Sprofiler: Automatic Generating System of Container-Native System Call Filtering Rules for Attack Surface Reduction
Takashi Iiguni, Hitoshi Kamei, Keizo Saisho · 2021 International Conference on Computational Science and Computational Intelligence (CSCI) · 2021
Containerized virtualization technologies are applied to many production environments. Compared with VMs, the image size of containers is relatively small and the containers launch quickly. Therefore, containers can achieve fast scale-out, high portability, and fast release cycles. Meanwhile, containerized virtualization may cause security incidents when operated in a multi-tenant environment, such as public cloud. Container runtimes may have a vulnerability of privilege escalation attack from a container to its host because containers and their host share the kernel of operating system. Even if there is no vulnerability in container runtimes, the privilege escalation attacks may be possible when the container runtimes are configured inadequately. As a countermeasure, restricting system calls using system call filter such as Seccomp-BPF could be applied. However, it is difficult for system administrators to know the system calls issued by applications. It is necessary to have a function that examines the system calls issued by the application and support the creation of filtering rules.In this study, we propose Sprofiler which generates filtering rules that are suitable for a workload of a container by combining static analysis of application executable files and dynamic analysis of system calls issued from the container. This paper describes the design and implementation of the Sprofiler. Moreover, it shows the evaluation results of the effectiveness by applying system call filtering rules generated by the Sprofiler.