Detection, Analysis and Countermeasures for Container based Misconfiguration using Docker and Kubernetes
Vijay B Mahajan, Sunil B. Mane · 2022 International Conference on Computing, Communication, Security and Intelligent Systems (IC3SIS) · 2022
In the era of a fast, productive project delivery lifecycle, the technologies like Docker containers are used in mass for deployment as well as development and production phases of the SDLC (Software Development Life Cycle) phase. Container technology changed ways of application packaging and delivery methods with the efforts of deploying them as a service in the cloud environment. Docker is a leading technology that automates the process of deployment of containers. Kubernetes is a container management tool that helps to automate multiple container deployment, descaling, and load balancing. Container technology brings a new, faster, and easier way of achieving software building phases, but it also comes with a cost of security. As containers are lightweight and are a cloud-based technology for implementing virtualization in a unique way of itself, it also brings security concerns with it, that can give adversaries a way to exploit the containerization process and cause security attacks within the containers. Such attacks may be caused due to misconfiguration of containers while deploying the containers at the early phase, which leads to a vulnerable environment ready to be exploited by adversaries or which creates vulnerabilities that can cause havoc. The purpose of the research is to analyze the container deployment misconfigurations, which may be the first step of defense for container security that is required to evade further exploitation before it occurs. The attempt is to give possible container deployment security policies that can help secure the cloud environment from security attacks with proper configurations done during the deployment phase of containers. The proposed system may be used to implement a tool that can possibly detect the misconfigurations and help secure the process.