Insight from a Docker Container Introspection

Insight from a Docker Container Introspection
复制标题

DOI:
10.24251/hicss.2019.863
复制
发表时间:
2019-01
期刊:
--
影响因子:
--
通讯作者:
Thomas Watts;Ryan G. Benton;W. Glisson;Jordan Shropshire
Thomas Watts;Ryan G. Benton;W. Glisson;Jordan Shropshire
中科院分区:
其他
文献类型:
--
作者:
Thomas Watts;Ryan G. Benton;W. Glisson;Jordan Shropshire

文献摘要

被引文献

相似文献

虚拟容器的大规模采用引起了从业者和学者对数据采集的可行性和可靠性的担忧,因为收集相关数据点的窗口越来越小。这些问题促使人们想到,能够在系统运行时从系统中获取数据的内省工具既可以用作早期预警系统来保护该系统,也可以用作数据捕获系统来收集从数字取证角度来看有价值的数据。利用Docker引擎和Prometheus作为内省工具进行了探索性案例研究。这项研究的贡献是双重的。首先,它提供了经验支持的想法,可以利用内省工具,以确定原始和受感染的容器之间的差异。其次,它为未来的研究提供了基础工作,在虚拟云中分析大规模容器化应用程序。
Large-scale adoption of virtual containers has stimulated concerns by practitioners and academics about the viability of data acquisition and reliability due to the decreasing window to gather relevant data points. These concerns prompted the idea that introspection tools, which are able to acquire data from a system as it is running, can be utilized as both an early warning system to protect that system and as a data capture system that collects data that would be valuable from a digital forensic perspective. An exploratory case study was conducted utilizing a Docker engine and Prometheus as the introspection tool. The research contribution of this research is two-fold. First, it provides empirical support for the idea that introspection tools can be utilized to ascertain differences between pristine and infected containers. Second, it provides the ground work for future research conducting an analysis of large-scale containerized applications in a virtual cloud.