{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:32:17Z","timestamp":1750221137146,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,12,10]],"date-time":"2018-12-10T00:00:00Z","timestamp":1544400000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,12,10]]},"DOI":"10.1145\/3284028.3284031","type":"proceedings-article","created":{"date-parts":[[2018,11,21]],"date-time":"2018-11-21T13:51:49Z","timestamp":1542808309000},"page":"17-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["D\u00e9j\u00e0Vu"],"prefix":"10.1145","author":[{"given":"Shripad","family":"Nadgowda","sequence":"first","affiliation":[{"name":"IBM TJ Watson Research Center"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Canturk","family":"Isci","sequence":"additional","affiliation":[{"name":"IBM TJ Watson Research Center"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mustafa","family":"Bal","sequence":"additional","affiliation":[{"name":"Harvard University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,12,10]]},"reference":[{"key":"e_1_3_2_2_1_1","first-page":"27","volume-title":"NSDI","volume":"6","author":"Aguilera M. K.","year":"2006","unstructured":"M. K. Aguilera , S. Spence , and A. C. Veitch . Olive: Distributed point-in-time branching storage for real systems . In NSDI , volume 6 , pages 27 -- 27 , 2006 . M. K. Aguilera, S. Spence, and A. C. Veitch. Olive: Distributed point-in-time branching storage for real systems. In NSDI, volume 6, pages 27--27, 2006."},{"key":"e_1_3_2_2_2_1","unstructured":"Aqua. Container security made simple. https:\/\/www.aquasec.com\/about-us\/our-story\/.  Aqua. Container security made simple. https:\/\/www.aquasec.com\/about-us\/our-story\/."},{"key":"e_1_3_2_2_3_1","first-page":"167","volume-title":"LISA","author":"Banikazemi M.","year":"2008","unstructured":"M. Banikazemi , D. Daly , and B. Abali . Sysman: A virtual file system for managing clusters . In LISA , pages 167 -- 174 , 2008 . M. Banikazemi, D. Daly, and B. Abali. Sysman: A virtual file system for managing clusters. In LISA, pages 167--174, 2008."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3154448.3154453"},{"key":"e_1_3_2_2_5_1","volume-title":"cadvisor. Analyzes resource usage and performance characteristics of running containers. https:\/\/github.com\/google\/cadvisor","author":"G.","year":"2017","unstructured":"G. cadvisor. Analyzes resource usage and performance characteristics of running containers. https:\/\/github.com\/google\/cadvisor , 2017 . G. cadvisor. Analyzes resource usage and performance characteristics of running containers. https:\/\/github.com\/google\/cadvisor, 2017."},{"key":"e_1_3_2_2_6_1","volume-title":"CIS Benchmark Securing Kubernetes. https:\/\/www.cisecurity.org\/benchmark\/kubernetes\/","author":"CIS.","year":"2017","unstructured":"CIS. CIS Benchmark Securing Kubernetes. https:\/\/www.cisecurity.org\/benchmark\/kubernetes\/ , 2017 . CIS. CIS Benchmark Securing Kubernetes. https:\/\/www.cisecurity.org\/benchmark\/kubernetes\/, 2017."},{"volume-title":"agentless-system-crawler: A tool to crawl systems like crawlers for the web. https:\/\/github.com\/cloudviz\/agentless-system-crawler","year":"2017","key":"e_1_3_2_2_7_1","unstructured":"cloudviz. agentless-system-crawler: A tool to crawl systems like crawlers for the web. https:\/\/github.com\/cloudviz\/agentless-system-crawler , 2017 . cloudviz. agentless-system-crawler: A tool to crawl systems like crawlers for the web. https:\/\/github.com\/cloudviz\/agentless-system-crawler, 2017."},{"volume-title":"Modern monitoring and analytics","year":"2017","key":"e_1_3_2_2_8_1","unstructured":"Datadog. Modern monitoring and analytics , 2017 . Datadog. Modern monitoring and analytics, 2017."