节点文献
基于命名空间与文件系统代理的容器安全框架研究
Research on Container Security Framework Based on Namespace and Filesystem Proxy
【摘要】 针对现有容器云平台在用户身份隔离与文件系统权限控制方面存在的安全缺陷,文章提出一种基于用户命名空间与用户态文件系统代理机制的容器安全加固框架SecPod。该框架以容器运行时为对象,采用容器UID/GID动态映射机制实现容器间身份隔离,并设计容器文件系统代理模块以虚拟化容器视图,对文件访问操作进行精细化权限管理。实验结果表明,SecPod在不影响容器兼容性的前提下,能够有效阻止多种典型的逃逸与提权攻击,显著提升了容器的隔离强度。
【Abstract】 To address the security deficiencies in user identity isolation and filesystem permission control on current container platforms,this paper proposed SecPod,a container security hardening framework based on user namespaces and user-space filesystem proxy mechanisms.Targeting the container runtime layer,SecPod dynamically assigned per-container UID/GID mappings to enforce inter-container identity isolation.Meanwhile,it introduced a container filesystem proxy module that virtualized the container’s filesystem view and provided fine-grained access control for file operations.Experimental results show that SecPod effectively blocks various typical container escape and privilege escalation attacks while maintaining compatibility with standard container applications,significantly improving the isolation strength.
- 【文献出处】 信息网络安全 ,Netinfo Security , 编辑部邮箱 ,2025年08期
- 【分类号】TP393.08
- 【下载频次】8