides services; the external access module is a module that actively initiates network requests to the outside; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules.
8. A zero-day vulnerability protection device based on containerization, characterized in that, It includes a splitting module, a management module, and an alarm module; Among them, the splitting module is used to split the various services of the network application into several modules; among them, the several modules include an open service module, an external access module, and an internal module; The management module is used to manage container network permissions and access control for the various services, prohibit the open service module from actively initiating requests to the outside, control the external access module to actively access a preset Internet, and prohibit the internal module from interacting with the Internet; The alarm module is used to alarm and repair the abnormal behaviors of the containers marked in the various services.
9. The zero-day vulnerability protection device based on containerization according to claim 8, wherein, The management module includes a permission unit, a protection unit, and an access unit; Among them, the permission unit is used to restrict the read and write permissions of the containers of the various services through container configuration; among them, the various services include web services and non-web services; The protection unit is used to proxy forward and access control the network access requests of several containers in the various services, and perform vulnerability protection on the several modules according to a preset container network security policy; among them, the container network security policy includes prohibiting the open service module from actively initiating requests to the outside, controlling the external access module to actively access a preset Internet, and prohibiting the internal module from interacting with the Internet; The access unit is used to perform network access control between the several modules.
10. A containerization-based zero-day vulnerability protection device according to claim 9, characterized in that, The permission unit is specifically: Based on the various services, mount the host directory to several containers in the principle of minimization, control the containers of the web service to be mounted with the web directory in a read-only manner, and prohibit the writable mounting of a preset sensitive directory.
11. A zero-day vulnerability protection device based on containerization according to claim 9, characterized in that, The protection unit includes a permission subunit, an access subunit, and a request subunit; Among them, the permission subunit is used to control the open service module to provide services to the outside only through port mapping; The access subunit is used to prohibit the internal module from accessing the Internet; The request subunit is used to allow the external access module to send Internet network requests and restrict the network protocol type and destination address used by the external access module when initiating requests.
12. The zero-day vulnerability protection device based on containerization according to claim 9, characterized in that, The access unit is specifically: Compare the request and access control lists between several containers in the several modules, and intercept predefined illegal requests according to the comparison result; among them, the access control list is established according to the access relationship between the several modules.
13. A zero-day vulnerability protection device based on containerization according to claim 8, characterized in that The management module includes a communication unit, an interface unit, and an interaction unit; Among them, the communication unit is used to prohibit the open service module from actively initiating communication requests to the outside, and control the open service module to open preset external services to the Internet through port mapping; The interface unit is used to prohibit the external access module from providing service interfaces to the outside, but retain the active access permission of the external access module to the preset Internet; The interaction unit is used to prohibit any form of data inflow or outflow between the internal module and the Internet.
14. A zero-day vulnerability protection device based on containerization according to claim 8, characterized in that, The splitting module is specifically: According to the characteristics and functions of the application software, split the various services of the network application into several modules including the open service module, the external access module, and the internal module; Among them, the open service module is a module that is open to the outside and provides services; the external access module is a module that actively initiates network requests to the outside; the internal module is a module that has no interaction with the external network and only communicates and exchanges data with other internal modules.
15. A storage medium, characterized in that, A computer program is stored on the storage medium, and the computer program is called and executed by a computer to implement a containerization-based zero-day vulnerability protection method as described in any one of claims 1 to 7 above.