},{"volume-title":"Data science studio","year":"2017","key":"e_1_3_2_2_9_1","unstructured":"Dataiku. Data science studio , 2017 . Dataiku. Data science studio, 2017."},{"volume-title":"Minify and Secure Docker containers. https:\/\/github.com\/docker-slim\/docker-slim","year":"2016","key":"e_1_3_2_2_10_1","unstructured":"docker slim. Minify and Secure Docker containers. https:\/\/github.com\/docker-slim\/docker-slim , 2016 . docker slim. Minify and Secure Docker containers. https:\/\/github.com\/docker-slim\/docker-slim, 2016."},{"key":"e_1_3_2_2_11_1","volume-title":"Slim application containers (using docker). blog, april","author":"Dowideit S.","year":"2015","unstructured":"S. Dowideit . Slim application containers (using docker). blog, april 2015 . S. Dowideit. Slim application containers (using docker). blog, april 2015."},{"key":"e_1_3_2_2_12_1","unstructured":"EMC. Emc atmos installable file system (ifs).  EMC. Emc atmos installable file system (ifs)."},{"key":"e_1_3_2_2_13_1","volume-title":"Expanding vulnerability management to container security. https:\/\/www.flawcheck.com\/","author":"Flawcheck T.","year":"2017","unstructured":"T. Flawcheck . Expanding vulnerability management to container security. https:\/\/www.flawcheck.com\/ , 2017 . T. Flawcheck. Expanding vulnerability management to container security. https:\/\/www.flawcheck.com\/, 2017."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517326.2451534"},{"key":"e_1_3_2_2_16_1","first-page":"191","volume-title":"Ndss","volume":"3","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel , M. Rosenblum , A virtual machine introspection based architecture for intrusion detection . In Ndss , volume 3 , pages 191 -- 206 , 2003 . T. Garfinkel, M. Rosenblum, et al. A virtual machine introspection based architecture for intrusion detection. In Ndss, volume 3, pages 191--206, 2003."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/RoEduNet.2013.6511732"},{"key":"e_1_3_2_2_18_1","volume-title":"Mar. 18","author":"Goodman D. P.","year":"2014","unstructured":"D. P. Goodman , S. Gopisetty , S. Nadgowda , and R. R. Routray . Remote data protection in a networked storage computing environment , Mar. 18 2014 . US Patent 8,676,763. D. P. Goodman, S. Gopisetty, S. Nadgowda, and R. R. Routray. Remote data protection in a networked storage computing environment, Mar. 18 2014. US Patent 8,676,763."},{"key":"e_1_3_2_2_19_1","volume-title":"Optimizing service delivery with minimal runtimes","author":"Gschwind K.","year":"2017","unstructured":"K. Gschwind , C. Adam , S. Duri , S. Nadgowda , and M. Vukovic . Optimizing service delivery with minimal runtimes . 2017 . K. Gschwind, C. Adam, S. Duri, S. Nadgowda, and M. Vukovic. Optimizing service delivery with minimal runtimes. 2017."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1807128.1807134"},{"key":"e_1_3_2_2_21_1","volume-title":"Oct. 6","author":"Hitz D.","year":"1998","unstructured":"D. Hitz , M. Malcolm , J. Lau , and B. Rakitzis . Method for maintaining consistent states of a file system and for creating user-accessible read-only copies of a file system , Oct. 6 1998 . US Patent 5,819,292. D. Hitz, M. Malcolm, J. Lau, and B. Rakitzis. Method for maintaining consistent states of a file system and for creating user-accessible read-only copies of a file system, Oct. 6 1998. US Patent 5,819,292."},{"key":"e_1_3_2_2_22_1","unstructured":"IBM. Endpoint manager ibm bigfix.  IBM. Endpoint manager ibm bigfix."},{"key":"e_1_3_2_2_23_1","volume-title":"https:\/\/console.bluemix.net\/docs\/containers\/va\/","author":"BM.","year":"2015","unstructured":"I BM. Managing container and image security with vulnerability advisor. https:\/\/console.bluemix.net\/docs\/containers\/va\/ , 2015 . IBM. Managing container and image security with vulnerability advisor. https:\/\/console.bluemix.net\/docs\/containers\/va\/, 2015."