3.8 Proceedings Paper

Managed Containers: A Framework for Resilient Containerized Mission Critical Systems

出版社

IEEE
DOI: 10.1109/CLOUD.2018.00142

关键词

Linux containers; availability; moving target defense; cyber survivability; virtualization

资金

  1. Northrop Grumman Corporation (NGC)

向作者/读者索取更多资源

Traditional defense mechanisms are insufficient for protecting containerized mission critical systems. These systems are mostly based on cloud-based images (e.g., Docker) that need to be always-on-always-connected. High availability and data integrity become crucial to deliver their mission. Unable to guarantee uncompromisable security and given that systems will inevitably be attacked, we must change our goals to emphasize resiliency and mission survivability. This paper presents work-in-progress to create a framework for cloud-based container resiliency. Our resilient framework makes use of Linux containers to provide resiliency to services. It is designed to orchestrate and manage the container lifecycle while enforcing security and returning a service to a previous secure state in case of a cyber-attack. It achieves this by expanding upon the generic container model with additional layers that enhance security and increase auditability. We coin the term managed containers to refer to the enhanced containers managed by our resilient framework. In case of an anomaly, it generates a report and allows the operator to choose a resiliency strategy. In our tests, our framework is able to securely recover from a fault in less time than a pure Docker solution while protecting against the most common container vulnerabilities.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据