A Perfect Fit? - Towards Containers on Microkernels

Till Miemietz, Viktor Reusch, Matthias Hille, Max Kurze, Adam Lackorzyński, Michael Roitzsch, Hermann Härtig · 2024

Containers are a light weight alternative to virtual machines, building on sandboxed processes whose permissions are restricted by additional security mechanisms such as seccomp-bpf. However, these mechanisms increase the kernel's attack surface, thus prompting new security challenges. In this paper, we ask the question of whether a system with processes properly restricted by design enables a container infrastructure with better security posture. For instance, microkernels with capability-based access control provide container-style isolation out of the box. On the basis of real-world CVEs, we argue that this conceptual simplicity actually results in a better security posture than that typically found on monolithic systems.

Read the paper · More papers on PaperTik