Securing Container-based Clouds with Syscall-aware Scheduling

Michael V. Le, Salman Ahmed, Dan Williams, Hani Jamjoom · 2023

Container-based clouds—in which containers are the basic unit of isolation—face security concerns because, unlike Virtual Machines, containers directly interface with the underlying highly privileged kernel through the wide and vulnerable system call interface. Regardless of whether a container itself requires dangerous system calls, a compromised or malicious container sharing the host (a bad neighbor) can compromise the host kernel using a vulnerable syscall, thereby compromising all other containers sharing the host.

Read the paper · More papers on PaperTik