返回
Securing the Shared Kernel: Exploring Kernel Isolation and Emerging Challenges in Modern Cloud Computing
DOI:10.1109/ACCESS.2024.3507215.png)
摘要
En 中文
Containerization is a rapidly advancing technology in cloud computing, facilitating the seamless development, deployment, and management of applications across diverse computing environments. This technology offers lightweight operations, portability, efficiency, and scalability advantages, applicable to developer workstations, mission-critical web servers, and the public cloud. However, unlike Virtual Machines (VMs), containers share the underlying machine's operating system (OS) kernel, which introduces unique security challenges alongside speed and efficiency benefits. These challenges include the risks of container escape attacks, privilege escalation, and exploitation of kernel vulnerabilities. This paper comprehensively reviews state-of-the-art containerization security solutions, focusing on various kernel isolation approaches. It proposes a thematic taxonomy of containerization security, highlighting essential parameters to help developers understand the security needs within a shared kernel environment. This paper describes the current landscape of container security by examining critical developments, challenges, and trends in the existing literature-from system calls to kernel isolation. Additionally, it identifies open research issues and discusses industry best practices and emerging developments in container security, aiming to guide future research and implementation strategies.
Keyword:
Containers
Security
Kernel
Taxonomy
Linux
Libraries
Computer architecture
Cloud computing
Workstations
System kernels
Containerization
kernel isolation & security
shared kernel environment
cloud computing security
container escape attacks
privilege escalation
virtual machine (VM)
system call filtering
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Correlation of atomic force microscopy sidewall roughness measurements with scanning electron microscopy line-edge roughness measurements on chemically amplified resists exposed by x-ray lithography化学放大抗蚀剂经X射线光刻曝光后,原子力显微镜侧壁粗糙度测量与扫描电子显微镜线边缘粗糙度测量的相关性
Confine: Fine-grained system call filtering for container attack surface reduction
COMPUTERS & SECURITY
IF5.4

