Comprehensive defense scheme against container escape related to container management procedure

Zhimin Guo,Zhuo Lv,Nuannuan Li, Tao Yuan, Xue Gao, Zekun Yuan

2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC)(2022)

引用 0|浏览3
暂无评分
摘要
Container technology has become a widely used virtualization technology in cloud platform because of its lightweight virtualization characteristics. However, compared with traditional virtual machine technology, the security and isolation of the container are poor and it may lead to container escape, because container technology shares the kernel with the host. This attack will pose a serious threat to the host and other containers on the same host. We studied the container escape attack caused by container management vulnerabilities, and propose a comprehensive container security protection scheme by using AppArmor and Seccomp. Through the simulation of vulnerability environment, the structure proves that the scheme is indeed effective.
更多
查看译文
关键词
container escape,security hardening,container security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要