Covert Channels Through Docker Image Manipulation
Jacob Fricano, Nicholas Geigel, Daryl Johnson · 2025
Technologies such as Docker help to improve the efficiency of software development lifecycles. They are portable and lightweight packages that can be specially tailored to a wide range of use cases. That said, the nature of shared resources and portability regarding container technology poses serious risks to the security of containers as a whole. While platforms such as DockerHub enable developers to share software packages like never before, they also facilitate the distribution of container risks and vulnerabilities, including opportunities for covert channels. We present a covert channel methodology that leverages Docker-Hub as a distribution platform for covert messages embedded in Docker images. Contrary to existing container covert channels, we focus on static data embedding in Docker images rather than runtime behavior. Our implementation embeds encoded data into files within Docker images, and using sending/receiving orchestrators, we establish a reliable method for encoding, transmitting, and retrieving covert messages via DockerHub. This proof-of-concept highlights the potential for leveraging container platforms like DockerHub for covert communications. We discuss the limitations of our approach and propose future enhancements involving advanced steganography techniques and resilience testing against machine-learning-based detection methods.