Abstract
Container platforms ease the deployment of applications and respond to failures. The advantages of container platforms have promoted their use in information services. However, the use of container platforms is accompanied by associated security risks. For instance, malware uploaded by users can leak important information, and malicious operators can cause unauthorized modifications to important files to create service errors. These security threats degrade the quality of information services and reduce their reliability. To overcome these issues, important container files should be protected by file-access control functions. However, legacy file-access control techniques, such as umask and SecureOS, do not support container platforms. To address this problem, we propose a novel kernel-based architecture in this study to control access to container files. The proposed container file-access control architecture comprises three components. The functionality and performance of the proposed architecture were assessed by implementing it on a Linux platform. Our analysis confirmed that the proposed architecture adequately controls users’ access to container files and performs on par with legacy file-access control techniques.
Funder
Tongmyong University Research
Subject
Electrical and Electronic Engineering,Computer Networks and Communications,Hardware and Architecture,Signal Processing,Control and Systems Engineering
Reference52 articles.
1. Ferreira, A.P., and Sinnott, R. (2019, January 13–16). A performance evaluation of containers running on managed Kubernetes services. Proceedings of the IEEE International Conference on Cloud Computing Technology and Science (CloudCom), Bangkok, Thailand.
2. The state-of-the-art in container technologies: Application, orchestration and security;Casalicchio;Concurr. Comput. Pract. Exper.,2020
3. Sabharwal, N., and Pandey, P. (2020). Pro Google Kubernetes Engine, Apress.
4. AixViPMaP®—An operational platform for microstructure modeling workflows;Koschmieder;Integr. Mater. Manuf. Innov.,2019
5. Becker, S., Schmidt, F., and Kao, O. (2021, January 29–31). EdgePier: P2P-based container image distribution in edge computing environments. Proceedings of the IEEE International Performance, Computing, and Communications Conference (IPCCC), Computing, Austin, TX, USA.
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献