Program verification method and device, product, equipment and medium
By obtaining test cases and calling defense programs in the mirror processing stage to prevent risk images from risking and generating verification results, the problem of low and incomplete verification of defense programs in the existing technology is solved, and efficient and comprehensive verification results are achieved.
Patent Information
- Application Number
- CN202410095712.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-23
- Publication Date
- 2025-07-29
AI Technical Summary
In the prior art, the effectiveness testing of security products through manual methods is inefficient and incomplete, making it difficult to effectively verify the defense effectiveness of the defense program.
By obtaining the test cases corresponding to the verification scenario, the test cases call the defense program in the mirror processing stage to prevent the risk image, and generate verification results to indicate the defense effectiveness of the defense program.
It realizes automated verification of the defense effectiveness of defense programs, improving verification efficiency and completeness.
Smart Images

Figure CN120386712A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a program verification method, apparatus, product, device, and medium. Background Art
[0002] An image is a form of file storage. Generally, a program can be encapsulated as an image, and then corresponding processing can be performed on the image to implement the running of the program encapsulated in the image. For example, a container corresponding to the image can be created, and then the program in the image can be run in the created container.
[0003] Among them, in the process of processing the image, it is necessary to perform risk defense on the processed image through a security product to avoid the risky image attacking the system when processing a risky image. Therefore, in the existing applications, the effectiveness of the security product can be tested manually, but the manual method will make the test efficiency of the security product very low, and it is very likely that the test of the security product is also incomplete. Summary of the Invention
[0004] This application provides a program verification method, apparatus, product, device, and medium, which can improve the verification efficiency and verification completeness of the defense effectiveness of the defense program.
[0005] On the one hand, this application provides a program verification method, which includes:
[0006] Obtain test cases corresponding to the verification scenario; the test cases are used to verify the defense effectiveness of the defense program in the verification scenario;
[0007] Based on the test cases, process the risky images in the verification scenario at at least one image processing stage; and,
[0008] At each image processing stage of the at least one image processing stage, call the defense program to perform risk defense on the processed risky images to obtain the processing results of the risky images at each image processing stage;
[0009] Generate a verification result for the defense program based on the processing results of the risky images at each image processing stage; the verification result is used to indicate whether the defense program has the defense effectiveness against the risky images or does not have the defense effectiveness against the risky images in the verification scenario.
[0010] On the one hand, this application provides a program verification apparatus, which includes:
[0011] An acquisition module, configured to obtain test cases corresponding to the verification scenario; the test cases are used to verify the defense effectiveness of the defense program in the verification scenario;
[0012] A processing module, configured to process risk images in a verification scenario in at least one image processing stage based on test cases; and,
[0013] A defense module, configured to call a defense program to perform risk defense on the processed risk images in each image processing stage of at least one image processing stage, so as to obtain the processing results of the risk images in each image processing stage;
[0014] A generation module, configured to generate a verification result for the defense program based on the processing results of the risk images in each image processing stage; the verification result is used to indicate whether the defense program has the defense effectiveness against the risk images or does not have the defense effectiveness against the risk images in the verification scenario.
[0015] Optionally, the verification scenario includes at least one of the following:
[0016] An image pulling verification scenario for processing images in an image repository;
[0017] An image import verification scenario for processing images stored in a file storage device;
[0018] An image reconstruction verification scenario for processing images reconstructed based on existing base images.
[0019] Optionally, the image processing stages in the image pulling verification scenario include at least one of the following:
[0020] An image processing stage of pulling an image from an image repository and storing the pulled image on disk in a local image list;
[0021] An image processing stage of performing isolation detection on the image that has been successfully stored on disk in the local image list;
[0022] An image processing stage of creating a corresponding image container based on the image that has been successfully stored on disk in the local image list and has not been isolated.
[0023] Optionally, the image repository contains risk images; if the verification scenario includes an image pulling verification scenario, the manner in which the processing module processes the risk images in the verification scenario in at least one image processing stage based on test cases includes:
[0024] Pulling a risk image from the image repository based on test cases and storing the pulled risk image on disk in the local image list;
[0025] If the pulled risk image is successfully stored on disk in the local image list, performing isolation detection on the risk image that has been successfully stored on disk in the local image list;
[0026] If the risky image successfully landed in the local image list is not isolated, a corresponding image container is created based on the non-isolated risky image.
[0027] Optionally, the way the generation module generates the verification result for the defense program based on the processing results of the risky image in each image processing stage includes:
[0028] If the pulled risky image is successfully landed in the local image list, the risky image successfully landed in the local image list is not isolated, and the image container corresponding to the non-isolated risky image is successfully created, it is determined that the verification result includes that the defense program does not have the defense effectiveness against the risky image in the image pull verification scenario;
[0029] If the pulled risky image is not successfully landed in the local image list, the risky image successfully landed in the local image list is isolated, or the image container corresponding to the non-isolated risky image is not successfully created, it is determined that the verification result includes that the defense program has the defense effectiveness against the risky image in the image pull verification scenario.
[0030] Optionally, the image processing stages in the image import verification scenario include at least one of the following:
[0031] The image processing stage of exporting the image file from the file storage device and landing the exported image file in the local file list;
[0032] The image processing stage of performing isolation detection on the image file successfully landed in the local file list;
[0033] The image processing stage of importing the image file successfully landed in the local file list and not isolated into the local image list;
[0034] The image processing stage of creating a corresponding image container based on the image file successfully imported into the local image list.
[0035] Optionally, the file storage device stores risky images; if the verification scenario includes the image import verification scenario, the way the processing module processes the risky image in the verification scenario in at least one image processing stage based on the test case includes:
[0036] Export the risky image from the file storage device based on the test case and land the exported risky image in the local file list; where the exported risky image is the exported image file;
[0037] If the risky image is successfully landed in the local file list, perform isolation detection on the risky image successfully landed in the local file list;
[0038] If the risk image is not isolated, import the unisolated risk image into the local image list;
[0039] If the unisolated risk image is successfully imported into the local image list, create a corresponding image container based on the risk image successfully imported into the local image list.
[0040] Optionally, the way the generation module generates the verification result for the defense program based on the processing results of the risk image in each image processing stage includes:
[0041] If the exported risk image is successfully saved to the local file list, the risk image successfully saved to the local file list is not isolated, the unisolated risk image is successfully imported into the local image list, and the image container corresponding to the risk image successfully imported into the local image list is successfully created, it is determined that the verification result includes that the defense program does not have the defense effectiveness against the risk image in the image import verification scenario;
[0042] If the exported risk image is not successfully saved to the local file list, the risk image successfully saved to the local file list is isolated, the unisolated risk image is not successfully imported into the local image list, or the image container corresponding to the risk image successfully imported into the local image list is not successfully created, it is determined that the verification result includes that the defense program has the defense effectiveness against the risk image in the image import verification scenario.
[0043] Optionally, the image processing stages in the image reconstruction verification scenario include at least one of the following:
[0044] The image processing stage of reconstructing the existing base image to obtain the reconstructed image;
[0045] The image processing stage of performing isolation detection on the successfully reconstructed image;
[0046] The image processing stage of creating a corresponding image container based on the successfully reconstructed and unisolated image.
[0047] Optionally, the existing base image includes a base risk image, and the base risk image is used to reconstruct the risk image; if the verification scenario includes the image reconstruction verification scenario, the way the processing module processes the risk image in the verification scenario in at least one image processing stage based on the test case includes:
[0048] Perform reconstruction processing on the base risk image based on the test case;
[0049] If the risk image is successfully reconstructed based on the base risk image, perform isolation detection on the successfully reconstructed risk image;
[0050] If the risk image successfully reconstructed is not isolated, create a corresponding image container based on the non-isolated risk image.
[0051] Optionally, the generation module generates a verification result for the defense program based on the processing results of the risk image in each image processing stage, including:
[0052] If a risk image is successfully reconstructed based on the basic risk image, the successfully reconstructed risk image is not isolated, and the image container corresponding to the non-isolated risk image is successfully created, it is determined that the verification result is that the defense program does not have the defense effectiveness against the risk image in the image reconstruction verification scenario;
[0053] If a risk image is not successfully reconstructed based on the basic risk image, the successfully reconstructed risk image is isolated, or the image container corresponding to the non-isolated risk image is not successfully created, it is determined that the verification result is that the defense program has the defense effectiveness against the risk image in the image reconstruction verification scenario.
[0054] Optionally, the above processing module is further configured to:
[0055] Detect the availability of the execution environment of all image processing stages in the verification scenario based on the test case;
[0056] If the execution environments of all image processing stages in the verification scenario are available, execute the process of processing the risk image in at least one image processing stage in the verification scenario based on the test case.
[0057] Optionally, at least one image processing stage includes the image processing stage of creating a corresponding image container based on the risk image. If the image container corresponding to the risk image is successfully created, the successfully created image container contains an entry program, and the entry program contains the call path of the program in the risk image; the test case contains a security program;
[0058] The above program verification device is further configured to:
[0059] Replace the call path in the entry program of the successfully created image container with the call path of the security program;
[0060] Run the security program in the successfully created image container based on the call path of the security program replaced in the entry program.
[0061] Optionally, the above program verification device is further configured to:
[0062] If the verification result indicates that the defense program has the defense effectiveness against the risk image, report and process the verification result according to the first reporting method; and,
[0063] If the verification result indicates that the defense program does not have the defense effectiveness against the risk image, the verification result shall be reported and processed according to the second reporting method.
[0064] On the one hand, the present application provides a computer device, including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the method in one aspect of the present application.
[0065] On the one hand, the present application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is caused to execute the method in the above-mentioned one aspect.
[0066] According to one aspect of the present application, there is provided a computer program product including a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, causing the computer device to execute the method provided in the above-mentioned one aspect and various optional manners.
[0067] The present application can obtain test cases corresponding to a verification scenario; the test cases are used to verify the defense effectiveness of a defense program in the verification scenario; and based on the test cases, the risk image in the verification scenario can be processed in at least one image processing stage in the verification scenario; and further, in each image processing stage of the at least one image processing stage, the defense program can be called to perform risk defense on the processed risk image to obtain the processing result of the risk image in each image processing stage; thus, based on the processing results of the risk image in each image processing stage, a verification result for the defense program can be generated; the verification result can be used to indicate whether the defense program has the defense effectiveness against the risk image or does not have the defense effectiveness against the risk image in the verification scenario. It can be seen that the method proposed by the present application can realize the automated verification of the defense effectiveness of the defense program through the test cases configured for the verification scenario, thereby ensuring the high efficiency of verifying the defense effectiveness of the defense program; and during the verification process, the defense effectiveness of the defense program against the risk image in each image processing stage of the verification scenario can be verified through the processing results of the risk image in each image processing stage of the verification scenario, so the completeness of verifying the defense effectiveness of the defense program can also be ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0069] Figure 1 It is a schematic structural diagram of a network architecture provided by an embodiment of the present application;
[0070] Figure 2 It is a schematic diagram of a scenario for verifying a defense program provided by an embodiment of the present application;
[0071] Figure 3 It is a schematic flowchart of a program verification method provided by an embodiment of the present application;
[0072] Figure 4 It is a schematic structural diagram of a framework for verifying a defense program provided by an embodiment of the present application;
[0073] Figure 5 It is a schematic flowchart of a process for verifying a defense program provided by an embodiment of the present application;
[0074] Figure 6 It is another schematic flowchart of a process for verifying a defense program provided by an embodiment of the present application;
[0075] Figure 7 It is a schematic flowchart of a process for verifying a defense program in a mirror pulling verification scenario provided by an embodiment of the present application;
[0076] Figure 8 It is a schematic flowchart of a process for verifying a defense program in a mirror importing verification scenario provided by an embodiment of the present application;
[0077] Figure 9 It is a schematic flowchart of a process for verifying a defense program in a mirror reconstruction verification scenario provided by an embodiment of the present application;
[0078] Figure 10 It is a schematic structural diagram of a program verification device provided by an embodiment of the present application;
[0079] Figure 11 It is a schematic structural diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0080] Next, the technical solutions in this application will be clearly and completely described in conjunction with the accompanying drawings in this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0081] First of all, it should be noted that all the data collected in this application (such as relevant data of test cases, images, processing results of images, etc.) are collected with the consent and authorization of the object to which the data belongs (such as users, institutions or enterprises), and the collection, use and processing of relevant data need to comply with the relevant laws, regulations and standards in the relevant regions.
