Pith. sign in

REVIEW 2 cited by

Understanding the Quality of Container Security Vulnerability Detection Tools

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2101.03844 v1 pith:QXXABWOT submitted 2021-01-11 cs.CR

classification cs.CR
keywords containertoolsscanningvulnerabilitiesexistingimagesqualitysecurity
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Virtualization enables information and communications technology industry to better manage computing resources. In this regard, improvements in virtualization approaches together with the need for consistent runtime environment, lower overhead and smaller package size has led to the growing adoption of containers. This is a technology, which packages an application, its dependencies and Operating System (OS) to run as an isolated unit. However, the pressing concern with the use of containers is its susceptibility to security attacks. Consequently, a number of container scanning tools are available for detecting container security vulnerabilities. Therefore, in this study, we investigate the quality of existing container scanning tools by proposing two metrics that reflects coverage and accuracy. We analyze 59 popular public container images for Java applications hosted on DockerHub using different container scanning tools (such as Clair, Anchore, and Microscanner). Our findings show that existing container scanning approach does not detect application package vulnerabilities. Furthermore, existing tools do not have high accuracy, since 34% vulnerabilities are being missed by the best performing tool. Finally, we also demonstrate quality of Docker images for Java applications hosted on DockerHub by assessing complete vulnerability landscape i.e., number of vulnerabilities detected in images.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Vulnerabilities, Secrets and Misconfiguration in the Highest-Exposure Docker Hub Images

    cs.CR 2026-08 conditional novelty 6.0 of 10

    Near-universal vulnerabilities and misconfigurations among high-exposure Docker Hub images, with three scanners agreeing on only 2.7% of distinct vulnerability groups.

  2. ORCA: Unveiling Obscure Containers In The Wild

    cs.SE 2025-09 conditional novelty 6.0 of 10

    ORCA reconstructs container layer history to detect packages hidden by deleted metadata or source-built software, reporting a median 40% higher file coverage than Docker Scout and Syft.

Pith tools