View and handle detected image risks
The container image scan feature of Security Center detects system vulnerabilities, application vulnerabilities, baseline risks, malicious samples, and sensitive files in your image assets and displays the results by category. This helps you understand the security risks in your image assets. This topic describes how to view the security risks in your image assets and how to remediate them.
Prerequisites
An image scan is performed. For more information, see Configure and run image security scans.
Background information
The container image scan feature detects system vulnerabilities, application vulnerabilities, baseline risks, malicious samples, and sensitive files in images. Only some system vulnerabilities can be fixed. For other types of risks, we recommend that you use the fix commands, impact descriptions, or malicious file paths provided by Security Center to handle the security risks in your images in a timely manner.
View risk statistics
Security Center allows you to view the numbers of images at high, medium, and low risk levels, as well as the numbers of scanned and unscanned images. This helps you quickly identify images with security risks.
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
In the upper section of the Container Image Scan page, view the following statistics.
-
Numbers of images at high, medium, and low risk levels
Click the number under High-risk Image, Medium-risk Image, or Low-risk Image to go to the Container page and view the details of the affected assets.
-
Numbers of scanned and unscanned images
Click the number under Scanned Images or Unscanned Image to view the image list in the Scanned Images or Unscanned Images panel.
ImportantUnscanned images include images that have not been scanned and images that failed to scan.
-
Container Image Scan quota
If the remaining quota is insufficient, click Add Authorization to purchase more Container Image Scan on the buy page.
-
View image scan results
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
On the Container Image Scan page, click a tab to view image scan results.
Image vulnerability risks
On the System Vulnerability and Application Vul(s) tabs, you can view the detected vulnerability lists. You can perform the following operations:
-
Search for vulnerabilities
You can select Image Scan or Container Runtime Image Scan from the drop-down list above the vulnerability list, select a vulnerability severity level (high, medium, or low), or search by instance ID, repository name, namespace, digest, or vulnerability name to find vulnerabilities.
NoteFuzzy search is supported for repository names and vulnerability names.
-
View vulnerability details
Click View in the Actions column for a vulnerability to view the vulnerability details page. On the vulnerability details page, you can perform the following operations:
-
View Alibaba Cloud vulnerability library details
Click a vulnerability ID to go to the Alibaba Cloud vulnerability library, where you can view detailed information about the vulnerability, including the description, basic information, and fix recommendations.
-
View fix commands and impact descriptions for image vulnerabilities
In the affected images or containers list, click Details to view the fix commands and impact descriptions for the image vulnerability.
NoteIf a PAI label appears to the right of Image Address/Version, the image is deployed through Platform for AI (PAI).
-
Image baseline check
On the Image Baseline Check tab, view the image baseline check results. You can perform the following operations:
-
Search for baseline check results
You can use the search component above the list to search for baseline check results by severity (High Risk, Medium-risk Items, Low Risk), baseline name, or baseline category.
-
View image baseline check results
In the image baseline check results list, you can view the Baseline Name/Category, Affected Image, Last Scan Time, First Scan Time, and baseline fix Status for each baseline.
-
View image baseline check result details
In the image baseline check results list, click Details in the Actions column to open the details panel. You can view the affected image and container assets, including the image address, image version, container information, detection time, first detection time, and the number of baseline risks at different levels.
-
Click Details in the Actions column for an image asset to open the Risk Item panel and view the risk check items for that image asset.
-
Click the Affected Image or Affected Container tab and click the
icon to export the risk list of affected images or containers.
-
Malicious image samples
ImportantMalicious image samples can compromise your server system by changing memory attributes from readable and writable to readable and executable, or by modifying network proxy settings. We recommend that you handle malicious image samples as soon as possible.
On the Malicious Image Sample tab, view the detected malicious image samples. You can perform the following operations:
-
Search for malicious image samples
In the upper-left corner of the malicious image sample list, select the severity level: Urgent, Suspicious, or Notice. You can also search by instance ID, repository name, namespace, digest, or malicious sample name.
-
View the malicious image sample list
In the malicious image sample list, you can view the sample name, number of affected images, first or last scan time, and processing status.
-
View malicious image sample details
Click Details in the operation column for a Malicious Image Sample sample to view its details.
Sensitive image files
On the Sensitive Image File tab, view the detected sensitive image files. You can perform the following operations:
-
Search for sensitive image files
In the upper-left corner of the sensitive image file list, select the severity level: high, medium, or low. You can also search by alert type of sensitive files or type of sensitive information.
-
View the sensitive image file list
In the sensitive image file list, you can view the alert types, types of sensitive information, total number of affected images, number of unhandled affected images, first scan time, and last scan time.
-
View sensitive image file details
Click Details in the operation column for a sensitive file to view the list of affected images. Click Details in the operation column for an affected image to view the list of files that contain sensitive information.
Image build command risks
On the Image Build Command Risks tab, view the detected image build command risks. You can perform the following operations:
-
Search for image build command risks
In the upper-left corner of the image build command risk list, select the severity level: High Risk, Medium-risk Items, or Low Risk. You can also search by risk type or category.
-
View the image build command risk list
In the image build command risk list, you can view the risk types, risk categories, total number of affected images, number of unhandled affected images, first scan time, and last scan time.
-
View image build command risk details
Click Details in the operation column for a risk to view the list of affected images. Click Details in the operation column for an affected image to view the build command risks detected in that image.
-
-
Optional: On the Container Image Scan page, click the Image Vulnerability, Image Baseline Check, or Malicious Image Sample tab, and then click the
icon in the upper-right corner of the list to export the scan results.
Handle detected image risks
You can handle vulnerabilities and risks based on the risk details and fix recommendations.
-
Image Vulnerability: Investigate and fix vulnerabilities in images based on the vulnerability details and fix recommendations.
Security Center supports one-click fixing for some image system vulnerabilities. When an affected image is updated and fixable packages are available, you can use the following methods:
NoteYou can go to the page and click the Image tab to view the image repository details. For more information, see View image information.
-
Manual fix: In the system vulnerability list, find a vulnerability with Fix highlighted in the Actions column. Click Fix. In the Affected Image list, click Fix in the operation column for the target image and follow the prompts to fix the vulnerability.
-
Automatic fix: Configure the fix cycle and scope. For more information, see Image fixing.
-
-
Image Baseline Check: Investigate and fix baseline risks in images manually based on the baseline check result details.
-
Malicious Image Sample: We recommend that you handle malicious samples in images as soon as possible based on the malicious sample details, such as the paths of malicious files.
If you confirm that the affected image has no risks, you can go to the details panel of the malicious sample, find the affected image, and click Handle in the Actions column to add the alert type to the whitelist. After whitelisting, the system no longer detects the malicious sample risk for the image.
-
Sensitive Image File and Image Build Command Risks: We recommend that you assess the risks based on your business conditions, remove or correct files and build commands that may contain security risks, and recreate the images.
In the details panel of a sensitive file or build command, click Handle in the operation column and choose a handling method:
-
Add to Whitelist: If you confirm that the sensitive file or image build command has no risks, you can add the alert type to the whitelist. After whitelisting, the system no longer detects the sensitive file or image build command risk for the image.
-
Ignore: Ignore the current risk alert. When the image is scanned again and matches the detection policy, a new alert is generated.
-
Mark as False Positive: If you confirm that the risk is a false positive, mark it as a false positive. Security Center optimizes its scanning capabilities based on your feedback.
-
After handling the detected image risks, you can go to the Container Image Scan page and click Scan Now to rescan images and update the scan results.