File detection method and device, electronic equipment and medium

By capturing system call events in the container in real time, tracking the file source path and comparing it with the host file system, the problem of insufficient file traceability in containerized application scenarios is solved, and the security and reliability of container operation are improved.

CN120337282APending Publication Date: 2025-07-18BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510400283.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing technology lacks real-time traceability of file sources in containerized application scenarios, which makes it difficult to timely identify threats such as malicious code injection and shared library replacement, affecting the security and integrity of the container operating environment.

Method used

By capturing system call events in the container in real time, tracking the source path of the file, and comparing it with the file system of the container host, determining the location of the file in the multi-layer file system, and achieving rapid trustworthiness verification of the file.

Benefits of technology

Real-time monitoring and rapid verification of files during container operation is realized, ensuring the integrity and security of the container environment, and reducing the risk of maintenance costs and response lag.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337282A_ABST
    Figure CN120337282A_ABST
Patent Text Reader

Abstract

The invention provides a file detection method and device, electronic equipment, a computer readable storage medium and a computer program product, and relates to the field of computers, in particular to the technical field of containers and data processing. According to the implementation scheme, a file which is being executed by a system call event in a container is determined; obtaining first path information of the file in a first file system in the container; acquiring second path information of the container in a second file system corresponding to the host machine of the container; determining third path information corresponding to the file based on the first path information and the second path information; and determining position information of the file in the second file system based on the third path information so as to determine a detection result of the file based on the position information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computers, and more particularly to the fields of containers and data processing technologies. Specifically, it relates to a file detection method, apparatus, electronic device, computer-readable storage medium, and computer program product. Background Art

[0002] The security of the R & D supply chain is crucial for enterprises, especially in containerized application scenarios. Programs within containers are extremely vulnerable to threats such as malicious code injection and shared library replacement during operation, which seriously undermine the integrity of the container runtime. Summary of the Invention

[0003] The present disclosure provides a file detection method, apparatus, electronic device, computer-readable storage medium, and computer program product.

[0004] According to one aspect of the present disclosure, there is provided a file detection method, including: determining a file on which a system call event within a container is being executed; obtaining first path information of the file in a first file system within the container; obtaining second path information of the container in a corresponding second file system on its host; determining third path information corresponding to the file based on the first path information and the second path information; and determining location information of the file in the second file system based on the third path information, so as to determine a detection result of the file based on the location information.

[0005] According to another aspect of the present disclosure, there is provided a file detection apparatus, including: a monitoring unit configured to determine a file on which a system call event within a container is being executed; a first obtaining unit configured to obtain first path information of the file in a first file system within the container; a second obtaining unit configured to obtain second path information of the container in a corresponding second file system on its host; a first determining unit configured to determine third path information corresponding to the file based on the first path information and the second path information; and a second determining unit configured to determine location information of the file in the second file system based on the third path information, so as to determine a detection result of the file based on the location information.

[0006] According to another aspect of the present disclosure, there is provided an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method described in the present disclosure.

[0007] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method described in the present disclosure.

[0008] According to another aspect of the present disclosure, there is provided a computer program product including a computer program which, when executed by a processor, implements the method described in the present disclosure.

[0009] According to one or more embodiments of the present disclosure, by real-time capturing system call events occurring within a container, it is possible to track in real time the source path of the files loaded during the runtime of the container, and compare this path with the original files in the container host, thereby quickly identifying and verifying its credibility.

[0010] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The drawings exemplarily illustrate embodiments and form a part of the specification, and are used together with the written description of the specification to explain the exemplary embodiments of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. In all the drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0012] Figure 1 A schematic diagram of an exemplary system in which the various methods described herein can be implemented according to an embodiment of the present disclosure is shown;

[0013] Figure 2 A flowchart of a file detection method according to an embodiment of the present disclosure is shown;

[0014] Figure 3 A flowchart of a file detection method according to an embodiment of the present disclosure is shown;

[0015] Figure 4 A schematic diagram of a second file system according to an embodiment of the present disclosure is shown;

[0016] Figure 5 A flowchart of a file detection method according to an exemplary embodiment of the present disclosure is shown;

[0017] Figure 6 A block diagram of the structure of a file detection device according to an embodiment of the present disclosure is shown; and

[0018] Figure 7 A block diagram of the structure of an exemplary electronic device capable of implementing the embodiments of the present disclosure is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] Exemplary embodiments of the present disclosure will be described below with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.