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/191177.191183"},{"key":"e_1_3_2_2_26_1","volume-title":"HotCloud","author":"Koller R.","year":"2015","unstructured":"R. Koller , C. Isci , S. Suneja , and E. De Lara . Unified monitoring and analytics in the cloud . In HotCloud , 2015 . R. Koller, C. Isci, S. Suneja, and E. De Lara. Unified monitoring and analytics in the cloud. In HotCloud, 2015."},{"key":"e_1_3_2_2_27_1","first-page":"1","volume-title":"LISA","volume":"7","author":"McNett M.","year":"2007","unstructured":"M. McNett , D. Gupta , A. Vahdat , and G. M. Voelker . Usher: An extensible framework for managing clusters of virtual machines . In LISA , volume 7 , pages 1 -- 15 , 2007 . M. McNett, D. Gupta, A. Vahdat, and G. M. Voelker. Usher: An extensible framework for managing clusters of virtual machines. In LISA, volume 7, pages 1--15, 2007."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLUSTR.2006.311843"},{"key":"e_1_3_2_2_29_1","unstructured":"N. Murilo and K. Steding-Jessen. chkrootkit: locally checks for signs of a rootkit.  N. Murilo and K. Steding-Jessen. chkrootkit: locally checks for signs of a rootkit."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/242857.242869"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-45065-5_11"},{"volume-title":"CIS Kubernetes Benchmark. https:\/\/github.com\/neuvector\/kubernetes-cis-benchmark","year":"2017","key":"e_1_3_2_2_32_1","unstructured":"Neuvector. CIS Kubernetes Benchmark. https:\/\/github.com\/neuvector\/kubernetes-cis-benchmark , 2017 . Neuvector. CIS Kubernetes Benchmark. https:\/\/github.com\/neuvector\/kubernetes-cis-benchmark, 2017."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3154448.3154455"},{"key":"e_1_3_2_2_35_1","volume-title":"Security compliance. https:\/\/github.com\/OpenSCAP\/openscap","author":"SCAP.","year":"2014","unstructured":"Open SCAP. Security compliance. https:\/\/github.com\/OpenSCAP\/openscap , 2014 . OpenSCAP. Security compliance. https:\/\/github.com\/OpenSCAP\/openscap, 2014."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1216370.1216373"},{"issue":"2","key":"e_1_3_2_2_37_1","first-page":"221","article-title":"Plan 9 from bell labs","volume":"8","author":"Pike R.","year":"1995","unstructured":"R. Pike , D. Presotto , S. Dorward , B. Flandrena , K. Thompson , H. Trickey , and P. Winterbottom . Plan 9 from bell labs . Computing systems , 8 ( 2 ): 221 -- 254 , 1995 . R. Pike, D. Presotto, S. Dorward, B. Flandrena, K. Thompson, H. Trickey, and P. Winterbottom. Plan 9 from bell labs. Computing systems, 8(2):221--254, 1995.","journal-title":"Computing systems"},{"key":"e_1_3_2_2_38_1","first-page":"257","volume-title":"USENIX Security Symposium","author":"Provos N.","year":"2003","unstructured":"N. Provos . Improving host security with system call policies . In USENIX Security Symposium , pages 257 -- 272 , 2003 . N. Provos. Improving host security with system call policies. In USENIX Security Symposium, pages 257--272, 2003."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2611166.2611174"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2014.36"},{"key":"e_1_3_2_2_41_1","unstructured":"R. Rizun. S3fs: Fuse-based file system backed by amazon s3.  R. Rizun. S3fs: Fuse-based file system backed by amazon s3."},{"volume-title":"Full-stack monitoring for today's business. https:\/\/sensuapp.org\/","year":"2017","key":"e_1_3_2_2_42_1","unstructured":"Sensu. Full-stack monitoring for today's business. https:\/\/sensuapp.org\/ , 2017 . Sensu. Full-stack monitoring for today's business. https:\/\/sensuapp.org\/, 2017."