{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T16:18:41Z","timestamp":1784823521761,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,13]],"date-time":"2021-08-13T00:00:00Z","timestamp":1628812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Swiss National Foundation","award":["P1TIP2_191490"],"award-info":[{"award-number":["P1TIP2_191490"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,8,13]]},"DOI":"10.1145\/3481646.3481661","type":"proceedings-article","created":{"date-parts":[[2021,11,26]],"date-time":"2021-11-26T23:06:13Z","timestamp":1637967973000},"page":"95-101","source":"Crossref","is-referenced-by-count":23,"title":["An Evaluation of Container Security Vulnerability Detection Tools"],"prefix":"10.1145","author":[{"given":"Omar","family":"Javed","sequence":"first","affiliation":[{"name":"University of Lugano, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Salman","family":"Toor","sequence":"additional","affiliation":[{"name":"Uppsala University, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Cloud Computing: State of the Art and Security Issues. ACM SIGSOFT Software Engineering Notes","author":"Chhabra Shruti","year":"2015"},{"key":"e_1_3_2_1_2_1","volume-title":"Model-based Evaluation of Scalability and Security Tradeoffs: A Case Study on a Multi-Service Platform. Notes in Theoretical Computer Science","author":"Montecchi Leonardo","year":"2015"},{"key":"e_1_3_2_1_3_1","volume-title":"Docker ecosystem - vulnerability analysis. Computer Communications","author":"Martin Antony","year":"2018"},{"key":"e_1_3_2_1_4_1","volume-title":"Containers and Cloud: From LXC to Docker to Kubernetes","author":"Bernstein David","year":"2014"},{"key":"e_1_3_2_1_5_1","unstructured":"451research. 2020. Container status.https:\/\/451research.com\/images\/Marketing\/press_releases\/Application-container-market-will-reach-2-7bn-in- 2020_final_graphic.pdf?p=job%2FojM67fw2. (Accessed on 10\/07\/2020).  451research. 2020. Container status.https:\/\/451research.com\/images\/Marketing\/press_releases\/Application-container-market-will-reach-2-7bn-in- 2020_final_graphic.pdf?p=job%2FojM67fw2. (Accessed on 10\/07\/2020)."},{"key":"e_1_3_2_1_6_1","unstructured":"Diamanti. 2020. Container adoption benchmark survey. (Accessed on 10\/10\/2020).  Diamanti. 2020. Container adoption benchmark survey. (Accessed on 10\/10\/2020)."},{"key":"e_1_3_2_1_7_1","unstructured":"Docker blog. 2020. InfraKit a toolkit for creating and managing declarative self-healing infrastructure.https:\/\/blog.docker.com\/2016\/10\/introducing- infrakit-an-open-source-toolkit-for-declarative-infrastructure\/. (Accessed on 12\/10\/2020).  Docker blog. 2020. InfraKit a toolkit for creating and managing declarative self-healing infrastructure.https:\/\/blog.docker.com\/2016\/10\/introducing- infrakit-an-open-source-toolkit-for-declarative-infrastructure\/. (Accessed on 12\/10\/2020)."},{"key":"e_1_3_2_1_8_1","unstructured":"DockerHub. 2020. DockerHub Main page.https:\/\/www.docker.com\/products\/docker-hub. (Accessed on 12\/08\/2020).  DockerHub. 2020. DockerHub Main page.https:\/\/www.docker.com\/products\/docker-hub. (Accessed on 12\/08\/2020)."},{"key":"e_1_3_2_1_9_1","volume-title":"A study of security vulnerabilities on DockerHub. Data and Application Security and Privacy","author":"Shu Rui","year":"2017"},{"key":"e_1_3_2_1_10_1","unstructured":"Arstechnica. 2020. Backdoored images downloaded 5 million times finally removed from DockerHub.https:\/\/arstechnica.com\/information- technology\/2018\/06\/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub\/. (Accessed on 09\/10\/2020).  Arstechnica. 2020. Backdoored images downloaded 5 million times finally removed from DockerHub.https:\/\/arstechnica.com\/information- technology\/2018\/06\/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub\/. (Accessed on 09\/10\/2020)."