Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
Mubin Ul Haque, M. Ali Babar

TL;DR
This empirical study investigates the exploitability and impact of vulnerabilities in container base-images, analyzing their prevalence and characteristics in open-source containerized software to improve security awareness.
Contribution
It provides the first comprehensive empirical analysis of base-image vulnerabilities, characterizing their exploitability, impact, and prevalence in real-world containerized applications.
Findings
Identified 1,983 unique vulnerabilities in base-images.
Discovered 13 novel insights about vulnerability exploitability and impact.
Found widespread presence of vulnerable base-images in open-source projects.
Abstract
Container technology, (e.g., Docker) is being widely adopted for deploying software infrastructures or applications in the form of container images. Security vulnerabilities in the container images are a primary concern for developing containerized software. Exploitation of the vulnerabilities could result in disastrous impact, such as loss of confidentiality, integrity, and availability of containerized software. Understanding the exploitability and impact characteristics of vulnerabilities can help in securing the configuration of containerized software. However, there is a lack of research aimed at empirically identifying and understanding the exploitability and impact of vulnerabilities in container images. We carried out an empirical study to investigate the exploitability and impact of security vulnerabilities in base-images and their prevalence in open-source containerized…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Software System Performance and Reliability · Cloud Data Security Solutions
