500 rub
Journal Neurocomputers №4 for 2026 г.
Article in number:
A technique for secure Docker containerization of software agents while preserving steganographic transformation in batch neural network programs
Type of article: scientific article
DOI: https://doi.org/10.18127/j19998554-202604-02
UDC: 004.056
Authors:

P.I. Sharikov1, S.I. Shterenberg2
1, 2 Bonch-Bruevich Saint Petersburg State University of Telecommunications (St. Petersburg, Russia)
1 sharikov.pavel@ro.ru, 2 shterenberg.si@sut.ru

Abstract:

Porting batch neural network programs based on software agents to containerized environments is fraught with security threats: code vulnerabilities, information leaks, and violation of steganographic properties when packaged in Docker containers. Additional difficulties are created by the need to ensure cross-platform compatibility and independence from programming languages and libraries.

The goal of the aritcle is development of a methodology for secure containerization of software agents as part of batch neural network programs, ensuring their protection from common vulnerabilities, preserving the properties of steganographic data processing, resistance to dynamic execution conditions and reducing dependence on external components of the software environment.

A technique has been proposed for the automatic generation of secure Docker images for agents of batch neural network programs, covering the entire lifecycle: from generating a secure Dockerfile to running in an orchestrated environment. Supply chain tracking, vulnerability checking, access rights restriction, protection against compromise through configuration, and digital watermark preservation have been provided. There is an experimentally confirmed successful launch of attack-resistant containers, demonstrating the ability to dynamically replace agents and high security of steganographic information.

The technique is suitable for intelligent attack detection systems, decentralized platforms, IoT, and enterprise AI solutions that require reliable code isolation and resilience to change. The approach simplifies the migration of neural network agents, automates assembly/deployment, reducing the burden on staff, and provides protection against privilege escalation, data leaks, and malicious code. In practice, this allows you to implement Zero Trust in containerized batch neural network programs, providing control and manageability of distributed systems.

Pages: 18-33
For citation

Sharikov P.I., Shterenberg S.I. A technique for secure Docker containerization of software agents while preserving steganographic transformation in batch neural network programs // Neurocomputers. 2026. V. 28. № 4. P. 18–33. DOI: https://doi.org/10.18127/ j19998554-202604-02

References
  1. Kozachok A.V., Kochetkov E.V. Obnaruzhenie vredonosnogo programmnogo obespecheniya na osnove vyyavleniya anomal'noj setevoj aktivnosti. Informacionnye sistemy i tekhnologii. 2016. № 5(97). S. 107−114 (in Russian).
  2. Zhuoqun Fu, Mingxuan Liu, Yue Qin, Jia Zhang, Yuan Zou, Qilei Yin, Qi Li, Haixin Duan. Encrypted Malware Traffic Detection via Graph-based Network Analysis. Proceedings of the 25th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID 2022). October 26–28. 2022. Limassol, Cyprus. Р. 495−510. DOI: 10.1145/3545948.3545983. 
  3. Diogo Barradas, Carlos Novo, Bernardo Portela, Sofia Romeiro, Nuno Santos. Extending C2 Traffic Detection Methodologies: From TLS 1.2 to TLS 1.3-enabled Malware. Research in Attacks, Intrusions and Defenses (RAID 2024). September 30 October 02. 2024. Padua. Italy. ACM. New York. NY. USA. Р. 181−196. DOI: 10.1145/3678890.3678921.
  4. Carlos Novo, Ricardo Morla. Flow-based Detection and Proxy-based Evasion of Encrypted Malware C2 Traffic. in AISec'20: Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security. 09 November 2020. Р. 83–91. DOI: 10.1145/3411508.3421379.
  5. Revnivyh A.V., Velizhanin A.S. Metod avtomatizirovannogo issledovaniya struktury dizassemblirovannogo predstavleniya programmnogo koda s uyazvimost'yu na perepolnenie bufera s ispol'zovaniem matrichnogo podhoda. Kibernetika i programmirovanie. 2018. № 6. S. 11−30. DOI: 10.25136/2644-5522.2018.6.28288 (in Russian).
  6. Liu P. et al. Understanding the security risks of docker hub. Computer Security–ESORICS 2020: 25th European Symposium on Research in Computer Security. ESORICS 2020. Guildford. UK. September 14–18. 2020. Part I 25. Springer International Publishing. 2020. Р. 257−276.
  7. Sharikov P.I., Cvetkov A.Yu., Sigacheva V.V., Sirotina L.K. Issledovanie i algoritm predotvrashcheniya ekspluatacii uyazvimostej biblioteki zhurnalirovaniya Log4j v informacionnyh sistemah java-prilozhenij. Vestnik Sankt-Peterburgskogo gosudarstvennogo universiteta tekhnologii i dizajna. Seriya 1. Estestvennye i tekhnicheskie nauki. 2023. № 4. S. 100−106. DOI: 10.46418/2079-8199_2023_4_19 (in Russian).
  8. Bui Q.C., Laukötter M., Scandariato R. DockerCleaner: Automatic Repair of Security Smells in Dockerfiles. 2023 IEEE International Conference on Software Maintenance and Evolution (ICSME). IEEE. 2023. Р. 160−170.
  9. Zerouali A. et al. On the relation between outdated docker containers, severity vulnerabilities, and bugs. 2019 ieee 26th international conference on software analysis, evolution and reengineering (saner). IEEE. 2019. Р. 491−501.
  10. Maruszczak A., Walkowski M., Sujecki S. Base Systems for Docker Containers-Security Analysis. 2022 International Conference on Software, Telecommunications and Computer Networks (SoftCOM). IEEE. 2022. Р. 1−5.
  11. Yu J., ChuanJia D.P. A review of docker security research. Computer Science and Application. 2019. V. 9. № 5. Р. 926−933.
  12. Saxena P. Container image security with trivy and istio inter-service secure communication in kubernetes. Dublin. National College of Ireland. 2023.
  13. Javed O., Toor S. An evaluation of container security vulnerability detection tools. Proceedings of the 2021 5th International Conference on Cloud and Big Data Computing. 2021. Р. 95−101.
  14. Xu Q. et al. Blockchain-based decentralized content trust for docker images. Multimedia Tools and Applications. 2018. V. 77. Р. 18223−18248.
  15. Malhotra R., Bansal A., Kessentini M. Vulnerability analysis of docker hub official images and verified images. 2023 IEEE International Conference on Service-Oriented System Engineering (SOSE). IEEE. 2023. Р. 150−155.
  16. Krasov A., Sharikov P. A technique for analyzing bytecode in a java project for the purpose of an automated assessment of the possibility and effectiveness of the hidden investment of information and its volumes in a java project. 12th International Congress on Ultra Modern Telecommunications and Control Systems and Workshops. ICUMT 2020. Brno: Institute of Electrical and Electronics Engineers, 2020. P. 258−263. DOI: 10.1109/ICUMT51630.2020.9222419.
  17. Sharikov P.I. Issledovanie ustojchivosti cifrovogo vodyanogo znaka k atakam napravlennoj dekompilyacii sostavnyh chastej prilozheniya Java. Elektronnyj setevoj politematicheskij zhurnal «Nauchnye trudy KubGTU». 2022. № 2. S. 100−112 (in Russian).
  18. Ekhlakov O. A systematic approach to user file security: from primary validation to isolation in Docker. International Journal of Open Information Technologies. 2025. V. 13. №. 9. Р. 43−49.
Date of receipt: 27.05.2025
Approved after review: 04.07.2025
Accepted for publication: 29.06.2026