[0020] In the present disclosure, unless otherwise specified, the terms "first", "second", etc. are used to describe various elements and are not intended to limit the positional relationship, temporal relationship, or relative importance of these elements. Such terms are only used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of the element, and in certain cases, based on the context description, they may also refer to different instances.

[0021] The terms used in the description of the various examples in the present disclosure are only for the purpose of describing specific examples and are not intended to be limiting. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element may be one or more. In addition, the term "and / or" used in the present disclosure covers any one of the listed items and all possible combinations.

[0022] Embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0023] Figure 1 A schematic diagram of an exemplary system 100 in which the various methods and apparatuses described herein can be implemented according to embodiments of the present disclosure is shown. Referring Figure 1 , the system 100 includes one or more client devices 101, 102, 103, 104, 105, and 106, a server 120, and one or more communication networks 110 that couple the one or more client devices to the server 120. The client devices 101, 102, 103, 104, 105, and 106 can be configured to execute one or more applications.

[0024] In an embodiment of the present disclosure, the server 120 can run one or more services or software applications that enable a method for file detection to be executed.

[0025] In some embodiments, server 120 may also provide other services or software applications, which may include non-virtual environments and virtual environments. In some embodiments, these services may be provided as web-based services or cloud services, such as provided to users of client devices 101, 102, 103, 104, 105, and / or 106 under a software as a service (SaaS) model.

[0026] In Figure 1 the configuration shown, server 120 may include one or more components that implement the functions performed by server 120. These components may include software components, hardware components, or a combination thereof executable by one or more processors. Users operating client devices 101, 102, 103, 104, 105, and / or 106 may in turn utilize one or more client applications to interact with server 120 to utilize the services provided by these components. It should be understood that various different system configurations are possible, which may differ from system 100. Thus, Figure 1 is an example of a system for implementing the various methods described herein and is not intended to be limiting.

[0027] Users may use client devices 101, 102, 103, 104, 105, and / or 106 to input user instructions or obtain detection results. The client device may provide an interface that enables a user of the client device to interact with the client device. The client device may also output information to the user via the interface. Although Figure 1 only six client devices are depicted, those skilled in the art will be able to understand that the present disclosure may support any number of client devices.

[0028] Client devices 101, 102, 103, 104, 105, and / or 106 may include various types of computing devices, such as portable handheld devices, general-purpose computers (such as personal computers and laptop computers), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors, or other sensing devices, etc. These computing devices may run various types and versions of software applications and operating systems, such as MICROSOFT Windows, APPLE iOS, UNIX-like operating systems, Linux or Linux-like operating systems (such as GOOGLE Chrome OS); or include various mobile operating systems, such as MICROSOFT WindowsMobile OS, iOS, Windows Phone, Android. Portable handheld devices may include cellular phones, smartphones, tablets, personal digital assistants (PDAs), etc. Wearable devices may include head-mounted displays (such as smart glasses) and other devices. Gaming systems may include various handheld gaming devices, Internet-enabled gaming devices, etc. Client devices are capable of executing various different applications, such as various Internet-related applications, communication applications (such as email applications), short message service (SMS) applications, and may use various communication protocols.

[0029] Network 110 may be any type of network known to those skilled in the art, which may support data communication using any one of a variety of available protocols (including but not limited to TCP / IP, SNA, IPX, etc.). By way of example only, one or more networks 110 may be a local area network (LAN), an Ethernet-based network, token ring, wide area network (WAN), the Internet, virtual network, virtual private network (VPN), intranet, extranet, blockchain network, public switched telephone network (PSTN), infrared network, wireless network (such as Bluetooth, WIFI), and / or any combination of these and / or other networks.

[0030] Server 120 may include one or more general-purpose computers, dedicated server computers (such as PC (personal computer) servers, UNIX servers, midrange servers), blade servers, mainframe computers, server clusters, or any other suitable arrangement and / or combination. Server 120 may include one or more virtual machines running a virtual operating system, or other computing architectures involving virtualization (such as one or more flexible pools of logical storage devices that can be virtualized to maintain virtual storage devices for the server). In various embodiments, server 120 may run one or more services or software applications that provide the functions described below.

[0031] The computing unit in server 120 can run one or more operating systems including any of the above-mentioned operating systems and any commercially available server operating systems. Server 120 can also run any one of a variety of additional server applications and / or middleware applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, etc.

