Abstract:
Due to less time consumption for starting up containers, the use of container technology has grown compared to virtual machines usage. Though many container platforms exi...Show MoreMetadata
Abstract:
Due to less time consumption for starting up containers, the use of container technology has grown compared to virtual machines usage. Though many container platforms exist, Docker is the widely used container platform as it let developers easily pack, transport, and run applications using lightweight, portable and self- sufficient containers that can execute in any environment. To use Docker containers, the images are downloaded from a registry called the Docker hub. Since container technology shares the OS-kernel with the host, it is extremely important to strengthen and monitor the security of containers and the images they run from. As a result, there are numerous tools for container scanning that helps to find the security vulnerabilities exist in containers. Grype proves to be the most accurate tool among various other container image tools exist like Trivy, Dagda etc. It still misses significant of vulnerabilities while scanning an image. Addressing this kind of inefficiency scanning is vital to ensure the security of the host machine which runs the container. Complete understanding of the Grype tool and resolving some of the persistent issues in Grype like failing to detect all the vulnerabilities in an image and the absence of a user interface is focused. A comparative analysis on existing scanning tools and proposed scanning tool is presented to showcase the strength of the proposed tool.
Published in: 2023 2nd International Conference on Advancements in Electrical, Electronics, Communication, Computing and Automation (ICAECA)
Date of Conference: 16-17 June 2023
Date Added to IEEE Xplore: 07 August 2023
ISBN Information: