Abstract

Docker image is the foundation for container operation. Docker Hub is the largest online repository of public container images. Users can upload and download any random image file to the hub due to the absence of adequate security scanning and detection, potentially causing substantial security risks. This paper introduces ZeroDVS, a container image traceability and security detection system based on inheritance graphs. In ZeroDVS, a basic image inheritance graph is built with 160 official images published by Docker Hub. Then, the basic image source of the downloaded image can be identified, and the public vulnerability database is used to scan for public vulnerabilities in image files. ZeroDVS scans the public container images of Docker Hub and identifies the inheritance relationship of public container images to detect public vulnerabilities in the image layer above the parent image simultaneously. Docker image is the foundation for container operation. Docker Hub is the largest online repository of public container images. Users can upload and download any random image file to the hub due to the absence of adequate security scanning and detection, potentially causing substantial security risks. This paper introduces ZeroDVS, a container image traceability and security detection system based on inheritance graphs. In ZeroDVS, a basic image inheritance graph is built with 160 official images published by Docker Hub. Then, the basic image source of the downloaded image can be identified, and the public vulnerability database is used to scan for public vulnerabilities in image files. ZeroDVS scans the public container images of Docker Hub and identifies the inheritance relationship of public container images to detect public vulnerabilities in the image layer above the parent image simultaneously.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.