[0032] In some embodiments, server 120 can include one or more applications to analyze and merge data feeds and / or event updates received from users of client devices 101, 102, 103, 104, 105, and 106. Server 120 can also include one or more applications to display data feeds and / or real-time events via one or more display devices of client devices 101, 102, 103, 104, 105, and 106.

[0033] In some embodiments, server 120 can be a server of a distributed system or a server incorporating a blockchain. Server 120 can also be a cloud server, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology. A cloud server is a host product in the cloud computing service system to address the defects of high management difficulty and weak business scalability existing in traditional physical hosts and virtual private server (VPS) services.

[0034] System 100 can also include one or more databases 130. In certain embodiments, these databases can be used to store data and other information. For example, one or more of databases 130 can be used to store information such as various types of files. Databases 130 can reside in various locations. For example, the databases used by server 120 can be local to server 120, or can be remote from server 120 and can communicate with server 120 via a network-based or dedicated connection. Databases 130 can be of different types. In certain embodiments, the databases used by server 120 can be, for example, relational databases. One or more of these databases can store, update, and retrieve data to and from the databases in response to commands.

[0035] In certain embodiments, one or more of databases 130 can also be used by applications to store application data. The databases used by applications can be different types of databases, such as key-value repositories, object repositories, or conventional repositories supported by a file system.

[0036] Figure 1The system 100 can be configured and operated in various ways to enable the application of the various methods and apparatuses described in this disclosure.

[0037] Container dynamic integrity detection refers to monitoring the state of a container during its runtime to ensure that it has not been tampered with or attacked. This is different from static checks (such as image signature verification), and dynamic checks focus on the behavior during runtime and changes in the file system.

[0038] Currently, container abnormal activities are usually monitored based on security monitoring tools. For example, tools such as Falco, SysdigSecure, and Aqua Security mainly detect abnormal activities by real-time monitoring the behavior patterns of programs inside the container. That is, during the runtime of the container, the security tool monitors the container behavior in real time, such as what websites are accessed and what capabilities of the system are called (i.e., monitoring the results of system calls). However, in the scenario of container dynamic integrity detection, such tools lack the ability to quickly trace the sources of executable files and shared libraries inside the container. When threats such as malicious code injection or shared library replacement occur, these tools may not be able to identify and respond in a timely manner, resulting in potential security vulnerabilities and thus affecting the overall security of the container runtime environment.

[0039] Alternatively, container abnormal activities are usually monitored based on file integrity monitoring tools. For example, AIDE and Tripwire, etc., can be configured to check for changes in the container file system; file integrity monitoring tools detect unauthorized changes by periodically checking the file system status and comparing it with a baseline file system. On the one hand, such tools usually run in a periodic scanning manner rather than real-time monitoring. This means that attacks occurring within the time window between two checks may not be detected in a timely manner, resulting in a lag in response. On the other hand, such tools need to maintain a "clean" baseline file as a comparison standard. However, in a container environment, after each application update, configuration change, or container restart, the baseline file system needs to be synchronously updated. The dynamic nature of the container environment (such as the frequent startup and destruction of containers and the temporariness of the file system) makes it extremely difficult to maintain a consistent baseline file system. This frequent maintenance operation increases the time and labor costs, and the usage cost is relatively high.

[0040] The above two types of common tools have certain security detection capabilities in traditional environments, but in the containerized and dynamic cloud-native environment, both have significant limitations. Container runtime tools lack the ability to trace the sources of files, while file integrity monitoring tools face problems such as poor real-time performance, high maintenance costs, and insufficient adaptability, making it difficult to meet the security requirements of modern container environments.

[0041] Accordingly, embodiments of the present disclosure provide a file detection method for enhancing the integrity of a container during the running phase and ensuring the security and reliability of an application throughout its life cycle. Figure 2 FIG. shows a flowchart of a file dynamic detection method according to an embodiment of the present disclosure, as Figure 2 shown, method 200 includes: determining a file on which a system call event in the container is being executed (step 210); obtaining first path information of the file in a first file system in the container (step 220); obtaining second path information of the container in a corresponding second file system on its host machine (step 230); determining third path information corresponding to the file based on the first path information and the second path information (step 240); and determining location information of the file in the second file system based on the third path information, so as to determine a detection result of the file based on the location information (step 250).

[0042] According to an embodiment of the present disclosure, by capturing in real time system call events occurring in the container, it is possible to track in real time the source path of a file loaded during the running of the container, and compare the path with the original file in the container host machine, so as to quickly identify and verify its credibility.

