课题基金 / 基金详情

Analysis of Linux Container-based Security Mechanisms

Analysis of Linux Container-based Security Mechanisms
基于Linux容器的安全机制分析
批准号:
487286-2015
负责人:
Mannan, Mohammad
金额:
$1.82万
依托单位:
依托单位国家:
加拿大
项目类别:
Engage Grants Program
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31

项目摘要

项目成果

Mannan, Mohammad的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Virtual machines (VMs) and hypervisors are typically relied on to achieve isolation between mutually hostile or untrustworthy applications. In recent times, the phenomenal growth of cloud computing and data centers lead to renewed interest in OS-based, lightweight isolation mechanisms due to their superior performance. This research will first identify key differences (from a security perspective) in existing virtualization technologies based on traditional hypervisors (e.g., virtual machines), and operating systems (e.g., Linux containers). We will then perform a security analysis of different OS-level virtualization mechanisms, with the focus on Linux containers. Particularly, we would like to understand how containerization could be attacked and how its security could be improved in order to build a more secure isolation technique for multi-tenant, untrusted environment, specifically for data center operations. We will analyze the limits of resource isolation provided by Linux containers, and consider the following attack avenues: exploiting shared hardware resources that are not isolated by containers (e.g., processor cache, memory, input/output devices); and exploitation of known Linux kernel vulnerabilities that may allow a malicious application to breakout of the confinement of a container. We will then outline some recommendations on how the identified limitations (if any) can be alleviated for a safer cloud computing environment, which is the primary goal of our industry partner, Huawei Canada. We will consult with our contacts at Huawei, and seek their feedback in all steps of this project. Results from our analysis is expected to help Huawei in choosing OS-based isolation mechanisms for their data center environment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2021
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2020
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2019
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
国内基金
海外基金
Linux操作系统二进制镜像的漏洞修复评估方法研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    59万元
  • 批准年份:
    2021
  • 负责人:
    张源
  • 依托单位:
针对Linux内核漏洞的高精度崩溃分析技术研究
  • 批准号:
    62102154
  • 项目类别:
    青年科学基金项目(C类)
  • 资助金额:
    30.0万元
  • 批准年份:
    2021
  • 负责人:
    慕冬亮
  • 依托单位:
基于Linux Cluster并行GIS的并行实现模式研究
  • 批准号:
    41001221
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    18.0万元
  • 批准年份:
    2010
  • 负责人:
    黄方
  • 依托单位:
基于LINUX的新疆维哈柯汉英多语种信息处理平台
  • 批准号:
    60163001
  • 项目类别:
    地区科学基金项目
  • 资助金额:
    17.0万元
  • 批准年份:
    2001
  • 负责人:
    吾守尔·斯拉木
  • 依托单位: