首页> 外文会议>Latin-American Symposium on Dependable Computing >An Empirical Study of Docker Vulnerabilities and of Static Code Analysis Applicability
【24h】

An Empirical Study of Docker Vulnerabilities and of Static Code Analysis Applicability

机译:Docker漏洞和静态代码分析适用性的实证研究

获取原文

摘要

Containers are a lighter solution to traditional virtualization, avoiding the overhead of starting and configuring the virtual machines. Docker is very popular due to its portability, ease of deployment and configuration. However, the security problems that it may have are still not completely understood. This paper aims at understanding Docker security vulnerabilities and what could have been done to avoid them. For this, we performed a detailed analysis of the security reports and respective vulnerabilities, systematizing them according to causes, effects, and consequences. Then, we analyzed the applicability of static code analyzers in Docker codebase, trying to understand, in hindsight, the usefulness of tools reports. For a deeper understanding, we analyzed concrete exploits for some vulnerabilities. The results show a prevalence of bypass and gain privileges, and that the used tools are rather ineffective, not helping to identify the analyzed vulnerabilities. We also observed that some vulnerabilities would be easy to find using robustness or penetration testing, while others would be really challenging.
机译:容器是传统虚拟化的较轻解决方案,避免了启动和配置虚拟机的开销。 Docker因其可移植性,易于部署和配置而非常受欢迎。但是,它可能存在的安全问题仍未完全理解。本文旨在了解Docker安全漏洞以及如何避免这些漏洞。为此,我们对安全报告和相应的漏洞进行了详细的分析,并根据原因,结果和后果将其系统化。然后,我们分析了静态代码分析器在Docker代码库中的适用性,试图事后理解工具报告的有用性。为了更深入地了解,我们分析了一些漏洞的具体利用。结果表明,普遍存在绕过和获取特权的现象,并且所使用的工具效果不佳,无法帮助识别所分析的漏洞。我们还观察到,使用健壮性或渗透性测试很容易发现某些漏洞,而其他漏洞则确实具有挑战性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号