{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T00:59:51Z","timestamp":1784595591345,"version":"3.55.0"},"reference-count":71,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea (NRF) Grant through the Korea Government, Ministry of Science, ICT (Information and Communication Technology) and Future Planning","doi-asserted-by":"publisher","award":["2022R1C1C1006093"],"award-info":[{"award-number":["2022R1C1C1006093"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE\/ACM Trans. Networking"],"published-print":{"date-parts":[[2023,4]]},"DOI":"10.1109\/tnet.2022.3206781","type":"journal-article","created":{"date-parts":[[2022,9,22]],"date-time":"2022-09-22T22:59:24Z","timestamp":1663887564000},"page":"934-947","source":"Crossref","is-referenced-by-count":25,"title":["Secure Inter-Container Communications Using XDP\/eBPF"],"prefix":"10.1109","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8907-5495","authenticated-orcid":false,"given":"Jaehyun","family":"Nam","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, Dankook University, Yongin, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6883-1869","authenticated-orcid":false,"given":"Seungsoo","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Incheon National University, Incheon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Phillip","family":"Porras","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1077-5606","authenticated-orcid":false,"given":"Seungwon","family":"Shin","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering, KAIST, Daejeon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Everything at Google Runs in Containers","year":"2022"},{"key":"ref2","volume-title":"How Yelp Runs Millions of Tests Every Day","year":"2022"},{"key":"ref3","volume-title":"Titus, the Netflix Container Management Platform, is Now Open Source","year":"2022"},{"key":"ref4","volume-title":"State of Container Security Report","year":"2022"},{"key":"ref5","volume-title":"Stealing Infrastructure: Cryptomining Attacks on Container Environments","year":"2022"},{"key":"ref6","volume-title":"Clair","year":"2022"},{"key":"ref7","volume-title":"Docker Security Scanning","year":"2021"},{"key":"ref8","volume-title":"Atomic Scan\u2014Container Vulnerability Detection","year":"2022"},{"key":"ref9","volume-title":"AppArmor Project","year":"2022"},{"key":"ref10","volume-title":"Seccomp","year":"2022"},{"key":"ref11","volume-title":"SELinux Project","year":"2022"},{"key":"ref12","volume-title":"Microservice","year":"2022"},{"key":"ref13","volume-title":"Content Trust in Docker","year":"2022"},{"key":"ref14","volume-title":"Docker Hub","year":"2022"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102924"},{"key":"ref16","volume-title":"SELinux Policy Generation for Containers","year":"2022"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_11"},{"key":"ref18","first-page":"443","article-title":"Confine: Automated system call policy generation for container attack surface reduction","volume-title":"Proc. Int. Symp. Res. Attacks, Intrusions Defenses","author":"Ghavamnia"},{"key":"ref19","volume-title":"Aqua Security","year":"2022"},{"key":"ref20","volume-title":"StackRox","year":"2022"},{"key":"ref21","volume-title":"TwistLock","year":"2022"},{"key":"ref22","volume-title":"Docker","year":"2022"},{"key":"ref23","volume-title":"Kubernetes","year":"2022"},{"key":"ref24","volume-title":"Compose","year":"2022"},{"key":"ref25","volume-title":"Netfilter and IPtables","year":"2022"},{"key":"ref26","volume-title":"Flannel","year":"2022"},{"key":"ref27","volume-title":"Weave Net","year":"2022"},{"key":"ref28","volume-title":"Project Calico","year":"2022"},{"key":"ref29","volume-title":"API-Aware Networking and Security","year":"2022"},{"key":"ref30","volume-title":"HAProxy","year":"2022"},{"key":"ref31","volume-title":"OpenVPN","year":"2022"},{"key":"ref32","volume-title":"MemSQL","year":"2022"},{"key":"ref33","volume-title":"Production Quality, Multilayer Open Virtual Switch","author":"vSwitch","year":"2022"},{"key":"ref34","volume-title":"Vulnerability Exploitation in Docker Container Environments","author":"Bettini","year":"2022"},{"key":"ref35","volume-title":"LunaSec","year":"2022"},{"key":"ref36","volume-title":"A Busybox AutoCompletion Vulnerability","year":"2021"},{"key":"ref37","volume-title":"Breaking Bad: Detecting Real World Container Exploits","year":"2021"},{"key":"ref38","volume-title":"Hacking Docker Containers by Exploiting Imagemagick Vulnerabilities","year":"2022"},{"key":"ref39","volume-title":"Abusing Privileged and Unprivileged Linux Containers","year":"2016"},{"key":"ref40","volume-title":"Escaping Docker Container Using Waitid","year":"2021"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3058060.3058085"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382258"},{"key":"ref43","volume-title":"Stan Robot Shop, A Sample Microservice Application","year":"2022"},{"key":"ref44","volume-title":"Sock Shop\u2014A Microservices Demo Application","year":"2022"},{"key":"ref45","volume-title":"Nginx","year":"2022"},{"key":"ref46","volume-title":"Redis","year":"2022"},{"key":"ref47","volume-title":"Extended Berkeley Packet Filter","year":"2022"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3281411.3281443"},{"key":"ref49","volume-title":"eXpress Data Path","year":"2022"},{"key":"ref50","first-page":"229","article-title":"Snort: Lightweight intrusion detection for networks","volume-title":"Proc. Large Installation Syst. Admin. Conf.","author":"Roesch"},{"key":"ref51","volume-title":"Threat Detection Engine","year":"2022"},{"key":"ref52","volume-title":"NetPerf: Network Performance Benchmark","year":"2022"},{"key":"ref53","volume-title":"Network Bandwidth Measurement Tool","year":"2022"},{"key":"ref54","volume-title":"Emerging Threat Ruleset","year":"2022"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2014.41"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.49"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/i-Society.2016.7854163"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029832"},{"key":"ref59","first-page":"313","article-title":"Understanding security implications of using containers in the cloud","volume-title":"Proc. Annu. Tech. Conf.","author":"Tak"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94289-6_8"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2015.7346917"},{"key":"ref62","first-page":"1423","article-title":"Security namespace: Making Linux security frameworks available to containers","volume-title":"Proc. Secur. Symp.","author":"Sun"},{"key":"ref63","first-page":"689","article-title":"SCONE: Secure Linux containers with Intel SGX","volume-title":"Proc. Symp. Operating Syst. Design Implement.","author":"Arnautov"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132763"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304016"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/2940147.2940155"},{"key":"ref67","first-page":"331","article-title":"Slim: OS kernel support for a low-overhead container overlay network","volume-title":"Proc. Symp. Netw. Syst. Design Implement.","author":"Zhuo"},{"key":"ref68","article-title":"Analysis of Docker security","author":"Bui","year":"2015","journal-title":"arXiv:1501.02967"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2016.100"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/SCC.2016.123"},{"key":"ref71","volume-title":"Romana V2.0","year":"2021"}],"container-title":["IEEE\/ACM Transactions on Networking"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/90\/10103748\/09900301.pdf?arnumber=9900301","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,22]],"date-time":"2024-01-22T22:58:15Z","timestamp":1705964295000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9900301\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4]]},"references-count":71,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tnet.2022.3206781","relation":{},"ISSN":["1063-6692","1558-2566"],"issn-type":[{"value":"1063-6692","type":"print"},{"value":"1558-2566","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4]]}}}