{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T12:25:27Z","timestamp":1780316727103,"version":"3.54.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T00:00:00Z","timestamp":1695859200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T00:00:00Z","timestamp":1695859200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001729","name":"Stiftelsen f\u00f6r Strategisk Forskning","doi-asserted-by":"publisher","award":["RIT17-0032"],"award-info":[{"award-number":["RIT17-0032"]}],"id":[{"id":"10.13039\/501100001729","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["768892"],"award-info":[{"award-number":["768892"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003252","name":"Lund University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100003252","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The rapid development of containerization technology comes with remarkable benefits for developers and operation teams. Container solutions allow building very flexible software infrastructures. Although lots of efforts have been devoted to enhancing containerization security, containerized environments still have a huge attack surface. Completely avoiding severe security issues have so far not been possible to achieve. However, the security problems due to vulnerabilities in for instance kernels, can be largely reduced if the container privileges are as restricted as possible. Mandatory access control is an efficient way to achieve this using for instance AppArmor. As manual AppArmor generation is tedious and error prone, automatic generation of protection profile is necessary. In previous research, a new tool for tight AppArmor profile generation was presented. In this paper we show how, in a system setting, such tool can be combined with container service testing, to provide a cloud based container service for automatic AppArmore profile generation. We present solutions for profile generation both for centrally collected and generated container logs and for log collection through a local agent. To evaluate the effectiveness of the profile generation service, we enable it on a widely used containerized web service to generate profiles and test them with real-world attacks. We generate an exploit database with 11 exploits harmful to the tested web service. These exploits are sifted from the 56 exploits of Exploit-db targeting the tested web service\u2019s software. We launch these exploits on the web service protected by the profile. The results show that the proposed profile generation service improves the test web service\u2019s overall security a lot compared to using the default Docker security profile. This together with the very user friendly and robust principle for setting up and running the service, clearly indicates that the approach is an important step for improving container security in real deployments.<\/jats:p>","DOI":"10.1007\/s42979-023-02186-1","type":"journal-article","created":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T12:01:56Z","timestamp":1695902516000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Access Security Policy Generation for Containers as a Cloud Service"],"prefix":"10.1007","volume":"4","author":[{"given":"Hui","family":"Zhu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8003-200X","authenticated-orcid":false,"given":"Christian","family":"Gehrmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paula","family":"Roth","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,9,28]]},"reference":[{"key":"2186_CR1","doi-asserted-by":"crossref","unstructured":"Casalicchio E, Iannucci S. The state-of-the-art in container technologies: application, orchestration and security. Concurrency and Computation: Practice and Experience. 2020;5668.","DOI":"10.1002\/cpe.5668"},{"key":"2186_CR2","unstructured":"Stopel D, Levin L, Yankovich L. Profiling of container images and enforcing security policies respective thereof. Google Patents. US Patent 10,586,042 (2020)."},{"key":"2186_CR3","unstructured":"Levin L, Stopel D, Yanay E. Filesystem action profiling of containers and security enforcement. Google Patents. US Patent 10,664,590 (2020)."},{"key":"2186_CR4","unstructured":"Levin L, Stopel D, Yanay E. Networking-based profiling of containers and security enforcement. Google Patents. US Patent 10,599,833 (2020)."},{"key":"2186_CR5","unstructured":"Daniel J, El-Moussa F. Software container profiling. Google Patents. US Patent App. 16\/300,169 (2019)."