{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T23:10:57Z","timestamp":1768345857418,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,6]],"date-time":"2023-08-06T00:00:00Z","timestamp":1691280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,6]]},"DOI":"10.1145\/3599957.3606222","type":"proceedings-article","created":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T17:48:17Z","timestamp":1693331297000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["SecCo"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7155-7429","authenticated-orcid":false,"given":"Luca","family":"Verderame","sequence":"first","affiliation":[{"name":"DIBRIS - University of Genova, Genova, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6466-3354","authenticated-orcid":false,"given":"Luca","family":"Caviglione","sequence":"additional","affiliation":[{"name":"Consiglio Nazionale delle Ricerche, Genova, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2853-4269","authenticated-orcid":false,"given":"Roberto","family":"Carbone","sequence":"additional","affiliation":[{"name":"Fondazione Bruno Kessler, Trento, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2272-2376","authenticated-orcid":false,"given":"Alessio","family":"Merlo","sequence":"additional","affiliation":[{"name":"Centre for High Defense Studies, Rome, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"2021 Fifth World Conference on Smart Trends in Systems Security and Sustainability (WorldS4). 152--156","author":"Abhishek Manish Kumar","unstructured":"Manish Kumar Abhishek and D. Rajeswara Rao . 2021. Framework to Secure Docker Containers . In 2021 Fifth World Conference on Smart Trends in Systems Security and Sustainability (WorldS4). 152--156 . Manish Kumar Abhishek and D. Rajeswara Rao. 2021. Framework to Secure Docker Containers. In 2021 Fifth World Conference on Smart Trends in Systems Security and Sustainability (WorldS4). 152--156."},{"key":"#cr-split#-e_1_3_2_1_2_1.1","doi-asserted-by":"crossref","unstructured":"Alessio Merlo Luca Verderame Alessandro Armando Gabriele Costa. 2014. Enabling BYOD through secure meta-market. 219--230. https:\/\/doi.org\/10.1145\/2627393.2627410 10.1145\/2627393.2627410","DOI":"10.1145\/2627393.2627410"},{"key":"#cr-split#-e_1_3_2_1_2_1.2","doi-asserted-by":"crossref","unstructured":"Alessio Merlo Luca Verderame Alessandro Armando Gabriele Costa. 2014. Enabling BYOD through secure meta-market. 219--230. https:\/\/doi.org\/10.1145\/2627393.2627410","DOI":"10.1145\/2627393.2627410"},{"key":"e_1_3_2_1_3_1","volume-title":"From model-checking to automated testing of security protocols: Bridging the gap. 7305 LNCS","author":"Alessio Merlo Davide Balzarotti Roberto Carbone","year":"2012","unstructured":"Roberto Carbone Alessio Merlo Davide Balzarotti Alessandro Armando , Giancarlo Pellegrino . 2012. From model-checking to automated testing of security protocols: Bridging the gap. 7305 LNCS ( 2012 ), 3--18. https:\/\/doi.org\/10.1007\/978-3-642-30473-6_3 10.1007\/978-3-642-30473-6_3 Roberto Carbone Alessio Merlo Davide Balzarotti Alessandro Armando, Giancarlo Pellegrino. 2012. From model-checking to automated testing of security protocols: Bridging the gap. 7305 LNCS (2012), 3--18. https:\/\/doi.org\/10.1007\/978-3-642-30473-6_3"},{"key":"e_1_3_2_1_4_1","volume-title":"Accessed","author":"Besic Nera","year":"2021","unstructured":"Nera Besic . 2021 . Microservices Security: Challenges and Best Practices. https:\/\/brightsec.com\/blog\/microservices-security\/. (2021) . Accessed : July 12, 2023. Nera Besic. 2021. Microservices Security: Challenges and Best Practices. https:\/\/brightsec.com\/blog\/microservices-security\/. (2021). Accessed: July 12, 2023."},{"key":"e_1_3_2_1_5_1","volume-title":"Accessed","author":"Besic Nera","year":"2023","unstructured":"Nera Besic . 2023 . Container Vulnerability Scanning. https:\/\/anchore.com\/container-vulnerability-scanning\/. (2023) . Accessed : July 12, 2023. Nera Besic. 2023. Container Vulnerability Scanning. https:\/\/anchore.com\/container-vulnerability-scanning\/. (2023). Accessed: July 12, 2023."},{"key":"e_1_3_2_1_6_1","volume-title":"Accessed","year":"2023","unstructured":"Clair. 2023 . Vulnerability static analysis for containers. https:\/\/github.com\/quay\/clair. (2023) . Accessed : July 12, 2023. Clair. 2023. Vulnerability static analysis for containers. https:\/\/github.com\/quay\/clair. (2023). Accessed: July 12, 2023."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","first-page":"1699","DOI":"10.32604\/cmc.2022.025096","article-title":"DAVS: Dockerfile Analysis for Container Image Vulnerability Scanning","volume":"72","author":"Doan Thien-Phuc","year":"2022","unstructured":"Thien-Phuc Doan and Souhwan Jung . 2022 . DAVS: Dockerfile Analysis for Container Image Vulnerability Scanning . CMC-COMPUTERS MATERIALS & CONTINUA 72 , 1 (2022), 1699 -- 1711 . Thien-Phuc Doan and Souhwan Jung. 2022. DAVS: Dockerfile Analysis for Container Image Vulnerability Scanning. CMC-COMPUTERS MATERIALS & CONTINUA 72, 1 (2022), 1699--1711.","journal-title":"CMC-COMPUTERS MATERIALS & CONTINUA"},{"key":"e_1_3_2_1_8_1","volume-title":"Accessed","year":"2019","unstructured":"Docker. 2019 . Security best practices. https:\/\/docs.docker.com\/develop\/security-best-practices\/. (2019) . Accessed : July 12, 2023. Docker. 2019. Security best practices. https:\/\/docs.docker.com\/develop\/security-best-practices\/. (2019). Accessed: July 12, 2023."},{"key":"e_1_3_2_1_9_1","volume-title":"Manuel Mazzara, Fabrizio Montesi, Ruslan Mustafin, and Larisa Safina.","author":"Dragoni Nicola","year":"2017","unstructured":"Nicola Dragoni , Saverio Giallorenzo , Alberto Lluch Lafuente , Manuel Mazzara, Fabrizio Montesi, Ruslan Mustafin, and Larisa Safina. 2017 . Microservices: yesterday, today, and tomorrow. Present and ulterior software engineering (2017), 195--216. Nicola Dragoni, Saverio Giallorenzo, Alberto Lluch Lafuente, Manuel Mazzara, Fabrizio Montesi, Ruslan Mustafin, and Larisa Safina. 2017. Microservices: yesterday, today, and tomorrow. Present and ulterior software engineering (2017), 195--216."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/LADC.2018.00013"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1109\/MS.2022.3213285","article-title":"DevOps in Practice","volume":"40","author":"Ebert Christof","year":"2023","unstructured":"Christof Ebert and Lorin Hochstein . 2023 . DevOps in Practice . IEEE Software 40 , 1 (2023), 29 -- 36 . https:\/\/doi.org\/10.1109\/MS.2022.3213285 10.1109\/MS.2022.3213285 Christof Ebert and Lorin Hochstein. 2023. DevOps in Practice. IEEE Software 40, 1 (2023), 29--36. https:\/\/doi.org\/10.1109\/MS.2022.3213285","journal-title":"IEEE Software"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 34th ACM\/SIGAPP Symposium on Applied Computing (SAC '19)","author":"Gabriel","unstructured":"Gabriel P. Fernandez and Andrey Brito. 2019. Secure Container Orchestration in the Cloud: Policies and Implementation . In Proceedings of the 34th ACM\/SIGAPP Symposium on Applied Computing (SAC '19) . Association for Computing Machinery, New York, NY, USA, 138--145. https:\/\/doi.org\/10.1145\/3297280.3297296 10.1145\/3297280.3297296 Gabriel P. Fernandez and Andrey Brito. 2019. Secure Container Orchestration in the Cloud: Policies and Implementation. In Proceedings of the 34th ACM\/SIGAPP Symposium on Applied Computing (SAC '19). Association for Computing Machinery, New York, NY, USA, 138--145. https:\/\/doi.org\/10.1145\/3297280.3297296"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1016\/j.procs.2020.07.025","article-title":"A review of native container security for running applications","volume":"175","author":"Flauzac Olivier","year":"2020","unstructured":"Olivier Flauzac , Fabien Mauhourat , and Florent Nolot . 2020 . A review of native container security for running applications . Procedia Computer Science 175 (2020), 157 -- 164 . Olivier Flauzac, Fabien Mauhourat, and Florent Nolot. 2020. A review of native container security for running applications. Procedia Computer Science 175 (2020), 157--164.","journal-title":"Procedia Computer Science"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3481646.3481661"},{"key":"e_1_3_2_1_15_1","volume-title":"An analysis of security vulnerabilities in container images for scientific data analysis. GigaScience 10, 6","author":"Kaur Bhupinder","year":"2021","unstructured":"Bhupinder Kaur , Mathieu Dugr\u00e9 , Aiman Hanna , and Tristan Glatard . 2021. An analysis of security vulnerabilities in container images for scientific data analysis. GigaScience 10, 6 ( 2021 ), giab025. Bhupinder Kaur, Mathieu Dugr\u00e9, Aiman Hanna, and Tristan Glatard. 2021. An analysis of security vulnerabilities in container images for scientific data analysis. GigaScience 10, 6 (2021), giab025."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2976874"},{"key":"e_1_3_2_1_17_1","volume-title":"Trends for the DevOps Security. A Systematic Literature Review. In International Symposium on Business Modeling and Software Design. Springer, 200--217","author":"Lepp\u00e4nen Tiina","year":"2022","unstructured":"Tiina Lepp\u00e4nen , Anne Honkaranta , and Andrei Costin . 