Analysis Performance of Container Runtime RunC, gVisor, and Kata Containers Against Denial Of Services Attacks
Aldi Khan Sakti Alvayadi, Mega Pranata · 2025
One technology that is widely used by companies to run applications effectively and safely is containers. Through containers, each application only needs to have dependences that are needed by the program without any unnecessary dependencies. Container runtime is a core component in the container to be able bridge the processes in the container and host server. One of the problems that arises behind the widespread use of containers is cyberattacks such as Denial of Service (DOS) attacks that can cause servers to be down. The urgency in preparing container runtime that is resilient against DOS attacks is increasingly necessary. This research aims to give a comprehensive analysis of performance between the commonly used container runtime runC, and container runtimes that have high security isolation architecture such as gVisor and Kata Containers. The performance of runC, Kata Containers and gVisor is based on host CPU, host memory usages, container CPU, container memory usages, web throughput, and web response time.