Container hardening through automated seccomp profiling

16Citations
Citations of this article
20Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Nowadays the use of container technologies is ubiquitous and thus the need to make them secure arises. Container technologies such as Docker provide several options to better improve container security, one of those is the use of a Seccomp profile. A major problem with these profiles is that they are hard to maintain because of two different factors: They need to be updated quite often and present a complex and time consuming task to determine exactly what to update, therefore not many people use them. The research goal of this paper is to make Seccomp profiles a viable technique in a production environment by proposing a reliable method to generate custom Seccomp profiles for arbitrary containerized application. This research focused on developing a solution with few requirements allowing for an easy integration with any environment with no human intervention. Results show that using a custom Seccomp profile can mitigate several attacks and even some zero day vulnerabilities on containerized applications. This represents a big step forward on using Seccomp in a production environment, which would benefit users worldwide.

Author supplied keywords

Cite

CITATION STYLE

APA

Lopes, N., Martins, R., Correia, M. E., Serrano, S., & Nunes, F. (2020). Container hardening through automated seccomp profiling. In WOC 2020 - Proceedings of the 2020 6th International Workshop on Container Technologies and Container Clouds, Part of Middleware 2020 (pp. 31–36). Association for Computing Machinery, Inc. https://doi.org/10.1145/3429885.3429966

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free