ContainerLeaks: Emerging Security Threats of Information Leakages in Container Clouds

被引:70
|
作者
Gao, Xing [1 ,2 ]
Gu, Zhongshu [3 ]
Kayaalp, Mehmet [3 ]
Pendarakis, Dimitrios [3 ]
Wang, Haining [1 ]
机构
[1] Univ Delaware, Newark, DE 19716 USA
[2] Coll William & Mary, Williamsburg, VA 23185 USA
[3] IBM TJ Watson Res Ctr, Yorktown Hts, NY USA
关键词
D O I
10.1109/DSN.2017.49
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Container technology provides a lightweight operating system level virtual hosting environment. Its emergence profoundly changes the development and deployment paradigms of multi-tier distributed applications. However, due to the incomplete implementation of system resource isolation mechanisms in the Linux kernel, some security concerns still exist for multiple containers sharing an operating system kernel on a multi-tenancy container cloud service. In this paper, we first present the information leakage channels we discovered that are accessible within the containers. Such channels expose a spectrum of system-wide host information to the containers without proper resource partitioning. By exploiting such leaked host information, it becomes much easier for malicious adversaries (acting as tenants in the container clouds) to launch advanced attacks that might impact the reliability of cloud services. Additionally, we discuss the root causes of the containers' information leakages and propose a two-stage defense approach. As demonstrated in the evaluation, our solution is effective and incurs trivial performance overhead.
引用
收藏
页码:237 / 248
页数:12
相关论文
共 50 条
  • [1] A Study on the Security Implications of Information Leakages in Container Clouds
    Gao, Xing
    Steenkamer, Benjamin
    Gu, Zhongshu
    Kayaalp, Mehmet
    Pendarakis, Dimitrios
    Wang, Haining
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (01) : 174 - 191
  • [2] The container security initiative and ocean container threats
    Haveman, Jon D.
    Jennings, Ethan M.
    Shatz, Howard J.
    Wright, Greg C.
    [J]. JOURNAL OF HOMELAND SECURITY AND EMERGENCY MANAGEMENT, 2007, 4 (01):
  • [3] Ontological insecurity and cognitive threats: emerging security challenges in the Information Age
    de Castris, Arcangelo Leone
    [J]. H-ERMES-JOURNAL OF COMMUNICATION, 2023, 25 : 167 - 183
  • [4] Information Security Threats and Information Assurance
    Yalman, Yildiray
    Yesilyurt, Murat
    [J]. TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2013, 2 (03): : 247 - 252
  • [5] New and Emerging Threats to Maritime Security
    Abeyratne, Ruwantissa
    [J]. ASIA PACIFIC LAW REVIEW, 2010, 18 (02) : 171 - 196
  • [6] Converging and emerging threats to health security
    Raina MacIntyre C.
    Engells T.E.
    Scotch M.
    Heslop D.J.
    Gumel A.B.
    Poste G.
    Chen X.
    Herche W.
    Steinhöfel K.
    Lim S.
    Broom A.
    [J]. Environment Systems and Decisions, 2018, 38 (2) : 198 - 207
  • [7] Web Security: Emerging Threats and Defense
    Almutairi, Abdulwahed Awad
    Mishra, Shailendra
    AlShehri, Mohammed
    [J]. COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2022, 40 (03): : 1233 - 1248
  • [8] Threats to Health Information Security
    Samy, Ganthan Narayana
    Ahmad, Rabiah
    Ismail, Zuraini
    [J]. FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 540 - 543
  • [9] Insider Threats in Information Security
    Elmrabit, Ncbrase
    Yang, Shuang-Hua
    Yang, Lili
    [J]. 2015 21ST INTERNATIONAL CONFERENCE ON AUTOMATION AND COMPUTING (ICAC), 2015, : 108 - 113
  • [10] COMPUTER THREATS AND INFORMATION SECURITY
    Tarazona T, Cesar H.
    [J]. DERECHO PENAL Y CRIMINOLOGIA, 2007, 28 (84): : 137 - 146