Confine: Automated System Call Policy Generation for Container Attack Surface Reduction

Confine: Automated System Call Policy Generation for Container Attack Surface Reduction
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis
Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis
中科院分区:
其他
文献类型:
--
作者:
Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis

文献摘要

被引文献

相似文献

减少OS内核的攻击表面是一种应许在易于抗拒的系统的脆弱隔离的方法,而恶意容器可以利用基础内核中的脆弱性,以完全损害宿主和主机和主机,所有其他容器在其上运行的容器攻击效果都在动态分析和使用逼真的工作负载方面放松但是,这些方法都不会详尽地捕获所有可能因未来工作量或罕见的运行时条件所需的代码,因此不合适地作为通用解决方案。容器,在本文中,我们提出了一种通用的方法,用于自动生成docker容器的限制性系统呼叫策略。容器化的应用程序及其所有依赖项,确定容器正确操作所需的系统调用的超集,并生成相应的Seccomp系统呼叫策略,可以在加载容器时容易强制执行。 Docker图像表明,Confinen可以通过将145个或更多系统调用(在326中)禁用一半以上的容器,从而成功地降低其攻击表面中和51个先前披露的内核漏洞。
Reducing the attack surface of the OS kernel is a promising defense-in-depth approach for mitigating the fragile isolation guarantees of container environments. In contrast to hypervisor-based systems, malicious containers can exploit vulnerabilities in the underlying kernel to fully compromise the host and all other containers running on it. Previous container attack surface reduction efforts have relied on dynamic analysis and training using realistic workloads to limit the set of system calls exposed to containers. These approaches, however, do not capture exhaustively all the code that can potentially be needed by future workloads or rare runtime conditions, and are thus not appropriate as a generic solution. Aiming to provide a practical solution for the protection of arbitrary containers, in this paper we present a generic approach for the automated generation of restrictive system call policies for Docker containers. Our system, named Confine , uses static code analysis to inspect the containerized application and all its dependencies, identify the superset of system calls required for the correct operation of the container, and generate a corresponding Seccomp system call policy that can be readily enforced while loading the container. The results of our experimental evaluation with 150 publicly available Docker images show that Confine can successfully reduce their attack surface by disabling 145 or more system calls (out of 326) for more than half of the containers, which neutralizes 51 previously disclosed kernel vulnerabilities.