Method, system and equipment for detecting and updating container vulnerability mirror image of power monitoring system

Through multi-level vulnerability detection and automatic update mechanism, the problems of low efficiency of container mirror vulnerability detection and error-prone update in the power monitoring system are solved, and the security and stability of the system are improved.

CN120429897APending Publication Date: 2025-08-05CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510515408.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In the power monitoring system, the vulnerability detection efficiency of container images is inefficient, manual updates are prone to errors, lack of targeting, and affecting system stability and security.

Method used

A multi-level vulnerability detection mechanism is adopted, including mirror layer, file-level and component-level vulnerability detection, combined with static code analysis and software component analysis, custom detection rules, realize automatic update policies, and improve security through mirror signature verification, access control and resource limitation.

Benefits of technology

It improves the efficiency and accuracy of vulnerability detection, realizes an automated update process, ensures the security and stability of the system, and reduces operation and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429897A_ABST
    Figure CN120429897A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a system and equipment for detecting and updating a container vulnerability mirror image of an electric power monitoring system. The method comprises the following steps: acquiring layer structure information of a container mirror image, extracting and analyzing file information of each mirror image layer, matching the file information with a preset vulnerability library, and detecting whether a mirror image layer vulnerability exists or not; analyzing the files in each mirror image layer one by one to obtain the contents, structures and dependencies of the files, and detecting whether file-level vulnerabilities exist or not by matching with a preset vulnerability library; performing component analysis operation on the container mirror image, identifying component information used in the container mirror image, performing matching operation on the component information and a preset component vulnerability library, and detecting whether component-level vulnerabilities exist or not; and evaluating and classifying the detection results of the mirror layer vulnerability, the file level vulnerability and the component level vulnerability, and selecting an updating strategy according to the severity and the emergency degree of the vulnerabilities. According to the invention, the vulnerability detection efficiency and accuracy of the power monitoring system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of micro-application data security in electric power monitoring systems, and in particular to a method, system, and device for detecting and updating container vulnerability images in electric power monitoring systems. Background Art

[0002] With the rapid development of the power industry and the deepening of digital transformation, power monitoring systems are playing an increasingly important role in ensuring the safe and stable operation of the power grid. Microapplications are created by breaking large applications into small, independent, and reusable modular applications. Each microapplication focuses on a single function or business area. Each modular application can be independently developed, tested, deployed, and scaled, and works collaboratively with other microapplications through lightweight communication mechanisms. Containers provide a standardized operating environment for microapplications, ensuring consistent behavior across different environments (development, testing, and production). Each microapplication can run in an independent container, avoiding mutual interference and improving system stability and security. Containers can dynamically allocate resources such as CPU and memory based on the resource requirements of the microapplication, improving resource utilization.

[0003] With the widespread adoption of container technology, power monitoring systems are also adopting containerized deployment to improve system flexibility and scalability. However, container security issues in power monitoring systems are becoming increasingly prominent. Container images, as encapsulations of applications and their operating environments, pose a serious threat to the stable operation of power systems if they contain security vulnerabilities.

[0004] In current power monitoring systems, container image security management primarily relies on manual inspection and updates, an approach that presents numerous problems. First, manual inspection is inefficient, making it difficult to detect all potential security vulnerabilities in a timely manner. Second, manual image updates are not only time-consuming and labor-intensive, but also prone to errors, potentially leading to system instability or even downtime. Furthermore, as power monitoring systems expand in scale and complexity, traditional security management methods are no longer sufficient to meet real-world needs.

[0005] While some vulnerability detection and update technologies for container images exist, these technologies are often targeted at general scenarios and lack the expertise and specificity required for power monitoring systems. For example, some general-purpose container image scanning tools can only detect common vulnerability types and are unable to optimize for the specific needs of power monitoring systems. Furthermore, existing automatic update technologies often lack update strategies tailored to the specific characteristics of power monitoring systems. In summary, the main shortcomings of existing technologies include:

[0006] 1) Inefficient vulnerability detection: The lack of specialized vulnerability libraries and scanning tools for power monitoring systems results in low vulnerability detection efficiency, making it difficult to promptly identify all potential security vulnerabilities. 2) Complex and error-prone update processes: Manually updating images is not only time-consuming and labor-intensive, but also prone to errors, potentially leading to system instability or even downtime. 3) Lack of specificity: Existing vulnerability detection and update technologies are often targeted at general scenarios and cannot fully meet the specific needs of power monitoring systems. These shortcomings pose risks to the security management of container images for power monitoring systems, potentially impacting the stable operation of the power system. Summary of the Invention

[0007] The purpose of the present invention is to address the problems in the above-mentioned prior art and provide a method, system and device for detecting and updating vulnerability images in power monitoring system containers, which is specifically aimed at detecting vulnerability images in power monitoring system containers, improves the efficiency and accuracy of vulnerability detection, and realizes adaptive strategy updates, reduces operation and maintenance costs, and enhances the security of the power monitoring system.

[0008] In order to achieve the above object, the present invention has the following technical solutions:

[0009] In a first aspect, a method for detecting and updating container vulnerability images in a power monitoring system is provided, comprising:

[0010] Obtain the layer structure information of the container image, divide it into the various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are image layer vulnerabilities;

[0011] Parse the files in each image layer one by one to obtain the file content, structure, and dependencies, and detect whether there are file-level vulnerabilities by matching them with the preset vulnerability library;

[0012] Perform component parsing on the container image to identify all component information used in the container image, match the component information with the preset component vulnerability library, and detect whether there are component-level vulnerabilities;

[0013] Evaluate and categorize the detection results of image-level vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select update strategies based on the severity and urgency of the vulnerabilities.

