SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense Mechanisms
Md. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer, Turgay Korkmaz, Ahmad-Reza Sadeghi
Abstract
Container-based applications are increasingly favored for their efficiency in software development, deployment, and operation across various platforms. However, the growing number of security and privacy attacks poses significant concerns. Exploiting vulnerabilities within containers may compromise the entire host system, as both share the same operating system. Unfortunately, container defense mechanisms are inadequate due to the ever-evolving and dynamic attack landscape.
In this paper, we systematize container attacks and defense mechanisms. We systematically analyze the effectiveness of (i) static container scanning tools proposed for vulnerability detection and reveal their shortcomings, as well as (ii) existing run-time anomaly-based detection approaches. We then establish an evaluation framework and comprehensively reevaluate cutting-edge anomaly detection techniques tailored for containers using an extensive dataset of 51 real-world vulnerabilities. We emphasize that existing defenses are ineffective in protecting containers against state-of-the-art attacks. While anomaly detection-based approaches show potential in addressing dynamic attack landscapes, their high false positive rates and limited training data hinder practicality. Therefore, our work highlights the urgent need for further research to enhance the security of container-based applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0e7d8a96-629c-47ae-94e2-e05448e8d5a5Cited by top-tier papers2
- JANUS: Cross-World, Cooperative Nested Virtualization for Secure ContainersJiangshan Lai, Hang Huang, Quan Xu, Zhen Ren et al.OSDI 2026
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang et al.NDSS 2026
Builds on7
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis et al.USENIX Security 2018 · 79 citations
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom et al.CCS 2019 · 62 citations
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 36 citations
Related papers
- Exploring the Unchartered Space of Container Registry TyposquattingGuannan Liu, Xing Gao, Haining Wang, Kun SunUSENIX Security 2022
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu et al.NDSS 2026 · 3 citations
- Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationZhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan et al.CCS 2023 · 6 citations
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie et al.EuroSys 2026 · 1 citation
