DockerGate: Automated Seccomp Policy Generation for Docker Images
Rohit Venkata Satya Kuppili · 2025
With Docker's rising adoption in cloud services, security concerns arise due to its default access to extensive system calls, increasing the host kernel's attack surface. Docker's Seccomp profiles offer a way to restrict system calls but require intricate, image-specific configurations. I introduce DockerGate, a tool for automated Seccomp policy generation tailored to Docker images. DockerGate employs static analysis to map and aggregate the necessary system calls from binaries within a container image, generating minimal privilege profiles. my methodology involves analyzing ELF binaries using tools like nm, 1dd, and objdump to identify system calls invoked by dynamically linked libraries. Testing DockerGate on 110 Docker images demonstrates its effectiveness in reducing system call access while maintaining container functionality, significantly narrowing the attack surface and enhancing security in containerized environments.