[0014] As a preferred solution, the layer structure information of the container image includes the creation time, size and user of each image layer; the file information in each image layer includes the file type, permissions and owner; in the step of matching the file information with the preset vulnerability library to detect whether there is an image layer vulnerability, if a vulnerability is found, the location, type and severity of the vulnerability are recorded.

[0015] As a preferred solution, the files in each image layer are parsed one by one to obtain the content, structure and dependencies of the files. Then, a static code analysis tool is used to perform a code audit on the files. The results of the static code analysis are matched with a preset vulnerability library. If a vulnerability is found, the specific location, type and impact range of the vulnerability are recorded.

[0016] As a preferred solution, in the step of performing component parsing on the container image, a software component analysis tool is used to perform component parsing on the container image; after matching the component information with a preset component vulnerability library, if a successfully matched component-level vulnerability is found, the component name, version, and vulnerability type of the vulnerability are recorded; based on the severity and impact scope of the component-level vulnerability, the impact on the power monitoring system is evaluated, and a corresponding repair strategy is formulated.

[0017] As a preferred solution, the power monitoring system container vulnerability image detection and update method also includes the step of customizing detection rules, and, in the vulnerability detection process, loading the customized detection rules in real time, matching the container image information with the customized detection rules, and if a problem record with a successful match is found, storing the corresponding information in the security alarm log.

[0018] As a preferred solution, in the step of selecting an update strategy based on the severity and urgency of the vulnerability, the latest image version is pulled from the image repository and verified; the pulled image version is configured and customized according to the actual needs of the power monitoring system; the container image is rebuilt, and additional security reinforcement measures are added during the construction process to improve the security of the image;

[0019] Based on the rebuilt container image, stop and delete the old container instance, start a new container instance using the new image version, and configure the container's resources to meet business needs; perform functional verification operations on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system, and perform performance testing operations to evaluate the container's performance and optimization space.

[0020] As a preferred solution, during the container image building process, an image signature tool is used to generate image signature information, and during the image pulling and deployment process, an image signature verification tool is used to verify the image signature information. If the signature verification fails, the corresponding image is refused to be deployed and a corresponding security warning log is generated.

[0021] As a preferred solution, the power monitoring system container vulnerability image detection and update method also includes defining access rights levels for different users or user groups to meet business needs and security policy requirements, using access control tools to configure and manage access rights for container images, monitoring access control log information to discover and handle unauthorized access and operation behaviors, and recording and analyzing abnormal access behaviors.

[0022] As a preferred solution, the power monitoring system container vulnerability image detection and update method also includes defining resource restriction parameters that can be used by the container image, using container management tools to configure and manage the resource restriction parameters of the container; monitoring the resource usage of the container to discover abnormal resource usage behavior, and recording and analyzing the abnormal resource usage behavior.

[0023] In a second aspect, a power monitoring system container vulnerability image detection and update system is provided, comprising:

[0024] The image layer vulnerability detection module is used to obtain the layer structure information of the container image, divide the container image into various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are image layer vulnerabilities;

[0025] The file-level vulnerability detection module is used to parse the files in each image layer one by one, obtain the file content, structure and dependencies, and detect whether there are file-level vulnerabilities by matching them with the preset vulnerability library;

[0026] The component-level vulnerability detection module is used to perform component parsing operations on container images, identify all component information used in the container image, match the component information with the preset component vulnerability library, and detect whether there are component-level vulnerabilities;

[0027] The update strategy selection module is used to evaluate and classify the detection results of image layer vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select the update strategy according to the severity and urgency of the vulnerabilities.

[0028] As a preferred solution, the layer structure information of the container image obtained by the image layer vulnerability detection module includes the creation time, size and user of each image layer; the file information in each image layer includes the file type, permissions and owner; the image layer vulnerability detection module matches the file information with the preset vulnerability library to detect whether there is an image layer vulnerability. If a vulnerability is found, the location, type and severity of the vulnerability are recorded.

[0029] As a preferred solution, the file-level vulnerability detection module parses the files in each image layer one by one, obtains the content, structure and dependencies of the files, and then uses a static code analysis tool to perform code audits on the files. The results of the static code analysis are matched with a preset vulnerability library. If a vulnerability is found, the specific location, type and impact range of the vulnerability are recorded.

[0030] As a preferred solution, the component-level vulnerability detection module uses a software component analysis tool to perform component parsing operations on container images; after matching the component information with a preset component vulnerability library, if a successfully matched component-level vulnerability is found, the component name, version, and vulnerability type of the vulnerability are recorded; based on the severity and impact scope of the component-level vulnerability, the impact on the power monitoring system is evaluated, and a corresponding repair strategy is formulated.

[0031] As a preferred solution, the power monitoring system container vulnerability image detection and update system also includes a custom detection module for customizing detection rules, and loading the custom detection rules in real time during the vulnerability detection process, matching the container image information with the custom detection rules, and if a successful matching problem record is found, the corresponding information is stored in the security alarm log.

[0032] As a preferred solution, the update strategy selection module pulls the latest image version from the image repository and verifies the pulled image version; configures and customizes the pulled image according to the actual needs of the power monitoring system; rebuilds the container image and adds additional security reinforcement measures during the construction process to improve the security of the image;

[0033] Based on the rebuilt container image, stop and delete the old container instance, start a new container instance using the new image version, and configure the container's resources to meet business needs; perform functional verification operations on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system, and perform performance testing operations to evaluate the container's performance and optimization space.

