AppArmor Profile Generator as a Cloud Service

    Forskningsoutput: Kapitel i bok/rapport/Conference proceedingKonferenspaper i proceedingPeer review

    Sammanfattning

    Along with the rapid development of containerization technology, remarkable benefits have been created for developers and operation teams, and overall software infrastructure. Although lots of effort has been devoted to enhancing containerization security, containerized environments still have a huge attack surface. This paper proposes a secure cloud service for generating a Linux security module, AppArmor profiles for containerized services. The profile generator service implements container runtime profiling to apply customized AppArmor policies to protect containerized services without the need to make hard and potentially error-prone manual policy configurations. To evaluate the effectiveness of the profile generator service, we enable it on a widely used containerized web service to generate profiles and test them with real-world attacks. We generate an exploit database with 11 exploits harmful to the tested web service. These exploits are sifted from the 56 exploits of Exploit- db targeting the tested web service’s software. We launch these exploits on the web service protected by the profile. The results show that the proposed profile generator service improves the test web service’s overall security a lot compared to using the default Docker security profile.
    Originalspråkengelska
    Titel på värdpublikationProceedings of the 11th International Conference on Cloud Computing and Services Science
    FörlagSciTech Publishing
    Sidor45-55
    Antal sidor10
    ISBN (elektroniskt)978-989-758-510-4
    DOI
    StatusPublished - 2021 apr. 28
    Evenemang11th International Conference on Cloud Computing and Services Science, CLOSER 2021 - Online
    Varaktighet: 2021 apr. 282021 apr. 30
    Konferensnummer: 11
    http://closer.scitevents.org/?y=2021

    Konferens

    Konferens11th International Conference on Cloud Computing and Services Science, CLOSER 2021
    Förkortad titelCLOSER
    Period2021/04/282021/04/30
    Internetadress

    Ämnesklassifikation (UKÄ)

    • Datavetenskap (Datalogi)
    • Datorsystem

    Fingeravtryck

    Utforska forskningsämnen för ”AppArmor Profile Generator as a Cloud Service”. Tillsammans bildar de ett unikt fingeravtryck.

    Citera det här