arrow
返回

Securing the Shared Kernel: Exploring Kernel Isolation and Emerging Challenges in Modern Cloud Computing

delete2024-01-01
delete0
delete
OA
AI
S
Sehar Zehra
H
Hassan Jamil Syed *
F
Fahad Samad
U
Ummay Faseeha
M
Muhammad Khurram Khan
DOI:10.1109/ACCESS.2024.3507215delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Containerization is a rapidly advancing technology in cloud computing, facilitating the seamless development, deployment, and management of applications across diverse computing environments. This technology offers lightweight operations, portability, efficiency, and scalability advantages, applicable to developer workstations, mission-critical web servers, and the public cloud. However, unlike Virtual Machines (VMs), containers share the underlying machine's operating system (OS) kernel, which introduces unique security challenges alongside speed and efficiency benefits. These challenges include the risks of container escape attacks, privilege escalation, and exploitation of kernel vulnerabilities. This paper comprehensively reviews state-of-the-art containerization security solutions, focusing on various kernel isolation approaches. It proposes a thematic taxonomy of containerization security, highlighting essential parameters to help developers understand the security needs within a shared kernel environment. This paper describes the current landscape of container security by examining critical developments, challenges, and trends in the existing literature-from system calls to kernel isolation. Additionally, it identifies open research issues and discusses industry best practices and emerging developments in container security, aiming to guide future research and implementation strategies.
Keyword:
Containers
Security
Kernel
Taxonomy
Linux
Libraries
Computer architecture
Cloud computing
Workstations
System kernels
Containerization
kernel isolation & security
shared kernel environment
cloud computing security
container escape attacks
privilege escalation
virtual machine (VM)
system call filtering

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

K
King Saud University
学者数:
3.4W
论文数: 3.8W
被引数: 815
引用论文

引用论文

Ca2+ signal contributing to jasmonic acid‐induced direct and indirect defense against the whitefly Bemisia tabaci in tomato plants
err2021-07-18
err0
PREAI
errXin Liu; Sabir Hussain; Wen Xie; Zhaojiang Guo; Qingjun Wu; Shaoli Wang; Yong Liu; Youjun Zhang
err分享
err收藏
err分享
err收藏
Secure Inter-Container Communications Using XDP/eBPF
err2023-04-01
err8
PREAI
errNam, Jaehyun; Lee, Seungsoo; Porras, Phillip; Yegneswaran, Vinod; Shin, Seungwon
err分享
err收藏
err分享
err收藏
Confine: Fine-grained system call filtering for container attack surface reduction
err2023-09-01
err2
errOAAI
errRostamipoor, Maryam; Ghavamnia, Seyedhamed; Polychronakis, Michalis
err分享
err收藏
A Novel Pacemaker Mechanism Drives Gastrointestinal Rhythmicity
err2000-12-01
err0
PREAI
errKenton M. Sanders; Tamás Ördög; Sang Don Koh; Sean M. Ward
err分享
err收藏
学者 查看更多内容