[0034] As a preferred solution, the power monitoring system container vulnerability image detection and update system also includes a security reinforcement module for implementing image signature verification. During the container image construction process, an image signature tool is used to generate image signature information. During the image pulling and deployment process, an image signature verification tool is used to verify the image signature information. If the signature verification fails, the corresponding image is refused to be deployed and a corresponding security alarm log is generated.

[0035] As a preferred solution, the security reinforcement module is also used to implement access control, define access rights levels for different users or user groups to meet business needs and security policy requirements, use access control tools to configure and manage access rights for container images, monitor access control log information to discover and handle unauthorized access and operation behaviors, and record and analyze abnormal access behaviors.

[0036] As a preferred solution, the security reinforcement module is also used to implement resource restrictions, define the resource restriction parameters that can be used by the container image, and use the container management tool to configure and manage the resource restriction parameters of the container; monitor the resource usage of the container to discover abnormal resource usage behavior, and record and analyze the abnormal resource usage behavior.

[0037] In a third aspect, an electronic device is provided, comprising a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the power monitoring system container vulnerability image detection and update method.

[0038] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores at least one instruction, and when the at least one instruction is executed by a processor, the power monitoring system container vulnerability image detection and update method is implemented.

[0039] Compared with the prior art, the first aspect of the present invention has at least the following beneficial effects:

[0040] The power monitoring system container vulnerability image detection and update method of the present invention proposes a multi-level vulnerability detection mechanism for power monitoring system micro-applications, completes image layer vulnerability detection, file level vulnerability detection and component level vulnerability detection, covers vulnerability detection of containers carrying micro-applications, discovers known vulnerabilities and configuration errors that may exist in the image, prevents malicious code or vulnerable configurations from entering the power production area, detects whether there is a risk of malicious code or sensitive information leakage in the file content, ensures the security of applications running in the container and the files they depend on, ensures that each component is safe, and realizes special and accurate detection of specific types of vulnerabilities or security incidents. The present invention proposes an automatic update mechanism for power monitoring system micro-applications, which can automatically select a suitable update strategy according to the severity and urgency of the vulnerability, realizes full-process automated management, and solves the problems of low efficiency of manual update, difficulty in selecting update strategy and lack of verification after update.

[0041] Furthermore, the present invention designs security reinforcement for the micro-application of the power monitoring system, and realizes image signature verification, access control and resource limitation. Through image signature verification, the integrity and credibility of the image are ensured, and only verified images can run, effectively preventing the intrusion of malicious images. Through access control, the access rights to the container image are restricted, further improving the security of the system. In addition, the present invention also effectively prevents the occurrence of excessive container image resource usage or denial of service attacks through resource limitation technology. Through the security reinforcement design, the security risk problems faced by the micro-application of the power monitoring system are solved, achieving the effect of improving system security, protecting data integrity and ensuring service continuity.

[0042] It can be understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0044] Figure 1 Vulnerability detection flow chart of the power monitoring system container vulnerability image detection and update method according to an embodiment of the present invention;

[0045] Figure 2 Automatic update flow chart of the method for detecting and updating container vulnerabilities in a power monitoring system according to an embodiment of the present invention;

[0046] Figure 3 A safety protection flow chart of a method for detecting and updating container vulnerabilities in a power monitoring system according to an embodiment of the present invention;

[0047] Figure 4 Flowchart of an embodiment of the present invention for detecting whether there is an image layer vulnerability;

[0048] Figure 5 Flowchart of detecting whether there is a file-level vulnerability according to an embodiment of the present invention;

[0049] Figure 6 Flowchart of detecting whether there is a component-level vulnerability according to an embodiment of the present invention;

[0050] Figure 7 Flowchart of custom feature detection according to an embodiment of the present invention;

[0051] Figure 8 Update strategy selection flow chart of the embodiment of the present invention;

[0052] Figure 9 Flowchart of image pulling and building according to an embodiment of the present invention;

[0053] Figure 10 Flowchart of container hot update according to an embodiment of the present invention;

[0054] Figure 11 Flowchart of image signature verification according to an embodiment of the present invention;

[0055] Figure 12 Access control flow chart of an embodiment of the present invention;

[0056] Figure 13 Flowchart of resource restriction configuration according to an embodiment of the present invention. DETAILED DESCRIPTION

[0057] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0058] The power monitoring system is an automated system used to monitor and control the operation of the power system, including functions such as data acquisition, transmission, processing, display, and execution of control commands. Container images are the core components of container technology, containing applications and their required operating environments, and can be considered as lightweight virtual machines. Vulnerability detection is the process of discovering and reporting security vulnerabilities in systems or applications by scanning and analyzing them. In response to the security management risks of power monitoring system container images, an embodiment of the present invention proposes a method for detecting and updating vulnerability images in power monitoring system containers, which mainly includes the following steps:

[0059] S1. Obtain the layer structure information of the container image, divide it into the various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are any image layer vulnerabilities;

[0060] S2. Parse each file in each image layer one by one to obtain the file's content, structure, and dependencies. Then, match them against a pre-set vulnerability library to detect file-level vulnerabilities.

[0061] S3. Perform component parsing on the container image to identify all component information used in the container image. This information is then matched against a pre-defined component vulnerability library to detect component-level vulnerabilities.

[0062] S4. Evaluate and classify the detection results of image-level vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select an update strategy based on the severity and urgency of the vulnerabilities.

