论文标题
关于与Docker成像的容器化应用程序的安全措施
On Security Measures for Containerized Applications Imaged with Docker
论文作者
论文摘要
Linux容器在过去几年中越来越受欢迎,他们进入了商业IT服务产品(例如PAAS),应用程序部署以及各个开发团队中的连续交付/集成管道。随着码头工人的广泛采用,安全漏洞和担忧也浮出水面。在这项调查中,我们目前检查了最受欢迎的容器系统的安全状态:Docker。我们还将研究其起源于OS本身内置的Linux技术。检查内在漏洞,例如Docker Image实现;并提供对现场使用的当前工具和现代方法的分析,以评估和增强其安全性。对于每个部分,我们都会指出感兴趣的指标,因为它们在域中的研究人员和专家揭示了它们,并总结了他们的发现,以描绘出这些发现背后的努力的整体图片。最后,我们研究了行业中用于简化Docker安全扫描和分析的工具,这些扫描和分析提供了密钥指标内置的聚合。
Linux containers have risen in popularity in the last few years, making their way to commercial IT service offerings (such as PaaS), application deployments, and Continuous Delivery/Integration pipelines within various development teams. Along with the wide adoption of Docker, security vulnerabilities and concerns have also surfaced. In this survey, we examine the state of security for the most popular container system at the moment: Docker. We will also look into its origins stemming from the Linux technologies built into the OS itself; examine intrinsic vulnerabilities, such as the Docker Image implementation; and provide an analysis of current tools and modern methodologies used in the field to evaluate and enhance its security. For each section, we pinpoint metrics of interest, as they have been revealed by researchers and experts in the domain and summarize their findings to paint a holistic picture of the efforts behind those findings. Lastly, we look at tools utilized in the industry to streamline Docker security scanning and analytics which provide built-in aggregation of key metrics.