国科大密码学院最新成果被TIFS(CCF-A)接收

文摘   2025-01-08 19:03   上海  

20246月,国科大密码学院王跃武研究员指导学生,在IEEE Transactions on Information Forensics and Security(TIFS)期刊发表了题为“Condo: Enhancing Container Isolation through Kernel Permission Data Protection”的研究论文论文中提出了一种通过内核数据保护来增强容器隔离性的方案研究工作得到国家重点研发计划2022YFB3103301的支持。


Abstract
Container technology is widely adopted due to its features such as light weight and ease of rapid deployment. However, as an OS-level virtualization mechanism, container isolation relies on the kernel’s security mechanisms and the kernel permission data (usually non-control flow data) used by these mechanisms. None of the existing mitigation schemes for non-control flow data attacks provide an effective and practical solution to container security since they either trigger too much overhead, have limited effectiveness over attacks launched in specific ways, or can only be used to protect some specific kernel data. In addition, none of them accurately identify the kernel data associated with container isolation. In this paper, we provide a solution called Condo that enhances container isolation by protecting the associated kernel permission data. We first present a generic non-control flow kernel data protection mechanism that protects different types of kernel data uniformly with low overhead and is not limited by attack methods or data types. We then demystify the models of various kernel access control mechanisms in the container environment, and identify the subject and object permission data that are critical to container isolation. Finally, we provide a solution named Condo to enhance container isolation, which is completely transparent to the existing container ecosystem, including containerized applications and container management/orchestration tools such as Docker. Experimental results show that Condo can effectively reduce the compromises of container isolation due to memory corruption attacks with an acceptable overhead.



论文信息

Shouyin Xu , Yuewu Wang, Lingguang Lei , Kun Sun, Jiwu Jing, Siyuan Ma, Jie Wang and Heqing Huang: "Condo: Enhancing Container Isolation through Kernel Permission Data Protection," in IEEE Transactions on Information Forensics and Security, doi: 10.1109/TIFS.2024.3411915.(CCF-A)





来源:中国科学院大学密码学院


信息网络安全    

《信息网络安全》创刊于2001年,是由公安部主管,公安部第三研究所、中国计算机学会主办,面向国内外公开发行的国内首批信息安全类期刊之一,于2015年成为中国科技核心期刊,2017年成为中国科学引文数据库来源期刊,2018年成为中文核心期刊,2022年入选CCF计算领域高质量科技期刊分级目录。



中文核心期刊

中国科技核心期刊

中国科学引文数据库来源期刊

CCF计算领域高质量科技期刊


我们在不断努力和完善中,期待您的关注和支持!


信息网络安全杂志
深入介绍信息安全理论,瞄准信息安全领域迫切需要的前沿技术,传达贯彻国家信息安全重要方针政策,及时反映国内外信息安全的热点技术及最新发展趋势。
 最新文章