[0063] See also Figure 1 The vulnerability detection in the embodiment of the present invention includes image layer vulnerability detection, file level vulnerability detection, component level vulnerability detection, and custom feature detection, which are as follows:

[0064] Image layer vulnerability detection: A container image is usually composed of multiple image layers stacked together, and each image layer contains a specific file system and configuration information. The present invention parses the layer structure of the container image to obtain the metadata and file information of each image layer, and then performs vulnerability detection on each image layer. The implementation method includes: first, using the image parsing tool (history command) to obtain the layer structure information of the container image, including metadata such as the creation time, size, and user of each image layer. Then, perform file extraction and parsing on each image layer to obtain detailed information such as file type, permissions, and owner. Match the extracted file information with the preset vulnerability library to detect whether there are known vulnerabilities. If a vulnerability is found, record the location, type, severity, and other information of the vulnerability, and generate a vulnerability detection report.

[0065] File-level vulnerability detection: Based on the image layer vulnerability detection, the present invention further performs vulnerability detection on each file in the container image. By deeply analyzing the content, structure and dependencies of the files, more hidden vulnerabilities can be discovered. The implementation method includes: parsing the files in each image layer one by one, extracting information such as the content, structure, and dependencies of the files. Use a static code analysis tool (Fortify) to perform code audits on the files to detect whether there are coding errors, security vulnerabilities and other problems. The results of the static code analysis are matched with the preset vulnerability library to further confirm the existence of the vulnerability. If a vulnerability is found, record the specific location, type, impact range and other information of the vulnerability, and update the vulnerability detection report.

[0066] Component-level vulnerability detection: A container image usually contains multiple software components (such as library files, plug-ins, etc.), which may have known security vulnerabilities. The present invention can detect whether there are security issues with the components used in the container image through component-level vulnerability detection. The implementation method includes: using a software component analysis tool (Docker Bench Security) to perform component parsing on the container image to obtain all component information used in the image. Match the component information with the preset component vulnerability library to detect whether there are known component vulnerabilities. If a component vulnerability is found, the component name, version, vulnerability type and other information of the vulnerability are recorded, and the vulnerability detection report is updated. According to the severity and scope of the component vulnerability, its impact on the power monitoring system is evaluated, and a corresponding repair strategy is formulated.

[0067] Custom feature detection: In order to meet the actual needs of different users, the present invention introduces a security detection mechanism of custom features. Users can define specific detection rules according to their own security policies and business needs, thereby realizing targeted detection of specific types of vulnerabilities. The implementation method includes: providing a user-friendly interface or API interface to allow users to define custom detection rules. The detection rules may include multiple dimensions such as file type, file content, component name, component version, etc. The user-defined detection rules are stored in the database and matched in real time during the vulnerability detection process. If a problem that meets the custom detection rules is found, the detailed information of the problem is recorded and a corresponding security alert is generated.

[0068] See also Figure 2 In step S4 of the embodiment of the present invention, the detection results of image layer vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities are evaluated and classified. When selecting an update strategy based on the severity and urgency of the vulnerability, the process specifically includes update strategy selection, image pulling and building, and container restart and verification. The specific contents of each process are as follows:

[0069] Update Policy Selection: Automatically selects an appropriate update policy based on the severity and urgency of the vulnerability. For critical and urgent vulnerabilities, an immediate update policy is selected; for common vulnerabilities, scheduled updates or manual confirmation of the update policy are available. Implementation Details: Analyze vulnerability detection reports and assess the severity and urgency of each vulnerability. Based on the assessment results and pre-set update policy rules, an appropriate update policy is selected. The selected update policy is notified to the user or automated system for execution.

[0070] Image Pulling and Building: After determining the update strategy, you need to pull the latest image version from the image repository and rebuild the container image. Implementation details include: using image management tools (such as Kubernetes) to pull the latest image version from the image repository. Performing necessary configuration and customization on the pulled image based on the actual needs of the power monitoring system. Using image building tools (Dockerfiles), rebuild the container image and generate a new image version.

[0071] Container restart and verification: After updating the container image, you need to restart the container and verify the success of the update. By monitoring the container's running status and log information, you can promptly identify and resolve any issues that may arise during the update. Implementation details include: using the container management tool (Kubernetes) to stop and delete the old container instance. Starting a new container instance using the new image version and configuring the corresponding network, storage, and other resources. Monitoring the container's running status and log information to ensure that the container can operate normally and handle the tasks of the power monitoring system. Perform functional verification and performance testing on the updated container to ensure that the update has not introduced new issues.

[0072] See also Figure 3 The embodiment of the present invention also includes a method for detecting and updating image vulnerabilities in a power monitoring system container. The security reinforcement is divided into image signature verification, access control, and resource restriction. The specific contents are as follows:

[0073] Image signature verification: This ensures the integrity and trustworthiness of container images by verifying their signatures. Only images with verified signatures are allowed to run in the power monitoring system. Implementation details include: generating image signatures during the image build process and storing them in the image repository. Verifying image signatures during image pull and deployment ensures image integrity and trustworthiness. If image signature verification fails, deployment of the image is rejected and a corresponding security alert is generated.

[0074] Access Control: Implement strict access control policies to limit access to container images and prevent unauthorized access and manipulation. Implementation details include defining access levels for different users or user groups, such as read-only, read-write, and administrative. Use access control tools (such as Kubernetes' RBAC mechanism) to configure and manage access rights to container images. Monitor access control logs to promptly identify and address unauthorized access and manipulation.

