首页> 外文会议>IEEE International Conference on Distributed Computing Systems Workshops >Leveraging the Serverless Architecture for Securing Linux Containers
【24h】

Leveraging the Serverless Architecture for Securing Linux Containers

机译:利用无服务器架构保护Linux容器的安全

获取原文

摘要

Linux containers present a lightweight solution to package applications into images and instantiate them in isolated environments. Such images may include vulnerabilities that can be exploited at runtime. A vulnerability scanning service can detect these vulnerabilities by periodically scanning the containers and their images for potential threats. When a threat is detected, an event may be generated to (1) quarantine or terminate the compromised container(s) and optionally (2) remedy the vulnerability by rebuilding a secure image. We believe that such event-driven process is a great fit to be implemented in a serverless architecture. In this paper we explore the design of an automated threat mitigation architecture based on OpenWhisk and Kubernetes.
机译:Linux容器提供了一种轻量级的解决方案,可以将应用程序打包到映像中并在隔离的环境中实例化它们。此类映像可能包含可以在运行时利用的漏洞。漏洞扫描服务可以通过定期扫描容器及其映像以发现潜在威胁来检测这些漏洞。当检测到威胁时,可能会生成事件以(1)隔离或终止受感染的容器,并可以选择(2)通过重建安全映像来补救漏洞。我们认为,这种事件驱动的过程非常适合在无服务器架构中实现。在本文中,我们探索了基于OpenWhisk和Kubernetes的自动威胁缓解架构的设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号