Author:
Zhao Baohua,Wang Zhihao,An Ningyu,Ren Chunhui
Abstract
Abstract
Container technology has a series of advantages such as low physical resource consumption, fast startup speed, high concurrency, and can run in a variety of environments. It is widely used in scenarios such as big data and cloud computing. Container technology has certain advantages in performance, but there are some shortcomings in security. The container technology shares the kernel with the host, and its security mainly depends on the host. Once the attacker breaks through the host’s defense, he can easily access the files deployed in the container, steal or tamper with the file data, and cause losses to users and users. In response to the above problems, this paper proposes a container-oriented isolation control technology, which realizes further isolation of files inside the container by adding domain names to programs and files. If the program domain name matches the file part, the files in the current container cannot be accessed, and the security of the files in the container can be effectively ensured after the host is compromised.
Subject
General Physics and Astronomy
Reference15 articles.
1. Cloud computing resource adaptive management method based on container technology;Shu;Computer Science,2017
2. Discussion on the overall protection technology of cloud platform information security;Yang;China Management Informationization,2021
3. Analysis and Research on Container Security;Chen;Communications Technology,2020
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献