@article{ART002627060},
author={Jihyeok Yang and Byungchul Tak},
title={Security Assessment Technique of a Container Runtime Using System Call Weights},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2020},
volume={25},
number={9},
pages={21-29},
doi={10.9708/jksci.2020.25.09.021}
TY - JOUR
AU - Jihyeok Yang
AU - Byungchul Tak
TI - Security Assessment Technique of a Container Runtime Using System Call Weights
JO - Journal of The Korea Society of Computer and Information
PY - 2020
VL - 25
IS - 9
PB - The Korean Society Of Computer And Information
SP - 21
EP - 29
SN - 1598-849X
AB - In this paper, we propose quantitative evaluation method that enable security comparison between Security Container Runtimes. security container runtime technologies have been developed to address security issues such as Container escape caused by containers sharing the host kernel. However, most literature provides only a analysis of the security of container technologies using rough metrics such as the number of available system calls, making it difficult to compare the secureness of container runtimes quantitatively. While the proposed model uses a new method of combining the degree of exposure of host system calls with various external vulnerability metrics. With the proposed technique, we measure and compare the security of runC (Docker default Runtime) and two representative Security Container Runtimes, gVisor, and Kata container.
KW - Container Security;Container Runtime;Vulnerability;System call;Exploit
DO - 10.9708/jksci.2020.25.09.021
ER -
Jihyeok Yang and Byungchul Tak. (2020). Security Assessment Technique of a Container Runtime Using System Call Weights. Journal of The Korea Society of Computer and Information, 25(9), 21-29.
Jihyeok Yang and Byungchul Tak. 2020, "Security Assessment Technique of a Container Runtime Using System Call Weights", Journal of The Korea Society of Computer and Information, vol.25, no.9 pp.21-29. Available from: doi:10.9708/jksci.2020.25.09.021
Jihyeok Yang, Byungchul Tak "Security Assessment Technique of a Container Runtime Using System Call Weights" Journal of The Korea Society of Computer and Information 25.9 pp.21-29 (2020) : 21.
Jihyeok Yang, Byungchul Tak. Security Assessment Technique of a Container Runtime Using System Call Weights. 2020; 25(9), 21-29. Available from: doi:10.9708/jksci.2020.25.09.021
Jihyeok Yang and Byungchul Tak. "Security Assessment Technique of a Container Runtime Using System Call Weights" Journal of The Korea Society of Computer and Information 25, no.9 (2020) : 21-29.doi: 10.9708/jksci.2020.25.09.021
Jihyeok Yang; Byungchul Tak. Security Assessment Technique of a Container Runtime Using System Call Weights. Journal of The Korea Society of Computer and Information, 25(9), 21-29. doi: 10.9708/jksci.2020.25.09.021
Jihyeok Yang; Byungchul Tak. Security Assessment Technique of a Container Runtime Using System Call Weights. Journal of The Korea Society of Computer and Information. 2020; 25(9) 21-29. doi: 10.9708/jksci.2020.25.09.021
Jihyeok Yang, Byungchul Tak. Security Assessment Technique of a Container Runtime Using System Call Weights. 2020; 25(9), 21-29. Available from: doi:10.9708/jksci.2020.25.09.021
Jihyeok Yang and Byungchul Tak. "Security Assessment Technique of a Container Runtime Using System Call Weights" Journal of The Korea Society of Computer and Information 25, no.9 (2020) : 21-29.doi: 10.9708/jksci.2020.25.09.021