[0075] Resource limits: By limiting the resources available to container images (such as CPU, memory, and disk), we prevent container images from causing excessive resource usage or denial of service attacks on the power monitoring system. Implementation details include defining resource limit parameters in the container configuration file, such as CPU usage limits and memory size limits. Use container management tools (such as the Docker CLI and Kubernetes) to configure and manage container resource limits. Monitor container resource usage to promptly identify and address issues such as excessive resource usage and denial of service attacks.

[0076] See also Figure 4 In one possible implementation, the specific process of detecting whether there is an image layer vulnerability in step S1 of the embodiment of the present invention includes:

[0077] Step 1: Get the image layer structure information;

[0078] Use the history command of the Docker CLI to obtain the layer structure information of the container image.

[0079] The obtained layer structure information is stored in the local database for subsequent analysis.

[0080] Step 2: File extraction and parsing;

[0081] Perform file extraction operations on each image layer to obtain the contents of the file system.

[0082] Use the file parsing tool (file) to identify the type and parse the permissions of the extracted files.

[0083] Step 3: Vulnerability matching and report generation;

[0084] The parsed file information is matched with the preset vulnerability library.

[0085] If a successfully matched vulnerability record is found, its detailed information (including server address, virtual machine address (if any), vulnerability location, hosted application type, region, severity, etc.) will be stored in the vulnerability detection report.

[0086] Generate a final vulnerability detection report and provide it to users or automated systems for review and processing.

[0087] See also Figure 5 In one possible implementation, the specific process of detecting whether there is a file-level vulnerability in step S2 of the embodiment of the present invention includes:

[0088] Step 1: Document analysis and audit;

[0089] Parse the files in each image layer one by one to obtain the content and structure information of the files.

[0090] Use static code analysis tools (such as SonarQube, Fortify, etc.) to perform code audit operations on files.

[0091] Store the results of the code audit in a local database for subsequent analysis.

[0092] Step 2: Vulnerability matching and confirmation;

[0093] Match the code audit results with the preset vulnerability library.

[0094] If a successful matching vulnerability record is found, further confirm the existence and impact scope of the vulnerability.

[0095] The confirmed vulnerability records are updated in the vulnerability detection report and provided to users or automated systems for review and processing.

[0096] See also Figure 6 In one possible implementation, the specific process of detecting whether there is a component-level vulnerability in step S3 of the embodiment of the present invention includes:

[0097] Step 1: Component analysis and identification;

[0098] Use software component analysis tools (such as Clair, Docker Bench Security, etc.) to perform component analysis on container images.

[0099] Identify all component information used in the image (such as component name, version, etc.) and store it in a local database.

[0100] Step 2: Component vulnerability matching;

[0101] Match component information with the preset component vulnerability library.

[0102] If a successfully matched component vulnerability record is found, further assess the scope and severity of its impact on the power monitoring system.

[0103] The assessed component vulnerability records are updated in the vulnerability detection report and provided to users or automated systems for review and processing.

[0104] See also Figure 7 In one possible implementation, the method for detecting and updating container vulnerabilities in a power monitoring system according to an embodiment of the present invention further includes the step of customizing detection rules. The specific process includes:

[0105] Step 1: Define custom detection rules;

[0106] Provide a user-friendly interface or API interface for users to define customized detection rules.

[0107] Store user-defined detection rules in the local database for subsequent matching.

[0108] Step 2: Customize rule matching;

[0109] Load user-defined custom detection rules in real time during the vulnerability detection process.

[0110] Match the container image information (such as file content, component information, etc.) with the custom detection rules.

[0111] If a matching problem record is found, its detailed information is stored in the security alarm log and provided to the user or automated system for review and processing.

[0112] Automatic update refers to the process of automatically downloading, installing, and configuring new versions of software according to preset policies and rules. Figure 8 In one possible implementation, the update strategy selection implementation details of the embodiment of the present invention include:

[0113] Step 1: Vulnerability assessment and classification;

[0114] Evaluate and classify vulnerability records in vulnerability detection reports.

[0115] Vulnerabilities are classified according to their severity (such as high risk, medium risk, low risk, etc.) and urgency (such as urgent, general, etc.).

[0116] Step 2: Update strategy selection;

[0117] Select an appropriate update strategy based on the vulnerability classification results and preset update strategy rules.

[0118] Notify the user or automated system of the selected update strategy for execution.

[0119] See also Figure 9 In one possible implementation, the image pulling and building implementation details of the embodiment of the present invention include:

[0120] Step 1: Pull the image;

[0121] Use tools such as Docker CLI or Kubernetes to pull the latest image version from the image repository.

[0122] Verify the pulled image version (such as signature verification, integrity check, etc.) to ensure its credibility and integrity.

[0123] Step 2: Image configuration and customization;

[0124] Perform necessary configuration and customization operations on the pulled image according to the actual needs of the power monitoring system.

[0125] For example, modify environment variables, configuration files, startup scripts, etc. to meet specific business needs.

[0126] Step 3: Mirror image building;

[0127] Rebuild the container image using tools such as Dockerfile or Kubernetes Pod definition files.

[0128] Additional security reinforcement measures (for example, adding digital signatures, access control, access time requirements, access source address requirements, etc.) can be added during the build process to improve the security of the image.

[0129] See also Figure 10 In one possible implementation, the container restart and verification implementation details of the embodiment of the present invention include:

[0130] Step 1: Stop and delete the container;

[0131] Use Kubernetes tools to stop and delete the old container instance.