[0082] Here, relevant technical concepts involved in this application are described:
[0083] Invasion and attack simulation: A technology that reproduces attack behaviors in real attack scenarios after harmless treatment within / outside an enterprise to verify the effectiveness of the enterprise's security defense measures.
[0084] Docker: An open-source platform for developing, deploying, and running application programs. Based on containerization technology, it can package application programs and their dependent environments into a lightweight, portable, isolated, and secure image file, thereby achieving the rapid construction, efficient distribution, and cross-platform operation of application programs.
[0085] Docker image: A read-only template for defining and running Docker containers, which contains the file system and parameter configuration of the container. A Docker image consists of multiple layers, each layer corresponding to a change in the file system. The layers are stacked through a union file system to form a complete image. Optionally, a Docker image can be built according to a Dockerfile file (a file for building an image) through the docker build command (a command for building an image), or it can also be obtained in other ways.
[0086] Docker image file: A file format for storing and distributing Docker images, which contains all the layers and metadata of the image. It can be exported and imported through the docker save (a command for exporting an image file) and docker load (a command for importing an image file) commands. The file size of a Docker image file depends on the number of layers and content of the image.
[0087] Docker Container: A lightweight virtualization technology for running applications. It is created based on Docker images and can perform various operations in an isolated environment, such as starting, stopping, deleting, etc. A Docker container consists of a read-only image layer and a writable container layer. The container layer stores the runtime state and data of the container, and changes in the container layer do not affect the image layer. Docker containers can be created according to images using the docker run command (an instruction for creating containers), or new images can be created according to containers using the docker commit command (an instruction for creating images).
[0088] Docker Image Repository: A place for centrally storing Docker image files. It can be public or private, local or remote, single or distributed. The role of a Docker image repository is to facilitate users in storing, sharing, downloading, and managing Docker image files.
[0089] Risky Docker Image (which can be abbreviated as risky image): A Docker image that contains risky instructions, files, or parameters, may contain malicious code or backdoors, or has the ability to exceed permissions, cause damage, etc. It includes container images stored and spread in DockerHub (an image repository) or other public container repositories that contain malware or vulnerabilities, or images built based on risky images as base images. Risky Docker images may be used by malicious actors to perform various malicious acts, such as embedding backdoors, stealing information, intercepting network traffic, and other malicious acts.
[0090] File Server: A computer or device for storing and sharing files. It can provide file access services to multiple clients through a network and support different file systems and protocols, such as NFS (a network file system), SMB (a network protocol name), FTP (a file transfer protocol), etc. The role of a file server is to achieve centralized management and backup of files, improve the availability and security of files, and save storage space and network bandwidth.
[0091] Please refer to Figure 1 , Figure 1 It is a schematic diagram of the structure of a network architecture provided by an embodiment of this application. As Figure 1As shown in the figure, the network architecture may include a scheduling server 100a, a host server 101a, and a terminal device 102a. Among them, a network connection can be established between the scheduling server 100a and the host server 101a to facilitate data interaction between the scheduling server 100a and the host server 101a; similarly, a network connection can be established between the host server 101a and the terminal device 102a to facilitate data interaction between the host server 101a and the terminal device 102a.
[0092] As Figure 1 shown, the servers (including the scheduling server 100a and the host server 101a) can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal device can be: intelligent terminals such as smart phones, tablet computers, notebook computers, desktop computers, smart TVs, vehicle-mounted terminals, and smart home appliances.
[0093] Among them, the host server 101a can provide a proxy service, and this proxy service can be used to execute test cases (also called verification cases) for verifying the defense program, that is, the verification of the defense program can be performed by the host server based on this proxy service. The defense program is a program for risk defense of the processed image. The scheduling server 100a can include a scheduling controller, and this scheduling controller can be used to control the proxy service to perform corresponding verification tasks on the defense program. And the terminal device 102a can be the terminal device of relevant technical personnel and can be used to receive the verification result of the defense program by the host server. The above host server 101a can be a server specifically used to process images, and the processed images need to be stored on the local of the host server. Therefore, this application can implement the verification of the defense program at the host level.
[0094] Please also refer to Figure 2 , Figure 2 which is a schematic diagram of a scenario for verifying a defense program provided by an embodiment of this application. As Figure 2 shown, the scheduling server 100a can initiate a verification task for verifying the defense program in a specific verification scenario through the scheduling controller, so as to send the test case associated (corresponding) with this verification scenario to the host server 101a, and this test case can be a case for verifying the defense program. One or more image processing stages can be included in this verification scenario. As the name implies, this image processing stage is the stage for processing the image.
[0095] Therefore, the host server 101a can execute the test case through the proxy service to process the risk image in at least one image processing stage of the verification scenario, and can call the defense program to perform risk defense on the processed risk image in each image processing stage of processing the risk image. Thus, under the risk defense of the defense program on the risk image, the processing stage of the risk image in each processed image processing stage can be obtained.
[0096] Furthermore, the host server 101a can generate a verification result for the defense program based on the processing results of the risk image in each processed image processing stage. This verification result can be a result indicating that the risk defense of the defense program on the risk image is effective, or this verification result can be a result indicating that the risk defense of the defense program on the risk image is ineffective. The host server 101a can report (such as send) the generated verification result to the terminal device 102a, so that the terminal device 102a can output the verification result for relevant technical personnel to view.
[0097] By using the method provided in this application, the effectiveness of the risk defense of the defense program on the processed image in each image processing stage of the verification scenario can be automatically and comprehensively verified through the test case, thereby improving the efficiency and accuracy of verifying the defense program.
[0098] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of a program verification method provided by an embodiment of this application. The execution subject in the embodiment of this application can be an image processing device. This image processing device can be a computer device or a computer device cluster composed of multiple computer devices. This computer device can be a server or other devices, and no limitation is made thereto. As Figure 3 shown, the method can include:
[0099] Step S101, obtain a test case corresponding to the verification scenario; the test case is used to verify the defense effectiveness of the defense program in the verification scenario.
[0100] Optionally, the image processing device can obtain a test case corresponding to the verification scenario. This verification scenario can be a scenario for verifying the defense program, and one or more image processing stages can be included in this verification scenario. As the name implies, this image processing stage is a stage for processing the image. Among them, each image processing stage in the verification scenario can be set accordingly according to the content actually required to verify the defense program.
[0101] Therefore, it can be understood that the defense program can be used to defend against risks of the processed images in each image processing stage in the verification scenario, and the test case can be used to verify the defense effectiveness of the defense program in each image processing stage in the verification scenario. Among them, a series of business logics for processing images in the verification scenario can be configured in the test case. For example, how to obtain images, how to process the obtained images in the corresponding verification scenario, and how to obtain the verification result of the defense effectiveness of the defense program based on the processing result of the images and other related business logics can be configured in the test case.
[0102] Among them, verifying the defense effectiveness of the defense program is to verify whether the defense program can effectively defend against the risky images being processed, such as aborting the processing of the risky images or isolating the risky images.
[0103] Exemplarily, the above verification scenario may include at least one of the following:
[0104] The first type: the scenario of processing images in the image repository. Since in this verification scenario, the images pulled from the image repository are processed, this verification scenario can be called the image pull verification scenario. In other words, the image pull verification scenario is the scenario that needs to pull and process images from the image repository.
[0105] The second type: the scenario of processing images stored in the file storage device. Since this verification scenario needs to import the images exported from the file storage device as local files into the local image list, this verification scenario can be called the image import verification scenario. In other words, the image import verification scenario is the scenario that needs to export and process images from the file storage device. Optionally, the file storage device can be a file server, and the image files to be stored can be uploaded to the file storage device for storage.
[0106] The third type: the scenario of processing images reconstructed from existing base images. Since the images need to be reconstructed in this verification scenario, this verification scenario can be called the image reconstruction verification scenario. In other words, the image reconstruction verification scenario is the scenario that needs to reconstruct the existing base images and process the newly reconstructed images.
[0107] It can be understood that the above different verification scenarios are mainly due to the different sources of the processed images. It should be understood that this application is not limited to the above 3 verification scenarios. In actual application scenarios, other more verification scenarios can also be introduced, and the method provided by this application can also be used.
[0108] Among them, the above defense program can be configured with relevant detection logics for risk detection of the processed images in each image processing stage under various verification scenarios, that is, it is configured with relevant program codes (detection logics for indicating risk detection of images) for detecting whether the processed images have risks in each image processing stage. What specific detection logics the defense program is configured with can be determined according to the actual application scenario, and there is no limitation on this.
[0109] Optionally, the image processing stages in the above image pulling verification scenario may include at least one of the following:
[0110] ① The image processing stage of pulling an image from the image repository and storing the pulled image on disk in the local image list. As the name implies, this local image list can be a list used locally to store images. In this image processing stage, the defense program can detect whether the pulled image has risks (that is, detect whether the pulled image is malicious), so as to determine whether the pulled image can be successfully stored on disk in the local image list. It can be understood that if the defense program detects that the pulled image has risks (such as the pulled image is a malicious image), then the pulled image will not be successfully stored on disk in the local image list; on the contrary, if the defense program detects that the pulled image has no risks (such as the pulled image is a safe image), then the pulled image can be successfully stored on disk in the local image list.
[0111] ② The image processing stage of isolating and detecting the image that has been successfully stored on this local image list. In this image processing stage, it is a processing stage where the defense program can detect whether the image that has been successfully stored on this local image list needs to be isolated. It can be understood that if the defense program detects that the image stored on this local image list has risks, then the image will be isolated; on the contrary, if the defense program detects that the image stored on this local image list has no risks, then the image will not be isolated.
[0112] ③ The image processing stage of creating a corresponding image container (such as a Docker container) through the image that has been successfully stored on the local image list and has not been isolated. In this image processing stage, the defense program can detect whether the image used to create the image container has risks. If it is detected that the image used to create the image container has risks (that is, the image is a risky image), then the operation of creating an image container through this image can be aborted, and the creation of the image container fails (that is, it is not successfully created); on the contrary, if it is detected that the image used to create the image container has no risks (that is, the image is not a risky image), then the corresponding image container can be successfully created through this image, that is, the image container corresponding to this image is successfully created.
