Abstract
Abstract
In view of the incomplete isolation of docker, the image file is easy to be tampered with, and the problem of insecure container operation. Based on the analysis of the existing isolation mechanism and security enhancement technology of docker container, this article uses trusted computing technologies such as cryptographic algorithms, integrity measurement, realtime monitoring, etc., a hardening method for docker containers is proposed. The feasibility of the reinforcement method was verified by experiments. The results show that this method can realize that docker is in a trusted and secure environment during the entire process of downloading the image from the container to the container, and ensuring that the container and the image file are not tampered with. When the container is enabled, the system resources are in a monitorable state, which greatly improves the credibility and security of the docker container.
Subject
General Physics and Astronomy
Cited by
4 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Design Scheme of a Full-stack Cloud Service Platform Based on Container Virtualization;2024 2nd International Conference on Mechatronics, IoT and Industrial Informatics (ICMIII);2024-06-12
2. On the Security of Containers: Threat Modeling, Attack Analysis, and Mitigation Strategies;Computers & Security;2023-05
3. Security hardening solution for docker container;2022 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC);2022-10
4. Local image management system in a multi-user environment based on Docker;2022 2nd International Conference on Computer Graphics, Image and Virtualization (ICCGIV);2022-09