IP Library › Granted Patent US 12,602,484
Granted Patent B2
US 12,602,484 · App. 17/382,771 · Granted Apr 14, 2026

Docker image vulnerability inspection device and method for performing docker file analysis

Inventors: Souhwan Jung (Seoul, KR); Thien-Phuc Doan (Seoul, KR); Songi Gwak (Seoul, KR)
Assignee: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
G06F21/577G06F9/30145G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,484
App. No.
17/382,771
Filed
Jul 22, 2021
Granted
Apr 14, 2026
Kind
B2
Art Unit
2432
USPC
726/25
Abstract

Provided is a docker image vulnerability inspection device, which extracts and classifies an instruction by analyzing a manifest file of a docker image, maps a file designated in the instruction to a plurality of classes, sets vulnerability of the file according to an extraction condition preset to each of the plurality of classes, and checks vulnerability of the file according to the vulnerability set to the file based on a CVE database prepared in advance.

Claims (35)

1 . A docker image vulnerability inspection device, comprising:

an instruction extracting unit configured to extract an instruction by analyzing a manifest file of a docker image and classify the instruction according to a name of the instruction;

a file mapping unit configured to map a file designated in the instruction to a plurality of classes based on the instruction classified according to the name of the instruction;

a vulnerability setting unit configured to set vulnerability of the file mapped into the plurality of classes according to an extraction condition preset to each of the plurality of classes; and

a vulnerability checking unit configured to check the set vulnerability of the file based on a CVE database prepared in advance,

wherein the instruction extracting unit is further configured to classify the instruction extracted by analyzing the manifest file into a no-operation instruction or an operation instruction according to whether there is a no-operation symbol appearing from the name of the instruction,

wherein when the instruction extracted by analyzing the manifest file is classified into the no-operation instruction, the instruction extracting unit is further configured to classify the instruction into a base instruction showing any file of an operating system in which the docker image is executed or an additional instruction provided to create any file by the docker image, according to a name of the no-operation instruction,

wherein the file mapping unit is further configured to perform:

when the instruction is classified according to the name of the instruction into a base instruction showing any file of an operating system in which the docker image is executed, mapping the file designated in the base instruction to a base class;

when the instruction is classified according to the name of the instruction into an additional instruction provided to create any file by the docker image, mapping the file designated in the additional instruction to an additional class; and

when the instruction is classified according to the name of the instruction into an execution instruction provided to execute the file by the docker image, mapping the file designated in the execution instruction to an execution class,

wherein the vulnerability setting unit is further configured to perform:

for the file mapped to the base class, setting the vulnerability as safe;

for the file mapped to the additional class, setting the vulnerability as weak; and

for the file mapped to the execution class, when the file mapped to the execution class has a download command or a compile command, setting the vulnerability as weak,

wherein the instruction extracting unit is further configured to extract the manifest file provided in the docker image and extract at least one instruction from a history field appearing in the manifest file.

2 . The device of claim 1 ,

wherein when the instruction extracted by analyzing the manifest file is classified into the operation instruction, the instruction extracting unit is further configured to classify the instruction classified as the operation instruction into an execution instruction provided to execute any file by the docker image.

3 . A docker image vulnerability inspection method, comprising:

extracting an instruction by analyzing a manifest file of a docker image and classifying the instruction according to a name of the instruction;

mapping a file designated in the instruction to a plurality of classes based on the instruction classified according to the name of the instruction;

setting vulnerability of the file mapped into the plurality of classes according to an extraction condition preset to each of the plurality of classes; and

checking the vulnerability of the file based on a CVE database prepared in advance,

wherein the classifying the instruction comprises classifying the instruction extracted by analyzing the manifest file into a no-operation instruction or an operation instruction according to whether there is a no-operation symbol appearing from the name of the instruction,

wherein when the instruction extracted by analyzing the manifest file is classified into the no-operation instruction, the classifying the instruction further comprises classifying the instruction into a base instruction showing any file of an operating system in which the docker image is executed or an additional instruction provided to create any file by the docker image, according to a name of the no-operation instruction,

wherein the mapping the file to the plurality of classes comprises:

when the instruction is classified according to the name of the instruction into a base instruction showing any file of an operating system in which the docker image is executed, mapping the file designated in the base instruction to a base class;