[0113] Optionally, the image processing stage in the above image import verification scenario may include at least one of the following:
[0114] ① An image processing stage of exporting an image file from a file storage device (i.e., exporting the image) and storing the exported image file on the local file list. Optionally, the file storage device may be the above file server. In this image processing stage, the defense program may perform risk display on the image file exported from the file storage device. If it is detected that the exported image file has a risk (i.e., the exported image file is a risky image file), the operation of storing the exported image file on the local file list may be aborted, that is, the exported image file will not be stored on the local file list; conversely, if it is detected that the exported image file has no risk (i.e., the exported image file is a non-risky image), the exported image file may be stored on the local file list, that is, the exported image file can be successfully stored on the local file list.
[0115] ② An image processing stage of performing isolation detection on the image file stored on the local file list. In this image processing stage, risk detection may be performed on the image file that has been successfully stored on the local file list (i.e., the above image file exported from the file storage device). If it is detected that the image file has a risk, the image file may be isolated on the local file list, that is, the image file is isolated; conversely, if it is detected that the image file has no risk, the image file may not be isolated, that is, the image file is not isolated.
[0116] Among them, the image file exported from the file storage device is first stored in the above local file list, and then, the image file needs to be imported from the local file list to the local image list. The local image list is a list used locally to store available images. Therefore, there is the following third image processing stage, as described below.
[0117] ③ An image processing stage of importing the image file that has been successfully stored on the local file list and has not been isolated (which is also the same as the above exported image file) into the local image list. In this image processing stage, the above defense program may be used to perform risk detection on the image file to be imported into the local image list (i.e., the image file that has been successfully stored on the local file list and has not been isolated). If it is detected that the image file has a risk, the image file will not be imported into the local image list, that is, the import of the image file into the local image list will fail, which means that the image file has not been successfully imported into the local image list; conversely, if it is detected that the image file has no risk, the image file will be imported into the local image list, that is, the image file will be successfully imported into the local image list.
[0118] ④The mirror processing stage of creating a corresponding mirror container through the mirror file successfully imported into the local mirror list (which is also the same mirror file exported above). Similarly, in this mirror processing stage, the above defense program can also be used to detect risks for the mirror file used to create the mirror container (i.e., the mirror file successfully imported into the local mirror list). If it is detected that the mirror file has risks, the operation of creating a corresponding mirror container using this mirror file can be aborted, that is, the creation of the mirror container corresponding to this mirror file fails, which means that the mirror container corresponding to this mirror file is not successfully created; conversely, if it is detected that the mirror file has no risks, the corresponding mirror container can be successfully created through this mirror file, that is, the mirror container corresponding to this mirror file is successfully created.
[0119] Optionally, the mirror processing stage in the above mirror reconstruction verification scenario may include at least one of the following:
[0120] ①The mirror processing stage of reconstructing the existing base mirror to obtain a reconstructed mirror. In this mirror processing stage, the defense program can be used to detect risks for the mirror to be reconstructed (i.e., the existing base mirror). If it is detected that the existing base mirror has risks (i.e., the existing base mirror is a risky mirror), the operation of reconstructing a new mirror through the existing base mirror can be aborted. In this case, a new mirror is not successfully reconstructed through the existing base mirror, that is, the mirror reconstruction fails; conversely, if it is detected that the existing base mirror has no risks (i.e., the existing base mirror is not risky), a new mirror can be successfully reconstructed through the existing base mirror, that is, the mirror reconstruction is successful.
[0121] ②The mirror processing stage of performing isolation detection on the successfully reconstructed mirror (such as the new mirror reconstructed above). In this mirror processing stage, the defense program can be used to detect risks for the successfully reconstructed mirror. If it is detected that the successfully reconstructed mirror has risks, the successfully reconstructed mirror can be isolated, that is, the successfully reconstructed mirror is isolated; conversely, if it is detected that the successfully reconstructed mirror has no risks, the successfully reconstructed mirror does not need to be isolated, that is, the successfully reconstructed mirror is not isolated.
[0122] ③The mirror processing stage of creating a corresponding mirror container for the mirror that has been successfully reconstructed and not isolated. In this mirror processing stage, a defense program can be used to detect risks for the mirror used to create the mirror container (i.e., the mirror that has been successfully reconstructed and not isolated). If a risk is detected in the mirror, the operation of creating a corresponding mirror container using this mirror can be aborted, that is, the creation of the mirror container corresponding to this mirror fails, which means the mirror container corresponding to this mirror is not successfully created; conversely, if no risk is detected in the mirror, then the corresponding mirror container can be successfully created through this mirror, that is, the mirror container corresponding to this mirror is successfully created.
[0123] From the above description, it can be understood that the main difference among the above three verification scenarios (including the mirror pulling verification scenario, the mirror import verification scenario, and the mirror reconstruction verification scenario) can be the different sources of the mirrors being processed. For example, in the mirror pulling verification scenario, the mirror being processed can be pulled from a mirror repository; in the mirror import verification scenario, the mirror being processed can be exported from a file storage device; in the mirror reconstruction verification scenario, the mirror being processed can be obtained by reconstructing an existing base mirror. It can be seen that this application can comprehensively and automatically verify the defense effectiveness of the defense program through mirrors from multiple sources in multiple verification scenarios. Thus, it can also improve the detection accuracy and detection efficiency of the defense effectiveness of the defense program.
[0124] Furthermore, it should be noted that the above three verification scenarios are exemplary descriptions. In actual application scenarios, more verification scenarios can be introduced to conduct more verifications on the defense effectiveness of the defense program. The verification scenarios for verifying the defense program in this application can simultaneously include the above three verification scenarios. The verification processes of the defense program in each verification scenario can be independent of each other. The verification of the defense program in each verification scenario can be carried out synchronously and in parallel, or sequentially in any set order.
[0125] Step S102: Based on the test cases, process the risk mirrors in at least one mirror processing stage in the verification scenario.
[0126] Step S103: In each mirror processing stage of the at least one mirror processing stage, call the defense program to perform risk defense on the processed risk mirrors to obtain the processing results of the risk mirrors in each mirror processing stage.
[0127] Step S104: Based on the processing results of the risk mirrors in each mirror processing stage, generate a verification result for the defense program; the verification result is used to indicate whether the defense program has the defense effectiveness against the risk mirrors or does not have the defense effectiveness against the risk mirrors in the verification scenario.
[0128] Among them, for the convenience of description, the present application synchronously describes the specific implementation processes of the above steps S102-S104 as described below.
[0129] Optionally, the mirror processing device can process the risk mirror in the verification scenario through the above test cases at at least one mirror processing stage in the verification scenario, that is, the mirror processed by the present application in the verification scenario can be the risk mirror in the verification scenario, and the risk mirror is a mirror with risks, and the risk mirror can be any mirror with risks designed by the developer himself. In other words, the present application specifically verifies the defense effectiveness of the defense program in the corresponding verification scenario by using the risk mirror in the verification scenario.
[0130] Since the test case is configured with the specific business logic for processing the mirror in the verification scenario, the mirror processing device can process the risk mirror in the verification scenario through the above test cases at at least one mirror processing stage in the verification scenario, as described below.
[0131] The above mirror repository may include the above risk mirror. If the above verification scenario includes the above mirror pulling verification scenario, based on each mirror processing stage of the above-described mirror pulling verification scenario, the process of processing the risk mirror in the verification scenario through the test case at at least one mirror processing stage and the process of obtaining the verification result may include:
[0132] The mirror processing device can pull the risk mirror from the mirror repository through the test case, and can disk the pulled risk mirror to the local mirror list (the risk mirror pulled from the mirror repository can be directly disked to the local mirror list). If the pulled risk mirror fails to be successfully disked to the local mirror list (that is, the processing result of the risk mirror in this mirror processing stage is the result of failing to be successfully disked to the local mirror list), it indicates that the pulled risk mirror is detected as a risky mirror by the defense program, which also means that the defense of the defense program is effective. At this time, the subsequent mirror processing stages in the mirror pulling verification scenario will no longer be performed on the pulled risk mirror. In this case, the verification result obtained for the defense program may include that the defense program has the defense effectiveness against the risk mirror in the mirror pulling verification scenario, that is, the defense program has defense effectiveness in the mirror pulling verification scenario.
[0133] If the pulled risky image is successfully stored in the local image list (i.e., the processing result of the risky image in this image processing stage is the result of successful storage in the local image list), then the isolated detection of the risky image successfully stored in the local image list can continue in the next image processing stage of the image pulling verification scenario. If the risky image successfully stored in the local image list is isolated (i.e., the processing result of the risky image in this image processing stage is the result of being isolated), it indicates that the risky image successfully stored in the local image list detected by the defense program is a risky image, which also means that the defense of the defense program is effective. Similarly, in this case, the subsequent image processing stages in the image pulling verification scenario will no longer be performed on the risky image successfully stored in the local image list. In this situation, the verification result obtained for the defense program can also include that the defense program has the defense effectiveness against the risky image in the image pulling verification scenario, that is, the defense program has defense effectiveness in the image pulling verification scenario.
[0134] However, if the risky image successfully stored in the local image list is not isolated (i.e., the processing result of the risky image in this image processing stage is the result of not being isolated), then the corresponding image container can be created with the non-isolated risky image in the next image processing stage of the image pulling verification scenario. If the image container corresponding to the risky image is not successfully created (i.e., the processing result of the risky image in this image processing stage is the result of the corresponding image container not being successfully created), it indicates that the risky image used to create the image container detected by the defense program is risky, which also means that the defense of the defense program is effective. Similarly, in this case, the verification result obtained for the defense program can include that the defense program has the defense effectiveness against the risky image in the image pulling verification scenario, that is, the defense program has defense effectiveness in the image pulling verification scenario.
[0135] On the contrary, if the image container corresponding to the risky image is successfully created (i.e., the processing result of the risky image in this image processing stage is the result of the corresponding image container being successfully created), it indicates that the defense of the defense program fails in all image processing stages of the image pulling verification scenario. At this time, it can be determined that the verification result for the defense program can include that the defense program does not have the defense effectiveness against the risky image in the image pulling verification scenario, that is, the defense program does not have defense effectiveness in the image pulling verification scenario.
[0136] Moreover, the above file storage device may include the above risk images. If the above verification scenario includes the above image import verification scenario, then based on each image processing stage of the above-described image import verification scenario, the process of processing the risk images in the verification scenario through test cases in at least one image processing stage of the verification scenario and the process of obtaining the verification results may include:
[0137] The image processing device can export the risk image from the file storage device through the test case, and can save the exported risk image to the local file list (the image exported from the file storage device usually cannot be directly saved to the local image list). If the exported risk image is not successfully saved to the local file list (that is, the processing result of the risk image in this image processing stage is the result of not being successfully saved to the local file list), it indicates that the exported risk image is detected as a risky image through the defense program, which also means that the defense of the defense program is effective. At this time, the subsequent image processing stages in the image import verification scenario will no longer be performed on the exported risk image. In this case, the verification result obtained for the defense program may include that the defense program has the defense effectiveness for the risk image in the image import verification scenario, that is, the defense program has the defense effectiveness in the image pull verification scenario. Among them, the risk image exported from the file storage device can be the image file exported from the file storage device.
