论文标题
LIC-SEC:增强的Apparmor Docker安全配置文件生成器
Lic-Sec: an enhanced AppArmor Docker security profile generator
论文作者
论文摘要
随着云计算技术的快速发展,集装技术引起了行业和学术界的广泛关注。在本文中,我们对Docker-SEC进行了比较测量分析,该分析是2018年提出的Linux安全模块,以及一个名为LIC-SEC的新型Apparmor配置文件生成器,该机构将Docker-SEC与修改版本的Licshield结合在一起,该版本是LICSHIELD的修改版本,该版本在2015年也不允许使用Linux Security,不允许使用docker-sec和LICKER SECORTION。手动配置。 LIC-SEC汇集了它们的优势,并提供了更强大的保护。我们通过使用现实世界的攻击测试Docker-SEC和LIC-SEC的有效性和性能。我们生成一个具有42个利用功能的漏洞数据库,可在exploit-db上从最新400个漏洞中选择的Docker容器有效。我们在与Docker-SEC和LIC-SEC产生的容器上启动这些漏洞。我们的评估表明,对于苛刻的图像,LIC-SEC为Docker-SEC未能提供保护的所有特权升级攻击提供了保护。
Along with the rapid development of cloud computing technology, containerization technology has drawn much attention from both industry and academia. In this paper, we perform a comparative measurement analysis of Docker-sec, which is a Linux Security Module proposed in 2018, and a new AppArmor profile generator called Lic-Sec, which combines Docker-sec with a modified version of LiCShield, which is also a Linux Security Module proposed in 2015. Docker-sec and LiCShield can be used to enhance Docker container security based on mandatory access control and allows protection of the container without manually configurations. Lic-Sec brings together their strengths and provides stronger protection. We evaluate the effectiveness and performance of Docker-sec and Lic-Sec by testing them with real-world attacks. We generate an exploit database with 42 exploits effective on Docker containers selected from the latest 400 exploits on Exploit-db. We launch these exploits on containers spawned with Docker-sec and Lic-Sec separately. Our evaluations show that for demanding images, Lic-Sec gives protection for all privilege escalation attacks for which Docker-sec failed to give protection.