OSCAIR: OS-Level System Call Dataset for Attack Identity Resolution in Containers
Suhas Thalanki, Sachin Shankar, Krithika Ragothaman, Divya Shekar, Subramanian Kalambur · 2022
Behavior and resource usage of the OS during the event of an exploit of a vulnerability has a unique prevalence in intrusion detection. Furthermore, the advancement and widespread adoption of cloud technology from virtual machines to containers that run on the host OS demands better container security. We provide a dataset containing system calls and associated system parameters invoked during a wide range of relevant and diverse external and internal attacks that compromise container security. The vulnerabilities chosen have a high impact on real-world applications in terms of damage done and ease of attack. Additionally, these are more recently identified vulnerabilities than those present in previous datasets. Furthermore, we provide the system calls and parameters invoked during the normal, safe container functioning as a baseline. Our dataset thus facilitates the analysis and early identification of vulnerabilities via system calls invoked at the OS level.