Understanding the Quality of Container Security Vulnerability Detection Tools

Understanding the Quality of Container Security Vulnerability Detection Tools
复制标题

了解容器安全漏洞检测工具的质量

DOI:
--
复制
发表时间:
2021
期刊:
arXiv.org
影响因子:
--
通讯作者:
S. Toor
S. Toor
中科院分区:
--
文献类型:
--
作者:
Omar Javed;S. Toor

文献摘要

被引文献

相似文献

虚拟化使信息和通信技术行业能够更好地管理计算资源。在这方面,虚拟化方法的改进以及需要一致的运行时环境,较低的开销和较小的包装尺寸导致容器的采用量不断增长。这是一项包装应用程序,其依赖项和操作系统(OS)的技术,可以作为孤立的单元运行。但是,使用容器的紧迫关注是其对安全攻击的敏感性。因此,许多容器扫描工具可用于检测容器安全漏洞。因此,在这项研究中,我们通过提出两个反映覆盖范围和准确性的指标来研究现有容器扫描工具的质量。我们使用不同的容器扫描工具(例如Clair,Anchore和Microscanner)分析了59个流行的公共容器图像,用于在Dockerhub上托管的Java应用程序。我们的发现表明,现有的容器扫描方法无法检测应用程序包漏洞。此外,现有工具的精度没有很高的精度,因为最佳性能工具会错过34%的漏洞。最后,我们还通过评估完整的脆弱性景观(即,图像中检测到的漏洞数量)来展示在Dockerhub上托管的Java应用程序的质量。
Virtualization enables information and communications technology industry to better manage computing resources. In this regard, improvements in virtualization approaches together with the need for consistent runtime environment, lower overhead and smaller package size has led to the growing adoption of containers. This is a technology, which packages an application, its dependencies and Operating System (OS) to run as an isolated unit. However, the pressing concern with the use of containers is its susceptibility to security attacks. Consequently, a number of container scanning tools are available for detecting container security vulnerabilities. Therefore, in this study, we investigate the quality of existing container scanning tools by proposing two metrics that reflects coverage and accuracy. We analyze 59 popular public container images for Java applications hosted on DockerHub using different container scanning tools (such as Clair, Anchore, and Microscanner). Our findings show that existing container scanning approach does not detect application package vulnerabilities. Furthermore, existing tools do not have high accuracy, since 34% vulnerabilities are being missed by the best performing tool. Finally, we also demonstrate quality of Docker images for Java applications hosted on DockerHub by assessing complete vulnerability landscape i.e., number of vulnerabilities detected in images.