{"title":"Comprehensive defense scheme against container escape related to container management procedure","authors":"Zhimin Guo, Zhuo Lv, Nuannuan Li, Tao Yuan, Xue Gao, Zekun Yuan","doi":"10.1109/cyberc55534.2022.00051","DOIUrl":null,"url":null,"abstract":"Container technology has become a widely used virtualization technology in cloud platform because of its lightweight virtualization characteristics. However, compared with traditional virtual machine technology, the security and isolation of the container are poor and it may lead to container escape, because container technology shares the kernel with the host. This attack will pose a serious threat to the host and other containers on the same host. We studied the container escape attack caused by container management vulnerabilities, and propose a comprehensive container security protection scheme by using AppArmor and Seccomp. Through the simulation of vulnerability environment, the structure proves that the scheme is indeed effective.","PeriodicalId":234632,"journal":{"name":"2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC)","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/cyberc55534.2022.00051","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Container technology has become a widely used virtualization technology in cloud platform because of its lightweight virtualization characteristics. However, compared with traditional virtual machine technology, the security and isolation of the container are poor and it may lead to container escape, because container technology shares the kernel with the host. This attack will pose a serious threat to the host and other containers on the same host. We studied the container escape attack caused by container management vulnerabilities, and propose a comprehensive container security protection scheme by using AppArmor and Seccomp. Through the simulation of vulnerability environment, the structure proves that the scheme is indeed effective.