DC Field | Value | Language |
---|---|---|
dc.contributor.author | Bargmann, Christian Frank | - |
dc.contributor.author | Tropmann-Frick, Marina | - |
dc.date.accessioned | 2020-09-02T15:40:47Z | - |
dc.date.available | 2020-09-02T15:40:47Z | - |
dc.date.issued | 2019-12-04 | - |
dc.identifier.issn | 1613-0073 | en_US |
dc.identifier.uri | http://hdl.handle.net/20.500.12738/4989 | - |
dc.description.abstract | Container virtualization has become the tool of choice for running isolated applications in cloud environments. Linux-Containers virtualize at the operating system level, with multiple containers running atop the operating system kernel directly. Therefore, threats to one container are potentially threats to many others. Especially for PaaS and Serverless providers, the secure execution of untrusted workloads on their platform in order to mitigate software vulnerabilities from spreading has high priority. Containers face a variety of different threats, vulnerabilities and historical weaknesses that need to be considered and defended against. This paper presents current approaches to securing container workloads. gVisor, Kata Containers and Firecracker are presented and compared with each other. Although sandbox containers have different attack surfaces such as the container daemon process, network, or storage, this paper focuses on the Linux kernel itself as a vulnerability in sandbox containers and examines how each approach implements protection. | en |
dc.language.iso | en | en_US |
dc.publisher | RWTH Aachen | en_US |
dc.relation.ispartof | CEUR workshop proceedings | en_US |
dc.subject.ddc | 004: Informatik | en_US |
dc.title | A survey on secure container isolation approaches for multi-tenant container workloads and serverless computing | en |
dc.type | inProceedings | en_US |
dc.relation.conference | Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications 2019 | en_US |
dc.description.version | PeerReviewed | en_US |
local.contributorPerson.editor | Budimac, Zoran | - |
local.contributorPerson.editor | Koteska, Bojana | - |
tuhh.container.endpage | 1:10 | en_US |
tuhh.container.startpage | 1:1 | en_US |
tuhh.container.volume | 2508 | en_US |
tuhh.oai.show | true | en_US |
tuhh.publication.institute | Department Informatik | en_US |
tuhh.publication.institute | Fakultät Technik und Informatik | en_US |
tuhh.publisher.url | https://ceur-ws.org/Vol-2508/paper-bar.pdf | - |
tuhh.publisher.url | http://nbn-resolving.de/urn:nbn:de:0074-2508-8 | - |
tuhh.relation.ispartofseries | Eighth Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications - SQAMIA 2019 : Ohrid, North Macedonia, 22-25.09.2019 : proceedings | en_US |
tuhh.type.opus | InProceedings (Aufsatz / Paper einer Konferenz etc.) | - |
dc.rights.cc | https://creativecommons.org/licenses/by/4.0/ | en_US |
dc.type.casrai | Conference Paper | - |
dc.type.dini | contributionToPeriodical | - |
dc.type.driver | contributionToPeriodical | - |
dc.type.status | info:eu-repo/semantics/publishedVersion | en_US |
dcterms.DCMIType | Text | - |
item.languageiso639-1 | en | - |
item.fulltext | No Fulltext | - |
item.creatorGND | Bargmann, Christian Frank | - |
item.creatorGND | Tropmann-Frick, Marina | - |
item.tuhhseriesid | Eighth Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications - SQAMIA 2019 : Ohrid, North Macedonia, 22-25.09.2019 : proceedings | - |
item.openairetype | inProceedings | - |
item.grantfulltext | none | - |
item.creatorOrcid | Bargmann, Christian Frank | - |
item.creatorOrcid | Tropmann-Frick, Marina | - |
item.seriesref | Eighth Workshop on Software Quality Analysis, Monitoring, Improvement, and Applications - SQAMIA 2019 : Ohrid, North Macedonia, 22-25.09.2019 : proceedings | - |
item.cerifentitytype | Publications | - |
item.openairecristype | http://purl.org/coar/resource_type/c_5794 | - |
crisitem.author.dept | Department Informatik | - |
crisitem.author.dept | Department Informatik | - |
crisitem.author.orcid | 0000-0003-1623-5309 | - |
crisitem.author.parentorg | Fakultät Technik und Informatik | - |
crisitem.author.parentorg | Fakultät Technik und Informatik | - |
Appears in Collections: | Publications without full text |
Add Files to Item
Note about this record
Export
This item is licensed under a Creative Commons License