首页> 外文期刊>IEEE transactions on dependable and secure computing >A Study on the Security Implications of Information Leakages in Container Clouds
【24h】

A Study on the Security Implications of Information Leakages in Container Clouds

机译:集装箱云信息泄漏安全影响研究

获取原文
获取原文并翻译 | 示例

摘要

Container technology provides a lightweight operating system level virtual hosting environment. Its emergence profoundly changes the development and deployment paradigms of multi-tier distributed applications. However, due to the incomplete implementation of system resource isolation mechanisms in the Linux kernel, some security concerns still exist for multiple containers sharing an operating system kernel on a multi-tenancy container-based cloud service. In this paper, we first present the information leakage channels we discovered that are accessible within containers. Such channels expose a spectrum of system-wide host information to containers without proper resource partitioning. By exploiting such leaked host information, it becomes much easier for malicious adversaries (acting as tenants in a container cloud) to launch attacks that might impact the reliability of cloud services. We demonstrate that the information leakage channels could be exploited to infer private data, detect and verify co-residence, build covert channels, and launch more advanced cloud-based attacks. We discuss the root causes of the containers' information leakage and propose a two-stage defense approach. As demonstrated in the evaluation, our defense is effective and incurs trivial performance overhead.
机译:集装箱技术提供了轻量级操作系统级虚拟托管环境。它的出现深刻地改变了多层分布式应用程序的开发和部署范例。然而,由于Linux内核中系统资源隔离机制的不完整实现,多个容器在基于多租户容器的云服务上共享操作系统内核的多个容器仍然存在一些安全问题。在本文中,我们首先介绍了我们发现的信息泄漏渠道,该信息可在容器内访问。此类信道将系统范围广泛的主信息公开到容器,而无需适当的资源分区。通过利用这种泄露的主机信息,恶意对手(作为集装箱云中的租户的租户)变得更加容易发射可能影响云服务可靠性的攻击。我们证明信息泄漏通道可以利用来推断私有数据,检测和验证共同住所,构建隐蔽频道,并启动更高级的基于云的攻击。我们讨论了集装箱信息泄漏的根本原因,并提出了一种两级防御方法。如在评估中所证明,我们的防范是有效的,并遭受琐碎的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号