[0043] In the present disclosure, a system call event is a core mechanism for a user-mode program to request services from the kernel through a software interrupt, and is used for privileged operations such as accessing hardware resources, managing processes, or operating a file system. For example, performing system calls such as openat or getdents in a file system can implement operations such as file opening and directory traversal.

[0044] According to some embodiments, the file includes at least one of an executable file and a shared library.

[0045] In the present disclosure, an executable file refers to a file that can be loaded and executed by an operating system. In different operating system environments, the presentation of an executable file is different. For example, in a Windows operating system, an executable file can be a file of type.exe,.sys,.com, etc.; in a Linux operating system, an executable file can be a file of type.tx,.rodata,.data, etc.

[0046] In this disclosure, a shared library is a type of library file in an operating system that contains functions, variables, or other resources that can be used by multiple programs simultaneously, without having to compile these resources separately into the executable files of each program. They are typically dynamically linked, which means they are loaded into memory only when the program is running, rather than being embedded directly into the program at compile time. Shared libraries, such as the.so files in Linux and the.dll files in Windows, are reusable functional modules in the operating system. Their core purpose is to provide common code and resources for application programs, avoiding duplicate compilation and storing redundant data.

[0047] In some embodiments, by monitoring system call events within a container, the file being executed for the captured system call events is determined. For example, through kernel-level tools such as eBPF, strace, LD_DEBUG, etc., system calls during container runtime can be captured in real time, and information about relevant events can be extracted, such as the identifier of the current container (e.g., ID) and the file attribute information of the file being executed (e.g., file name).

[0048] In some examples, system calls related to the execution of executable files or the loading of shared libraries that occur within a container (such as execve, open, and mmap, etc.) can be captured in real time through eBPF probes, and relevant event information can be extracted. The extended Berkeley Packet Filter (eBPF) is an evolution of the original BPF technology. It extends the functionality of BPF by providing a more powerful and flexible way to perform dynamic tracing, network analysis, and performance monitoring. It allows developers to write programs and load them into the kernel, and these programs can be attached to various hooks and events in the system, providing real-time insights and control over system activities.

[0049] In some examples, the dynamic linker (ld.so) of the Linux system supports outputting debug information through the environment variable LD_DEBUG to directly record the loading behavior of shared libraries. Therefore, in some examples, information about the shared libraries being loaded can be captured through LD_DEBUG. An example command can be: copy LD_DEBUG=files,libs. / your_program. Thus, the current system call events and the corresponding event information can be captured.

[0050] It can be understood that the monitoring of system call events within a container can be implemented in any suitable way, including but not limited to, based on LD_PRELOAD, ltrace, / proc, etc., and there is no limitation here.

[0051] According to some embodiments, such as Figure 3As shown, the determination of the location information of the file in the second file system (i.e., step 250) may include: obtaining the verification value of the image corresponding to the container determined when running the container (step 310); obtaining the reference value of the image corresponding to the container determined when building the container, where the verification value and the reference value are calculated from the corresponding image data through the same algorithm (step 320); comparing the verification value with the reference value (step 330); and in response to determining that the verification value and the reference value are the same, determining the location information of the file in the second file system (step 340).

[0052] That is, before performing "determining the location information of the file in the second file system based on the third path information" in step 250, the comparison operation between the verification value and the reference value can be performed. Further, before performing any one of steps 220 - 250, the comparison operation between the verification value and the reference value can be performed first.

[0053] In some examples, the verification value and the reference value can be hash values. That is, the hash value of the container image at build time and the hash value of the container image when running the container can be calculated respectively through the corresponding algorithm. A hash value, also known as a hash or message digest, is a process of mapping input data of any length to a fixed-length string or number through a hash algorithm. This mapping relationship is one-way, that is, the hash value can only be calculated from the input data, and the original input data cannot be deduced reversely from the hash value, which ensures the security of the data.

[0054] In some examples, after real-time capturing system call events occurring in the container, the container identifier can be captured. For example, by monitoring system call events (such as the process creation event when the container starts), the unique ID of the container to which the system call belongs can be matched. Based on this container ID, for example, by calling the interface or command-line tool of the container engine (such as Docker, containerd), the image information used by this container can be queried, including the image source repository (Repository) and the unique hash value (Digest).