[0138] If the exported risk image is successfully saved to the local file list (that is, the processing result of the risk image in this image processing stage is the result of being successfully saved to the local file list), then the risk image successfully saved to the local file list can be further subjected to isolation detection in the next image processing stage of the image import verification scenario. If the risk image successfully saved to the local file list is isolated (that is, the processing result of the risk image in this image processing stage is the result of being isolated), it indicates that the risk image successfully saved to the local image list is detected as a risky image through the defense program, which also means that the defense of the defense program is effective. Similarly, at this time, the subsequent image processing stages in the image import verification scenario will no longer be performed on the risk image successfully saved to the local file list. In this case, the verification result obtained for the defense program may also include that the defense program has the defense effectiveness for the risk image in the image import verification scenario, that is, the defense program has the defense effectiveness in the image import verification scenario.
[0139] If the risk image that has successfully landed in the local file list is not isolated (i.e., the processing result of the risk image in this image processing stage is the result of not being isolated), then it can continue to import the non-isolated risk image into the local image list in the next image processing stage of the image import verification scenario. If the non-isolated risk image is not successfully imported into the local image list (i.e., the processing result of the risk image in this image processing stage is the result of not being successfully imported into the local image list), it indicates that the risk image detected by the defense program that has not been isolated is a risky image, which also means that the defense of the defense program is effective. Similarly, at this time, the subsequent image processing stages in the image import verification scenario will no longer be performed on the risk image that has not been successfully imported into the local image list. In this case, the verification result obtained for the defense program can also include that the defense program has the defense effectiveness against the risk image in the image import verification scenario, that is, the defense program has defense effectiveness in the image import verification scenario.
[0140] However, if the non-isolated risk image is successfully imported into the local image list (i.e., the processing result of the risk image in this image processing stage is the result of being successfully imported into the local image list), then it can continue to create a corresponding image container from the risk image that has been successfully imported into the local image list in the next image processing stage of the image import verification scenario. If the corresponding image container cannot be successfully created from the risk image that has been successfully imported into the local image list (i.e., the processing result of the risk image in this image processing stage is the result of the corresponding image container not being successfully created), that is, the creation of the image container corresponding to the risk image that has been successfully imported into the local image list fails, it indicates that the risk image used to create the image container detected by the defense program is a risky image, which also means that the defense of the defense program is effective. In this case, the verification result obtained for the defense program can also include that the defense program has the defense effectiveness against the risk image in the image import verification scenario, that is, the defense program has defense effectiveness in the image import verification scenario.
[0141] If the corresponding image container can be successfully created from the risk image that has been successfully imported into the local image list (i.e., the processing result of the risk image in this image processing stage is the result of the corresponding image container being successfully created), that is, the creation of the image container corresponding to the risk image that has been successfully imported into the local image list is successful, it indicates that the defense program has not detected that the risk image used to create the image container is a risky image, which also means that the defense of the defense program has failed, that is, the defense program does not have the defense effectiveness against the risk image in each image processing stage of the image import verification scenario. In this case, the verification result obtained for the defense program can include that the defense program does not have the defense effectiveness against the risk image in the image import verification scenario, that is, the defense program does not have defense effectiveness in the image import verification scenario.
[0142] Furthermore, the existing base images mentioned above may include base risk images. The base risk images are base images with risks, and these base risk images can be used to reconstruct the above-mentioned risk images. If the above verification scenario includes the above-mentioned image reconstruction verification scenario, then based on each image processing stage of the image reconstruction verification scenario described above, the process of processing the risk images in the verification scenario through test cases in at least one image processing stage of the verification scenario and the process of obtaining the verification results may include:
[0143] The image processing device can perform reconstruction processing on the base risk image through this test case. If the risk image fails to be successfully created through this base risk image (that is, the processing result of the risk image in this image processing stage is the result of not being successfully reconstructed), it indicates that the base risk image used for reconstruction processing is detected by the defense program as a base image with risks, which also means that the defense of the defense program is effective. At this time, the subsequent image processing stages in the image reconstruction verification scenario will no longer be carried out through the base risk image. In this case, the verification result obtained for the defense program may include that the defense program has the defense effectiveness against the risk image in the image reconstruction verification scenario, that is, the defense program has defense effectiveness in the image reconstruction verification scenario.
[0144] If the image processing device successfully creates a risk image through this base risk image (that is, the processing result of the risk image in this image processing stage is the result of being successfully reconstructed), the image processing device can continue to perform isolation detection on the successfully reconstructed risk image in the next image processing stage in the image reconstruction verification scenario. If the successfully reconstructed risk image is isolated (that is, the processing result of the risk image in this image processing stage is the result of being isolated), it indicates that the successfully reconstructed risk image is detected by the defense program as a base image with risks, which also means that the defense of the defense program is effective. At this time, the subsequent image processing stages in the image reconstruction verification scenario will no longer be carried out through the successfully reconstructed risk image. In this case, the verification result obtained for the defense program may include that the defense program has the defense effectiveness against the risk image in the image reconstruction verification scenario, that is, the defense program has defense effectiveness in the image reconstruction verification scenario.
[0145] However, if the successfully reconstructed risk image is not isolated (i.e., the processing result of the risk image in this image processing stage is not isolated), then the corresponding image container can be created in the next image processing stage in the image reconstruction verification scenario using this non-isolated risk image. If the corresponding image container cannot be successfully created using this non-isolated risk image (i.e., the processing result of the risk image in this image processing stage is that the corresponding image container is not successfully created), that is, the creation of the image container corresponding to this non-isolated risk image fails, it indicates that the defense program has detected that the risk image used to create the image container is risky, which also means that the defense of the defense program is effective. In this case, the verification result obtained for the defense program can include that the defense program has the defense effectiveness for the risk image in the image reconstruction verification scenario, that is, the defense program has defense effectiveness in the image reconstruction verification scenario.
[0146] On the other hand, if the corresponding image container is successfully created using this non-isolated risk image (i.e., the processing result of the risk image in this image processing stage is that the corresponding image container is successfully created), that is, the creation of the image container corresponding to this non-isolated risk image is successful, it indicates that the defense program has not detected that the risk image used to create the image container is a risky image, which also means that the defense of the defense program is ineffective, that is, the defense program does not have the defense effectiveness for the risk image in each image processing stage in the image reconstruction verification scenario. In this case, the verification result obtained for the defense program can include that the defense program does not have the defense effectiveness for the risk image in the image reconstruction verification scenario, that is, the defense program does not have defense effectiveness in the image reconstruction verification scenario.
[0147] In more feasible implementation manners, before processing the risk image in at least one image processing stage in the verification scenario through test cases, the present application can also detect the availability of the execution environment of all image processing stages in this verification scenario, that is, detect whether the execution environments of each image processing stage in this verification scenario can all normally perform business processing (if there are multiple verification scenarios, the availability of all image processing stages in each verification scenario needs to be detected).
[0148] Therefore, if it is detected that the execution environments of all image processing stages in this verification scenario are all available, then the above process of processing the risk image in at least one image processing stage in this verification scenario through test cases can be executed. In other words, before verifying the defense effectiveness of the defense program through the risk image, it is necessary to ensure that the execution environments of each image processing stage in the verification scenario to be verified are all available (that is, all have availability).
[0149] In another feasible implementation, the present application can also perform harmless treatment on the risk mirror used to verify the defense effectiveness of the defense program, that is, the risk mirror used to verify the defense program will not harm the program or system of the present application (such as not attacking the program or system of the present application, nor implanting harmful programs into the program or system of the present application).
[0150] At least one mirror processing stage for processing the risk mirror in the above verification scenario may include a mirror processing stage of creating a corresponding mirror container through the risk mirror. If the mirror container corresponding to the risk mirror is successfully created, the successfully created mirror container may include an entry program, and the entry program may include the call path of the program in the risk mirror. The entry program is used to default to run the program in the risk mirror based on the call path when the mirror container is enabled.
[0151] Since the program in the risk mirror is risky (i.e., harmful), in order to prevent the mirror container from defaulting to run the program in the risk mirror when enabled, a security program may also be configured in the test case of the present application, and the security program may be any non-risky program configured by the developer. The present application can, through the test case, replace the call path in the above entry program of the successfully created mirror container with the call path of the security program. Furthermore, the mirror processing device can run the security program in the successfully created mirror container through the call path of the security program replaced in the entry program, rather than running the program in the risk mirror, so as to ensure that in the case of verifying the defense effectiveness of the defense program through the risk mirror, the risk mirror will not harm the system or main program of the present application (such as the relevant system or program for processing the mirror in the verification scenario). Among them, the created mirror container after the call path replacement can also be called a harmless container.
[0152] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of a framework for verifying a defense program provided by an embodiment of the present application. As Figure 4As shown in the figure, the framework may include a scheduling controller, an agent service, a host to be tested, a test case set, a Docker image file server, and a Docker image repository. The host to be tested may be the above-mentioned image processing device for processing images. The agent service may be deployed on the host to be tested. The scheduling controller may be on other background devices except the host to be tested. The test case set may include pre-configured test cases for verifying the defense effectiveness of the defense program in various verification scenarios. Each test case in the test case set corresponds (or can be understood as associated) to its own verification scenario. The number of test cases in the test case set may be determined according to the actual application scenario. Optionally, the test case set may exist in any suitable background device. The Docker image file server may be the above-mentioned image storage device (such as the above file server), and the Docker image repository is the above-mentioned image repository.
[0153] The scheduling controller can be used to control in which verification scenario the defense program needs to be verified and generate corresponding verification tasks. The verification tasks can be used to indicate the verification scenarios that need to be verified and can issue the verification tasks to the agent service in the host to be tested. Thus, the agent service can obtain the test cases corresponding to the verification scenarios indicated by the verification tasks from the test case set and verify the defense program according to the above principles through the obtained test cases.
[0154] If the verification scenario that needs to be verified includes the above-mentioned image import verification scenario, the host to be tested can download (i.e., export) the corresponding image file (such as the above risk image) from the Docker image file server for processing. If the verification scenario that needs to be verified includes the above-mentioned image pull verification scenario or / and image import verification scenario, the host to be tested can pull the corresponding image (such as the above risk image or / and basic risk image) from the Docker image repository.
[0155] Please refer to Figure 5 , Figure 5 which is a schematic flowchart of a process for verifying a defense program provided by an embodiment of the present application. As Figure 5As shown, the verification scenarios that need to be verified in this application may include the above-mentioned mirror pulling verification scenario, mirror import verification scenario, and mirror reconstruction verification scenario. The mirror processing device can sequentially verify the defense program in these 3 verification scenarios. For example, the mirror processing device can first verify directly pulling a risky mirror (i.e., directly pulling a risky mirror from the mirror repository, belonging to the above-mentioned mirror pulling verification scenario). Then, the mirror processing device can verify importing a risky mirror locally (i.e., importing the mirror file in the local file list (which can be exported from a file storage device) into the local mirror list, belonging to the above-mentioned mirror import verification scenario). Furthermore, the mirror processing device can also verify building other mirrors based on a basic risky mirror (such as building the above-mentioned risky mirror through the basic risky mirror, belonging to the above-mentioned mirror reconstruction verification scenario). In this way, the verification of the defense program can be achieved in the above 3 verification scenarios.
[0156] Optionally, this application can also report and process the verification results obtained for the defense program. For example, if the verification result is used to indicate that the defense program has the defense effectiveness against risky mirrors in the corresponding verification scenario, the verification result can be reported and processed according to the first reporting method. If the verification result is used to indicate that the defense program does not have the defense effectiveness against risky mirrors in the corresponding verification scenario, the verification result can be reported and processed according to the second reporting method. Among them, reporting and processing the verification result can be reporting the verification result to the corresponding technical personnel (such as developers). For example, the verification result can be sent to the terminal device of this technical personnel. The first reporting method and the second reporting method can be different reporting methods, that is, this application can report the verification result according to different reporting methods based on different verification results, so as to more alert the corresponding technical personnel.
