BPFContain: Fixing the Soft Underbelly of Container Security

02/13/2021
by   William Findlay, et al.
0

Linux containers currently provide limited isolation guarantees. While containers separate namespaces and partition resources, the patchwork of mechanisms used to ensure separation cannot guarantee consistent security semantics. Even worse, attempts to ensure complete coverage results in a mishmash of policies that are difficult to understand or audit. Here we present BPFContain, a new container confinement mechanism designed to integrate with existing container management systems. BPFContain combines a simple yet flexible policy language with an eBPF-based implementation that allows for deployment on virtually any Linux system running a recent kernel. In this paper, we present BPFContain's policy language, describe its current implementation as integrated into docker, and present benchmarks comparing it with current container confinement technologies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/18/2012

A trust-based security mechanism for nomadic users in pervasive systems

The emergence of network technologies and the appearance of new varied a...
research
09/17/2023

OSmosis: No more Déjà vu in OS isolation

Operating systems provide an abstraction layer between the hardware and ...
research
02/20/2023

Programmable System Call Security with eBPF

System call filtering is a widely used security mechanism for protecting...
research
09/01/2021

CorbFuzz: Checking Browser Security Policies with Fuzzing

Browsers use security policies to block malicious behaviors. Cross-Origi...
research
05/05/2021

Trusted Enforcement of Application-specific Security Policies

While there have been approaches for integrating security policies into ...
research
11/14/2017

Practical Whole-System Provenance Capture

Data provenance describes how data came to be in its present form. It in...
research
01/24/2018

vLibOS: Babysitting OS Evolution with a Virtualized Library OS

Many applications have service requirements that are not easily met by e...

Please sign up or login with your details

Forgot password? Click here to reset