LETTER Understanding File System Operations of a Secure Container Runtime Using System Call Tracing Technique

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

This letter presents a technique that observes system call mapping behavior of the proxy kernel layer of secure container runtimes. We applied it to file system operations of a secure container runtime, gVisor. We found that gVisor's operations can become more expensive than the native by 48x more syscalls for open, and 6x for read and write.

키워드

secure container runtime; system call; gVisor
제목
LETTER Understanding File System Operations of a Secure Container Runtime Using System Call Tracing Technique
저자
Jang, Sunwoo; Suh, Young-Kyoon; Tak, Byungchul
DOI
10.1587/transinf.2023EDL8039
발행일
2024-02
유형
Article
저널명
IEICE Transactions on Information and Systems
권
E107
호
2
페이지
229 ~ 233