[0157] Among them, the first reporting method and the second reporting method can be set by themselves according to the actual application scenario. For example, the first reporting method can be a reporting method based on prompt information, and the second reporting method can be a reporting method based on a voice call (such as an automatic call from a call robot), and so on.
[0158] This application can obtain test cases corresponding to a verification scenario; the test cases are used to verify the defense effectiveness of a defense program in the verification scenario; and based on the test cases, the risk images in the verification scenario can be processed in at least one image processing stage in the verification scenario; moreover, in each image processing stage among the at least one image processing stage, the defense program can be called to perform risk defense on the processed risk images to obtain the processing results of the risk images in each image processing stage; thus, based on the processing results of the risk images in each image processing stage, a verification result for the defense program can be generated; this verification result can be used to indicate whether the defense program has the defense effectiveness against the risk images or does not have the defense effectiveness against the risk images in the verification scenario. It can be seen that the method proposed in this application can achieve the automated verification of the defense effectiveness of the defense program through the test cases configured for the verification scenario, thereby ensuring the high efficiency of verifying the defense effectiveness of the defense program; and during the verification process, through the processing results of the risk images in each image processing stage in the verification scenario, the defense effectiveness of the defense program against the risk images in each image processing stage of this verification scenario can be verified, so the completeness of verifying the defense effectiveness of the defense program can also be ensured.
[0159] Please refer to Figure 6 , Figure 6 which is another schematic flowchart for verifying a defense program provided by an embodiment of this application. As Figure 6 shown, this process may include:
[0160] 1. The scheduling controller can start the first verification scenario for verifying the above defense program. The first verification scenario can be the above mirror pulling verification scenario, and the mirror pulling verification scenario is a scenario for verifying the risk images pulled from the mirror repository. The scheduling controller can send a verification task for verifying the defense program in this mirror pulling verification scenario to the proxy service.
[0161] 2. After receiving the verification task sent by the scheduling controller to verify the defense program in the mirror pulling verification scenario, the proxy service can obtain the test cases for verifying the defense program in the mirror pulling verification scenario from the test case set based on this verification task, that is, the test cases corresponding to the mirror pulling verification scenario. Among them, the test case set can contain several test cases corresponding to the mirror pulling verification scenario. Different test cases corresponding to the mirror pulling verification scenario can be used to verify the defense program diversely and comprehensively in different dimensions of the mirror pulling verification scenario (such as different types of risk images). During the process of verifying the defense program in the mirror pulling verification scenario, the proxy service can successively adopt each test case corresponding to the mirror pulling verification scenario in the test case set to verify the defense program in the mirror pulling verification scenario.
[0162] 3. The test case set can return (which can be returned by the background device where the test case set is located) the test cases corresponding to the mirror pulling verification scenario it has obtained. Optionally, after the proxy service executes a test case corresponding to the mirror pulling verification scenario (that is, after verifying the defense program using a test case corresponding to the mirror pulling verification scenario), the proxy service can obtain the next test case corresponding to the mirror pulling verification scenario from the test case set and continue to verify the defense program in the mirror pulling verification scenario through this next test case until the verification of the defense program is completed using all the test cases corresponding to the mirror pulling verification scenario in the test case set.
[0163] 4. After receiving the test cases corresponding to the mirror pulling verification scenario returned by the test case set, the proxy service can execute the received test cases corresponding to the mirror pulling verification scenario. The process of executing this test case is the process of verifying the defense program in the mirror pulling verification scenario using this test case. After executing this test case, the proxy service can generate the verification result of the defense program under this test case corresponding to the mirror pulling verification scenario.
[0164] 5. The proxy service can return the verification result of the defense program generated under this test case corresponding to the mirror pulling verification scenario to the scheduling controller, that is, the verification result generated for the defense program can be returned to the scheduling controller for processing.
[0165] 6. Then, the scheduling controller can also start the second verification scenario for verifying the defense program. This second verification scenario can be the above-mentioned mirror import verification scenario, which is the scenario of verifying that the host loads the risk image. The scheduling controller can send a verification task to the proxy service to verify the defense program in this mirror import verification scenario.
[0166] 7. After receiving the verification task sent by the scheduling controller to verify the defense program in the mirror import verification scenario, the proxy service can obtain the test cases for verifying the defense program in the mirror pull verification scenario from the test case set based on this verification task, that is, the test cases corresponding to the mirror import verification scenario. Similarly, the test case set can contain several test cases corresponding to the mirror import verification scenario, and different test cases corresponding to the mirror import verification scenario can be used to verify the defense program in different dimensions (such as different types of risk mirrors) of the mirror import verification scenario in a diverse and comprehensive manner. During the process of verifying the defense program in the mirror import verification scenario, the proxy service can successively adopt each test case corresponding to the mirror import verification scenario in the test case set to verify the defense program in the mirror import verification scenario.
[0167] 8. The test case set can return (which can be returned by the background device where the test case set is located) the test cases corresponding to the mirror import verification scenario it has obtained. Optionally, after the proxy service executes a test case corresponding to the mirror import verification scenario (that is, after verifying the defense program using a test case corresponding to the mirror import verification scenario), the proxy service can obtain the next test case corresponding to the mirror import verification scenario from the test case set and continue to verify the defense program in the mirror import verification scenario through this next test case until the verification of the defense program is completed using all the test cases corresponding to the mirror import verification scenario in the test case set.
[0168] 9. After receiving the test cases corresponding to the mirror import verification scenario returned by the test case set, the proxy service can execute the received test cases corresponding to the mirror import verification scenario. The process of executing this test case is the process of verifying the defense program in the mirror import verification scenario using this test case. After executing this test case, the proxy service can generate the verification result of the defense program under this test case corresponding to the mirror import verification scenario.
[0169] 10. The proxy service can return the verification result of the defense program generated under this test case corresponding to the mirror import verification scenario to the scheduling controller for the scheduling controller to process this verification result.
[0170] 11. Then, the scheduling controller can also start the third verification scenario for verifying the above defense program. This third verification scenario can be the above mirror reconstruction verification scenario, which is a scenario for verifying the defense program using the risk mirror constructed based on the basic risk mirror. The scheduling controller can send a verification task to the proxy service to verify the defense program in this mirror reconstruction verification scenario.
[0171] 12. After receiving the verification task sent by the scheduling controller to verify the defense program in the mirror reconstruction verification scenario, the proxy service can obtain, based on this verification task, test cases from the test case set for verifying the defense program in the mirror reconstruction verification scenario, that is, the test cases corresponding to the mirror reconstruction verification scenario. Among them, the test case set can contain several test cases corresponding to the mirror reconstruction verification scenario, and different test cases corresponding to the mirror reconstruction verification scenario can be used to conduct diverse and comprehensive verification of the defense program in different dimensions (such as different types of risk mirrors) of the mirror reconstruction verification scenario. During the process of verifying the defense program in the mirror reconstruction verification scenario, the proxy service can sequentially adopt each test case corresponding to the mirror reconstruction verification scenario in the test case set to verify the defense program in the mirror reconstruction verification scenario.
[0172] 13. The test case set can return (which can be returned by the background device where the test case set is located) the test cases corresponding to the mirror reconstruction verification scenario it has obtained. Optionally, after the proxy service executes a test case corresponding to the mirror reconstruction verification scenario (that is, after completing the verification of the defense program using a test case corresponding to the mirror reconstruction verification scenario), the proxy service can obtain the next test case corresponding to the mirror reconstruction verification scenario from the test case set and continue to verify the defense program in the mirror reconstruction verification scenario through this next test case until the verification of the defense program is completed using all the test cases corresponding to the mirror reconstruction verification scenario in the test case set.
[0173] 14. After receiving the test cases corresponding to the mirror reconstruction verification scenario returned by the test case set, the proxy service can execute the received test cases corresponding to the mirror reconstruction verification scenario. The process of executing this test case is the process of using this test case to verify the defense program in the mirror reconstruction verification scenario. After executing this test case, the proxy service can generate the verification result of the defense program in the mirror reconstruction verification scenario.
[0174] 15. The proxy service can return the verification result of the defense program under this test case corresponding to the mirror reconstruction verification scenario to the scheduling controller, enabling the scheduling controller to process this verification result.
[0175] 16. Through the above process, the scheduling controller can receive several verification results of the defense program in the above-mentioned mirror pulling verification scenario, mirror import verification scenario, and mirror reconstruction verification scenario. The scheduling server can integrate the several verification results (such as classifying and integrating them according to different verification scenarios) to obtain the integrated verification results (including the several verification results). The scheduling controller can report the integrated verification results to the corresponding technical personnel. For example, the scheduling controller can send the integrated verification results to the terminal devices of the corresponding technical personnel, so that the corresponding technical personnel can further analyze the defense effectiveness of the defense program based on the integrated verification results.
[0176] Through the above process, the automated verification of the defense effectiveness of the defense program in each verification scenario is achieved.
[0177] Please refer to Figure 7 , Figure 7 which is a schematic flowchart of a process for verifying a defense program in a mirror pulling verification scenario provided by an embodiment of the present application. As Figure 7 shown, the process may include:
[0178] Step S201: Optionally, the proxy service may be a proxy component. The proxy service may execute a mirror pulling command to request the mirror repository to pull a risk-free mirror (i.e., a mirror without risks) to verify the availability of the mirror repository through the pulled risk-free mirror, that is, to verify the availability of the execution environment in the mirror pulling verification scenario. The risk-free mirror may be any pre-designed risk-free mirror, and the processing complexity of the risk-free mirror may be relatively low. For example, the amount of information processed by the risk-free mirror may be less than the information amount threshold, so as to quickly verify the availability of the mirror repository using the risk-free mirror.
[0179] Step S202: The proxy service may check whether the mirror pulling command in step S201 is executed successfully. If the mirror pulling command is executed successfully, that is, a risk-free mirror is successfully pulled from the mirror repository, the following step S203 may be continued. If the mirror pulling command is not executed successfully, that is, a risk-free mirror is not successfully pulled from the mirror repository, the mirror repository may be marked as unavailable, and the following step S211 may be entered to end the current verification process.
[0180] Step S203: The proxy service may create a corresponding container (i.e., create a corresponding mirror container) through the risk-free mirror successfully pulled in step S201 to verify the availability of the local Docker service (container service).
[0181] Step S204: The proxy service can check whether the risk-free container in the above step S203 is successfully created. If the risk-free container is successfully created, the following step S205 can be continued. If the creation of the risk-free container fails, the container service can be marked as unavailable, and the following step S211 can be entered to end the current verification process.
[0182] Through the above process, the availability of the execution environment for each image processing stage in the image pull verification scenario can be verified. If the execution environment for any image processing stage in the image pull verification scenario is unavailable, the verification of the defense effectiveness of the defense program cannot be accurately achieved in this image pull verification scenario.
[0183] Step S205: After ensuring that the execution environments for all image processing stages in the image pull verification scenario are available, the proxy service can execute the image pull command again to request the image repository to pull the risky image (i.e., pull the image with risks).
[0184] Step S206: The proxy service can check whether the image pull command in step S205 is successfully executed. If the image pull command is successfully executed, the following step S207 can be continued. If the image pull command fails, it can be marked that the risky image is intercepted during the pull, indicating that the defense program is successful in defense. That is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S211 can be entered to end the current verification process.
