A Perfect Fit? - Towards Containers on Microkernels

Publikation: Beitrag in Buch/Konferenzbericht/Sammelband/GutachtenBeitrag in KonferenzbandBeigetragenBegutachtung

Beitragende

  • Till Miemietz - , Barkhausen Institut gGmbH (Autor:in)
  • Viktor Reusch - , Barkhausen Institut gGmbH (Autor:in)
  • Matthias Hille - , Barkhausen Institut gGmbH (Autor:in)
  • Max Kurze - , Technische Universität Dresden (Autor:in)
  • Adam Lackorzynksi - , Seniorprofessor für Betriebssysteme, Kernkonzept GmbH (Autor:in)
  • Michael Roitzsch - , Barkhausen Institut gGmbH (Autor:in)
  • Hermann Härtig - , Barkhausen Institut gGmbH (Autor:in)

Abstract

Containers are a lightweight alternative to virtual machines, building on sandboxed processes whose permissions are restricted by additional security mechanisms such as seccomp-bpf. However, these mechanisms increase the kernel's attack surface, thus promptingnew security challenges. In this paper, we ask the question of whether a system with processes properly restricted by design enables a container infrastructure with better security posture. For instance, microkernels with capability-based access control provide containerstyle isolation out of the box. On the basis of real-world CVEs, we argue that this conceptual simplicity actually results in a better security posture than that typically found on monolithic systems. We propose Oak, a container engine built on top of L4Re, a stateof-the-art microkernel-based operating system. For startup as well as for network microbenchmarks, containers running on L4Re exposed performance characteristics similar to that of containers on Linux.We thus conclude that building containers on microkernel is an approach worth pursuing further under both a performance and a security perspective.

Details

OriginalspracheEnglisch
TitelWoC '24: Proceedings of the 10th International Workshop on Container Technologies and Container Clouds
Seiten1-6
Seitenumfang6
ISBN (elektronisch)979-8-4007-1339-2
PublikationsstatusVeröffentlicht - 2 Dez. 2024
Peer-Review-StatusJa

Externe IDs

Scopus 85216390263