상세 보기
Sequence-based System Call Filtering for Enhanced Container Security, is it beneficial?
- Song, Somin;
- Suneja, Sahil;
- Le, Michael V.;
- Tak, Byungchul
WEB OF SCIENCE
1SCOPUS
1초록
One critical attack that exploits kernel vulnerabilities through system call invocations is the privilege escalation followed by the infamous container escape. The seccomp provides the first line of defense against it. However, it is known to be brittle since it operates at the granularity of the individual system call. Inadvertent filtering of necessary system calls may inhibit the correct execution while overly generous rules allow the attacks. We believe that, by looking at the sequence of system calls, we can achieve more accurate and effective blocking of attacks in containers. To this end, we analyzed the expected defensive power from applying the sequence-based filtering mechanisms by thoroughly analyzing a large set of collected kernel vulnerabilities to assess the feasibility.
키워드
- 제목
- Sequence-based System Call Filtering for Enhanced Container Security, is it beneficial?
- 저자
- Song, Somin; Suneja, Sahil; Le, Michael V.; Tak, Byungchul
- 발행일
- 2023
- 유형
- Proceedings Paper
- 저널명
- 2023 IEEE/ACM 23RD INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING WORKSHOPS, CCGRIDW
- 페이지
- 278 ~ 280
- 언어
- ENG
- 출판사
- IEEE COMPUTER SOC
- 발행국가
- 미국
- 분량
- 3 페이지