[0185] Step S207: The proxy service can execute the command to query the local image list.
[0186] Step S208: Based on this command, the proxy service can check whether the local image list contains the successfully pulled risky image. If it contains, it indicates that the pulled risky image is not isolated in the local image list, and the following step S209 can be continued. If it does not contain, it can be marked that the successfully pulled risky image is isolated in the local image list, indicating that the defense program is successful in defense. That is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S211 can be entered to end the current verification process.
[0187] Step S209: If the local image list contains the successfully pulled risky image, the proxy service can create a corresponding container in a harmless manner through the non-isolated risky image in the local image list (i.e., create a corresponding image container in a harmless manner), that is, replace the call address in the entry program of the created image container with the call address of the security program.
[0188] Step S210: The proxy service can check whether the mirror container in the above step S209 is successfully created. If the mirror container is successfully created, all defense actions of the defense program can be marked as failed (that is, the risk defenses in each mirror processing stage of the defense program in the mirror pulling verification scenario are ineffective), that is, a verification result that the defense program does not have defense effectiveness in the mirror pulling verification scenario is generated; conversely, if the creation fails, the operation defense of the security product (i.e., the defense program) against the risky mirror can be marked as successful, that is, a verification result that the defense program has defense effectiveness in the mirror pulling verification scenario is generated.
[0189] Step S211: The proxy service can clean up the traces generated during the above verification process (such as cleaning up the intermediate files generated during the verification process), and end the current verification process.
[0190] Through the above process, the automatic verification of the defense program in the mirror pulling verification scenario is realized.
[0191] Please refer to Figure 8 , Figure 8 which is a schematic flowchart of a process for verifying a defense program in a mirror import verification scenario provided by an embodiment of the present application. As Figure 8 shown, the process may include:
[0192] Step S301: The proxy service can execute a mirror file download command to request the download (i.e., export) of a risk-free mirror file (i.e., a mirror without risks) from the mirror file server (i.e., the above file server) to verify the availability of the mirror file server through the pulled risk-free mirror, that is, to verify the availability of the execution environment in the mirror import verification scenario. Similarly, the risk-free mirror can be any pre-designed risk-free mirror, and the processing complexity of the risk-free mirror can be relatively low. For example, the amount of information processed by the risk-free mirror can be less than the information amount threshold, so as to quickly verify the availability of the mirror file server using the risk-free mirror. Optionally, the risk-free mirror and / or the risky mirror obtained in different verification scenarios can be the same or different, which can be specifically determined according to the actual application scenario.
[0193] Step S302: The proxy service can check whether the mirror file download command in step S301 is successfully executed. If the mirror file download command is successfully executed, that is, the risk-free mirror is successfully downloaded from the mirror file server, the following step S303 can be continued. If the mirror file download command fails, that is, the risk-free mirror is not successfully downloaded from the mirror file server, the mirror file server can be marked as unavailable, and the following step S317 can be transferred to end the current verification process.
[0194] Step S303: Next, the proxy service can execute the mirror import command to import the successfully downloaded risk-free mirror file as a local mirror (i.e., import it into the local mirror list) to verify the availability of the local Docker service (container service).
[0195] Step S304: The proxy service can check whether the mirror import command in the above step S303 is executed successfully. If the mirror import command is executed successfully, it indicates that the execution environment for importing the file into the local mirror list is available, and then the following step S305 can be continued. If the mirror import command fails, it indicates that the execution environment for importing the file into the local mirror list is unavailable, and then the container service can be marked as unavailable, and it can go to step S317 to end the current verification process.
[0196] Step S305: The proxy service can create a corresponding container (i.e., create a corresponding mirror container) through the risk-free mirror successfully imported into the local mirror list in the above step S304 to verify the availability of the local Docker service (local container service).
[0197] Step S306: The proxy service can check whether the mirror container in the above step S305 is created successfully. If it is created successfully, it indicates that the execution environment for creating the container is available, and then the following step S307 can be continued. If it fails to be created, it indicates that the execution environment for creating the container is unavailable, and then the local container service can be marked as unavailable, and it can go to the following step S317 to end the current verification process.
[0198] Through the above process, it is possible to verify the availability of the execution environment in each mirror processing stage in the mirror import verification scenario. If the execution environment in any mirror processing stage in the mirror import verification scenario is unavailable, it is impossible to accurately verify the defense effectiveness of the defense program in this mirror import verification scenario.
[0199] Step S307: After ensuring that the execution environments in all mirror processing stages in the mirror import verification scenario are available, the proxy service can execute the file download command again to request the risk mirror file from the mirror file server (i.e., request to download the mirror with risks).
[0200] Step S308: The proxy service can check whether the file download command in the above step S307 is executed successfully. If the file download command is executed successfully, the following step S309 can be continued. If the file download command fails, it can be marked that the risk mirror file is intercepted during the download, indicating that the defense program is successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and it can go to the following step S317 to end the current verification process.
[0201] Step S309: The proxy service can execute the command to query the local file list.
[0202] Step S310: The proxy service can check whether the downloaded risky mirror file (i.e., the above-downloaded risky mirror) is included in the local file list based on this command. If it is included, it indicates that the downloaded risky mirror has not been isolated in the local file list, and the following Step S311 can be continued. If it is not included, the downloaded risky mirror file can be marked as isolated, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following Step S317 can be transferred to end the current verification process.
[0203] Step S311: The proxy service can execute the mirror import command to import the successfully downloaded risky mirror file in the local file list as a local mirror, that is, import it into the local mirror list.
[0204] Step S312: The proxy service can check whether the import of the downloaded risky mirror file in the local file list into the local mirror list is successful. If the import is successful, it indicates that the risky mirror file has not been intercepted during the import into the local mirror list, and the following Step S313 can be continued. If the import fails, the risky mirror file can be marked as intercepted during the import, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following Step S317 can be transferred to end the current verification process.
[0205] Step S313: The proxy service can execute the command to query the local mirror list.
[0206] Step S314: The proxy service can check whether the imported risky mirror file is included in the local mirror list based on this command. If it is included, it indicates that the risky mirror file imported into the local mirror list has not been isolated, and the following Step S315 can be continued. If it is not included, the risky mirror file can be marked as isolated, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following Step S317 can be transferred to end the current verification process.
[0207] Step S315: If the local mirror list contains the successfully imported risky mirror file, the proxy service can create a corresponding container (i.e., create a corresponding mirror container) in a harmless manner through the risky mirror file successfully imported into the local mirror list.
[0208] Step S316: The proxy service can check whether the image container in the above step S315 is successfully created. If it is successfully created, all defense actions of the defense program can be marked as failed, that is, the defense program is not effective in the image import verification scenario. On the contrary, if the creation fails, the security product can be marked as successfully defending against the risk image in the image import verification scenario, that is, the defense program is effective in the image import verification scenario.
[0209] Step S317: The proxy service can clean up the traces generated during the above verification process (such as cleaning up the intermediate files generated during the verification process), and end the current verification process.
[0210] Through the above process, the automatic verification of the defense program in the image import verification scenario is realized.
[0211] Please refer to Figure 9 , Figure 9 which is a schematic flowchart of a process for verifying a defense program in an image reconstruction verification scenario provided by an embodiment of the present application. As Figure 9 shown, the process may include:
[0212] Step S401: The proxy service can execute an image pull command to request a basic risk-free image (i.e., a risk-free basic image, which can be any image used to create other images) from the image repository to verify the availability of the image repository, and verify the availability of the execution environment in the image reconstruction verification scenario through the pulled basic risk-free image. The processing complexity of the basic risk-free image can also be relatively low. For example, the amount of information processed by the basic risk-free image can be less than the information threshold, so as to quickly verify the availability of the execution environment in the image reconstruction verification scenario using the basic risk-free image. The basic risk-free image can be used to create corresponding risk-free images.
[0213] Step S402: The proxy service can check whether the image pull command in the above step S401 is successfully executed. If the image pull command is successfully executed, that is, the basic risk-free image is successfully pulled from the image repository, the following step S403 can be continued. If the image pull command fails, that is, the basic risk-free image is not successfully pulled from the image repository, the image repository can be marked as unavailable, and the following step S417 can be transferred to.
[0214] Step S403: The proxy service can use the image successfully pulled in the above step S401 as the basic image and execute a local image build command to build a new image A1 (the new image A1 belongs to a risk-free image) to verify the availability of the local Docker service (local container service).
[0215] Step S404: The proxy service can check whether the execution of the image building command in the above step S403 is successful, that is, whether the new image A1 is successfully built. If the execution is successful, that is, the new image A1 is successfully built, the following step S405 can be continued. If the execution fails, that is, the new image A1 is not successfully built, the container service can be marked as unavailable, and the following step S417 can be entered.
[0216] Step S405: The proxy service can create a corresponding container (i.e., create a corresponding image container) through the successfully built image A above to verify the availability of the local Docker service.
[0217] Step S406: The proxy service can check whether the image container in the above step S405 is successfully created. If it is successfully created, the following step S407 can be continued. If the creation fails, the container service can be marked as unavailable, and the following step S417 can be entered.
[0218] Through the above process, the availability of the execution environment of each image processing stage in the image reconstruction verification scenario can be verified. If the execution environment of any image processing stage in the image reconstruction verification scenario is unavailable, the verification of the defense effectiveness of the defense program cannot be accurately achieved in this image reconstruction verification scenario.
[0219] Step S407: After ensuring that the execution environments of all image processing stages in the image reconstruction verification scenario are available, the proxy service can execute the image pulling command again to request the image repository to pull the basic risk image (i.e., the basic image with risks).
[0220] Step S408: The proxy service can check whether the image pulling command in the above step S407 is successfully executed. If the image pulling command is successfully executed, the following step S409 can be continued. If the image pulling command fails, it can be marked that the basic risk image is intercepted during the pulling process, indicating that the defense program is successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S417 can be entered to end the current verification process.
[0221] Step S409: The proxy service can execute the command to query the local image list.
[0222] Step S410: The proxy service can check whether the locally mirrored list contains the successfully pulled basic risk image based on this command. If it does, it indicates that the successfully pulled basic risk image has not been isolated in the locally mirrored list, and the following step S411 can be continued. If it does not, the pulled basic risk image can be marked as isolated, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S417 can be transferred to end the current verification process.
[0223] Step S411: The proxy service can execute a local image building command through the successfully pulled and non-isolated basic risk image in the above locally mirrored list to build a new image A2 (this new image A2 is a risky image).
[0224] Step S412: The proxy service can check whether the execution of the image building command in the above step S411 is successful, that is, whether the new image A2 is successfully built. If the execution is successful, the following step S413 can be continued. If the execution fails, the local building of the basic risk image can be marked as intercepted, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S417 can be transferred to end the current verification process.
[0225] Step S413: The proxy service can execute a command to query the locally mirrored list.
[0226] Step S414: The proxy service can check whether the locally mirrored list contains the above-built image A2 based on this command. If it does, that is, the new image A2 is successfully built, the following step S415 can be continued. If it does not, that is, the new image A2 is built unsuccessfully, the built image A2 can be marked as isolated, indicating that the defense program has successfully defended, that is, the verification result that the defense program has defense effectiveness can be obtained, and the following step S417 can be transferred to end the current verification process.
