Docker Remote API未授权访问漏洞利用工具
作者:

Docker Remote API Unauthorized Access Vulnerability Exploitation Tool
Author:
  • 摘要
  • | |
  • 访问统计
  • |
  • 参考文献 [6]
  • |
  • 相似文献 [20]
  • | | |
  • 文章评论
    摘要:

    通过分析Docker Remote API未授权访问漏洞的原理,设计并实现Docker Remote API未授权访问漏洞利用工具.该工具弥补了当前网络环境下此种漏洞检测工具的缺失,并提供批量检测功能,大大提高了漏洞检测效率,为漏洞修复等安全工作打下基础,是一种效果好成本低的Web应用安全防护方案.

    Abstract:

    Through the analysis of Docker Remote API Unauthorized Access Vulnerability, this paper proposes a vulnerability exploitation tool. The tool fills the gap of vulnerability detection tools and provides the batch testing function. It achieves high efficiency of vulnerability detection and lays the foundation for web security work such as bug fixes. It is effective and has low cost for the improvement of web security.

    参考文献
    1 2017 internet security threat report. https://www.symantec. com/security-center/threat-report.
    2 Yeo J. Using penetration testing to enhance your company's security. Computer Fraud & Security, 2013, 2013(4):17-20.
    3 Docker, Inc. What is Docker. http://www.docker.com/whatisdocker.[2015-01-29].
    4 Seo KT, Hwang HS, Moon IY, et al. Performance comparison analysis of Linux container and virtual machine for building cloud. Advanced Science and Technology Letters, 2014, 66:105-111.
    5 Docker, Inc. Understand what are the major Docker components. https://docs.docker.com/introduction/understanding-docker.[2015-03-21].
    6 孙宏亮. Docker源码分析(一):Docker架构. http://www.infoq.com/cn/articles/docker-source-code-analysis-part1.[2014-09-25].
    引证文献
    网友评论
    网友评论
    分享到微博
    发 布
引用本文

孙建,蔡翔,王潇,夏雨潇. Docker Remote API未授权访问漏洞利用工具.计算机系统应用,2017,26(8):247-251

复制
分享
文章指标
  • 点击次数:1812
  • 下载次数: 3131
  • HTML阅读次数: 0
  • 引用次数: 0
历史
  • 收稿日期:2016-11-21
  • 在线发布日期: 2017-10-31
文章二维码
您是第12829690位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京海淀区中关村南四街4号 中科院软件园区 7号楼305房间,邮政编码:100190
电话:010-62661041 传真: Email:csa (a) iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号