[0055] Through the above embodiments, the hash value of the image determined when the container is built can be saved as the reference value. Then, when the container is running, the hash value of the image corresponding to this container at this time is obtained again. Through hash value verification, it can be determined whether the container image has been modified within the time range from when the container is built to the current time when the container is running.

[0056] In some embodiments, if it is determined that the verification value and the reference value are inconsistent through comparison, it indicates that the image of the container has been tampered with before the container runs, and the file source is untrusted; if it is determined that the two are consistent, the verification of the path information in the next step will be entered.

[0057] According to some embodiments, the second file system is a multi-layer file system, and the multi-layer file system includes: a first file layer for storing the image corresponding to the container, a second file layer for storing the files modified during the running of the container, and a combined view layer for presenting the combined view of all the files in the first file layer and the second file layer.

[0058] In some examples, the first file layer in the second file system for storing the container image is a read-only layer. After the container is started, by default, the content of the first file layer cannot be modified. The first file layer, as a read-only layer, can be used to store the basic data of the file system. The second file layer in the second file system for storing the files modified during the running of the container can be used as a temporary write layer to implement the modification of the file system. That is, the second file layer is used to store the latest state of the file system, and all write operations on the file system will first act on the second file layer. By combining the first file layer and the second file layer, a unified file system view, that is, the combined view layer, can be provided. When the user accesses the file system through the combined view layer, what is seen is the combined view result after the merger of the first file layer and the second file layer. However, it can be understood that the combined view layer is not used to store real files, but is used to uniformly manage the files in the first file layer and the second file layer in a form similar to a link.

[0059] In some examples, the first file layer can be one or more. When there are multiple first file layers, the file directories are stacked in sequence.

[0060] Figure 4 The schematic diagram of the second file system according to an embodiment of the present disclosure is shown, as Figure 4 shown, the second file system includes a combined view layer, a second file layer, and two first file layers. Among them, the first file layer and the second file layer are different directories from the underlying file system, which can be specified by the user himself, and internally contain the file directories that the user wants to merge. The combined view layer is a mount point. After the file system is mounted, the content from the directories of each first file layer and the second file layer will be seen simultaneously under the combined view layer directory, and the user can also not (need not) perceive which of these files come from the first file layer and which come from the second file layer. What the user sees is just an ordinary file system root directory.

[0061] In some examples, the second file system may be an OverlayFS file system (i.e., a stacked file system). The OverlayFS file system achieves efficient file management through a layered file system union mount and a copy-on-write (CoW) mechanism. The three layers in the OverlayFS file system, namely LowerDir, Upperdir, and MergedDir, are respectively the first file layer, the second file layer, and the combined view layer described above.

[0062] Although the second file system, such as the OverlayFS file system, merges different layer directories, the first file layer and the second file layer are not completely equivalent, and there is a hierarchical relationship. First, when there are files with the same name in the first file layer and the second file layer, the files in the first file layer will be hidden, and users can only see the files from the second file layer. Then, there is also the same hierarchical relationship in each first file layer, and the files with the same name in the upper layer mask those in the lower layer. In addition, if there are directories with the same name, they will continue to be merged (the merger of the first file layer and the second file layer into the mount point directory is a typical example).

[0063] Through the second file system, the container image can be mounted as read-only, and modifications to the file system can be achieved through a temporary write layer. This method is very suitable for embedded devices or scenarios that require maintaining the integrity and security of system files.

[0064] Therefore, according to some embodiments, based on the third path information, determining the location information of the file in the second file system to determine the detection result of the file based on the location information includes: determining whether the file is located in the combined view layer based on the third path information; and in response to determining that the file is not located in the combined view layer, determining that the file is suspicious.

[0065] In an embodiment according to the present disclosure, it can be understood that the third path information can be expressed as the path of a file in a container image in the second file system. Therefore, the third path information can be used to determine whether the corresponding file is a file in the container image.

[0066] As described above, the combined view layer is the effect after the first file layer and the second file layer are merged. When the file does not exist in the combined view layer, it indicates that the file is not a file in the original container image, and its source is suspicious. At this time, the integrity of the container and its internal programs may be threatened. Therefore, when it is determined that the file is suspicious, the system can trigger an alarm and execute corresponding in-process defense strategies.

[0067] According to some embodiments, determining the location information of the file in the second file system based on the third path information to determine the detection result of the file further includes: in response to determining that the file is located in the union view layer, determining whether the file is located in the second file layer based on the third path information; and in response to determining that the file is located in the second file layer, determining that the file is suspicious.

[0068] Specifically, after determining that the file is located in the union view layer, it can be further verified whether the file exists in the second file layer. If it exists, it indicates that the file is a new file created during the running period after the container is started and is not a file within the original container image, and it is also determined that the source is suspicious. The system will trigger an alarm and execute a defense strategy.

[0069] According to some embodiments, determining the location information of the file in the second file system based on the third path information to determine the detection result of the file further includes: in response to determining that the file is located in the union view layer, determining whether the file is located in the second file layer based on the third path information; and in response to determining that the file is not located in the second file layer, determining that the file is trustworthy.

[0070] Specifically, after determining that the file is located in the union view layer, it can be further verified whether the file exists in the second file layer. If it is determined that the file does not exist in the second file layer, since the union view layer is the effect after the merged view of the first file layer and the second file layer, it can be known at this time that the file must be located in the first file layer. The first file layer is the read-only layer of the second file system, and the read-only layer belongs to the trustworthy files within the original container image, and if it exists, it is allowed to execute normally.

[0071] Figure 5 Shows a flowchart of a file dynamic detection method according to an exemplary embodiment of the present disclosure. As Figure 5 shown, the following operations can be performed:

[0072] In step 501: For example, through the eBPF probe technology, system calls related to the execution of executable files or the loading of shared libraries occurring within the container (such as execve, open, and mmap, etc.) are captured in real time, and relevant event information is extracted.

[0073] In step 502: From the captured system call events, the unique ID of the container's runtime is parsed, and then in combination with this ID, by accessing the container engine, the corresponding container image metadata information is parsed, such as including image repository information and image hash information, etc.

[0074] In step 503: Compare the image hash value obtained in step 502 with the original hash value (benchmark value) when the container was built. If the two are inconsistent, it indicates that the container has been tampered with before startup, and the file is determined to be suspicious; if they are consistent, continue to execute step 504.

[0075] In step 504: From the captured system call events, the absolute path of the executable file or shared library file in the container's file system (i.e., the first path information, for example: / test / 123456) can be further extracted. Combining with the container ID, the physical path of the corresponding second file system of the container on the host can be obtained (i.e., the second path information, for example: / data / docker / diff). Based on the first path information and the second path information, the physical path of the file in the second file system of the host can be determined (i.e., the third file path, for example: / data / docker / diff / test / 123456).

[0076] In step 505, verify whether the executable file or shared library exists in the union view layer. If it does not exist, it indicates that the file is not a file in the original container image, and its source is determined to be suspicious; if it exists, continue to execute step 506.

[0077] In step 506: Continue to verify whether the executable file or shared library exists in the second file layer (i.e., the read-write layer). If it is determined to exist, it indicates that the file is a new file created during the running period after the container starts up and is not a file in the original container image, and its source is also determined to be suspicious; if it is determined not to exist, confirm that the executable file or shared library is located in the first file layer (i.e., the read-only layer) and belongs to a trusted file in the original container image.

[0078] Through the above multi-level verification mechanism, potential tampering behaviors of executable files or shared libraries during container operation can be effectively identified and blocked, ensuring the integrity and security of the container environment.

[0079] According to an embodiment of the present disclosure, as Figure 6As shown, a file detection device 600 is also provided, including: a monitoring unit 610 configured to determine a file for which a system call event in a container is being executed; a first acquisition unit 620 configured to acquire first path information of the file in a first file system in the container; a second acquisition unit 630 configured to acquire second path information of the container in a second file system corresponding to it on its host; a first determination unit 640 configured to determine third path information corresponding to the file based on the first path information and the second path information; and a second determination unit 650 configured to determine location information of the file in the second file system based on the third path information, so as to determine a detection result of the file based on the location information.

[0080] Here, the operations of the above-mentioned units 610-650 of the file detection device 600 are respectively similar to the operations of steps 210-250 described above, and will not be elaborated here.

[0081] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure, etc. of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0082] According to an embodiment of the present disclosure, an electronic device, a readable storage medium, and a computer program product are also provided.

