IP Library › Granted Patent US 12,216,766
Granted Patent B2
US 12,216,766 · App. 17/592,737 · Granted Feb 4, 2025

Techniques for assessing container images for vulnerabilities

Inventor: Olgierd Stanislaw Pieczul (Dublin, IE)
Assignee: Oracle International Corporation
G06F21/577G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,216,766
App. No.
17/592,737
Granted
Feb 4, 2025
Kind
B2
Abstract

Techniques are described for assessing container images for vulnerabilities without actually scanning the container images. A vulnerability assessment system (VAS) is described that is configured to perform vulnerabilities assessment for container images. The VAS is configured to perform the vulnerability assessment without scanning the container images. In certain embodiments, the VAS calculates a vulnerability score for the container image where the vulnerability score is indicative of a probability that the container image contains a vulnerability.

Claims (52)

1. A method performed by one or more processors by executing a set of computer-readable instructions, the method comprising:

determining, based upon metadata associated with a container image to be processed for vulnerabilities, the container image including a hierarchy of a plurality of layers;

calculating a vulnerability score for each layer in the plurality of layers based upon scan results generated from scanning a plurality of container images for vulnerabilities at a given time;

computing a vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers by accessing the vulnerability scores calculated for each of the plurality of layers included in the container image, and based on a weight assigned to a position of the layer in the hierarchy of the plurality of layers;

generating a vulnerability report for the container image, the vulnerability report including the vulnerability score for the container image; and

determining whether to scan the container image based on the vulnerability report.

2. The method of claim 1 , wherein the plurality of container images does not include the container image for which the vulnerability score is computed.

3. The method of claim 1 , wherein calculating the vulnerability score for each layer in the plurality of layers comprises:

for a first layer in the plurality of layers, calculating a vulnerability score for the first layer based upon (a) a number of container images in the plurality of container images that include the first layer, and (b) a number of container images in the plurality of container images including the first layer that were found to contain a vulnerability.

4. The method of claim 1 , wherein calculating the vulnerability score for each layer in the plurality of layers comprises:

for a first layer in the plurality of layers, calculating the vulnerability score for the first layer as a ratio of (a) a number of container images in the plurality of container images that include the first layer, and (b) a number of container images in the plurality of container images including the first layer that were found to contain a vulnerability.

5. The method of claim 1 , wherein the plurality of container images includes the container image for which the vulnerability score is computed.

6. The method of claim 1 , further comprising:

determining, based upon the vulnerability score computed for the container image, whether an action is to be performed for the container image.

7. The method of claim 6 , wherein determining whether the action is to be performed comprises:

identifying a preconfigured rule; and

determining whether the action is to be performed based upon the vulnerability score computed for the container image and the identified rule.

8. The method of claim 6 , wherein determining whether the action is to be performed comprises:

determining that the action is to be performed if the vulnerability score computed for the container image is greater than a threshold value.

9. The method of claim 6 , wherein the action comprises performing a vulnerability scan on the container image.

10. The method of claim 6 , wherein the action comprises generating an ordered list of a set of container images and associated vulnerability scores, the set of container images including the container image for which the vulnerability score is computed, wherein the set of container images are ordered in the ordered list based upon their associated vulnerability scores and the container images in the ordered list are scheduled for a vulnerability scan based upon their order in the ordered list starting from a highest ranked container image in the ordered list.

11. The method of claim 1 , further comprising identifying a hierarchy between the layers in the plurality of layers in the container image, wherein computing the vulnerability score for the container image comprises:

generating the vulnerability score for the container image based upon the vulnerability scores calculated for plurality of layers, and for each layer, a weight assigned to the layer based upon a memory size of the layer.

12. The method of claim 1 , further comprising identifying the hierarchy between the layers in the plurality of layers in the container image, wherein computing the vulnerability score for the container image comprises:

generating the vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers in the hierarchy, and for each layer, the weight assigned to the layer based upon a most recent scan time of the layer.

13. The method of claim 1 , further comprising identifying a hierarchy between the layers in the plurality of layers in the container image, wherein computing the vulnerability score for the container image comprises determining an arithmetic mean of the vulnerability scores calculated for the plurality of layers.

14. The method of claim 1 wherein computing the vulnerability score for the container image comprises:

identifying, from a plurality of computation techniques, a first computation technique to be used for computing the vulnerability score for the container image; and

generating the vulnerability score for the container image by using the identified first computation technique.

15. The method of claim 1 , wherein computing the vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers comprises:

generating a first vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers;

determining a time period since a previous vulnerability scan of the container image;

generating a second vulnerability score for the container image based upon the first vulnerability score and the time period since the previous vulnerability scan of the container image, wherein the second vulnerability score is different from the first vulnerability score; and

outputting the second vulnerability score as the vulnerability score for the container image.

16. A system, comprising:

one or more processors; and

a non-transitory computer-readable storage medium comprising computer-executable instructions that, when executed by the processor, cause the system to perform processing comprising:

determining, based upon metadata associated with a container image to be processed for vulnerabilities, the container image including a hierarchy of a plurality of layers;

calculating a vulnerability score for each layer in the plurality of layers based upon scan results generated from scanning a plurality of container images for vulnerabilities at a given time;

computing a vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers by accessing the vulnerability scores calculated for each of the plurality of layers included in the container image, and based on a weight assigned to a position of the layer in the hierarchy of the plurality of layers;

generating a vulnerability report for the container image, the vulnerability report including the vulnerability score for the container image; and

determining whether to scan the container image based on the vulnerability report.

