Concentrated isolation for container networks toward application-aware sandbox tailoring

Concentrated isolation for container networks toward application-aware sandbox tailoring
复制标题

DOI:
10.1145/3468737.3494092
复制
发表时间:
2021-12
期刊:
Proceedings of the 14th IEEE/ACM International Conference on Utility and Cloud Computing
影响因子:
--
通讯作者:
Yuki Nakata;Katsuya Matsubara;Ryosuke Matsumoto
Yuki Nakata;Katsuya Matsubara;Ryosuke Matsumoto
中科院分区:
其他
文献类型:
--
作者:
Yuki Nakata;Katsuya Matsubara;Ryosuke Matsumoto

文献摘要

相似文献

容器为计算资源(如CPU、内存、存储和网络)提供了轻量级和细粒度的隔离,但它们的弱隔离引发了安全问题。因此,研究和开发工作集中于使用系统调用拦截和硬件虚拟化技术(如gVisor和Kata容器)重新设计真正的沙箱容器。然而,这种完全集成的沙箱可能会压倒容器的轻量级和可伸缩性。在这项工作中,我们提出了一种部分加固的沙箱机制,集中加强了网络隔离,重点考虑了容器化云和运行在其上的应用根据其独特的特征需要不同的隔离级别。我们描述了如何高效地实施该机制,以增强具有旁通管理程序的容器的网络隔离,并通过基准测试和实际应用报告评估结果。我们的发现表明,这种强化的网络隔离在为容器化的PaaS/Faas云定制沙盒方面具有很好的潜力。
Containers provide a lightweight and fine-grained isolation for computational resources such as CPUs, memory, storage, and networks, but their weak isolation raises security concerns. As a result, research and development efforts have focused on redesigning truly sandboxed containers with system call intercept and hardware virtualization techniques such as gVisor and Kata Containers. However, such fully integrated sandboxing could overwhelm the lightweight and scalable nature of the containers. In this work, we propose a partially fortified sandboxing mechanism that concentratedly fortifies the network isolation, focusing on the fact that containerized clouds and the applications running on them require different isolation levels in accordance with their unique characteristics. We describe how to efficiently implement the mechanism to fortify network isolation for containers with a para-passthrough hypervisor and report evaluation results with benchmarks and real applications. Our findings demonstrate that this fortified network isolation has good potential to tailor sandboxes for containerized PaaS/FaaS clouds.