Security hardening solution for docker container

Nan Yang, Cen Chen, Tao Yuan, Yujie Wang, Xiaofan Gu, Dan Yang · 2022

Docker uses software isolation mechanism while sharing the operating system kernel with the host, which results in insufficient isolation between containers and hosts. Attackers can affect the stable operation of hosts and other containers by attacking containers, causing container escape issues. In this paper, we design a security hardening scheme for docker containers. By detecting the vulnerabilities in container images, it avoids malicious vulnerabilities and performs image measurement to ensure that the images before the container is started has not been tampered. Through the container integrity measurement module, the process of measuring the code segment, data segment, and the shared library of the container ensures that the contents of these areas will not be tampered during the container’s operation. Further, it reduces the attacking surface by setting the system whitelist for the container process and restricting the interaction between the container and the external network. This improves the container safety and reliability.

Read the paper · More papers on PaperTik