当前位置:网站首页>Safe landing practice of software supply chain under salesforce containerized ISV scenario
Safe landing practice of software supply chain under salesforce containerized ISV scenario
2022-06-27 11:45:00 【InfoQ】
Containerization ISV Security challenges for delivery
- Third party and open source components bring security risks : Enterprise software projects tend to rely more and more on components from the vendor tripartite or open source community , These components are often transferred in the software supply chain in the form of basic images . An attacker may exploit a vulnerability in the component , Inject malicious code or control the third-party machine environment , Perform mining from cryptocurrency 、 spam 、 To launch through a large botnet DDoS attack .
- The long link of software delivery buries more risks : From the demand analysis of software development stage 、 Code development 、 Integrate 、 test , To ISV Channel specific software delivery in the delivery phase 、 End customer acceptance , The end-user software in the final running phase runs 、 Operation and maintenance . The whole software supply chain has a long cycle , There may be safety risks in all links , Lead to software vulnerabilities 、 Software backdoor 、 Malicious tampering 、 Intellectual property risk 、 Information leakage and other security threats .
- Containerized operation introduces more risk attack surfaces : Container application deployment depends on Linux The kernel feature , Many hackers exploit kernel system vulnerabilities , Launch targeted escape or intrusion attacks from multiple dimensions such as container runtime components and container application deployment configuration . Recent years K8s、Docker、Istio And other open source communities have exposed many high-risk vulnerabilities , This provides an opportunity for the attacker .
Alibaba cloud native software supply chain solution

- Image content security ,ACR It provides an enhanced container image scanning engine jointly with the cloud security center , Cover system vulnerabilities 、 Application vulnerability 、 Risk types such as baseline inspection and malicious samples , High recognition rate 、 Low false positive rate vulnerability scanning capability . meanwhile , Provides container image repair capability , Support automated and efficient repair of risk vulnerabilities , Realize the security closed loop from discovery to repair .
- Image cross account delivery , For inter enterprise ISV Application delivery scenarios ,ACR Cross account synchronization capability is provided to ensure the distribution security of container image and signature .ISV Pass the image and the corresponding signature information through ACR Cross account synchronization capability is delivered to ISV Customer instance of . The corresponding image turns on the immutable image version , Ensure that the version of the image cannot be overwritten .ISV Our customers are ACK When deploying images on , Will be based on ISV Public key signature verification , Ensure that the image is complete and from ISV.
- Deploy policy management :ACK be based on OPA Policy engine and rich preset policy templates , Effective constraint application configuration security , Support container business YAML Multi dimensional deployment policy management , Avoid privilege containers 、 Risk image deployment and other risk behaviors , Strengthen the active management capability of container security on the cluster side .
- Safe sandbox container : The end customer uses a secure sandbox container as the runtime , Compared with the original Docker Runtime , Container applications can be run in a lightweight virtual machine sandbox environment , Have a separate kernel , Better security isolation capability , Compared with the community Kata Container More stable .
- Container runtime security : The end customer uses the runtime security monitoring and alarm capabilities of the cloud security center container , Including virus and malicious program attacks in the container or at the host level 、 Intrusions inside containers 、 Main container side attacks such as container escape and high-risk operation warning , Help customers find security threats in assets in a timely manner 、 Grasp the asset security situation in real time .
Alicloud carries Salesforce It has been awarded as an excellent case of software supply chain security of ICT Academy

Improve the security of the whole link
- Safe delivery : adopt ACR Cross user synchronization links ensure the distribution security of images and signatures . adopt ACR Image tagging and ACK Cross account verification ensures that the contents of the image are trusted . And because the whole delivery process is based on the exclusive synchronization link , It can ensure that the information transferred in the software supply chain will not be accidentally disclosed .
- The security policy : Turn on ACR Mirror security scan policy , Ensure the content security of the image while blocking the delivery of the risk image . The implementation of ACK OPA Deploy policy management , Ensure that the container application configuration is effectively constrained to block the operation of similar privileged containers .
- Safe operation : be based on ACK Safe sandbox container running container , The application runs in a lightweight virtual machine sandbox environment , Have a separate kernel , Better security isolation capability . Based on the cloud security center container runtime security monitoring and alarm capabilities , Avoid malicious attacks at the container or host level , Early warning of high-risk operations .
Improve the efficiency of safety management
- Highly automated : adopt ACR Automatic synchronization 、 Automatic scanning 、 Automatic endorsement ,ACK Automatic signature verification 、 Automatic policy enforcement , And automatically block the follow-up process function after risk identification , Realize containerization DevSecOps The process of .
Alibaba cloud container service escorts the upgrading of the original biochemical architecture of the enterprise cloud

边栏推荐
- [tcapulusdb knowledge base] Introduction to tcapulusdb table data caching
- 飞桨产业级开源模型库:加速企业AI任务开发与应用
- 微软云 (Microsoft Cloud) 技术概述
- 【TcaplusDB知识库】TcaplusDB表数据缓写介绍
- 【TcaplusDB知识库】TcaplusDB单据受理-建表审批介绍
- 【TcaplusDB知识库】Tmonitor系统升级介绍
- [tcaplusdb knowledge base] Introduction to tcaplusdb tcaplusadmin tool
- 进程间通信详解
- Xuri 3sdb, installing the original ROS
- 杰理之IO 口中断使用注意事项【篇】
猜你喜欢

Salesforce 容器化 ISV 场景下的软件供应链安全落地实践

QStyle类用法总结(三)

JSP custom tag
![[tcapulusdb knowledge base] tcapulusdb operation and maintenance doc introduction](/img/04/b1194ca3340b23a4fb2091d1b2a44d.png)
[tcapulusdb knowledge base] tcapulusdb operation and maintenance doc introduction

Codeforces Round #786 (Div. 3) ABCDE

Prevent being rectified after 00? I. The company's recruitment requires that employees cannot sue the company

Oracle-分组统计查询

【值得收藏】Centos7 安装mysql完整操作命令

等等, 怎么使用 SetMemoryLimit?

优博讯出席OpenHarmony技术日,全新打造下一代安全支付终端
随机推荐
Ci/cd automatic test_ 16 best practices for CI / CD pipeline to accelerate test automation
[tcapulusdb knowledge base] tcapulusdb operation and maintenance doc introduction
In depth analysis of error solutions and problems in dynamic loading of unity shadow and outline components
[tcapulusdb knowledge base] tcapulusdb doc acceptance - Introduction to creating game area
等等, 怎么使用 SetMemoryLimit?
Co jump
进程间通信详解
巅峰小店APP仿站开发玩法模式讲解源码分享
QStyle类用法总结(三)
[tcapulusdb knowledge base] Introduction to tcapulusdb system management
After Jerry's sleep, the regular wake-up system continues to run without resetting [chapter]
【TcaplusDB知识库】TcaplusDB-tcapsvrmgr工具介绍(一)
KDD 2022 | 基于分层图扩散学习的癫痫波预测
Precautions for use of IO interface interrupt of Jerry [chapter]
R语言glm函数构建二分类logistic回归模型(family参数为binomial)、使用AIC函数比较两个模型的AIC值的差异(简单模型和复杂模型)
防止被00后整顿?一公司招聘要求员工不能起诉公司
机器学习系统在生产中的挑战
[tcapulusdb knowledge base] tcapulusdb business data backup introduction
Salesforce 容器化 ISV 场景下的软件供应链安全落地实践
15+城市道路要素分割应用,用这一个分割模型就够了!