Machine Learning Techniques to Enhance Container Network Security

Abhinav Kommula, Yen-Hung Frank Hu, Mary Ann Hoppa, Samuel Olatunbosun · 2020

Containers are designed as lightweight alternatives to Virtual Machines (VMs) with faster and more efficient deployment capabilities. As more applications are being run in the cloud, containers’ role in deploying microservices is becoming increasingly important. Retrofitting new technology like containers into existing technology such as Linux introduces security vulnerabilities. In this paper, we analyze in detail several aspects of container security: shared resources like memory and network in the public cloud. Through experimentation, we programmatically proved that there are no threats in memory sharing between containers on Linux Ubuntu 20.04LTS. However, shared networking imposes security vulnerabilities. To mitigate these issues of shared networking, we propose a machine learning solution in which a stateful network bridge can learn critical information, such as Media Access Control (MAC) addresses of containers and Internet Protocol (IP) addresses and port numbers used by applications, through Layer 2 and Layer 3 processing of packets within a Docker-Compose cluster. This solution will not only help identify spoofing attacks, but it will also prevent network traffic snooping, thus securing application containers. We hope that our analysis will augment current efforts in implementing more secure containers and provide new avenues of research in container network security.

Read the paper · More papers on PaperTik