节点文献

基于命名空间与文件系统代理的容器安全框架研究

Research on Container Security Framework Based on Namespace and Filesystem Proxy

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 路新喜郭建伟苑立娟柳燕徐彬彬刘杨

【Author】 LU Xinxi;GUO Jianwei;YUAN Lijuan;LIU Yan;XU Binbin;LIU Yang;School of Software, Beihang University;Beijing Academy of Science and Technology;Baoding University;Pipechina Digital Co., Ltd.;School of Automation Science and Electrical Engineering, Beihang University;

【通讯作者】 刘杨;

【机构】 北京航空航天大学软件学院北京市科学技术研究院保定学院北京智网数科技术有限公司北京航空航天大学自动化科学与电气工程学院

【摘要】 针对现有容器云平台在用户身份隔离与文件系统权限控制方面存在的安全缺陷,文章提出一种基于用户命名空间与用户态文件系统代理机制的容器安全加固框架SecPod。该框架以容器运行时为对象,采用容器UID/GID动态映射机制实现容器间身份隔离,并设计容器文件系统代理模块以虚拟化容器视图,对文件访问操作进行精细化权限管理。实验结果表明,SecPod在不影响容器兼容性的前提下,能够有效阻止多种典型的逃逸与提权攻击,显著提升了容器的隔离强度。

【Abstract】 To address the security deficiencies in user identity isolation and filesystem permission control on current container platforms,this paper proposed SecPod,a container security hardening framework based on user namespaces and user-space filesystem proxy mechanisms.Targeting the container runtime layer,SecPod dynamically assigned per-container UID/GID mappings to enforce inter-container identity isolation.Meanwhile,it introduced a container filesystem proxy module that virtualized the container’s filesystem view and provided fine-grained access control for file operations.Experimental results show that SecPod effectively blocks various typical container escape and privilege escalation attacks while maintaining compatibility with standard container applications,significantly improving the isolation strength.

【基金】 国家自然科学基金[62073020];保定市科技计划[2311ZN003]
  • 【文献出处】 信息网络安全 ,Netinfo Security , 编辑部邮箱 ,2025年08期
  • 【分类号】TP393.08
  • 【下载频次】8
节点文献中: 

本文链接的文献网络图示:

本文的引文网络