[0132] The state and data of the container can be saved before deletion for subsequent restoration.

[0133] Step 2: Start and configure the container;

[0134] Start a new container instance using the new image version.

[0135] Configure container resources such as network, storage, and environment variables to meet business needs.

[0136] Step 3: Functional verification and performance testing;

[0137] Functional verification operations are performed on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system.

[0138] Perform performance testing to evaluate container performance and optimize room for improvement.

[0139] If any problems or abnormalities are found, they should be promptly investigated and handled.

[0140] See also Figure 11 In one possible implementation, the image signature verification implementation details of the embodiment of the present invention include:

[0141] Step 1: Generate image signature;

[0142] During the image building process, the image signature tool (Docker Content Trust) is used to generate image signature information.

[0143] The generated image signature information is stored in the image repository for subsequent verification.

[0144] Step 2: Image signature verification;

[0145] During the image pulling and deployment process, the image signature verification tool is used to verify the image signature information.

[0146] If signature verification fails, the image will be rejected for deployment and a corresponding security warning log will be generated for the user to review and handle.

[0147] See also Figure 12 In one possible implementation, the access control implementation details of the embodiment of the present invention include:

[0148] Step 1: Access rights definition;

[0149] Define access rights (such as read-only, read-write, and management) for different users or user groups to meet business needs and security policy requirements.

[0150] Store defined access rights levels in the access control database for subsequent configuration and management.

[0151] Step 2: Access control configuration;

[0152] Use access control tools (such as Kubernetes' RBAC mechanism) to configure and manage access permissions for container images.

[0153] The configuration results are stored in the access control database for subsequent auditing and tracing.

[0154] Step 3: Access log monitoring;

[0155] Monitor access control log information to promptly detect and handle unauthorized access and operation behaviors.

[0156] Record and analyze abnormal access behaviors for subsequent investigation and processing.

[0157] See also Figure 13 In one possible implementation, the resource restriction implementation details of the embodiment of the present invention include:

[0158] Step 1: Resource constraint definition;

[0159] Define resource limit parameters that can be used by container images (such as CPU usage limit, memory size limit, etc.) to meet business needs and security policy requirements.

[0160] The defined resource limit parameters are stored in the resource limit database for subsequent configuration and management.

[0161] Step 2: Resource limit configuration;

[0162] Use container management tools (such as Docker CLI, Kubernetes, etc.) to configure and manage container resource limits.

[0163] The configuration results are stored in the resource limit database for subsequent auditing and traceability.

[0164] Step 3: Resource usage monitoring;

[0165] Monitor container resource usage to promptly identify and address issues such as excessive resource usage or denial of service attacks.

[0166] Record and analyze abnormal resource usage behavior for subsequent investigation and processing.

[0167] In some other possible implementations, vulnerability detection in the power monitoring system container vulnerability image detection and update method of the present invention can use other file parsing tools or scripts (such as a custom Python script using the tar command to decompress the image layer) to extract and parse file information. Automatic updates can use the integrated automated testing framework container restart and verification to perform functional verification and performance testing. Security reinforcement can also be implemented using limited resource restrictions and access control.

[0168] Compared to existing technologies, the container image vulnerability detection and update method for a power monitoring system proposed in an embodiment of the present invention can improve vulnerability detection efficiency. By integrating a multi-source vulnerability library and developing a specialized image scanning tool, the efficiency and accuracy of vulnerability detection can be significantly enhanced. A multi-source vulnerability library integrates information from multiple security vulnerability databases to provide more comprehensive and accurate vulnerability information. An image scanning tool is a software tool specifically designed to scan container images for potential security vulnerabilities. Compared to manual detection methods, the container image vulnerability detection and update method for a power monitoring system proposed in the present invention can more quickly discover potential security vulnerabilities. Furthermore, by automating the image update process and establishing a version management mechanism, operation and maintenance costs can be significantly reduced. Operation and maintenance personnel no longer need to manually download, install, and configure new image versions; they only need to focus on update strategies and verification results. The implementation of security hardening and monitoring measures, as well as the development of emergency response plans, can further enhance the security of the power monitoring system. This method can promptly detect and address potential security threats, ensuring stable system operation.

[0169] Another embodiment of the present invention further provides a power monitoring system container vulnerability image detection and update system, comprising:

[0170] The image layer vulnerability detection module is used to obtain the layer structure information of the container image, divide the container image into various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are image layer vulnerabilities;

[0171] The file-level vulnerability detection module is used to parse the files in each image layer one by one, obtain the file content, structure and dependencies, and detect whether there are file-level vulnerabilities by matching them with the preset vulnerability library;

[0172] The component-level vulnerability detection module is used to perform component parsing operations on container images, identify all component information used in the container image, match the component information with the preset component vulnerability library, and detect whether there are component-level vulnerabilities;

[0173] The update strategy selection module is used to evaluate and classify the detection results of image layer vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select the update strategy according to the severity and urgency of the vulnerabilities.

[0174] In one possible implementation, the layer structure information of the container image obtained by the image layer vulnerability detection module includes the creation time, size, and user of each image layer; the file information in each image layer includes the file type, permissions, and owner; the image layer vulnerability detection module matches the file information with a preset vulnerability library to detect whether there is an image layer vulnerability. If a vulnerability is found, the location, type, and severity of the vulnerability are recorded.

[0175] In one possible implementation, the file-level vulnerability detection module parses each file in each image layer one by one to obtain the file's content, structure, and dependencies. It then uses a static code analysis tool to perform a code audit on the file, matching the results of the static code analysis with a preset vulnerability library. If a vulnerability is found, the specific location, type, and impact range of the vulnerability are recorded.