},{"key":"e_1_3_2_1_11_1","unstructured":"Docker. 2020. Docker Security Scanning.https:\/\/beta.docs.docker.com\/v17.12\/docker-cloud\/builds\/image-scan\/. (Accessed on 10\/10\/2020).  Docker. 2020. Docker Security Scanning.https:\/\/beta.docs.docker.com\/v17.12\/docker-cloud\/builds\/image-scan\/. (Accessed on 10\/10\/2020)."},{"key":"e_1_3_2_1_12_1","unstructured":"Docker blog. 2020. Docker Security Scanning safeguards the container content lifecycle.https:\/\/blog.docker.com\/2016\/05\/docker-security-scanning\/. (Accessed on 05\/10\/2020).  Docker blog. 2020. Docker Security Scanning safeguards the container content lifecycle.https:\/\/blog.docker.com\/2016\/05\/docker-security-scanning\/. (Accessed on 05\/10\/2020)."},{"key":"e_1_3_2_1_13_1","unstructured":"Clair. 2020. Vulnerability static analysis for containers.https:\/\/coreos.com\/clair\/docs\/latest\/. (Accessed on 02\/11\/2020).  Clair. 2020. Vulnerability static analysis for containers.https:\/\/coreos.com\/clair\/docs\/latest\/. (Accessed on 02\/11\/2020)."},{"key":"e_1_3_2_1_14_1","unstructured":"Anchore. 2020. The Open Platform for Container Security and Compliance.https:\/\/anchore.com\/. (Accessed on 15\/11\/2020).  Anchore. 2020. The Open Platform for Container Security and Compliance.https:\/\/anchore.com\/. (Accessed on 15\/11\/2020)."},{"key":"e_1_3_2_1_15_1","volume-title":"Microscanner: New free image vulnerability scanner for developers.https:\/\/www.aquasec.com\/news\/microscanner- new-free-image-vulnerability-scanner-for-developers\/. (Accessed on 10\/04\/2020).","author":"Microscanner Aqua's","year":"2020"},{"key":"e_1_3_2_1_16_1","volume-title":"Brucker","author":"Othmane Lotfi Ben","year":"2017"},{"key":"e_1_3_2_1_17_1","unstructured":"Synposys. 2020. The latest Apache Struts vulnerability.https:\/\/www.synopsys.com\/blogs\/software-security\/cve-2018-11776-apache-struts- vulnerability\/. (Accessed on 09\/11\/2020).  Synposys. 2020. The latest Apache Struts vulnerability.https:\/\/www.synopsys.com\/blogs\/software-security\/cve-2018-11776-apache-struts- vulnerability\/. (Accessed on 09\/11\/2020)."},{"key":"e_1_3_2_1_18_1","unstructured":"JAXenter. 2020. Apache Struts threatens remote code execution.https:\/\/jaxenter.com\/new-vulnerability-discovered-apache-struts-148646.html. (Accessed on 09\/12\/2020).  JAXenter. 2020. Apache Struts threatens remote code execution.https:\/\/jaxenter.com\/new-vulnerability-discovered-apache-struts-148646.html. (Accessed on 09\/12\/2020)."},{"key":"e_1_3_2_1_19_1","unstructured":"Dataset. 2020. Vulnerability detection.https:\/\/www.dropbox.com\/sh\/j831hoqzb0fb60u\/AADf5mMhFHJEiaUn3i46CYYla?dl=0. (Accessed on 05\/12\/2020).  Dataset. 2020. Vulnerability detection.https:\/\/www.dropbox.com\/sh\/j831hoqzb0fb60u\/AADf5mMhFHJEiaUn3i46CYYla?dl=0. (Accessed on 05\/12\/2020)."},{"key":"e_1_3_2_1_20_1","unstructured":"GitHub. 2020. Introducing security alerts on GitHub.https:\/\/github.blog\/2017-11-16-introducing-security-alerts-on-github\/. (Accessed on 10\/08\/2020).  GitHub. 2020. Introducing security alerts on GitHub.https:\/\/github.blog\/2017-11-16-introducing-security-alerts-on-github\/. (Accessed on 10\/08\/2020)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Katrine Wist Malene Helsem and Danilo Gligoroski. 2020. Vulnerability Analysis of 2500 Docker Hub Images. arXiv:2006.02932[cs.CR]  Katrine Wist Malene Helsem and Danilo Gligoroski. 2020. Vulnerability Analysis of 2500 Docker Hub Images. arXiv:2006.02932[cs.CR]","DOI":"10.1007\/978-3-030-71017-0_22"},{"key":"e_1_3_2_1_22_1","unstructured":"App Armor. 2020. The Linux Kernel documentation.https:\/\/www.kernel.org\/doc\/html\/v4.15\/admin-guide\/LSM\/apparmor.html. (Accessed on 10\/04\/2020).  