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132752"},{"key":"e_1_3_2_2_44_1","unstructured":"T. Stack. Cloud security monitoring cloud protection. https:\/\/www.threatstack.com\/.  T. Stack. Cloud security monitoring cloud protection. https:\/\/www.threatstack.com\/."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2637364.2592009"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050766"},{"key":"e_1_3_2_2_47_1","volume-title":"Filesystem in userspace","author":"Szeredi M.","year":"2005","unstructured":"M. Szeredi . Fuse : Filesystem in userspace . 2005 . URL http:\/\/fuse.sourceforge.net. M. Szeredi. Fuse: Filesystem in userspace. 2005. URL http:\/\/fuse.sourceforge.net."},{"key":"e_1_3_2_2_48_1","first-page":"313","volume-title":"2017 USENIX Annual Technical Conference USENIX ATC 17","author":"Tak B.","year":"2017","unstructured":"B. Tak , C. Isci , S. Duri , N. Bila , S. Nadgowda , and J. Doran . Understanding security implications of using containers in the cloud . In 2017 USENIX Annual Technical Conference USENIX ATC 17 , pages 313 -- 319 . USENIX Association , 2017 . B. Tak, C. Isci, S. Duri, N. Bila, S. Nadgowda, and J. Doran. Understanding security implications of using containers in the cloud. In 2017 USENIX Annual Technical Conference USENIX ATC 17, pages 313--319. USENIX Association, 2017."},{"key":"e_1_3_2_2_49_1","unstructured":"Twistlock. Docker security and container security platform. https:\/\/www.twistlock.com\/.  Twistlock. Docker security and container security platform. https:\/\/www.twistlock.com\/."},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884434"},{"key":"e_1_3_2_2_51_1","first-page":"307","volume-title":"Proceedings of the 7th symposium on Operating systems design and implementation","author":"Weil S. A.","year":"2006","unstructured":"S. A. Weil , S. A. Brandt , E. L. Miller , D. D. Long , and C. Maltzahn . Ceph: A scalable, high-performance distributed file system . In Proceedings of the 7th symposium on Operating systems design and implementation , pages 307 -- 320 . USENIX Association , 2006 . S. A. Weil, S. A. Brandt, E. L. Miller, D. D. Long, and C. Maltzahn. Ceph: A scalable, high-performance distributed file system. In Proceedings of the 7th symposium on Operating systems design and implementation, pages 307--320. USENIX Association, 2006."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(84)90020-5"},{"key":"e_1_3_2_2_53_1","volume-title":"https:\/\/github.com\/wizzard\/SwiftFS","author":"FS.","year":"2014","unstructured":"Wizzard. Swift FS. https:\/\/github.com\/wizzard\/SwiftFS , 2014 . Wizzard. SwiftFS. https:\/\/github.com\/wizzard\/SwiftFS, 2014."}],"event":{"name":"Middleware '18: 19th International Middleware Conference","sponsor":["ACM Association for Computing Machinery","USENIX Assoc USENIX Assoc","IFIP International Federation for Information Processing"],"location":"Rennes France","acronym":"Middleware '18"},"container-title":["Proceedings of the 19th International Middleware Conference Industry"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3284028.3284031","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3284028.3284031","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T01:08:01Z","timestamp":1750208881000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3284028.3284031"}},"subtitle":["Bringing Black-box Security Analytics to Cloud"],"short-title":[],"issued":{"date-parts":[[2018,12,10]]},"references-count":52,"alternative-id":["10.1145\/3284028.3284031","10.1145\/3284028"],"URL":"https:\/\/doi.org\/10.1145\/3284028.3284031","relation":{},"subject":[],"published":{"date-parts":[[2018,12,10]]},"assertion":[{"value":"2018-12-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}