A Container Escape Detection Method Based on a Dependency Graph

5Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

With the rapid advancement in edge computing, container technology has gained widespread adoption. This is due to its lightweight isolation mechanisms, high portability, and fast deployment capabilities. Despite these advantages, container technology also introduces significant security risks. One of the most critical is container escape. However, current detection research is incomplete. Many methods lack comprehensive detection coverage or fail to fully reconstruct the attack process. To address these gaps, this paper proposes a container escape detection method based on a dependency graph. The method uses various nodes and edges to describe diverse system behaviors. This approach enables the detection of a broader range of attack types. It also effectively captures the contextual relationships between system events, facilitating attack traceability and reconstruction. We design a method to identify container processes on the dependency graph through label generation and propagation. Based on this, container escape detection is implemented using file access control within the graph. Experimental results demonstrate the effectiveness of the proposed method in detecting container escapes.

Cite

CITATION STYLE

APA

Chen, K., Zhao, Y., Guo, J., Gu, Z., Han, L., & Tang, K. (2024). A Container Escape Detection Method Based on a Dependency Graph. Electronics (Switzerland), 13(23). https://doi.org/10.3390/electronics13234773

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free