arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.25793cs.CRcs.SE

缩小差距:企业内部源代码中通过语义聚类自动发现安全Dockerfile参考标准

Closing the Gap: Automated Discovery of Secure Dockerfile Reference Standards via Semantic Clustering in Enterprise Inner Source

Jessica Hösl, Benedikt Hofmann, Patrick Stöckle

首次发表
浏览论文内容

中文总结 AI 辅助

针对企业内部源代码中Dockerfile的安全配置错误与技术债务问题,提出六阶段自动化流水线,发现其内部存在可提升安全态势的参考实现,为企业供应链安全推荐系统提供数据基础。

中文摘要 AI 辅助

容器化技术主导了企业软件交付,但用于构建容器镜像的Dockerfile常常存在安全配置错误和结构性技术债务。在企业内部源代码环境中,由于专有上下文和隔离治理机制,开源领域的研究成果难以直接应用,该问题尚未得到充分理解。本文提出一个六阶段自动化流水线:(1)爬取企业GitLab实例;(2)为每个Dockerfile补充静态安全与质量指标(Hadolint、ShellCheck、Trivy)及生命周期数据;(3)利用大语言模型生成的语义描述与HDBSCAN对功能相同的工作负载进行分组;(4)量化与集群内部参考实现的优化差距。将该流水线应用于某大型工业企业的6200多个仓库中的11470个Dockerfile,发现存在系统性缺陷:99%的文件至少存在一项安全配置错误,80.8%违反Dockerfile最佳实践,中位数制品已838天未修订。尽管如此,83%的功能集群中已存在高质量参考实现,采用这些内部标准无需开发任何新模板即可将平均安全态势评分提高60.4%。这些基于某组织内部源代码生态系统的发现,为未来针对企业供应链安全的自动化、上下文感知推荐系统提供了数据驱动的基础;观察到的技术债务分布与优化差距是否适用于其他企业,仍是未来多组织研究的开放问题。

英文摘要

Containerization dominates enterprise software delivery, yet Dockerfiles that assemble container images frequently harbor security misconfigurations and structural technical debt. This problem is poorly understood in corporate inner-source environments, where proprietary context and isolated governance prevent direct application of open-source findings. We present an automated, six-stage pipeline that: (1) crawls an enterprise GitLab instance, (2) enriches each Dockerfile with static security and quality metrics (Hadolint, ShellCheck, Trivy) and lifecycle data, (3) groups functionally identical workloads using LLM-generated semantic descriptions and HDBSCAN, and (4) quantifies the optimization gap against cluster-internal reference implementations. Applied to 11,470 Dockerfiles from over 6,200 repositories at a single large industrial company, we find a systemic deficit: 99\% of files contain at least one security misconfiguration, 80.8\% violate Dockerfile best practices, and the median artifact has not been revised for 838~days. Despite this, high-quality reference implementations already exist within 83\% of functional clusters. Adopting these internal standards would increase the average security posture score by 60.4\% without developing any new templates. These findings, grounded in one organization's inner-source ecosystem, provide a data-driven foundation for future automated, context-aware recommender systems targeting enterprise supply-chain security; whether the observed technical-debt distribution and optimization gap generalize to other enterprises remains an open question for future multi-organization study.

补充信息

↑