A Container Security Survey: Exploits, Attacks, and Defenses

被引:0
|
作者
Jarkas, Omar [1 ]
Ko, Ryan [2 ]
Dong, Naipeng [2 ]
Mahmud, Redo wan [3 ]
机构
[1] Univ Queensland, Brisbane, Australia
[2] Univ Queensland, St Lucia, Australia
[3] Curtin Univ, Perth, Australia
关键词
Containerization security; cloud computing; confidential computing; vul-; nerabilities; hardware-based security; DOCKER; MEMORY;
D O I
10.1145/3715001
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Containerization significantly boosts cloud computing efficiency by reducing resource consumption, enhancing scalability, and simplifying orchestration. Yet, these same features introduce notable security vulnerabilities due to the shared Linux kernel and reduced isolation compared to traditional virtual machines (VMs). This architecture, while resource-efficient, increases susceptibility to software vulnerabilities, exposing containers to potential breaches; a single kernel vulnerability could compromise all containers on the same host. Existing academic research on container security is often theoretical and lacks empirical data on the nature of attacks, exploits, and vulnerabilities. Studies that do look at vulnerabilities often focus on specific types. This lack of detailed data and breadth hampers the development of effective mitigation strategies and restricts insights into the inherent weaknesses of containers. To address these gaps, our study introduces a novel taxonomy integrating academic knowledge with industry insights and real-world vulnerabilities, creating a comprehensive and actionable framework for container security. We analyzed over 200 container-related vulnerabilities, categorizing them into 47 exploit types across 11 distinct attack vectors. This taxonomy not only advances theoretical understanding but also facilitates the identification of vulnerabilities and the implementation of effective mitigation strategies in containerized environments. Our approach enhances the resilience of these environments by mapping vulnerabilities to their corresponding exploits and mitigation strategies, especially in complex, multi-tenant cloud settings. By providing actionable insights, our taxonomy helps practitioners enhance container security. Our findings have identified critical areas for further investigation, thereby laying a comprehensive foundation for future research and improving container security in cloud environments.
引用
收藏
页数:36
相关论文
共 50 条
  • [41] A Survey of Neural Trojan Attacks and Defenses in Deep Learning
    Wang, Jie
    Hassan, Ghulam Mubashar
    Akhtar, Naveed
    arXiv, 2022,
  • [42] Visual privacy attacks and defenses in deep learning: a survey
    Guangsheng Zhang
    Bo Liu
    Tianqing Zhu
    Andi Zhou
    Wanlei Zhou
    Artificial Intelligence Review, 2022, 55 : 4347 - 4401
  • [43] Advances in Adversarial Attacks and Defenses in Computer Vision: A Survey
    Akhtar, Naveed
    Mian, Ajmal
    Kardan, Navid
    Shah, Mubarak
    IEEE ACCESS, 2021, 9 : 155161 - 155196
  • [44] A Measurement Study on Linux Container Security: Attacks and Countermeasures
    Lin, Xin
    Lei, Lingguang
    Wang, Yuewu
    Jing, Jiwu
    Sun, Kun
    Zhou, Quan
    34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018), 2018, : 418 - 429
  • [45] Dissecting Operational Cellular IoT Service Security: Attacks and Defenses
    Wang, Sihan
    Xie, Tian
    Chen, Min-Yue
    Tu, Guan-Hua
    Li, Chi-Yu
    Lei, Xinyu
    Chou, Po-Yi
    Hsieh, Fucheng
    Hu, Yiwen
    Xiao, Li
    Peng, Chunyi
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2024, 32 (02) : 1229 - 1244
  • [46] Experimental Analysis of Security Attacks for Docker Container Communications
    Lee, Haneul
    Kwon, Soonhong
    Lee, Jong-Hyouk
    ELECTRONICS, 2023, 12 (04)
  • [47] A Survey of Moving Target Defenses for Network Security
    Sengupta, Sailik
    Chowdhary, Ankur
    Sabur, Abdulhakim
    Alshamrani, Adel
    Huang, Dijiang
    Kambhampati, Subbarao
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2020, 22 (03): : 1909 - 1941
  • [48] Intelligent Security Authentication for Connected and Autonomous Vehicles: Attacks and Defenses
    Qiu, Xiaoying
    Yu, Jinwei
    Jiang, Wenbao
    Sun, Xuan
    ELECTRONICS, 2024, 13 (08)
  • [49] Security of Emerging Non-Volatile Memories: Attacks and Defenses
    Shamsi, Kaveh
    Jin, Yier
    2016 IEEE 34TH VLSI TEST SYMPOSIUM (VTS), 2016,
  • [50] Adversarial attacks and defenses on AI in medical imaging informatics: A survey
    Kaviani, Sara
    Han, Ki Jin
    Sohn, Insoo
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 198