Abstract
In view of the incomplete isolation of docker, the image file is easy to be tampered with, and the problem of insecure container operation. Based on the analysis of the existing isolation mechanism and security enhancement technology of docker container, this article uses trusted computing technologies such as cryptographic algorithms, integrity measurement, realtime monitoring, etc., a hardening method for docker containers is proposed. The feasibility of the reinforcement method was verified by experiments. The results show that this method can realize that docker is in a trusted and secure environment during the entire process of downloading the image from the container to the container, and ensuring that the container and the image file are not tampered with. When the container is enabled, the system resources are in a monitorable state, which greatly improves the credibility and security of the docker container.
Cite
CITATION STYLE
Shen, Y., & Yu, X. (2020). Docker container hardening method based on trusted computing. In Journal of Physics: Conference Series (Vol. 1619). IOP Publishing Ltd. https://doi.org/10.1088/1742-6596/1619/1/012014
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.