App Armor. 2020. The Linux Kernel documentation.https:\/\/www.kernel.org\/doc\/html\/v4.15\/admin-guide\/LSM\/apparmor.html. (Accessed on 10\/04\/2020)."},{"key":"e_1_3_2_1_23_1","unstructured":"Calico. 2020. Project Calico - Secure Networking for the Cloud Native Era.https:\/\/www.projectcalico.org\/. (Accessed on 10\/08\/2020).  Calico. 2020. Project Calico - Secure Networking for the Cloud Native Era.https:\/\/www.projectcalico.org\/. (Accessed on 10\/08\/2020)."},{"key":"e_1_3_2_1_24_1","unstructured":"Cilium. 2020. Cilium.https:\/\/cilium.io\/. (Accessed on 10\/08\/2020).  Cilium. 2020. Cilium.https:\/\/cilium.io\/. (Accessed on 10\/08\/2020)."},{"key":"e_1_3_2_1_25_1","unstructured":"Open policy. 2020. Open Policy Agent.https:\/\/www.openpolicyagent.org\/. (Accessed on 12\/10\/2019).  Open policy. 2020. Open Policy Agent.https:\/\/www.openpolicyagent.org\/. (Accessed on 12\/10\/2019)."},{"key":"e_1_3_2_1_26_1","unstructured":"Notary. 2020. Trust over arbitrary collections of data https:\/\/github.com\/theupdateframework\/notary. (Accessed on 10\/08\/2020).  Notary. 2020. Trust over arbitrary collections of data https:\/\/github.com\/theupdateframework\/notary. (Accessed on 10\/08\/2020)."},{"key":"e_1_3_2_1_27_1","unstructured":"Kubedex. 2020. Container Scanning - kubedex.com.https:\/\/kubedex.com\/container-scanning\/. (Accessed on 10\/04\/2020).  Kubedex. 2020. Container Scanning - kubedex.com.https:\/\/kubedex.com\/container-scanning\/. (Accessed on 10\/04\/2020)."},{"key":"e_1_3_2_1_28_1","unstructured":"Sysdig. 2020. 29 Docker security tools compared.https:\/\/sysdig.com\/blog\/20-docker-security-tools\/. (Accessed on 10\/10\/2020).  Sysdig. 2020. 29 Docker security tools compared.https:\/\/sysdig.com\/blog\/20-docker-security-tools\/. (Accessed on 10\/10\/2020)."},{"key":"e_1_3_2_1_29_1","unstructured":"Techbeacon. 2020. Top open-source tools for Docker security.https:\/\/techbeacon.com\/security\/10-top-open-source-tools-docker-security. (Accessed on 10\/10\/2020).  Techbeacon. 2020. Top open-source tools for Docker security.https:\/\/techbeacon.com\/security\/10-top-open-source-tools-docker-security. (Accessed on 10\/10\/2020)."},{"key":"e_1_3_2_1_30_1","unstructured":"SpotBugs. 2020. Find bugs in Java Programs.https:\/\/spotbugs.github.io\/. (Accessed on 12\/10\/2020).  SpotBugs. 2020. Find bugs in Java Programs.https:\/\/spotbugs.github.io\/. (Accessed on 12\/10\/2020)."},{"key":"e_1_3_2_1_31_1","unstructured":"Snyk. 2020. Snyk - The state of open source security.https:\/\/snyk.io\/opensourcesecurity-2019\/. (Accessed on 12\/07\/2020). [28]  Snyk. 2020. Snyk - The state of open source security.https:\/\/snyk.io\/opensourcesecurity-2019\/. (Accessed on 12\/07\/2020). [28]"},{"key":"e_1_3_2_1_32_1","volume-title":"On automated prepared statement generation to remove SQL injection vulnerabilities. Information and Software Technology","author":"Thomas Stephen","year":"2009"}],"event":{"name":"ICCBDC 2021: 2021 5th International Conference on Cloud and Big Data Computing","location":"Liverpool United Kingdom","acronym":"ICCBDC 2021"},"container-title":["2021 5th International Conference on Cloud and Big Data Computing (ICCBDC)"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3481646.3481661","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3481646.3481661","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:13Z","timestamp":1750193293000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3481646.3481661"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,13]]},"references-count":32,"alternative-id":["10.1145\/3481646.3481661","10.1145\/3481646"],"URL":"https:\/\/doi.org\/10.1145\/3481646.3481661","relation":{},"subject":[],"published":{"date-parts":[[2021,8,13]]}}}