容器化环境的容错和容错框架:基于规范的错误检测方法

Taous Madi, Paulo Esteves-Verissimo
{"title":"容器化环境的容错和容错框架:基于规范的错误检测方法","authors":"Taous Madi, Paulo Esteves-Verissimo","doi":"10.1109/SRMC57347.2022.00005","DOIUrl":null,"url":null,"abstract":"Container-based virtualization has gained momentum over the past few years thanks to its lightweight nature and support for agility. However, its appealing features come at the price of a reduced isolation level compared to the traditional host-based virtualization techniques, exposing workloads to various faults, such as co-residency attacks like container escape. In this work, we propose to leverage the automated management capabilities of containerized environments to derive a Fault and Intrusion Tolerance (FIT) framework based on error detection-recovery and fault treatment. Namely, we aim at deriving a specification-based error detection mechanism at the host level to systematically and formally capture security state errors indicating breaches potentially caused by malicious containers. Although the paper focuses on security side use cases, results are logically extendable to accidental faults. Our aim is to immunize the target environments against accidental and malicious faults and preserve their core dependability and security properties.","PeriodicalId":205724,"journal":{"name":"2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC)","volume":"72 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"A Fault and Intrusion Tolerance Framework for Containerized Environments: A Specification-Based Error Detection Approach\",\"authors\":\"Taous Madi, Paulo Esteves-Verissimo\",\"doi\":\"10.1109/SRMC57347.2022.00005\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Container-based virtualization has gained momentum over the past few years thanks to its lightweight nature and support for agility. However, its appealing features come at the price of a reduced isolation level compared to the traditional host-based virtualization techniques, exposing workloads to various faults, such as co-residency attacks like container escape. In this work, we propose to leverage the automated management capabilities of containerized environments to derive a Fault and Intrusion Tolerance (FIT) framework based on error detection-recovery and fault treatment. Namely, we aim at deriving a specification-based error detection mechanism at the host level to systematically and formally capture security state errors indicating breaches potentially caused by malicious containers. Although the paper focuses on security side use cases, results are logically extendable to accidental faults. Our aim is to immunize the target environments against accidental and malicious faults and preserve their core dependability and security properties.\",\"PeriodicalId\":205724,\"journal\":{\"name\":\"2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC)\",\"volume\":\"72 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SRMC57347.2022.00005\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Workshop on Secure and Reliable Microservices and Containers (SRMC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SRMC57347.2022.00005","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

基于容器的虚拟化由于其轻量级特性和对敏捷性的支持,在过去几年中发展势头强劲。然而,与传统的基于主机的虚拟化技术相比,其吸引人的特性是以降低隔离级别为代价的,这会使工作负载暴露于各种故障,例如容器逃逸等共同驻留攻击。在这项工作中,我们建议利用容器化环境的自动化管理功能来派生基于错误检测-恢复和故障处理的故障和入侵容忍(FIT)框架。也就是说,我们的目标是在主机级别派生一个基于规范的错误检测机制,以系统地和正式地捕获安全状态错误,这些错误表明可能由恶意容器引起的破坏。尽管本文关注的是安全方面的用例,但结果在逻辑上可扩展到意外故障。我们的目标是使目标环境免受意外和恶意故障的侵害,并保持其核心可靠性和安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Fault and Intrusion Tolerance Framework for Containerized Environments: A Specification-Based Error Detection Approach
Container-based virtualization has gained momentum over the past few years thanks to its lightweight nature and support for agility. However, its appealing features come at the price of a reduced isolation level compared to the traditional host-based virtualization techniques, exposing workloads to various faults, such as co-residency attacks like container escape. In this work, we propose to leverage the automated management capabilities of containerized environments to derive a Fault and Intrusion Tolerance (FIT) framework based on error detection-recovery and fault treatment. Namely, we aim at deriving a specification-based error detection mechanism at the host level to systematically and formally capture security state errors indicating breaches potentially caused by malicious containers. Although the paper focuses on security side use cases, results are logically extendable to accidental faults. Our aim is to immunize the target environments against accidental and malicious faults and preserve their core dependability and security properties.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信