{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:39:35Z","timestamp":1782833975449,"version":"3.54.5"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB3103301"],"award-info":[{"award-number":["2022YFB3103301"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3411915","type":"journal-article","created":{"date-parts":[[2024,6,10]],"date-time":"2024-06-10T17:21:57Z","timestamp":1718040117000},"page":"6168-6183","source":"Crossref","is-referenced-by-count":10,"title":["Condo: Enhancing Container Isolation Through Kernel Permission Data Protection"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7095-600X","authenticated-orcid":false,"given":"Shouyin","family":"Xu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5170-1253","authenticated-orcid":false,"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cryptography, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1936-0562","authenticated-orcid":false,"given":"Lingguang","family":"Lei","sequence":"additional","affiliation":[{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4152-2107","authenticated-orcid":false,"given":"Kun","family":"Sun","sequence":"additional","affiliation":[{"name":"George Mason University, Fairfax, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3409-6149","authenticated-orcid":false,"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siyuan","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0841-1045","authenticated-orcid":false,"given":"Jie","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heqing","family":"Huang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Amazon Ecs","year":"2023"},{"key":"ref2","volume-title":"Google Kubernetes Engine","year":"2023"},{"key":"ref3","volume-title":"Azure Kubernetes Service","year":"2023"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043574"},{"key":"ref5","volume-title":"Virtual Android on Android","year":"2019"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484544"},{"key":"ref7","volume-title":"Namespaces\u2014Overview of Linux Namespaces","year":"2022"},{"key":"ref8","volume-title":"Cgroups\u2014Linux Control Groups","year":"2022"},{"key":"ref9","volume-title":"An Introduction To Linux Access Control Lists (ACLS)","year":"2020"},{"key":"ref10","volume-title":"Capabilities\u2014Overview of Linux Capabilities","year":"2022"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274720"},{"key":"ref12","volume-title":"Samsung Trusted Boot and TrustZone Integrity Management Explained","year":"2019"},{"key":"ref13","volume-title":"CFI on ARM64 Series for V5.13-RC1","year":"2021"},{"key":"ref14","volume-title":"Kernel Control Flow Integrity","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"ref17","first-page":"147","article-title":"Securing software by enforcing data-flow integrity","volume-title":"Proc. OSDI","author":"Castro"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053029"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"ref21","volume-title":"CVE-2022-0185\u2014Winning a $31337 Bounty After Pwning Ubuntu and Escaping Google\u2019s Kctf Containers","year":"2022"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560585"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00041"},{"key":"ref24","volume-title":"Aarch64 Exception and Interrupt Handling","year":"2022"},{"key":"ref25","volume-title":"Trusted Execution Environment (TEE) Committee","year":"2022"},{"key":"ref26","volume-title":"TrustZone for Cortex-A","year":"2022"},{"key":"ref27","volume-title":"Corelink TrustZone Address Space Controller TZC-380 Technical Reference Manual","year":"2010"},{"key":"ref28","volume-title":"Overview of Secure Boot State in the Arm-based Socs","author":"Pijanowski","year":"2021"},{"key":"ref29","volume-title":"I.MX Secure and Encrypted Boot Using Habv4","year":"2019"},{"key":"ref30","volume-title":"Getting To Know Linux File Permissions","year":"2016"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23227"},{"key":"ref32","volume-title":"Seccomp Security Profiles for Docker","year":"2023"},{"key":"ref33","volume-title":"Arm\u2019s Growing Cloud Server Momentum","author":"McDowell","year":"2023"},{"key":"ref34","volume-title":"Top 10 Most Suggested Containers in Docker Hub","year":"2023"},{"key":"ref35","article-title":"Byte-unixbench: A unix benchmark suite","author":"Smith","year":"2011"},{"key":"ref36","volume-title":"Ab\u2014Apache Http Server Benchmarking Tool","year":"2015"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/1807128.1807152"},{"key":"ref38","volume-title":"Redis Benchmark","year":"2018"},{"key":"ref39","volume-title":"Unprivileged Ebpf Disabled By Default for Ubuntu 20.04 LTS, 18.04 LTS, 16.04 ESM","year":"2022"},{"key":"ref40","volume-title":"CVE-2017-5123","year":"2017"},{"key":"ref41","volume-title":"CVE-2021-22555: Turning X00X00 Into 10000$","author":"Nguyen","year":"2021"},{"key":"ref42","volume-title":"CVE-2022-25636\u2014Netfilter Nf_Dup_Netdev Heap Oob Write","year":"2021"},{"key":"ref43","volume-title":"[CVE-2021-42008] Exploiting a 16-Year-Old Vulnerability in the Linux 6pack Driver","year":"2021"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.163"},{"key":"ref45","article-title":"Secure virtual machine architecture reference manual","author":"Virtualization","year":"2005"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3268935.3268942"},{"key":"ref47","volume-title":"Openenclave Github Repository","year":"2020"},{"key":"ref48","volume-title":"Secgear","year":"2021"},{"key":"ref49","volume-title":"The Heartbleed Bug","year":"2014"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421012"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627113"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_11"},{"key":"ref53","first-page":"443","article-title":"Confine: Automated system call policy generation for container attack surface reduction","volume-title":"Proc. 23rd Int. Symp. Res. Attacks, Intrusions Defenses (RAID)","author":"Ghavamnia"},{"key":"ref54","first-page":"1423","article-title":"Security namespace: Making Linux security frameworks available to containers","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Sun"},{"key":"ref55","volume-title":"Intel Clear Containers 1: The Container Landscape","year":"2016"},{"key":"ref56","volume-title":"Isolation Modes","year":"2023"},{"key":"ref57","volume-title":"Kata Containers","year":"2019"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132763"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23009"},{"key":"ref60","volume-title":"Nabla Containers: A New Approach to Container Isolation","year":"2018"},{"key":"ref61","volume-title":"Gvisor: The Container Security Platform","year":"2018"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304016"},{"key":"ref63","first-page":"683","article-title":"BlackBox: A container security monitor for protecting containers on untrusted operating systems","volume-title":"Proc. 16th USENIX Symp. Operating Syst. Design Implement.","author":"Van\u2019t Hof"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10319981\/10552298.pdf?arnumber=10552298","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,25]],"date-time":"2024-06-25T19:35:33Z","timestamp":1719344133000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10552298\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3411915","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}