[0227] Step S415: If the locally mirrored list contains the successfully built image A2, the proxy service can create a corresponding container (i.e., create a corresponding image container) in a harmless manner through the successfully built image A2 in the locally mirrored list.
[0228] Step S416: The proxy service can check whether the image container in the above step S415 is successfully created. If it is successfully created, all defense actions of the defense program can be marked as failed, that is, the defense program does not have defense effectiveness in the image reconstruction verification scenario. On the contrary, if the creation fails, the running defense of the security product against the risky image in the image reconstruction verification scenario can be marked as successful, that is, the defense program has defense effectiveness in the image reconstruction verification scenario.
[0229] Step S417: The proxy service can clean up the traces generated during the above verification process (such as cleaning up intermediate files generated during the verification process), and end the current verification process.
[0230] Through the above process, the automatic verification of the defense program in the mirror reconstruction verification scenario is realized.
[0231] By adopting the above method of the present application, firstly, it realizes the automatic and complete (i.e., complete) verification of the defense program in the scenario of mirror security defense at the host level; secondly, it improves the verification efficiency of the defense effectiveness of the defense program against risk mirrors at the host level; thirdly, through the automatic verification scheme of the present application, it can realize the continuous, stable, and high-coverage inspection of the defense effectiveness of the defense program; fourthly, it can help enterprises (such as enterprises that need to verify the defense program) discover mirror security-related risks and problems faster at the host level; fifthly, it can effectively reduce the cost of verifying the defense effectiveness of the defense program in various verification scenarios.
[0232] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of a program verification device provided by an embodiment of the present application. As Figure 10 shown, the program verification device 101 may include: an acquisition module 1011, a processing module 1012, a defense module 1013, and a generation module 1014.
[0233] The acquisition module 1011 is used to acquire test cases corresponding to the verification scenario; the test cases are used to verify the defense effectiveness of the defense program in the verification scenario;
[0234] The processing module 1012 is used to process the risk mirror in the verification scenario at at least one mirror processing stage based on the test cases; and,
[0235] The defense module 1013 is used to call the defense program to perform risk defense on the processed risk mirror at each mirror processing stage in at least one mirror processing stage, so as to obtain the processing results of the risk mirror at each mirror processing stage;
[0236] The generation module 1014 is used to generate a verification result for the defense program based on the processing results of the risk mirror at each mirror processing stage; the verification result is used to indicate whether the defense program has the defense effectiveness against the risk mirror or does not have the defense effectiveness against the risk mirror in the verification scenario.
[0237] Optionally, the verification scenario includes at least one of the following:
[0238] The image pulling verification scenario for processing images in the image repository;
[0239] The image import verification scenario for processing images stored in the file storage device;
[0240] The image reconstruction verification scenario for processing images reconstructed based on existing base images.
[0241] Optionally, the image processing phases in the image pulling verification scenario include at least one of the following:
[0242] The image processing phase of pulling an image from the image repository and saving the pulled image to the local image list;
[0243] The image processing phase of performing isolation detection on the image that has been successfully saved to the local image list;
[0244] The image processing phase of creating a corresponding image container based on the image that has been successfully saved to the local image list and has not been isolated.
[0245] Optionally, the image repository contains risky images; if the verification scenario includes the image pulling verification scenario, the processing module 1012 processes the risky images in the verification scenario in at least one image processing phase in the verification scenario based on the test cases, including:
[0246] Pulling the risky image from the image repository based on the test case and saving the pulled risky image to the local image list;
[0247] If the pulled risky image is successfully saved to the local image list, perform isolation detection on the risky image that has been successfully saved to the local image list;
[0248] If the risky image that has been successfully saved to the local image list has not been isolated, create a corresponding image container based on the non-isolated risky image.
[0249] Optionally, the generation module 1014 generates the verification result for the defense program based on the processing results of the risky image in each image processing phase, including:
[0250] If the pulled risky image is successfully saved to the local image list, the risky image that has been successfully saved to the local image list has not been isolated, and the image container corresponding to the non-isolated risky image is successfully created, it is determined that the verification result includes that the defense program does not have the defense effectiveness against the risky image in the image pulling verification scenario;
[0251] If the pulled risky image fails to be successfully stored in the local image list, the risky image successfully stored in the local image list is isolated, or the image container corresponding to the non-isolated risky image fails to be successfully created, it is determined that the verification result includes the effectiveness of the defense program against risky images in the image pull verification scenario.
[0252] Optionally, the image processing stage in the image import verification scenario includes at least one of the following:
[0253] The image processing stage of exporting the image file from the file storage device and storing the exported image file in the local file list;
[0254] The image processing stage of performing isolation detection on the image file successfully stored in the local file list;
[0255] The image processing stage of importing the image file successfully stored in the local file list and not isolated into the local image list;
[0256] The image processing stage of creating a corresponding image container based on the image file successfully imported into the local image list.
[0257] Optionally, risky images are stored in the file storage device; if the verification scenario includes the image import verification scenario, the manner in which the processing module 1012 processes the risky images in at least one image processing stage in the verification scenario based on the test case includes:
[0258] Exporting the risky image from the file storage device based on the test case and storing the exported risky image in the local file list; wherein, the exported risky image is the exported image file;
[0259] If the risky image is successfully stored in the local file list, perform isolation detection on the risky image successfully stored in the local file list;
[0260] If the risky image is not isolated, import the non-isolated risky image into the local image list;
[0261] If the non-isolated risky image is successfully imported into the local image list, create a corresponding image container based on the risky image successfully imported into the local image list.
[0262] Optionally, the manner in which the generation module 1014 generates the verification result for the defense program based on the processing results of the risky image in each image processing stage includes:
[0263] If the exported risk image is successfully saved to the local file list, the risk image successfully saved to the local file list is not isolated, the non-isolated risk image is successfully imported into the local image list, and the image container corresponding to the risk image successfully imported into the local image list is successfully created, it is determined that the verification result includes that the defense program does not have the defense effectiveness against the risk image in the image import verification scenario;
[0264] If the exported risk image is not successfully saved to the local file list, the risk image successfully saved to the local file list is isolated, the non-isolated risk image is not successfully imported into the local image list, or the image container corresponding to the risk image successfully imported into the local image list is not successfully created, it is determined that the verification result includes that the defense program has the defense effectiveness against the risk image in the image import verification scenario.
[0265] Optionally, the image processing stage in the image reconstruction verification scenario includes at least one of the following:
[0266] The image processing stage of reconstructing the existing base image to obtain the reconstructed image;
[0267] The image processing stage of performing isolation detection on the successfully reconstructed image;
[0268] The image processing stage of creating the corresponding image container based on the successfully reconstructed and non-isolated image.
[0269] Optionally, the existing base image includes a base risk image, and the base risk image is used to reconstruct the risk image; if the verification scenario includes the image reconstruction verification scenario, the manner in which the processing module 1012 processes the risk image in the verification scenario at at least one image processing stage based on the test case includes:
[0270] Performing reconstruction processing on the base risk image based on the test case;
[0271] If the risk image is successfully reconstructed based on the base risk image, isolation detection is performed on the successfully reconstructed risk image;
[0272] If the successfully reconstructed risk image is not isolated, the corresponding image container is created based on the non-isolated risk image.
[0273] Optionally, the manner in which the generation module 1014 generates the verification result for the defense program based on the processing results of the risk image at each image processing stage includes:
[0274] If a risk image is successfully reconstructed based on the basic risk image, the successfully reconstructed risk image is not isolated, and the image container corresponding to the non-isolated risk image is successfully created, it is determined that the verification result is that the defense program does not have the defense effectiveness against the risk image in the image reconstruction verification scenario;
[0275] If a risk image is not successfully reconstructed based on the basic risk image, the successfully reconstructed risk image is isolated, or the image container corresponding to the non-isolated risk image is not successfully created, it is determined that the verification result is that the defense program has the defense effectiveness against the risk image in the image reconstruction verification scenario.
[0276] Optionally, the above processing module 1012 is further configured to:
[0277] Detect the availability of the execution environment of all image processing stages in the verification scenario based on the test case;
[0278] If the execution environments of all image processing stages in the verification scenario are all available, execute the process of processing the risk image in at least one image processing stage in the verification scenario based on the test case.
[0279] Optionally, at least one image processing stage includes the image processing stage of creating a corresponding image container based on the risk image. If the image container corresponding to the risk image is successfully created, the successfully created image container includes an entry program, and the entry program includes the call path of the program in the risk image; the test case includes a security program;
[0280] The above program verification device 101 is further configured to:
[0281] Replace the call path in the entry program of the successfully created image container with the call path of the security program;
[0282] Run the security program in the successfully created image container based on the call path of the security program replaced in the entry program.
[0283] Optionally, the above program verification device 101 is further configured to:
[0284] If the verification result indicates that the defense program has the defense effectiveness against the risk image, report and process the verification result according to the first reporting method; and,
[0285] If the verification result indicates that the defense program does not have the defense effectiveness against the risk image, report and process the verification result according to the second reporting method.
[0286] According to an embodiment of the present application, Figure 3 The steps involved in the program verification method shown can be performed by Figure 10Each module in the program verification device 101 shown is executed. For example, Figure 3 The step S101 shown in Figure 10 can be executed by the acquisition module 1011 in Figure 3 The step S102 shown in Figure 10 can be executed by the processing module 1012 in Figure 3 The step S103 shown in Figure 10 can be executed by the defense module 1013 in Figure 3 The step S104 shown in Figure 10 can be executed by the generation module 1014 in
[0287] This application can obtain test cases corresponding to the verification scenario; the test cases are used to verify the defense effectiveness of the defense program in the verification scenario; and based on the test cases, the risk images in the verification scenario can be processed in at least one mirror processing stage of the verification scenario; and, in each mirror processing stage of the at least one mirror processing stage, the defense program can be called to perform risk defense on the processed risk images to obtain the processing results of the risk images in each mirror processing stage; thus, based on the processing results of the risk images in each mirror processing stage, a verification result for the defense program can be generated; this verification result can be used to indicate whether the defense program has the defense effectiveness against the risk images or does not have the defense effectiveness against the risk images in the verification scenario. It can be seen that the device proposed in this application can achieve the automated verification of the defense effectiveness of the defense program through the test cases configured for the verification scenario, thereby ensuring the high efficiency of verifying the defense effectiveness of the defense program; and during the verification process, through the processing results of the risk images in each mirror processing stage of the verification scenario, the defense effectiveness of the defense program against the risk images in each mirror processing stage of this verification scenario can be verified, so the completeness of verifying the defense effectiveness of the defense program can also be ensured.
[0288] According to an embodiment of the present application, Figure 10 Each module in the program verification device 101 shown can be separately or all combined into one or several units to form, or a certain one (or some) of the units can be further split into multiple smaller sub-units in terms of function, and the same operations can be achieved without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In practical applications, the function of one module can also be realized by multiple units, or the functions of multiple modules can be realized by one unit. In other embodiments of the present application, the program verification device 101 can also include other units. In practical applications, these functions can also be assisted by other units and can be realized by the cooperation of multiple units.
[0289] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.
[0290] According to an embodiment of the present application, a computer program capable of executing the steps involved in the corresponding methods shown in the embodiments of the present application can be run on a general-purpose computer device (which may include processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), a read-only storage medium (ROM), etc.) to construct a program verification device 101 as shown in Figure 10 shown. The above computer program can be recorded on a computer-readable recording medium, and can be loaded into the above computer device through the computer-readable recording medium and run therein.