[0176] In one possible implementation, the component-level vulnerability detection module uses a software component analysis tool to perform component parsing operations on container images. After matching the component information with a preset component vulnerability library, if a successfully matched component-level vulnerability is found, the component name, version, and vulnerability type of the vulnerability are recorded. Based on the severity and scope of the component-level vulnerability, the impact on the power monitoring system is evaluated, and a corresponding repair strategy is formulated.

[0177] In one possible embodiment, the power monitoring system container vulnerability image detection and update system also includes a custom detection module for customizing detection rules, and loading the custom detection rules in real time during the vulnerability detection process, matching the container image information with the custom detection rules, and if a problem record with a successful match is found, storing the corresponding information in the security alarm log.

[0178] In one possible implementation, the update strategy selection module pulls the latest image version from the image repository and verifies the pulled image version; configures and customizes the pulled image according to the actual needs of the power monitoring system; and rebuilds the container image, adding additional security reinforcement measures during the build process to improve the security of the image.

[0179] Based on the rebuilt container image, stop and delete the old container instance, start a new container instance using the new image version, and configure the container's resources to meet business needs; perform functional verification operations on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system, and perform performance testing operations to evaluate the container's performance and optimization space.

[0180] In a possible embodiment, the power monitoring system container vulnerability image detection and update system also includes a security reinforcement module for implementing image signature verification. During the container image construction process, an image signature tool is used to generate image signature information. During the image pulling and deployment process, an image signature verification tool is used to verify the image signature information. If the signature verification fails, the corresponding image is refused to be deployed and a corresponding security alarm log is generated.

[0181] In one possible implementation, the security hardening module is also used to implement access control, define access rights levels for different users or user groups to meet business needs and security policy requirements, use access control tools to configure and manage access rights for container images, monitor access control log information to discover and handle unauthorized access and operation behaviors, and record and analyze abnormal access behaviors.

[0182] In one possible implementation, the security hardening module is also used to implement resource restrictions, define resource restriction parameters that can be used by container images, and use container management tools to configure and manage the resource restriction parameters of the container; monitor the resource usage of the container to discover abnormal resource usage behavior, and record and analyze abnormal resource usage behavior.

[0183] Another embodiment of the present invention further provides an electronic device, including a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the power monitoring system container vulnerability image detection and update method.

[0184] Another embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores at least one instruction, and when the at least one instruction is executed by a processor, the power monitoring system container vulnerability image detection and update method is implemented.

[0185] The computer program includes computer program code, which may be in source code form, object code form, executable file or some intermediate form. The computer-readable storage medium may include: any entity or device, medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory, random access memory, electric carrier signal, telecommunication signal and software distribution medium that can carry the computer program code. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals. For ease of explanation, the above content only shows the part related to the embodiment of the present invention. For specific technical details not disclosed, please refer to the method part of the embodiment of the present invention. The computer-readable storage medium is non-transitory and can be stored in a storage device formed by various electronic devices, and can implement the execution process recorded in the method of the embodiment of the present invention.

[0186] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0187] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0188] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0189] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0190] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for detecting and updating container vulnerabilities in a power monitoring system, characterized in that: include: Obtain the layer structure information of the container image, divide it into the various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are image layer vulnerabilities; Parse the files in each image layer one by one to obtain the file content, structure, and dependencies, and detect whether there are file-level vulnerabilities by matching them with the preset vulnerability library; Perform component parsing on the container image, identify the component information used in the container image, match the component information with the preset component vulnerability library, and detect whether there are component-level vulnerabilities; Evaluate and categorize the detection results of image-level vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select update strategies based on the severity and urgency of the vulnerabilities.

2. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 1, characterized in that: The layer structure information of the container image includes the creation time, size and user of each image layer; the file information in each image layer includes the file type, permissions and owner; in the step of matching the file information with the preset vulnerability library to detect whether there is an image layer vulnerability, if a vulnerability is found, the location, type and severity of the vulnerability are recorded.

3. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 1, characterized in that: The files in each image layer are parsed one by one to obtain the content, structure and dependencies of the files. Then, a static code analysis tool is used to perform code audit on the files. The results of the static code analysis are matched with a preset vulnerability library. If a vulnerability is found, the specific location, type and impact range of the vulnerability are recorded.

4. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 1, wherein: In the step of performing component parsing on the container image, a software component analysis tool is used to perform component parsing on the container image; after matching the component information with a preset component vulnerability library, if a successfully matched component-level vulnerability is found, the component name, version, and vulnerability type of the vulnerability are recorded; based on the severity and impact scope of the component-level vulnerability, the impact on the power monitoring system is evaluated, and a corresponding repair strategy is formulated.

5. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 1, wherein: It also includes the steps of customizing detection rules, as well as loading the custom detection rules in real time during the vulnerability detection process, matching the container image information with the custom detection rules, and if a successful matching problem record is found, storing the corresponding information in the security alert log.

6. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 1, characterized in that: In the step of selecting an update strategy according to the severity and urgency of the vulnerability, the latest image version is pulled from the image repository and the pulled image version is verified; Configure and customize the pulled image according to the actual needs of the power monitoring system; Rebuild the container image and add additional security hardening measures during the build process to improve the security of the image; Based on the rebuilt container image, stop and delete the old container instance, start a new container instance using the new image version, and configure the container's resources to meet business needs; perform functional verification operations on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system, and perform performance testing operations to evaluate the container's performance and optimization space.

7. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 6, characterized in that: During the container image building process, an image signature tool is used to generate image signature information. During the image pulling and deployment process, an image signature verification tool is used to verify the image signature information. If the signature verification fails, the corresponding image will be refused to be deployed and a corresponding security warning log will be generated.

8. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 6, wherein: It also includes defining access rights levels for different users or user groups to meet business needs and security policy requirements, using access control tools to configure and manage access rights for container images, monitoring access control log information to detect and handle unauthorized access and operation behaviors, and recording and analyzing abnormal access behaviors.

9. The method for detecting and updating container vulnerabilities in a power monitoring system according to claim 6, wherein: It also includes defining the resource limit parameters that can be used by container images, using container management tools to configure and manage the resource limit parameters of containers; monitoring the resource usage of containers to detect abnormal resource usage behavior, and recording and analyzing abnormal resource usage behavior.

10. A power monitoring system container vulnerability image detection and update system, characterized in that: include: The image layer vulnerability detection module is used to obtain the layer structure information of the container image, divide the container image into various image layers according to the layer structure information, extract and parse the file information of each image layer, match the file information with the preset vulnerability library, and detect whether there are image layer vulnerabilities; The file-level vulnerability detection module is used to parse the files in each image layer one by one, obtain the file content, structure and dependencies, and detect whether there are file-level vulnerabilities by matching them with the preset vulnerability library; The component-level vulnerability detection module is used to perform component parsing operations on container images, identify all component information used in the container image, match the component information with the preset component vulnerability library, and detect whether there are component-level vulnerabilities; The update strategy selection module is used to evaluate and classify the detection results of image layer vulnerabilities, file-level vulnerabilities, and component-level vulnerabilities, and select the update strategy according to the severity and urgency of the vulnerabilities.

11. The power monitoring system container vulnerability image detection and update system according to claim 10, characterized in that: The layer structure information of the container image obtained by the image layer vulnerability detection module includes the creation time, size and user of each image layer; the file information in each image layer includes the file type, permission and owner; The image layer vulnerability detection module matches the file information with a preset vulnerability library to detect whether there is an image layer vulnerability. If a vulnerability is found, the location, type and severity of the vulnerability are recorded.

12. The power monitoring system container vulnerability image detection and update system according to claim 10, characterized in that: The file-level vulnerability detection module parses the files in each image layer one by one, obtains the content, structure and dependencies of the files, and then uses a static code analysis tool to audit the files. The results of the static code analysis are matched with a preset vulnerability library. If a vulnerability is found, the specific location, type and impact range of the vulnerability are recorded.

13. The power monitoring system container vulnerability image detection and update system according to claim 10, characterized in that: The component-level vulnerability detection module uses a software component analysis tool to perform component parsing operations on container images; after matching component information with a preset component vulnerability library, if a successfully matched component-level vulnerability is found, the component name, version, and vulnerability type of the vulnerability are recorded; based on the severity and impact range of the component-level vulnerability, the impact on the power monitoring system is evaluated and a corresponding repair strategy is formulated.

14. The power monitoring system container vulnerability image detection and update system according to claim 10, characterized in that: It also includes a custom detection module for custom detection rules, and loads custom detection rules in real time during the vulnerability detection process, matches the container image information with the custom detection rules, and if a successful matching problem record is found, the corresponding information is stored in the security alarm log.

15. The power monitoring system container vulnerability image detection and update system according to claim 10, characterized in that: The update strategy selection module pulls the latest image version from the image repository and verifies the pulled image version; configures and customizes the pulled image according to the actual needs of the power monitoring system; Rebuild the container image and add additional security hardening measures during the build process to improve the security of the image; Based on the rebuilt container image, stop and delete the old container instance, start a new container instance using the new image version, and configure the container's resources to meet business needs; perform functional verification operations on the updated container to ensure that it can operate normally and handle the tasks of the power monitoring system, and perform performance testing operations to evaluate the container's performance and optimization space.

16. The power monitoring system container vulnerability image detection and update system according to claim 15, characterized in that: It also includes a security reinforcement module for implementing image signature verification. During the container image building process, an image signature tool is used to generate image signature information. During the image pulling and deployment process, an image signature verification tool is used to verify the image signature information. If the signature verification fails, the corresponding image will be refused to be deployed and a corresponding security warning log will be generated.

17. The power monitoring system container vulnerability image detection and update system according to claim 16, characterized in that: The security reinforcement module is also used to implement access control, define access rights levels for different users or user groups to meet business needs and security policy requirements, use access control tools to configure and manage access rights for container images, monitor access control log information to discover and handle unauthorized access and operation behaviors, and record and analyze abnormal access behaviors.

18. The power monitoring system container vulnerability image detection and update system according to claim 16, characterized in that: The security reinforcement module is also used to implement resource restrictions, define resource restriction parameters that can be used by container images, and use container management tools to configure and manage the resource restriction parameters of containers; monitor the resource usage of containers to discover abnormal resource usage behavior, and record and analyze abnormal resource usage behavior.

19. An electronic device, characterized in that: It includes a processor and a memory, and the processor is used to execute a computer program stored in the memory to implement the power monitoring system container vulnerability image detection and update method as described in any one of claims 1 to 9.

20. A computer-readable storage medium, characterized in that The computer-readable storage medium stores at least one instruction, and when the at least one instruction is executed by the processor, the method for detecting and updating vulnerability images of power monitoring system containers according to any one of claims 1 to 9 is implemented.