loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Hui Zhu and Christian Gehrmann

Affiliation: Department of Electrical and Information Technology, Lund University, Lund, Sweden

Keyword(s): Security-as-a-Service, Docker, Container, AppArmor.

Abstract: Along with the rapid development of containerization technology, remarkable benefits have been created for developers and operation teams, and overall software infrastructure. Although lots of effort has been devoted to enhancing containerization security, containerized environments still have a huge attack surface. This paper proposes a secure cloud service for generating a Linux security module, AppArmor profiles for containerized services. The profile generator service implements container runtime profiling to apply customized AppArmor policies to protect containerized services without the need to make hard and potentially error-prone manual policy configurations. To evaluate the effectiveness of the profile generator service, we enable it on a widely used containerized web service to generate profiles and test them with real-world attacks. We generate an exploit database with 11 exploits harmful to the tested web service. These exploits are sifted from the 56 exploits of Exploit- db targeting the tested web service’s software. We launch these exploits on the web service protected by the profile. The results show that the proposed profile generator service improves the test web service’s overall security a lot compared to using the default Docker security profile. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.139.82.23

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Zhu, H. and Gehrmann, C. (2021). AppArmor Profile Generator as a Cloud Service. In Proceedings of the 11th International Conference on Cloud Computing and Services Science - CLOSER; ISBN 978-989-758-510-4; ISSN 2184-5042, SciTePress, pages 45-55. DOI: 10.5220/0010434100450055

@conference{closer21,
author={Hui Zhu. and Christian Gehrmann.},
title={AppArmor Profile Generator as a Cloud Service},
booktitle={Proceedings of the 11th International Conference on Cloud Computing and Services Science - CLOSER},
year={2021},
pages={45-55},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010434100450055},
isbn={978-989-758-510-4},
issn={2184-5042},
}

TY - CONF

JO - Proceedings of the 11th International Conference on Cloud Computing and Services Science - CLOSER
TI - AppArmor Profile Generator as a Cloud Service
SN - 978-989-758-510-4
IS - 2184-5042
AU - Zhu, H.
AU - Gehrmann, C.
PY - 2021
SP - 45
EP - 55
DO - 10.5220/0010434100450055
PB - SciTePress