Security Analysis of Docker Containers for ARM Architecture

被引:1
|
作者
Haq, Md Sadun [1 ]
Tosun, Ali Saman [2 ]
Korkmaz, Turgay [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Univ N Carolina, Dept Math & Comp Sci, Pembroke, NC USA
关键词
Raspberry Pi; Images; Security; Containers; ARM Architecture; DockerHub;
D O I
10.1109/SEC54971.2022.00025
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Containers provide a better performance, faster deployment than virtual machines and provide near-native performance, with isolation and security drawbacks. Although the security of containers for the Intel architecture has been investigated in more detail, there is limited work on the security of containers for the ARM architecture. In this paper, we address this gap in research and focus on the security of containers designed for the ARM architecture, which is heavily used in IoT devices. Edge computing offers many advantages, including reduced latency and resource requirements at the cloud because data can be processed at the edge before it is sent to the cloud. Using containers at the edge nodes of IoT-Edge-Cloud systems can enhance such advantages at the cost of increasing security vulnerabilities in such systems. Therefore, it is essential to investigate the security of containers designed for the ARM architecture. Accordingly, we obtained official ARM images from DockerHub and used various security tools to scan these ARM images. We found that 72% of all the vulnerabilities show varying severity levels and each tool seems to work best for particular base images. We investigated how each tool detects sub-packages and achieves a different hit ratio while none of them alone can detect at least 80% of all the vulnerabilities. In addition, we also investigated how the Docker images and their vulnerability landscape change over a period of six months by running the scanning tools twice. Finally, we also conducted a dynamic analysis of some of the images on the Raspberry Pi and study their effects. We believe this paper will facilitate the use of ARM containers at the ARM-based edge nodes by addressing security issues.
引用
收藏
页码:264 / 276
页数:13
相关论文
共 50 条
  • [31] Forensic Analysis of Cryptojacking in Host-based Docker Containers Using Honeypots
    Franco, Javier
    Acar, Abbas
    Aris, Ahmet
    Uluagac, Selcuk
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 4860 - 4865
  • [32] How does docker affect energy consumption? Evaluating workloads in and out of Docker containers
    Santos, Eddie Antonio
    McLean, Carson
    Solinas, Christopher
    Hindle, Abram
    JOURNAL OF SYSTEMS AND SOFTWARE, 2018, 146 : 14 - 25
  • [33] Information Leakages of Docker Containers: Characterization and Mitigation Strategies
    Zuppelli, Marco
    Repetto, Matteo
    Caviglione, Luca
    Cambiaso, Enrico
    2023 IEEE 9TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT, 2023, : 462 - 467
  • [34] Checkpoint and Restoration of Micro-service in Docker Containers
    Yang, Chen
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON MECHATRONICS AND INDUSTRIAL INFORMATICS, 2015, 31 : 915 - 918
  • [35] Sarus: Highly Scalable Docker Containers for HPC Systems
    Benedicic, Lucas
    Cruz, Felipe A.
    Madonna, Alberto
    Mariotti, Kean
    HIGH PERFORMANCE COMPUTING: ISC HIGH PERFORMANCE 2019 INTERNATIONAL WORKSHOPS, 2020, 11887 : 46 - 60
  • [36] Emergency communication system with Docker Containers, OSM and Rsync
    Pentyala, Shiva Kumar
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON SMART TECHNOLOGIES FOR SMART NATION (SMARTTECHCON), 2017, : 1064 - 1069
  • [37] Building a Threshold Cryptographic Distributed HSM with Docker Containers
    Munoz, Caterina
    Montoto, Francisco
    Cifuentes, Francisco
    Bustos-Jimenez, Javier
    PROCEEDINGS OF THE 2018 APPLIED NETWORKING RESEARCH WORKSHOP (ANRW '18), 2018, : 66 - 66
  • [38] Koordinator: A Service Approach for Replicating Docker Containers in Kubernetes
    Netto, Hylson Vescovi
    Luiz, Aldelir Fernando
    Correiat, Miguel
    Recht, Luciana de Oliveira
    Oliveirat, Caio Pereira
    2018 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2018, : 58 - 63
  • [39] Docker Swarm and Kubernetes Containers for Smart Home Gateway
    Kang, Byungseok
    Jeong, Jaeyeop
    Choo, Hyunseung
    IT PROFESSIONAL, 2021, 23 (04) : 75 - 80
  • [40] Architecture Modelling and Task Scheduling of an Integrated Parallel CNC System in Docker Containers Based on Colored Petri Nets
    Jin, Hongyu
    Wang, Yang
    Wang, Qian
    Liu, Jiankang
    Wang, Shuhua
    Zhang, Jun
    Hao, Shanghua
    Fu, Hongya
    IEEE ACCESS, 2019, 7 : 47535 - 47549