Computer and Modernization

Previous Articles     Next Articles

SecDr:A Content Safe Docker Registry

  

  1.   (1.Nari Group Corporation/State Grid Electric Power Research Institute, Nanjing 210003, China; 
      2. State Grid Jiangsu Electric Power Co. Ltd., Nanjing 210024, China) 
  • Received:2017-12-06 Online:2018-06-13 Published:2018-06-13

Abstract:  Docker is a greatly popular container engine since its rapid deployment and extensive portability. However, it raises image content safe problem. Aiming at this issue, A Docker image content safe registry named SecDr is designed. Firstly, SecDr hierarchically scans Docker image files which are pushed to Docker registry to detect the static vulnerabilities, and confirms any of its installed software packages to match any known vulnerabilities’ features. The vulnerabilities are updated from common vulnerabilities and exposures (CVE) databases. Secondly, SecDr facilitates customized penetration testing to detect the vulnerabilities introduced by developers. The results show that SecDr is able to solve the content safe problem in Docker registry.

Key words: Docker, scanning, penetration test

CLC Number: