Prof-gen: Practical Study on System Call Whitelist Generation for Container Attack Surface Reduction

2021 IEEE 14th International Conference on Cloud Computing (CLOUD)(2021)

引用 4|浏览8
暂无评分
摘要
Container escape, which exploits vulnerabilities in the shared kernel to break container isolation, is a severe security threat in cloud-native computing. To alleviate the threat, we should allow the minimum number of system calls required by individual containers, but figuring out which system calls an arbitrary container will need is a challenging problem. This paper presents Prof-gen that autom...
更多
查看译文
关键词
Cloud computing,Whitelists,Runtime,Image edge detection,Pipelines,Containers,Tools
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要