[0291] Please refer to Figure 11 , Figure 11 which is a schematic structural diagram of a computer device provided by an embodiment of the present application. As shown in Figure 11 shown, the computer device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. In addition, in some embodiments, the computer device 1000 may further include: a user interface 1003, and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection communication between these components. Among them, the user interface 1003 may include a display screen (Display), a keyboard (Keyboard), and optionally the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a non-volatile memory, such as at least one disk memory. Optionally, the memory 1005 may further be at least one storage device located far from the aforementioned processor 1001. As shown in Figure 11 shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.
[0292] In Figure 11In the computer device 1000 shown, the network interface 1004 can provide network communication functions; the user interface 1003 is mainly used to provide an interface for users to input; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to implement:
[0293] Obtain test cases corresponding to the verification scenario; the test cases are used to verify the defense effectiveness of the defense program in the verification scenario;
[0294] Based on the test cases, process the risk images in the verification scenario in at least one mirror processing stage of the verification scenario; and,
[0295] In each mirror processing stage of the at least one mirror processing stage, call the defense program to perform risk defense on the processed risk images to obtain the processing results of the risk images in each mirror processing stage;
[0296] Generate a verification result for the defense program based on the processing results of the risk images in each mirror processing stage; the verification result is used to indicate whether the defense program has the defense effectiveness against the risk images or does not have the defense effectiveness against the risk images in the verification scenario.
[0297] It should be understood that the computer device 1000 described in the embodiments of the present application can execute the description of the above program verification method in the embodiments of the present application, and can also execute the description of the above program verification device 101 in the corresponding embodiments described above, which will not be elaborated here. In addition, the description of the beneficial effects of the same method will not be elaborated either. Figure 10 The description of the corresponding embodiments of the above program verification device 101 will not be elaborated here. In addition, the description of the beneficial effects of the same method will not be elaborated either.
[0298] In addition, it should be pointed out here that: the present application also provides a computer-readable storage medium, and a computer program is stored in the computer-readable storage medium. When the processor executes the computer program, it can execute the description of the program verification method in the embodiments of the present application. Therefore, it will not be elaborated here. In addition, the description of the beneficial effects of the same method will not be elaborated either. For the technical details not disclosed in the embodiments of the computer storage medium involved in the present application, please refer to the description of the method embodiments of the present application.
[0299] As an example, the above computer program can be deployed to be executed on a computer device, or deployed to be executed on multiple computer devices located at one location, or, executed on multiple computer devices distributed at multiple locations and interconnected through a communication network. The multiple computer devices distributed at multiple locations and interconnected through a communication network can form a blockchain network.
[0300] The above computer-readable storage medium may be an internal storage unit of the above computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device. Further, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store the data that has been output or is to be output.
[0301] The present application provides a computer program product, which includes a computer program stored in a computer-readable storage medium. The processor of the computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device executes the descriptions of the above program verification method in the embodiments of the present application. Therefore, the descriptions will not be repeated here. In addition, the descriptions of the beneficial effects of adopting the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the descriptions of the method embodiments of the present application.
[0302] The terms "first", "second", etc. in the description and claims of the embodiments of the present application and the drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product, or equipment that includes a series of steps or units is not limited to the listed steps or modules, but may optionally further include steps or modules not listed, or may optionally further include other step units inherent to these processes, methods, devices, products, or equipment.
[0303] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0304] The above disclosure is only a preferred embodiment of the present application. Of course, it cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A program verification method, characterized in that, The method includes: Obtaining test cases corresponding to a verification scenario; the test cases are used to verify the defense effectiveness of a defense program in the verification scenario; Based on the test cases, processing a risk image in at least one image processing stage in the verification scenario; and, In each image processing stage of the at least one image processing stage, invoking the defense program to perform risk defense on the processed risk image to obtain a processing result of the risk image in each image processing stage; Generating a verification result for the defense program based on the processing results of the risk image in each image processing stage; the verification result is used to indicate whether the defense program has the defense effectiveness against the risk image or does not have the defense effectiveness against the risk image in the verification scenario.
2. The method according to claim 1, wherein The verification scenario includes at least one of the following: An image pulling verification scenario for processing an image in an image repository; An image import verification scenario for processing an image stored in a file storage device; An image reconstruction verification scenario for processing an image reconstructed based on an existing base image.
3. The method according to claim 2, wherein The image processing stages in the image pulling verification scenario include at least one of the following: An image processing stage of pulling an image from the image repository and storing the pulled image on disk in a local image list; An image processing stage of performing isolation detection on the image successfully stored on disk in the local image list; An image processing stage of creating a corresponding image container based on the image successfully stored on disk in the local image list and not isolated.
4. The method according to claim 3, characterized in that, The risk image is included in the image repository; if the verification scenario includes the image pulling verification scenario, then based on the test cases, processing the risk image in at least one image processing stage in the verification scenario includes: Pulling the risk image from the image repository based on the test cases and storing the pulled risk image on disk in the local image list; If the pulled risk image is successfully stored on disk in the local image list, performing isolation detection on the risk image successfully stored on disk in the local image list; If the risk image successfully stored on disk in the local image list is not isolated, creating a corresponding image container based on the non-isolated risk image.
5. The method according to claim 4, characterized in that, The generating a verification result for the defense program based on the processing results of the risk image in each image processing stage includes: If the pulled risk image is successfully stored on disk in the local image list, the risk image successfully stored on disk in the local image list is not isolated, and the image container corresponding to the non-isolated risk image is successfully created, determining that the verification result includes that the defense program does not have the defense effectiveness against the risk image in the image pulling verification scenario; If the pulled risk image is not successfully stored in the local image list, the risk image successfully stored in the local image list is isolated, or the image container corresponding to the risk image not isolated is not successfully created, it is determined that the verification result includes that the defense program is effective in defending against the risk image in the image pull verification scenario.
6. The method according to claim 2, wherein The image processing phases in the image import verification scenario include at least one of the following: An image processing phase of exporting an image file from the file storage device and storing the exported image file in the local file list; An image processing phase of performing isolation detection on the image file successfully stored in the local file list; An image processing phase of importing the image file successfully stored in the local file list and not isolated into the local image list; An image processing phase of creating a corresponding image container based on the image file successfully imported into the local image list.
7. The method according to claim 6, characterized in that, The risk image is stored in the file storage device; if the verification scenario includes the image import verification scenario, then based on the test case, processing the risk image in at least one image processing phase in the verification scenario includes: Exporting the risk image from the file storage device based on the test case and storing the exported risk image in the local file list; wherein, the exported risk image is the exported image file; If the risk image is successfully stored in the local file list, perform isolation detection on the risk image successfully stored in the local file list; If the risk image is not isolated, import the non-isolated risk image into the local image list; If the non-isolated risk image is successfully imported into the local image list, create a corresponding image container based on the risk image successfully imported into the local image list.
8. The method according to claim 7, wherein Generating a verification result for the defense program based on the processing results of the risk image in each image processing phase includes: If the exported risk image is successfully stored in the local file list, the risk image successfully stored in the local file list is not isolated, the non-isolated risk image is successfully imported into the local image list, and the image container corresponding to the risk image successfully imported into the local image list is successfully created, it is determined that the verification result includes that the defense program is not effective in defending against the risk image in the image import verification scenario; If the exported risk image is not successfully stored in the local file list, the risk image successfully stored in the local file list is isolated, the non-isolated risk image is not successfully imported into the local image list, or the image container corresponding to the risk image successfully imported into the local image list is not successfully created, it is determined that the verification result includes that the defense program is effective in defending against the risk image in the image import verification scenario.
9. The method according to claim 2, wherein The mirror processing stage in the mirror reconstruction verification scenario includes at least one of the following: Reconstructing an existing base mirror to obtain a reconstructed mirror in the mirror processing stage; Performing isolation detection on the successfully reconstructed mirror in the mirror processing stage; Creating a corresponding mirror container based on the successfully reconstructed and non-isolated mirror in the mirror processing stage.
10. The method according to claim 9, characterized in that, The existing base mirror includes a base risk mirror, and the base risk mirror is used to reconstruct the risk mirror; if the verification scenario includes the mirror reconstruction verification scenario, then based on the test case, processing the risk mirror in at least one mirror processing stage in the verification scenario includes: Performing a reconstruction process on the base risk mirror based on the test case; If the risk mirror is successfully reconstructed based on the base risk mirror, performing isolation detection on the successfully reconstructed risk mirror; If the successfully reconstructed risk mirror is not isolated, creating a corresponding mirror container based on the non-isolated risk mirror.
11. The method according to claim 10, wherein Generating a verification result for the defense program based on the processing results of the risk mirror in each mirror processing stage includes: If the risk mirror is successfully reconstructed based on the base risk mirror, the successfully reconstructed risk mirror is not isolated, and the mirror container corresponding to the non-isolated risk mirror is successfully created, it is determined that the verification result is that the defense program does not have the defense effectiveness against the risk mirror in the mirror reconstruction verification scenario; If the risk mirror is not successfully reconstructed based on the base risk mirror, the successfully reconstructed risk mirror is isolated, or the mirror container corresponding to the non-isolated risk mirror is not successfully created, it is determined that the verification result is that the defense program has the defense effectiveness against the risk mirror in the mirror reconstruction verification scenario.
12. The method according to claim 1, characterized in that, The method further includes: Detecting the availability of the execution environment of all mirror processing stages in the verification scenario based on the test case; If the execution environments of all mirror processing stages in the verification scenario are available, executing the process of processing the risk mirror in at least one mirror processing stage in the verification scenario based on the test case.
13. The method according to claim 1, wherein The at least one mirror processing stage includes the mirror processing stage of creating a corresponding mirror container based on the risk mirror. If the mirror container corresponding to the risk mirror is successfully created, the successfully created mirror container contains an entry program, and the entry program contains the call path of the program in the risk mirror; The test case contains a security program; The method further includes: Replacing the call path in the entry program of the successfully created mirror container with the call path of the security program; Running the security program in the successfully created mirror container based on the call path of the security program replaced in the entry program.
14. The method according to claim 1, wherein The method further includes: If the verification result indicates that the defense program has the defense effectiveness against the risk image, report and process the verification result in accordance with the first reporting method; and If the verification result indicates that the defense program does not have the defense effectiveness against the risk image, report and process the verification result in accordance with the second reporting method.
15. A program verification device, characterized in that, The device includes: An acquisition module, configured to acquire a test case corresponding to a verification scenario; the test case is used to verify the defense effectiveness of a defense program in the verification scenario; A processing module, configured to process a risk image in the verification scenario in at least one image processing stage based on the test case; and A defense module, configured to, in each of the at least one image processing stage, call the defense program to perform risk defense on the processed risk image to obtain the processing result of the risk image in each of the image processing stages; A generation module, configured to generate a verification result for the defense program based on the processing results of the risk image in each of the image processing stages; the verification result is used to indicate that the defense program has the defense effectiveness against the risk image or does not have the defense effectiveness against the risk image in the verification scenario.
16. A computer program product, characterized in that, It includes a computer program / instructions which, when executed by a processor, implement the steps of the method according to any one of claims 1-14.
17. A computer device, characterized in that, It includes a memory and a processor. The memory stores a computer program which, when executed by the processor, causes the processor to execute the steps of the method according to any one of claims 1-14.
18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program which is applicable to be loaded and executed by a processor to perform the method according to any one of claims 1-14.