[0083] Refer to Figure 7 , and now a block diagram of an electronic device 700 that can be used as a server or a client of the present disclosure will be described. It is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0084] As Figure 7As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to computer programs stored in a read-only memory (ROM) 702 or computer programs loaded from a storage unit 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the electronic device 700 can also be stored. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0085] Multiple components in the electronic device 700 are connected to the I / O interface 705, including: an input unit 706, an output unit 707, a storage unit 708, and a communication unit 709. The input unit 706 can be any type of device capable of inputting information into the electronic device 700. The input unit 706 can receive input digital or character information and generate key signal inputs related to user settings and / or function controls of the electronic device, and can include, but is not limited to, a mouse, a keyboard, a touch screen, a track pad, a track ball, a joystick, a microphone, and / or a remote control. The output unit 707 can be any type of device capable of presenting information and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 708 can include, but is not limited to, magnetic disks and optical discs. The communication unit 709 allows the electronic device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, an 802.11 device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0086] The computing unit 701 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 executes the various methods and processes described above, such as method 200. For example, in some embodiments, method 200 can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of method 200 described above can be executed. Alternatively, in other embodiments, the computing unit 701 can be configured to execute method 200 in any other suitable manner (e.g., by means of firmware).

[0087] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0088] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0089] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0090] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0091] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), the Internet, and a blockchain network.

[0092] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server incorporating a blockchain.

[0093] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0094] Although the embodiments or examples of this disclosure have been described with reference to the accompanying drawings, it should be understood that the above methods, systems, and devices are merely exemplary embodiments or examples, and the scope of the present invention is not limited by these embodiments or examples, but is only defined by the authorized claims and their equivalent scope. Various elements in the embodiments or examples can be omitted or replaced by their equivalent elements. In addition, the steps can be executed in an order different from that described in this disclosure. Further, the various elements in the embodiments or examples can be combined in various ways. Importantly, with the evolution of technology, many of the elements described herein can be replaced by equivalent elements that emerge after this disclosure.

Claims

1. A file detection method, comprising: Determining a file for which a system call event in a container is being executed; Obtaining first path information of the file in a first file system within the container; Obtaining second path information of the container in a second file system corresponding to it on its host; Based on the first path information and the second path information, determining third path information corresponding to the file; And Based on the third path information, determining location information of the file in the second file system, so as to determine a detection result of the file based on the location information.

2. The method according to claim 1, wherein The second file system is a multi-layer file system, and the multi-layer file system includes: a first file layer for storing an image corresponding to the container, a second file layer for storing files modified during container operation, and a combined view layer for presenting a combined view of all files in the first file layer and the second file layer, and Wherein, based on the third path information, determining location information of the file in the second file system, so as to determine a detection result of the file based on the location information includes: Based on the third path information, determining whether the file is located in the combined view layer; and In response to determining that the file is not located in the combined view layer, determining that the file is suspicious.

3. The method according to claim 2, wherein, Based on the third path information, determining location information of the file in the second file system, so as to determine a detection result of the file based on the location information further includes: In response to determining that the file is located in the combined view layer, based on the third path information, determining whether the file is located in the second file layer; and In response to determining that the file is located in the second file layer, determining that the file is suspicious.

4. The method according to claim 2 or 3, wherein Based on the third path information, determining location information of the file in the second file system, so as to determine a detection result of the file based on the location information further includes: In response to determining that the file is located in the combined view layer, based on the third path information, determining whether the file is located in the second file layer; and In response to determining that the file is not located in the second file layer, determining that the file is trustworthy.

5. The method according to any one of claims 1-4, wherein The determining location information of the file in the second file system includes: Obtaining a check value of the image corresponding to the container determined when running the container; Obtaining a reference value of the image corresponding to the container determined when building the container, wherein the check value and the reference value are obtained by calculating corresponding image data through the same algorithm; Comparing the check value with the reference value; and In response to determining that the check value and the reference value are the same, determining location information of the file in the second file system.

6. The method according to claim 5, further comprising: In response to determining that the check value and the reference value are different, determining that the file is suspicious.

7. The method according to claim 1, wherein The file includes at least one of an executable file and a shared library.

8. A file detection device, comprising: A monitoring unit configured to determine a file for which a system call event in a container is being executed; A first acquisition unit, configured to acquire first path information of the file in a first file system within the container; A second acquisition unit, configured to acquire second path information of the container in a second file system corresponding to it on its host; A first determination unit, configured to determine third path information corresponding to the file based on the first path information and the second path information; and A second determination unit, configured to determine location information of the file in the second file system based on the third path information, so as to determine a detection result of the file based on the location information.

9. An electronic device, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the method according to any one of claims 1-7.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-7.

11. A computer program product comprising a computer program, wherein, The computer program, when executed by a processor, implements the method according to any one of claims 1-7.