A Fault and Intrusion Tolerance Framework for Containerized Environments: A Specification-Based Error Detection Approach

2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC)(2022)

引用 1|浏览11
暂无评分
摘要
Container-based virtualization has gained momentum over the past few years thanks to its lightweight nature and support for agility. However, its appealing features come at the price of a reduced isolation level compared to the traditional host-based virtualization techniques, exposing workloads to various faults, such as co-residency attacks like container escape. In this work, we propose to leverage the automated management capabilities of containerized environments to derive a Fault and Intrusion Tolerance (FIT) framework based on error detection-recovery and fault treatment. Namely, we aim at deriving a specification-based error detection mechanism at the host level to systematically and formally capture security state errors indicating breaches potentially caused by malicious containers. Although the paper focuses on security side use cases, results are logically extendable to accidental faults. Our aim is to immunize the target environments against accidental and malicious faults and preserve their core dependability and security properties.
更多
查看译文
关键词
Containerized Environments,Automated Management,Fault and Intrusion Tolerance,Error Detection and Recovery,Formal Verification
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要