17. The system of claim 16 , wherein calculating the vulnerability score for each layer in the plurality of layers comprises:

for a first layer in the plurality of layers, calculating the vulnerability score for the first layer based upon (a) a number of container images in the plurality of container images that include the first layer, and (b) a number of container images in the plurality of container images including the first layer that were found to contain a vulnerability.

18. A non-transitory computer-readable storage medium comprising computer-executable instructions that when executed by a processor, cause the processor to perform processing comprising:

determining, based upon metadata associated with a container image to be processed for vulnerabilities, the container image including a hierarchy of a plurality of layers;

calculating a vulnerability score for each layer in the plurality of layers based upon scan results generated from scanning a plurality of container images for vulnerabilities at a given time;

computing a vulnerability score for the container image based upon the vulnerability scores calculated for the plurality of layers by accessing the vulnerability scores calculated for each of the plurality of layers included in the container image, and based on a weight assigned to a position of the layer in the hierarchy of the plurality of layers;

generating a vulnerability report for the container image, the vulnerability report including the vulnerability score for the container image; and

determining whether to scan the container image based on the vulnerability report.

19. The method according to claim 1 , wherein a higher weight is given to a higher layer, and a lower weight is given to a lower layer.

20. The method according to claim 1 , wherein a higher weight is given to a layer with a larger memory size, and a lower weight is given to a layer with a lower memory size.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2022
From: PIECZUL, OLGIERD STANISLAW
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 058888/0861 →
Continuity (1)
Related Publication 20230252157A1 · Aug 10, 2023
References Cited (37)
US 7188367B1 · Edwards · 2007 [cited by examiner]
US 8661126B2 · Cole · 2014 [cited by examiner]
US 10467419B1 · Youngberg · 2019 [cited by examiner]
US 10719612B2 · Stopel · 2020 [cited by examiner]
US 10754637B1 · Zeng · 2020 [cited by examiner]
US 11757907B1 · Berger · 2023 [cited by examiner]
US 20060085852A1 · Sima · 2006 [cited by examiner]
US 20120304300A1 · LaBumbard · 2012 [cited by examiner]
US 20160294847A1 · Coronado · 2016 [cited by examiner]
US 20170098087A1 · Li · 2017 [cited by examiner]
US 20180253558A1 · Li · 2018 [cited by examiner]
US 20180324203A1 · Estes · 2018 [cited by examiner]
US 20190294461A1 · Woods · 2019 [cited by examiner]
US 20200082094A1 · Mcallister · 2020 [cited by examiner]
US 20200097662A1 · Hufsmith · 2020 [cited by examiner]
US 20200110885A1 · Bellis · 2020 [cited by examiner]
US 20200210590A1 · Doyle · 2020 [cited by examiner]
US 20200356806A1 · Li · 2020 [cited by examiner]
US 20210096894A1 · Rupprecht · 2021 [cited by examiner]
US 20210173935A1 · Ramasamy · 2021 [cited by examiner]
US 20210226978A1 · He · 2021 [cited by examiner]
US 20220171856A1 · Bhatt · 2022 [cited by examiner]
US 20220318395A1 · Janakiraman · 2022 [cited by examiner]
EP 3355193A1 · 2018 [cited by examiner]
KR 100656351B1 · 2006 [cited by examiner]
Christopher Thomas Enoch, Calculating Common Vulnerability Scoring System's Environmental Metrics Using Context-Aware Network Graphs, Dec. 15, 2021, Rochester Institute of Technology, MS Thesis, pp. 44-58 (Year: 2021). [cited by examiner]
Ehsan Mostajeran et al., “Quantitative Risk Assessment of Container Based Cloud Platform”, 2017 IEEE Conference on Application, Information and Network Security (AINS), Published 2017. (Year: 2017). [cited by examiner]
Harun Ecik, “Comparison of Active Vulnerability Scanning vs. Passive Vulnerability Detection”, 14th International Conference on Information Security and Cryptology, Published: Dec. 2-3, 2021 (Year: 2021). [cited by examiner]
“Container Analysis and Vulnerability Scanning”, Available Online at: https://cloud.google.com/container-registry/docs/container-analysis, Accessed from Internet on Feb. 3, 2022, pp. 1-3. [cited by applicant]
“Container Scanning”, Available Online at: https://cloud.google.com/container-analysis/docs/container-scanning-overview, Accessed from Internet on Feb. 3, 2022, pp. 1-6. [cited by applicant]
“Introduction to Microsoft Defender for Container Registries (Deprecated)”, Available Online at: https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-container-registries-introduction, Jan. 12, 2022, p… [cited by applicant]
“Managing Image Security with Vulnerability Advisor”, Available Online at: https://cloud.ibm.com/docs/va?topic=va-va_index&interface=ui, Accessed from Internet on Feb. 3, 2022, pp. 1-8. [cited by applicant]
“Open Source Container Security with Syft & Grype”, Anchore, Available Online at: https://anchore.com/opensource/, Accessed from Internet on Feb. 3, 2022, 12 pages. [cited by applicant]
“Overview of Microsoft Defender for Containers”, Available Online at: https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction?tabs=defender-for-container-arch-aks, Jan. 24, 2022, p… [cited by applicant]
“The Fundamentals of Container Security”, Anchore.com, 2020, 18 pages. [cited by applicant]
“What is Clair?”, Available Online at: https://www.redhat.com/en/topics/containers/what-is-clair, Jan. 8, 2019, pp. 1-7. [cited by applicant]
Hausenblas et al., “Native Container Image Scanning in Amazon ECR”, Available Online at: https://aws.amazon.com/blogs/containers/amazon-ecr-native-container-image-scanning/, Oct. 28, 2019, pp. 1-7. [cited by applicant]