Create an account


Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
A New Method of Containment: IBM Nabla Containers

#1
A New Method of Containment: IBM Nabla Containers

By James Bottomley

In the previous post about Containers and Cloud Security, I noted that most of the tenants of a Cloud Service Provider (CSP) could safely not worry about the Horizontal Attack Profile (HAP) and leave the CSP to manage the risk.  However, there is a small category of jobs (mostly in the financial and allied industries) where the damage done by a Horizontal Breach of the container cannot be adequately compensated by contractual remedies.  For these cases, a team at IBM research has been looking at ways of reducing the HAP with a view to making containers more secure than hypervisors.  For the impatient, the full open source release of the Nabla Containers technology is here and here, but for the more patient, let me explain what we did and why.  We’ll have a follow on post about the measurement methodology for the HAP and how we proved better containment than even hypervisor solutions.

The essence of the quest is a sandbox that emulates the interface between the runtime and the kernel (usually dubbed the syscall interface) with as little code as possible and a very narrow interface into the kernel itself.

The Basics: Looking for Better Containment


The HAP attack worry with standard containers is shown on the left: that a malicious application can breach the containment wall and attack an innocent application.  

Read more at Hansen Partnership

Click Here!

Reply



Possibly Related Threads…
Thread Author Replies Views Last Post
  Fedora - Use udica to build SELinux policy for containers xSicKxBot 0 1,694 05-07-2019, 02:22 AM
Last Post: xSicKxBot
  Key Differences in Security, Management for Serverless vs. Containers xSicKxBot 0 1,687 04-14-2019, 08:59 AM
Last Post: xSicKxBot
  Why Should You Use Microservices and Containers? xSicKxBot 0 1,719 11-27-2018, 01:17 AM
Last Post: xSicKxBot
  James Bottomley on Linux, Containers, and the Leading Edge xSicKxBot 0 2,042 08-16-2018, 10:55 PM
Last Post: xSicKxBot
  Using Linux Containers to Manage Embedded Build Environments xSicKxBot 0 1,720 07-20-2018, 05:35 PM
Last Post: xSicKxBot

Forum Jump:


Users browsing this thread:
1 Guest(s)

Forum software by © MyBB Theme © iAndrew 2016