Security Analysis of Docker Containers for ARM Architecture

被引:1
|
作者
Haq, Md Sadun [1 ]
Tosun, Ali Saman [2 ]
Korkmaz, Turgay [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Univ N Carolina, Dept Math & Comp Sci, Pembroke, NC USA
关键词
Raspberry Pi; Images; Security; Containers; ARM Architecture; DockerHub;
D O I
10.1109/SEC54971.2022.00025
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Containers provide a better performance, faster deployment than virtual machines and provide near-native performance, with isolation and security drawbacks. Although the security of containers for the Intel architecture has been investigated in more detail, there is limited work on the security of containers for the ARM architecture. In this paper, we address this gap in research and focus on the security of containers designed for the ARM architecture, which is heavily used in IoT devices. Edge computing offers many advantages, including reduced latency and resource requirements at the cloud because data can be processed at the edge before it is sent to the cloud. Using containers at the edge nodes of IoT-Edge-Cloud systems can enhance such advantages at the cost of increasing security vulnerabilities in such systems. Therefore, it is essential to investigate the security of containers designed for the ARM architecture. Accordingly, we obtained official ARM images from DockerHub and used various security tools to scan these ARM images. We found that 72% of all the vulnerabilities show varying severity levels and each tool seems to work best for particular base images. We investigated how each tool detects sub-packages and achieves a different hit ratio while none of them alone can detect at least 80% of all the vulnerabilities. In addition, we also investigated how the Docker images and their vulnerability landscape change over a period of six months by running the scanning tools twice. Finally, we also conducted a dynamic analysis of some of the images on the Raspberry Pi and study their effects. We believe this paper will facilitate the use of ARM containers at the ARM-based edge nodes by addressing security issues.
引用
收藏
页码:264 / 276
页数:13
相关论文
共 50 条
  • [1] Architecture for Predicting Live Video Transcoding Performance on Docker Containers
    Paakkonen, Pekka
    Heikkinen, Antti
    Aihkisalo, Tommi
    2018 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2018), 2018, : 65 - 72
  • [2] Performance Analysis of Virtual Machines and Docker Containers
    Kavitha, Babu
    Varalakshmi, Perumal
    DATA SCIENCE ANALYTICS AND APPLICATIONS, DASAA 2017, 2018, 804 : 99 - 113
  • [3] To Docker or Not to Docker: A Security Perspective
    Combe, Theo
    Martin, Antony
    Di Pietro, Roberto
    IEEE CLOUD COMPUTING, 2016, 3 (05): : 54 - 62
  • [4] GO-Docker A batch scheduling system with Docker containers
    Sallou, Olivier
    Monjeaud, Cyril
    2015 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING - CLUSTER 2015, 2015, : 514 - 515
  • [5] A Flexible Cyber Security Experimentation Platform Architecture Based on Docker
    Yin, Yongfeng
    Shao, Yuyan
    Wang, XueFeng
    Su, Qingran
    2019 COMPANION OF THE 19TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS-C 2019), 2019, : 413 - 420
  • [6] Performance Analysis of an Hyperconverged Infrastructure using Docker Containers and GlusterFS
    Leite, Rodrigo
    Solis, Priscila
    Alchieri, Eduardo
    CLOSER: PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2019, : 339 - 346
  • [7] Network Quality of Service in Docker Containers
    Dusia, Ayush
    Yang, Yang
    Taufer, Michela
    2015 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING - CLUSTER 2015, 2015, : 527 - 528
  • [8] Orchestrating Docker Containers in the HPC Environment
    Higgins, Joshua
    Holmes, Violeta
    Venters, Colin
    HIGH PERFORMANCE COMPUTING, ISC HIGH PERFORMANCE 2015, 2015, 9137 : 506 - 513
  • [9] Monitoring the Energy Consumption of Docker Containers
    Warade, Mehul
    Lee, Kevin
    Ranaweera, Chathurika
    Schneider, Jean-Guy
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 1703 - 1710
  • [10] An Introduction to Rocker: Docker Containers for R
    Boettiger, Carl
    Eddelbuettel, Dirk
    R JOURNAL, 2017, 9 (02): : 527 - 536