},{"key":"2186_CR6","doi-asserted-by":"crossref","unstructured":"Sarkale VV, Rad P, Lee W. Secure cloud container: Runtime behavior monitoring using most privileged container (mpc). In: 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud), IEEE; 2017. p. 351\u2013356.","DOI":"10.1109\/CSCloud.2017.68"},{"key":"2186_CR7","volume-title":"Computer security: principles and practice","author":"W Stallings","year":"2014","unstructured":"Stallings W, Brown L. Computer security: principles and practice. 3rd ed. USA: Prentice Hall Press; 2014.","edition":"3"},{"key":"2186_CR8","doi-asserted-by":"crossref","unstructured":"Mattetti M, Shulman-Peleg A, Allouche Y, Corradi A, Dolev S, Foschini L. Securing the infrastructure and the workloads of linux containers. In: 2015 IEEE conference on communications and network security (CNS), IEEE; 2015. p. 559\u2013567.","DOI":"10.1109\/CNS.2015.7346869"},{"key":"2186_CR9","doi-asserted-by":"crossref","unstructured":"Loukidis-Andreou F, Giannakopoulos I, Doka K, Koziris N. Docker-sec: A fully automated container security enhancement mechanism. In: 2018 IEEE 38th international conference on distributed computing systems (ICDCS), IEEE; 2018. p. 1561\u20131564.","DOI":"10.1109\/ICDCS.2018.00169"},{"key":"2186_CR10","doi-asserted-by":"crossref","unstructured":"Zhu H, Gehrmann C. Lic-sec: An enhanced apparmor docker security profile generator. J Inform Secur Appl. 2021;61.","DOI":"10.1016\/j.jisa.2021.102924"},{"key":"2186_CR11","doi-asserted-by":"crossref","unstructured":"Lin X, Lei L, Wang Y, Jing J, Sun K, Zhou Q. A measurement study on linux container security: Attacks and countermeasures. In: Proceedings of the 34th annual computer security applications conference, ACM; 2018. p. 418\u2013429.","DOI":"10.1145\/3274694.3274720"},{"key":"2186_CR12","doi-asserted-by":"crossref","unstructured":"Pothula DR, Kumar KM, Kumar S. Run time container security hardening using a proposed model of security control map. In: 2019 Global Conference for Advancement in Technology (GCAT), IEEE; 2019. p. 1\u20136.","DOI":"10.1109\/GCAT47503.2019.8978433"},{"key":"2186_CR13","doi-asserted-by":"crossref","unstructured":"Bacis E, Mutti S, Capelli S, Paraboschi S. Dockerpolicymodules: mandatory access control for docker containers. In: 2015 IEEE conference on communications and network security (CNS), IEEE; 2015. p. 749\u2013750.","DOI":"10.1109\/CNS.2015.7346917"},{"key":"2186_CR14","unstructured":"Sun Y, Safford D, Zohar M, Pendarakis D, Gu Z, Jaeger T. Security namespace: making linux security frameworks available to containers. In: 27th $$\\{$$USENIX$$\\}$$ security symposium ($$\\{$$USENIX$$\\}$$ security 18), 2018. p. 1423\u20131439."},{"key":"2186_CR15","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1016\/j.future.2019.02.026","volume":"97","author":"M De Benedictis","year":"2019","unstructured":"De Benedictis M, Lioy A. Integrity verification of docker containers for a lightweight cloud environment. Future Generat Comput Syst. 2019;97:236\u201346.","journal-title":"Future Generat Comput Syst."},{"key":"2186_CR16","unstructured":"Sailer R, Zhang X, Jaeger T, Van\u00a0Doorn L. Design and implementation of a tcg-based integrity measurement architecture. In: USENIX Security Symposium, 2004. vol. 13, p. 223\u2013238."},{"key":"2186_CR17","doi-asserted-by":"crossref","unstructured":"Priedhorsky R, Randles T. Charliecloud: Unprivileged containers for user-defined software stacks in hpc. In: Proceedings of the international conference for high performance computing, networking, storage and analysis, 2017. p. 1\u201310.","DOI":"10.1145\/3126908.3126925"},{"key":"2186_CR18","doi-asserted-by":"crossref","unstructured":"Azab A. Enabling docker containers for high-performance and many-task computing. In: 2017 Ieee international conference on cloud engineering (ic2e), IEEE; 2017. p. 279\u2013285.","DOI":"10.1109\/IC2E.2017.52"},{"issue":"5","key":"2186_CR19","doi-asserted-by":"publisher","first-page":"12080","DOI":"10.1002\/eng2.12080","volume":"1","author":"C-W Tien","year":"2019","unstructured":"Tien C-W, Huang T-Y, Tien C-W, Huang T-C, Kuo S-Y. Kubanomaly: anomaly detection for the docker orchestration platform with neural network approaches. Eng Rep. 2019;1(5):12080.","journal-title":"Eng Rep."},{"key":"2186_CR20","doi-asserted-by":"crossref","unstructured":"Du Q, Xie T, He Y. Anomaly detection and diagnosis for container-based microservices with performance monitoring. In: International conference on algorithms and architectures for parallel processing, Springer; 2018. p. 560\u2013572.","DOI":"10.1007\/978-3-030-05063-4_42"},{"key":"2186_CR21","first-page":"120","volume":"2019","author":"A Samir","year":"2019","unstructured":"Samir A, Pahl C. Anomaly detection and analysis for clustered cloud computing reliability. Cloud Comput. 