SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense Mechanisms
Md. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer, Turgay Korkmaz, Ahmad-Reza Sadeghi
摘要
Container-based applications are increasingly favored for their efficiency in software development, deployment, and operation across various platforms. However, the growing number of security and privacy attacks poses significant concerns. Exploiting vulnerabilities within containers may compromise the entire host system, as both share the same operating system. Unfortunately, container defense mechanisms are inadequate due to the ever-evolving and dynamic attack landscape.
In this paper, we systematize container attacks and defense mechanisms. We systematically analyze the effectiveness of (i) static container scanning tools proposed for vulnerability detection and reveal their shortcomings, as well as (ii) existing run-time anomaly-based detection approaches. We then establish an evaluation framework and comprehensively reevaluate cutting-edge anomaly detection techniques tailored for containers using an extensive dataset of 51 real-world vulnerabilities. We emphasize that existing defenses are ineffective in protecting containers against state-of-the-art attacks. While anomaly detection-based approaches show potential in addressing dynamic attack landscapes, their high false positive rates and limited training data hinder practicality. Therefore, our work highlights the urgent need for further research to enhance the security of container-based applications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- JANUS: Cross-World, Cooperative Nested Virtualization for Secure ContainersJiangshan Lai, Hang Huang, Quan Xu, Zhen Ren 等OSDI 2026
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang 等NDSS 2026
它引用的顶会 Paper7
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis 等USENIX Security 2018 · 被引用 79 次
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom 等CCS 2019 · 被引用 62 次
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 被引用 36 次
相关 Paper
- Exploring the Unchartered Space of Container Registry TyposquattingGuannan Liu, Xing Gao, Haining Wang, Kun SunUSENIX Security 2022
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu 等NDSS 2026 · 被引用 3 次
- Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationZhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan 等CCS 2023 · 被引用 6 次
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie 等EuroSys 2026 · 被引用 1 次
