CofferOS: Hardening OS-level Virtualization with Rust
Minkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park, Changjun Lee, Jongyul Kim, Jeehoon Kang, Youngjin Kwon
2026Year
Abstract
OS-level virtualization (e.g., Linux containers) has become a cornerstone of modern cloud systems. While it offers the illusion of isolated kernels for processes, these processes share the same underlying kernel, raising critical concerns around security, fault isolation, and the inability to customize kernels. Existing solutions address the issues by employing virtual machines that isolate kernels. However, these approaches incur significant performance overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 82821087-28dc-45f0-b34d-32c85cc99309Related papers
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie et al.EuroSys 2026 · 1 citation
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang et al.CCS 2021 · 32 citations
- MettEagle: Costs and Benefits of Implementing Containers on MicrokernelsTill Miemietz, Viktor Reusch, Matthias Hille, Lars Wrenger et al.OSDI 2025 · 2 citations
- PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native EnvironmentHang Huang, Jiangshan Lai, Jia Rao, Hui Lu et al.SOSP 2023 · 4 citations
