首页> 外文会议>IEEE International Conference on Cyber Security and Cloud Computing >Secure Cloud Container: Runtime Behavior Monitoring Using Most Privileged Container (MPC)
【24h】

Secure Cloud Container: Runtime Behavior Monitoring Using Most Privileged Container (MPC)

机译:安全云容器:使用大多数特权容器(MPC)进行运行时行为监控

获取原文

摘要

Hypervisor-based virtualization rapidly becomes a commodity, and it turns valuable in many scenarios such as resource optimization, uptime maximization, and consolidation. Container-based application virtualization is an appropriate solution to develop a light weighted partitioning by providing application isolation with less overhead. Undoubtedly, container based virtualization delivers a lightweight and efficient environment, however raises some security concerns as it allows isolated processes to utilize an underlying host kernel. A new security layer with the Most Privileged Container (MPC) is proposed in this article. The proposed MPC layer exhibits three main functional blocks: Access policies, Black list database, and Runtime monitoring. The introduced MPC layer implements privilege based access control and assigns resource access permissions based on policies and the security profiles of containerized application user processes. Furthermore, the monitoring block examines the runtime behavior of containers and black list database is updated if the container violets its policies. The proposed MPC layer provides higher level of application container security against potential threats.
机译:基于管理程序的虚拟化迅速成为一种商品,它在许多情况下变得有价值,如资源优化,正常运行时间最大化和整合。基于容器的应用程序虚拟化是一种适当的解决方案,可以通过提供具有较少开销的应用隔离来开发轻加权分区。毫无疑问,基于容器的虚拟化提供了轻量级和高效的环境,但是提出了一些安全问题,因为它允许隔离的过程利用底层主机内核。本文提出了一种具有最特权容器(MPC)的新安全层。所提出的MPC层展示了三个主要功能块:访问策略,黑名单数据库和运行时监控。引入的MPC层实现了基于权限的访问控制,并根据策略和容器化应用程序用户进程的安全配置文件分配资源访问权限。此外,监控块检查容器的运行时行为,如果容器viulets策略,则会更新黑色列表数据库。提议的MPC层提供更高水平的应用容器安全性,免受潜在威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号