Analysis of Linux Container-based Security Mechanisms
Analysis of Linux Container-based Security Mechanisms
批准号:
487286-2015
负责人:
Mannan, Mohammad
金额:
$1.82万
依托单位:
依托单位国家:
加拿大
项目类别:
Engage Grants Program
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Virtual machines (VMs) and hypervisors are typically relied on to achieve isolation between mutually hostile or
untrustworthy applications. In recent times, the phenomenal growth of cloud computing and data centers lead
to renewed interest in OS-based, lightweight isolation mechanisms due to their superior performance. This
research will first identify key differences (from a security perspective) in existing virtualization technologies
based on traditional hypervisors (e.g., virtual machines), and operating systems (e.g., Linux containers). We
will then perform a security analysis of different OS-level virtualization mechanisms, with the focus on Linux
containers. Particularly, we would like to understand how containerization could be attacked and how its
security could be improved in order to build a more secure isolation technique for multi-tenant, untrusted
environment, specifically for data center operations. We will analyze the limits of resource isolation provided
by Linux containers, and consider the following attack avenues: exploiting shared hardware resources that are
not isolated by containers (e.g., processor cache, memory, input/output devices); and exploitation of known
Linux kernel vulnerabilities that may allow a malicious application to breakout of the confinement of a
container. We will then outline some recommendations on how the identified limitations (if any) can be
alleviated for a safer cloud computing environment, which is the primary goal of our industry partner, Huawei
Canada. We will consult with our contacts at Huawei, and seek their feedback in all steps of this project.
Results from our analysis is expected to help Huawei in choosing OS-based isolation mechanisms for their data
center environment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Mannan, Mohammad
-
依托单位:
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2021
-
负责人:Mannan, Mohammad
-
依托单位:
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2020
-
负责人:Mannan, Mohammad
-
依托单位:
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2019
-
负责人:Mannan, Mohammad
-
依托单位:
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2018
-
负责人:Mannan, Mohammad
-
依托单位:
Data security through trusted execution and comprehensive analysis framework
-
批准号:RGPIN-2017-04797
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2017
-
负责人:Mannan, Mohammad
-
依托单位:
Security and Privacy of High Impact Computer Applications
-
批准号:418648-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.6万
-
财政年份:2016
-
负责人:Mannan, Mohammad
-
依托单位:
Security and Privacy of High Impact Computer Applications
-
批准号:418648-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.6万
-
财政年份:2015
-
负责人:Mannan, Mohammad
-
依托单位:
Security and Privacy of High Impact Computer Applications
-
批准号:418648-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.6万
-
财政年份:2014
-
负责人:Mannan, Mohammad
-
依托单位:
Security and Privacy of High Impact Computer Applications
-
批准号:418648-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.6万
-
财政年份:2013
-
负责人:Mannan, Mohammad
-
依托单位:
Network security in the age of smartphone malware
-
批准号:435349-2012
-
项目类别:Engage Grants Program
-
资助金额:$1.76万
-
财政年份:2012
-
负责人:Mannan, Mohammad
-
依托单位:
Security and Privacy of High Impact Computer Applications
-
批准号:418648-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.6万
-
财政年份:2012
-
负责人:Mannan, Mohammad
-
依托单位:
Restricting malware attacks using human-in-the-loop challenges
-
批准号:387622-2010
-
项目类别:Postdoctoral Fellowships
-
资助金额:$0.49万
-
财政年份:2011
-
负责人:Mannan, Mohammad
-
依托单位:
Restricting malware attacks using human-in-the-loop challenges
-
批准号:387622-2010
-
项目类别:Postdoctoral Fellowships
-
资助金额:$2.91万
-
财政年份:2010
-
负责人:Mannan, Mohammad
-
依托单位:
Mitigating Distributed Denial of Service Attacks
-
批准号:333570-2006
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2008
-
负责人:Mannan, Mohammad
-
依托单位:
Mitigating Distributed Denial of Service Attacks
-
批准号:333570-2006
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2007
-
负责人:Mannan, Mohammad
-
依托单位:
Mitigating Distributed Denial of Service Attacks
-
批准号:333570-2006
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2006
-
负责人:Mannan, Mohammad
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Linux操作系统二进制镜像的漏洞修复评估方法研究
-
批准号:--
-
项目类别:面上项目
-
资助金额:59万元
-
批准年份:2021
-
负责人:张源
-
依托单位:
针对Linux内核漏洞的高精度崩溃分析技术研究
-
批准号:62102154
-
项目类别:青年科学基金项目(C类)
-
资助金额:30.0万元
-
批准年份:2021
-
负责人:慕冬亮
-
依托单位:
基于Linux Cluster并行GIS的并行实现模式研究
-
批准号:41001221
-
项目类别:青年科学基金项目
-
资助金额:18.0万元
-
批准年份:2010
-
负责人:黄方
-
依托单位:
基于LINUX的新疆维哈柯汉英多语种信息处理平台
-
批准号:60163001
-
项目类别:地区科学基金项目
-
资助金额:17.0万元
-
批准年份:2001
-
负责人:吾守尔·斯拉木
-
依托单位:
基于Linux平台的开放式结构多媒体数控系统研究
-
批准号:59975055
-
项目类别:面上项目
-
资助金额:15.0万元
-
批准年份:1999
-
负责人:张承瑞
-
依托单位: