Skip to main navigation Skip to search Skip to main content

Container Introspection: Using External Management Containers to Monitor Containers in Cloud Computing

  • Dongyang Zhan*
  • , Kai Tan
  • , Lin Ye
  • , Haining Yu
  • , Hao Liu
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

116 Downloads (CityUHK Scholars)

Abstract

Cloud computing plays an important role in today's Internet environment, which meets the requirements of scalability, security and reliability by using virtualization technologies. Container technology is one of the two mainstream virtualization solutions. Its lightweight, high deployment efficiency make container technology widely used in large-scale cloud computing. While container technology has created huge benefits for cloud service providers and tenants, it cannot meet the requirements of security monitoring and management from a tenant perspective. Currently, tenants can only run their security monitors in the target container, but it is not secure because the attacker is able to detect and compromise the security monitor. In this paper, a secure external monitoring approach is proposed to monitor target containers in another management container. The management container is transparent for target containers, but it can obtain the executing information of target containers, providing a secure monitoring environment. Security monitors running inside management containers are secure for the cloud host, since the management containers are not privileged.We implement the transparent external management containers by performing the one-way isolation of processes and files. For process one-way isolation, we leverage Linux namespace technology to let management container become the parent of target containers. By mounting the file systemof target container to that of the management container, file system one-way isolation is achieved. Compared with the existing host-based monitoring approach, our approach is more secure and suitable in the cloud environment.
Original languageEnglish
Pages (from-to)3783-3794
JournalComputers, Materials & Continua
Volume69
Issue number3
DOIs
Publication statusPublished - 24 Aug 2021

Bibliographical note

Full text of this publication does not contain sufficient affiliation information. With consent from the author(s) concerned, the Research Unit(s) information for this record is based on the existing academic department affiliation of the author(s).

Research Keywords

  • Container introspection
  • External approach
  • Management container
  • One-way isolation

Publisher's Copyright Statement

  • This full text is made available under CC-BY 4.0. https://creativecommons.org/licenses/by/4.0/

Fingerprint

Dive into the research topics of 'Container Introspection: Using External Management Containers to Monitor Containers in Cloud Computing'. Together they form a unique fingerprint.

Cite this