...
首页> 外文期刊>Future generation computer systems >Integrity verification of Docker containers for a lightweight cloud environment
【24h】

Integrity verification of Docker containers for a lightweight cloud environment

机译:用于轻量级云环境的Docker容器的完整性验证

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Virtualisation techniques are growing in popularity and importance, given their application to server consolidation and to cloud computing. Remote Attestation is a well-known technique to assess the software integrity of a node. It works well with physical platforms, but not so well with virtual machines hosted in a full virtualisation environment (such as the Xen hypervisor or Kernel-based Virtual Machine) and it is simply not available for a lightweight virtualisation environment (such as Docker). On the contrary, the latter is increasingly used, especially in lightweight cloud platforms, because of its flexibility and limited overhead as compared to virtual machines. This paper presents a solution for security monitoring of a lightweight cloud infrastructure, which exploits Remote Attestation to verify the software integrity of cloud applications during their whole life-cycle. Our solution leverages mainstream tools and architectures, like the Linux Integrity Measurement Architecture, the OpenAttestation platform and the Docker container engine, making it practical and readily available in a real-world scenario. Compared to a standard Docker deployment, our solution enables run-time verification of container applications at the cost of a limited overhead. (C) 2019 Elsevier B.V. All rights reserved.
机译:鉴于应用于服务器整合和云计算,虚拟化技术越来越受欢迎和重要性。远程证明是一种众所周知的技术,用于评估节点的软件完整性。它适用于物理平台,但在完整的虚拟化环境中托管的虚拟机(例如基于Xen虚拟机管理程序或基于内核的虚拟机),并且它根本不适用于轻量级虚拟化环境(如Docker)。相反,后者越来越多地使用,特别是在轻质云平台上,由于其与虚拟机相比它的灵活性和有限的开销。本文提出了一种用于轻量级云基础架构的安全监控解决方案,它利用远程证明来验证整个生命周期中云应用程序的软件完整性。我们的解决方案利用主流工具和架构,如Linux完整性测量架构,Openattation平台和Docker集装箱发动机,使其在真实的场景中实用且随时可用。与标准Docker部署相比,我们的解决方案使得能够以有限的开销的成本运行时间验证容器应用。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号