when the instruction is classified according to the name of the instruction into an additional instruction provided to generate any file by the docker image, mapping the file designated in the additional instruction to an additional class; and

when the instruction is classified according to the name of the instruction into an execution instruction provided to execute the file by the docker image, mapping the file designated in the execution instruction to an execution class,

wherein the setting the vulnerability of the file comprises:

for the file mapped to the base class, setting the vulnerability as safe,

for the file mapped to the additional class, setting the vulnerability as weak, and

for the file mapped to the execution class, when the file mapped to the execution class has a download command or a compile command, setting the vulnerability as weak,

wherein the classifying the instruction comprises extracting the manifest file provided in the docker image and extracting at least one instruction from a history field appearing in the manifest file.

4 . The method of claim 3 , wherein when the instruction extracted by analyzing the manifest file is classified into the operation instruction, the classifying the instruction further comprises classifying the instruction classified as the operation instruction into an execution instruction provided to execute any file by the docker image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2021
From: JUNG, SOUHWAN; DOAN, THIEN-PHUC; GWAK, SONGI
To: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
Reel/Frame 056947/0423 →
Priority Claims (1)
KR 10-2020-0128988 · Oct 6, 2020 · national
Continuity (1)
Related Publication 20220108023A1 · Apr 7, 2022
References Cited (39)
US 8161548B1 · Wan · 2012 [cited by examiner]
US 9600668B2 · Wang · 2017 [cited by examiner]
US 10346611B1 · Mao · 2019 [cited by examiner]
US 10803177B2 · Adam · 2020 [cited by examiner]
US 11463478B2 · Nadgowda · 2022 [cited by examiner]
US 20120159629A1 · Lee · 2012 [cited by examiner]
US 20170109536A1 · Stopel · 2017 [cited by examiner]
US 20170116415A1 · Stopel · 2017 [cited by examiner]
US 20170177877A1 · Suarez · 2017 [cited by examiner]
US 20170318048A1 · Htay · 2017 [cited by examiner]
US 20180032720A1 · Milner · 2018 [cited by examiner]
US 20180114025A1 · Cui · 2018 [cited by examiner]
US 20180239903A1 · Bodin · 2018 [cited by examiner]
US 20180307837A1 · Ahn · 2018 [cited by examiner]
US 20180309747A1 · Sweet · 2018 [cited by examiner]
US 20190026474A1 · Adam · 2019 [cited by examiner]
US 20190354389A1 · Du · 2019 [cited by examiner]
US 20200082095A1 · Mcallister · 2020 [cited by examiner]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200159933A1 · Ciano · 2020 [cited by examiner]
US 20200193016A1 · Zeng · 2020 [cited by examiner]
US 20200218798A1 · Kosaka · 2020 [cited by examiner]
US 20200285733A1 · Kim · 2020 [cited by examiner]
US 20210117548A1 · Gokhman · 2021 [cited by examiner]
US 20210126949A1 · Nadgowda · 2021 [cited by examiner]
US 20210133330A1 · Boulton · 2021 [cited by examiner]
US 20210173935A1 · Ramasamy · 2021 [cited by examiner]
US 20210382997A1 · Yi · 2021 [cited by examiner]
US 20210390172A1 · Kim · 2021 [cited by examiner]
US 20220043916A1 · Wolfson · 2022 [cited by examiner]
JP 2020154861A · 2020 [cited by applicant]
KR 101445634B1 · 2014 [cited by applicant]
KR 1020190076212A · 2019 [cited by applicant]
KR 102048141B1 · 2019 [cited by applicant]
WO WO2017106726A1 · 2017 [cited by examiner]
WO WO2020161622A1 · 2020 [cited by examiner]
“What does #(nop) mean in docker history?,” StackOverflow, https://stackoverflow.com/questions/41298934/what-does-nop-mean-in-docker-history, 2016. [cited by examiner]
J. Cito, G. Schermann, J. E. Wittern, p. Leitner, S. Zumberi and H. C. Gall, “An Empirical Analysis of the Docker Container Ecosystem on GitHub,” 2017 IEEE/ACM 14th International Conference on Mining Software Repositori… [cited by examiner]
Jagelid, M. (2020). Container vulnerability scanners: An analysis. [cited by examiner]