A Secure Container Placement Algorithm Based on Microservice Invocation Criticality
Mingyang Li, Hongchao Hu, Wenyan Liu · 2024
The lightweight and efficient characteristics of container technology make it gradually become an important player in cloud computing. The characteristics of shared kernel and operating system make the risk of container co-resident attacks increasingly severe, while the complex calling relationship between microservices exacerbates the risk of co-resident attacks. The existing container placement algorithms only consider load balancing, the existing container placement algorithms either only consider load balancing, or do not fully consider all aspects of security risks that may be brought by container co-resident attacks. Aiming at the problems existing in the current research, this paper establishes a multi-application container cloud threat model to evaluate the risk of co-resident attacks within and between nodes, and comprehensively considers the risk of co-resident threats spreading with the service chain and the load balance of the system. On this basis, the Secure Container Placement Algorithm (SmCPA) is proposed based on the criticality of microservice invocations, which evaluates and ranks the criticality of microservices, and optimizes the container placement process step by step. Finally, the experimental results show that compared with the existing algorithms, SmCPA algorithm reduces the risk of co-resident attack by 17.38%, and improves the load balancing by 13.39%.