首页|面向容器运行时安全威胁的N变体架构

面向容器运行时安全威胁的N变体架构

扫码查看
容器技术以其轻量级和可伸缩性的优点促进了云计算的发展,但容器运行时安全威胁日益严重.现有的入侵检测和访问控制等技术无法有效应对利用容器运行时实现容器逃逸的攻击行为.针对上述安全威胁,结合N变体系统的冗余及多样性方法提出了一种面向容器运行时安全威胁的N变体架构,同时通过基于历史信息的投票算法以提高投票的准确率,并通过两阶段投票和调度策略优化容器应用服务质量.最后构建了原型系统,测试结果表明原型系统性能损失在可接受的范围内,并一定程度上减小了系统攻击面,进而达到了增强容器应用安全性的 目的.
N-variant Architecture for Container Runtime Security Threats
It is container technology that has promoted the development of cloud computing with its lightweight and scalability advantages,but the security threat of container runtime is increasingly serious.The existing intrusion detection and access control technology can't effectively deal with the attack behavior of using container runtime to achieve container escape.First of all,this paper proposes an N-variant architecture for container runtime security threats combined with the redundancy and diversity me-thods of N-variant system.Secondly,through the redundancy and diversity methods of the N-variant system and the combination of the voting algorithm based on historical information,the accuracy of the voting is improved.Besides,service quality of container applications is optimized through two-stage voting and scheduling strategies.Finally,a prototype system is built.The test results show that the performance loss of the prototype system is within an acceptable range,and the attack surface of the system is re-duced to a certain extent,thus achieving the purpose of enhancing the security of container applications.

Container safetyCloud computingN variantContainer runtimeDispatch

刘道清、扈红超、霍树民

展开 >

信息工程大学信息技术研究所 郑州 450000

紫金山实验室 南京 210000

容器安全 云计算 N变体 容器运行时 调度

国家自然科学基金国家自然科学基金国家重点研发计划国家重点研发计划

62072467620023832021YFB10062002021YFB1006201

2024

计算机科学
重庆西南信息有限公司(原科技部西南信息中心)

计算机科学

CSTPCD北大核心
影响因子:0.944
ISSN:1002-137X
年,卷(期):2024.51(6)
  • 42