BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating Systems

BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating Systems
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Alexander Van't Hof;Jason Nieh
Alexander Van't Hof;Jason Nieh
中科院分区:
其他
文献类型:
--
作者:
Alexander Van't Hof;Jason Nieh

文献摘要

相似文献

容器被广泛部署来打包、隔离和多路传输共享计算基础设施上的应用程序,但依赖于操作系统来加强其安全保证。由于大型操作系统代码库包含许多漏洞,这构成了显著的fi不能安全风险。我们创建了BlackBox,这是一种新的容器架构,可以在不信任操作系统的情况下为应用程序数据保密性和完整性提供fi细粒度保护。Blackbox引入了容器安全监控器,这是一个为每个容器创建受保护的物理地址空间(PPAS)的小型可信计算基础,因此不存在从容器到操作系统或其他容器PPAS的直接信息fl。间接信息flow只能通过监视器发生,监视器只能在容器PPAS和操作系统之间复制数据作为系统调用参数,根据需要对数据进行加密,以保护通过操作系统的进程间通信。容器化的应用程序不需要修改fi,仍然可以通过系统调用使用操作系统服务,但它们的中央处理器和内存状态与其他容器和操作系统隔离并受到保护。我们通过利用ARM硬件虚拟化支持实施了BlackBox,并使用嵌套分页来实施PPAS。可信计算的基础是几千行代码,比linux少了许多数量级,但支持广泛使用的linux容器,只有少量的modifi阳离子到linux内核。我们表明,BlackBox提供了优于传统管理程序和容器架构的安全保证,而实际应用程序工作负载的性能开销不大。
Containers are widely deployed to package, isolate, and multiplex applications on shared computing infrastructure, but rely on the operating system to enforce their security guarantees. This poses a significant security risk as large operating system codebases contain many vulnerabilities. We have created BlackBox, a new container architecture that provides fine-grain protection of application data confidentiality and integrity without trusting the operating system. BlackBox introduces a container security monitor, a small trusted computing base that creates protected physical address spaces (PPASes) for each container such that there is no direct information flow from container to operating system or other container PPASes. Indirect information flow can only happen through the monitor, which only copies data between container PPASes and the operating system as system call arguments, encrypting data as needed to protect interprocess communication through the operating system. Containerized applications do not need to be modified, can still make use of operating system services via system calls, yet their CPU and memory state are isolated and protected from other containers and the operating system. We have implemented BlackBox by leveraging Arm hardware virtualization support, using nested paging to enforce PPASes. The trusted computing base is a few thousand lines of code, many orders of magnitude less than Linux, yet supports widely-used Linux containers with only modest modifications to the Linux kernel. We show that BlackBox provides superior security guarantees over traditional hypervisor and container architectures with only modest performance overhead on real application workloads.