Security Analysis of Docker Containers for ARM Architecture

被引:1
|
作者
Haq, Md Sadun [1 ]
Tosun, Ali Saman [2 ]
Korkmaz, Turgay [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Univ N Carolina, Dept Math & Comp Sci, Pembroke, NC USA
关键词
Raspberry Pi; Images; Security; Containers; ARM Architecture; DockerHub;
D O I
10.1109/SEC54971.2022.00025
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Containers provide a better performance, faster deployment than virtual machines and provide near-native performance, with isolation and security drawbacks. Although the security of containers for the Intel architecture has been investigated in more detail, there is limited work on the security of containers for the ARM architecture. In this paper, we address this gap in research and focus on the security of containers designed for the ARM architecture, which is heavily used in IoT devices. Edge computing offers many advantages, including reduced latency and resource requirements at the cloud because data can be processed at the edge before it is sent to the cloud. Using containers at the edge nodes of IoT-Edge-Cloud systems can enhance such advantages at the cost of increasing security vulnerabilities in such systems. Therefore, it is essential to investigate the security of containers designed for the ARM architecture. Accordingly, we obtained official ARM images from DockerHub and used various security tools to scan these ARM images. We found that 72% of all the vulnerabilities show varying severity levels and each tool seems to work best for particular base images. We investigated how each tool detects sub-packages and achieves a different hit ratio while none of them alone can detect at least 80% of all the vulnerabilities. In addition, we also investigated how the Docker images and their vulnerability landscape change over a period of six months by running the scanning tools twice. Finally, we also conducted a dynamic analysis of some of the images on the Raspberry Pi and study their effects. We believe this paper will facilitate the use of ARM containers at the ARM-based edge nodes by addressing security issues.
引用
收藏
页码:264 / 276
页数:13
相关论文
共 50 条
  • [41] Integrity verification of Docker containers for a lightweight cloud environment
    De Benedictis, Marco
    Lioy, Antonio
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 97 : 236 - 246
  • [42] Sledge : Towards Efficient Live Migration of Docker Containers
    Xu, Bo
    Wu, Song
    Xiao, Jiang
    Jin, Hai
    Zhang, Yingxi
    Shi, Guoqiang
    Lin, Tingyu
    Rao, Jia
    Yi, Li
    Jiang, Jizhong
    2020 IEEE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2020), 2020, : 321 - 328
  • [43] Building a Threshold Cryptographic Distributed HSM with Docker Containers
    Munoz, Caterina
    Montoto, Francisco
    Cifuentes, Francisco
    Bustos-Jimenez, Javier
    2017 CHILEAN CONFERENCE ON ELECTRICAL, ELECTRONICS ENGINEERING, INFORMATION AND COMMUNICATION TECHNOLOGIES (CHILECON), 2017,
  • [44] Making containers lazy with Docker and CernVM-FS
    Hardi, N.
    Blomer, J.
    Ganis, G.
    Popescu, R.
    18TH INTERNATIONAL WORKSHOP ON ADVANCED COMPUTING AND ANALYSIS TECHNIQUES IN PHYSICS RESEARCH (ACAT2017), 2018, 1085
  • [45] Performance Comparison Between Virtual Machines And Docker Containers
    Yadav, R. R.
    Sousa, E. T. G.
    Callou, G. R. A.
    IEEE LATIN AMERICA TRANSACTIONS, 2018, 16 (08) : 2282 - 2288
  • [46] Performance Evaluation of Deep Learning Tools in Docker Containers
    Xu, Pengfei
    Shi, Shaohuai
    Chu, Xiaowen
    2017 3RD INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS (BIGCOM), 2017, : 395 - 403
  • [47] Docker Containers Across Multiple Clouds and Data Centers
    AbdelBaky, Moustafa
    Diaz-Montes, Javier
    Parashar, Manish
    Unuvar, Merve
    Steinder, Malgorzata
    2015 IEEE/ACM 8TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC), 2015, : 368 - 371
  • [48] DockerChannel: A framework for evaluating information leakages of Docker containers
    Cambiaso, Enrico
    Caviglione, Luca
    Zuppelli, Marco
    SOFTWAREX, 2023, 24
  • [49] Predictive Energy Management for Docker Containers in Cloud Computing: A Time Series Analysis Approach
    Algarni, Abdulmohsen
    Shah, Iqrar
    Jehangiri, Ali Imran
    Ala'Anzy, Mohammed Alaa
    Ahmad, Zulfiqar
    IEEE ACCESS, 2024, 12 : 52524 - 52538
  • [50] An architecture for genomics analysis in a clinical setting using Galaxy and Docker
    Digan, W.
    Countouris, H.
    Barritault, M.
    Baudoin, D.
    Laurent-Puig, P.
    Blons, H.
    Burgun, A.
    Rance, B.
    GIGASCIENCE, 2017, 6 (11):