MiniCon: Automatic Enforcement of a Minimal Capability Set for Security-Enhanced Containers

Cited 2 time in webofscience Cited 0 time in scopus
  • Hit : 58
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorKang, Haneyko
dc.contributor.authorKim, Jinwooko
dc.contributor.authorShin, Seungwonko
dc.date.accessioned2021-10-27T06:50:12Z-
dc.date.available2021-10-27T06:50:12Z-
dc.date.created2021-10-27-
dc.date.issued2021-04-
dc.identifier.citationIEEE International IOT, Electronics and Mechatronics Conference (IEMTRONICS), pp.490 - 494-
dc.identifier.urihttp://hdl.handle.net/10203/288347-
dc.description.abstractNowadays, containers have been widely adopted not only for clouds but also for individual users. On the one hand, containers provide much more light-weight virtualized infrastructure, but on the other hand, it is unavoidable to handle security issues since the isolation of containers is relatively weak, compared to the legacy VMs. Under the container architecture, adversaries are able to exploit kernel vulnerabilities to escalate privilege to gain root privilege, and leak system, privacy critical information. Although previous solutions provide strong security protection, unfortunately, none of them do provide a way to apply policies. Therefore, in this paper, we present an eBPF-based capability enforcement system, MiniCon, that automatically generates and enforces a minimal capability set by using Seccomp Filter. It monitors capability requests from containers, merges those requests to create a minimal capability set, and enforces capability policies through Seccomp Filter.-
dc.languageEnglish-
dc.publisherIEEE-
dc.titleMiniCon: Automatic Enforcement of a Minimal Capability Set for Security-Enhanced Containers-
dc.typeConference-
dc.identifier.wosid000675601600080-
dc.identifier.scopusid2-s2.0-85106668570-
dc.type.rimsCONF-
dc.citation.beginningpage490-
dc.citation.endingpage494-
dc.citation.publicationnameIEEE International IOT, Electronics and Mechatronics Conference (IEMTRONICS)-
dc.identifier.conferencecountryUS-
dc.identifier.conferencelocationELECTR NETWORK-
dc.identifier.doi10.1109/IEMTRONICS52119.2021.9422529-
dc.contributor.localauthorShin, Seungwon-
dc.contributor.nonIdAuthorKang, Haney-
dc.contributor.nonIdAuthorKim, Jinwoo-
Appears in Collection
EE-Conference Papers(학술회의논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 2 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0