2019;2019:120.","journal-title":"Cloud Comput."},{"key":"2186_CR22","doi-asserted-by":"crossref","unstructured":"Mart O, Negru C, Pop F, Castiglione A. Observability in kubernetes cluster: Automatic anomalies detection using prometheus. In: 2020 IEEE 22nd International Conference on High Performance Computing and Communications; IEEE 18th International Conference on Smart City; IEEE 6th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS), IEEE; 2020. p. 565\u2013570.","DOI":"10.1109\/HPCC-SmartCity-DSS50907.2020.00071"},{"key":"2186_CR23","doi-asserted-by":"crossref","unstructured":"Kitahara H, Gajananan K, Watanabe Y. Highly-scalable container integrity monitoring for large-scale kubernetes cluster. In: 2020 IEEE international conference on big data (Big Data), IEEE; 2020. p. 449\u2013454.","DOI":"10.1109\/BigData50022.2020.9377815"},{"key":"2186_CR24","doi-asserted-by":"crossref","unstructured":"Chelladhurai J, Chelliah PR, Kumar SA. Securing docker containers from denial of service (dos) attacks. In: 2016 IEEE international conference on services computing (SCC), IEEE; 2016. p. 856\u2013859.","DOI":"10.1109\/SCC.2016.123"},{"key":"2186_CR25","doi-asserted-by":"crossref","unstructured":"Hunger C, Vilanova L, Papamanthou C, Etsion Y, Tiwari M. Dats-data containers for web applications. In: Proceedings of the twenty-third international conference on architectural support for programming languages and operating systems. 2018. p. 722\u2013736.","DOI":"10.1145\/3296957.3173213"},{"key":"2186_CR26","doi-asserted-by":"crossref","unstructured":"Luo Y, Luo W, Sun X, Shen Q, Ruan A, Wu Z. Whispers between the containers: high-capacity covert channel attacks in docker. In: 2016 IEEE Trustcom\/BigDataSE\/ISPA. IEEE; 2016. p. 630\u2013637.","DOI":"10.1109\/TrustCom.2016.0119"},{"key":"2186_CR27","doi-asserted-by":"crossref","unstructured":"Jian Z, Chen L. A defense method against docker escape attack. In: Proceedings of the 2017 international conference on cryptography, security and privacy, ACM; 2017. p. 142\u2013146.","DOI":"10.1145\/3058060.3058085"},{"key":"2186_CR28","unstructured":"Arnautov S, Trach B, Gregor F, Knauth T, Martin A, Priebe C, Lind J, Muthukumaran D, O\u2019Keeffe D, Stillwell ML, et al. $$\\{$$SCONE$$\\}$$: Secure linux containers with intel $$\\{$$SGX$$\\}$$. In: 12th $$\\{$$USENIX$$\\}$$ Symposium on Operating Systems Design and Implementation ($$\\{$$OSDI$$\\}$$ 16). 2016. p. 689\u2013703."},{"issue":"10.1145","key":"2186_CR29","first-page":"2487726","volume":"11","author":"M Hoekstra","year":"2013","unstructured":"Hoekstra M, Lal R, Pappachan P, Phegade V, Del Cuvillo J. Using innovative instructions to create trustworthy software solutions. HASP@ ISCA. 2013;11(10.1145):2487726\u20138370.","journal-title":"HASP@ ISCA"},{"key":"2186_CR30","doi-asserted-by":"crossref","unstructured":"Kelbert F, Gregor F, Pires R, K\u00f6psell S, Pasin M, Havet A, Schiavoni V, Felber P, Fetzer C, Pietzuch P. Securecloud: Secure big data processing in untrusted clouds. In: Design, Automation & Test in Europe Conference & Exhibition (DATE), 2017. IEEE; 2017. p. 282\u2013285.","DOI":"10.23919\/DATE.2017.7926999"},{"key":"2186_CR31","doi-asserted-by":"crossref","unstructured":"Ranjbar A, Komu M, Salmela P, Aura T. Synaptic: Secure and persistent connectivity for containers. In: 2017 17th IEEE\/ACM international symposium on cluster, cloud and grid computing (CCGRID), IEEE; 2017. p. 262\u2013267.","DOI":"10.1109\/CCGRID.2017.62"}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-023-02186-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-023-02186-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-023-02186-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T12:38:42Z","timestamp":1695904722000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-023-02186-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,28]]},"references-count":31,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2023,11]]}},"alternative-id":["2186"],"URL":"https:\/\/doi.org\/10.1007\/s42979-023-02186-1","relation":{},"ISSN":["2661-8907"],"issn-type":[{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,28]]},"assertion":[{"value":"4 October 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 July 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 September 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"On behalf of all authors, the corresponding author states that there is no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"748"}}