课题基金 / 基金详情

Analysis of Linux Container-based Security Mechanisms

Analysis of Linux Container-based Security Mechanisms
基于Linux容器的安全机制分析
批准号:
487286-2015
负责人:
Mannan, Mohammad
金额:
$1.82万
依托单位:
依托单位国家:
加拿大
项目类别:
Engage Grants Program
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31

项目摘要

项目成果

Mannan, Mohammad的其他基金

相似基金

相关文献

中文摘要
翻译
通常依赖虚拟机(VM)和虚拟机管理程序来实现相互敌对或 不可靠的应用程序近年来,云计算和数据中心的惊人增长引领了 基于操作系统的轻量级隔离机制因其上级性能而重新受到关注。这 研究将首先确定现有虚拟化技术的主要差异(从安全角度来看 基于传统的管理程序(例如,虚拟机),以及操作系统(例如,Linux容器)。我们 然后,我将对不同的操作系统级虚拟化机制进行安全分析,重点是Linux 容器.特别是,我们想了解集装箱运输如何受到攻击,以及它如何 可以改进安全性,以便为多租户、不受信任的 环境,特别是数据中心运营。我们将分析提供的资源隔离的限制 通过Linux容器,并考虑以下攻击途径: 不被容器隔离(例如,处理器高速缓存、存储器、输入/输出设备);以及利用已知的 Linux内核漏洞可能允许恶意应用程序突破 货柜然后,我们将概述一些关于如何确定限制(如果有的话)的建议。 减轻了对更安全的云计算环境,这是我们的行业合作伙伴华为的首要目标 加拿大我们将与华为的联系人进行磋商,并在该项目的所有步骤中寻求他们的反馈。 我们的分析结果有望帮助华为为其数据选择基于操作系统的隔离机制 中心环境。
英文摘要
Virtual machines (VMs) and hypervisors are typically relied on to achieve isolation between mutually hostile or untrustworthy applications. In recent times, the phenomenal growth of cloud computing and data centers lead to renewed interest in OS-based, lightweight isolation mechanisms due to their superior performance. This research will first identify key differences (from a security perspective) in existing virtualization technologies based on traditional hypervisors (e.g., virtual machines), and operating systems (e.g., Linux containers). We will then perform a security analysis of different OS-level virtualization mechanisms, with the focus on Linux containers. Particularly, we would like to understand how containerization could be attacked and how its security could be improved in order to build a more secure isolation technique for multi-tenant, untrusted environment, specifically for data center operations. We will analyze the limits of resource isolation provided by Linux containers, and consider the following attack avenues: exploiting shared hardware resources that are not isolated by containers (e.g., processor cache, memory, input/output devices); and exploitation of known Linux kernel vulnerabilities that may allow a malicious application to breakout of the confinement of a container. We will then outline some recommendations on how the identified limitations (if any) can be alleviated for a safer cloud computing environment, which is the primary goal of our industry partner, Huawei Canada. We will consult with our contacts at Huawei, and seek their feedback in all steps of this project. Results from our analysis is expected to help Huawei in choosing OS-based isolation mechanisms for their data center environment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2021
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2020
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2019
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
国内基金
海外基金
Linux操作系统二进制镜像的漏洞修复评估方法研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    59万元
  • 批准年份:
    2021
  • 负责人:
    张源
  • 依托单位:
针对Linux内核漏洞的高精度崩溃分析技术研究
  • 批准号:
    62102154
  • 项目类别:
    青年科学基金项目(C类)
  • 资助金额:
    30.0万元
  • 批准年份:
    2021
  • 负责人:
    慕冬亮
  • 依托单位:
基于Linux Cluster并行GIS的并行实现模式研究
  • 批准号:
    41001221
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    18.0万元
  • 批准年份:
    2010
  • 负责人:
    黄方
  • 依托单位:
基于LINUX的新疆维哈柯汉英多语种信息处理平台
  • 批准号:
    60163001
  • 项目类别:
    地区科学基金项目
  • 资助金额:
    17.0万元
  • 批准年份:
    2001
  • 负责人:
    吾守尔·斯拉木
  • 依托单位: