Sequence-based System Call Filtering for Enhanced Container Security, is it beneficial?

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

1

초록

One critical attack that exploits kernel vulnerabilities through system call invocations is the privilege escalation followed by the infamous container escape. The seccomp provides the first line of defense against it. However, it is known to be brittle since it operates at the granularity of the individual system call. Inadvertent filtering of necessary system calls may inhibit the correct execution while overly generous rules allow the attacks. We believe that, by looking at the sequence of system calls, we can achieve more accurate and effective blocking of attacks in containers. To this end, we analyzed the expected defensive power from applying the sequence-based filtering mechanisms by thoroughly analyzing a large set of collected kernel vulnerabilities to assess the feasibility.

키워드

container security; seccomp; Linux kernel vulnerability; system call sequence pattern
제목
Sequence-based System Call Filtering for Enhanced Container Security, is it beneficial?
저자
Song, Somin; Suneja, Sahil; Le, Michael V.; Tak, Byungchul
DOI
10.1109/CCGridW59191.2023.00057
발행일
2023
유형
Proceedings Paper
저널명
2023 IEEE/ACM 23RD INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING WORKSHOPS, CCGRIDW
페이지
278 ~ 280