2022 . Trends for the DevOps Security. A Systematic Literature Review. In International Symposium on Business Modeling and Software Design. Springer, 200--217 . Tiina Lepp\u00e4nen, Anne Honkaranta, and Andrei Costin. 2022. Trends for the DevOps Security. A Systematic Literature Review. In International Symposium on Business Modeling and Software Design. Springer, 200--217."},{"key":"e_1_3_2_1_18_1","volume-title":"2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE, 1561--1564","author":"Loukidis-Andreou Fotis","year":"2018","unstructured":"Fotis Loukidis-Andreou , Ioannis Giannakopoulos , Katerina Doka , and Nectarios Koziris . 2018 . Docker-sec: A fully automated container security enhancement mechanism . In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE, 1561--1564 . Fotis Loukidis-Andreou, Ioannis Giannakopoulos, Katerina Doka, and Nectarios Koziris. 2018. Docker-sec: A fully automated container security enhancement mechanism. In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE, 1561--1564."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132211.3134460"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3055676"},{"key":"e_1_3_2_1_21_1","volume-title":"IDS: A step towards Green security. 1452--1457.","author":"Migliardi M.","year":"2011","unstructured":"M. Migliardi and A. Merlo . 2011 . Modeling the energy consumption of distributed IDS: A step towards Green security. 1452--1457. M. Migliardi and A. Merlo. 2011. Modeling the energy consumption of distributed IDS: A step towards Green security. 1452--1457."},{"key":"#cr-split#-e_1_3_2_1_22_1.1","doi-asserted-by":"crossref","unstructured":"M. Migliardi and A. Merlo. 2013. Improving energy efficiency in distributed intrusion detection systems. 19 3 (2013) 251--264. https:\/\/doi.org\/10.3233\/JHS-130476 10.3233\/JHS-130476","DOI":"10.3233\/JHS-130476"},{"key":"#cr-split#-e_1_3_2_1_22_1.2","doi-asserted-by":"crossref","unstructured":"M. Migliardi and A. Merlo. 2013. Improving energy efficiency in distributed intrusion detection systems. 19 3 (2013) 251--264. https:\/\/doi.org\/10.3233\/JHS-130476","DOI":"10.3233\/JHS-130476"},{"key":"e_1_3_2_1_23_1","volume-title":"Accessed","author":"Millman Rene","year":"2020","unstructured":"Rene Millman . 2020 . Most Docker container images have critical flaws. https:\/\/www.itpro.com\/development\/containers\/357984\/most-docker-container-images-have-critical-flaws. (2020) . Accessed : July 12, 2023. Rene Millman. 2020. Most Docker container images have critical flaws. https:\/\/www.itpro.com\/development\/containers\/357984\/most-docker-container-images-have-critical-flaws. (2020). Accessed: July 12, 2023."},{"key":"e_1_3_2_1_24_1","volume-title":"2017 CHILEAN Conference on Electrical, Electronics Engineering, Information and Communication Technologies (CHILECON). IEEE, 1--5.","author":"Munoz Caterina","year":"2017","unstructured":"Caterina Munoz , Francisco Montoto , Francisco Cifuentes , and Javier Bustos-Jim\u00e9nez . 2017 . Building a threshold cryptographic distributed HSM with docker containers . In 2017 CHILEAN Conference on Electrical, Electronics Engineering, Information and Communication Technologies (CHILECON). IEEE, 1--5. Caterina Munoz, Francisco Montoto, Francisco Cifuentes, and Javier Bustos-Jim\u00e9nez. 2017. Building a threshold cryptographic distributed HSM with docker containers. In 2017 CHILEAN Conference on Electrical, Electronics Engineering, Information and Communication Technologies (CHILECON). IEEE, 1--5."},{"key":"e_1_3_2_1_25_1","volume-title":"2020 IEEE 24th International Enterprise Distributed Object Computing Conference (EDOC). IEEE, 145--154","author":"Rangnau Thorsten","year":"2020","unstructured":"Thorsten Rangnau , Remco v Buijtenen , Frank Fransen , and Fatih Turkmen . 2020 . Continuous security testing: A case study on integrating dynamic security testing tools in ci\/cd pipelines . In 2020 IEEE 24th International Enterprise Distributed Object Computing Conference (EDOC). IEEE, 145--154 . Thorsten Rangnau, Remco v Buijtenen, Frank Fransen, and Fatih Turkmen. 2020. Continuous security testing: A case study on integrating dynamic security testing tools in ci\/cd pipelines. In 2020 IEEE 24th International Enterprise Distributed Object Computing Conference (EDOC). IEEE, 145--154."},{"key":"e_1_3_2_1_26_1","volume-title":"Container security: Issues, challenges, and the road ahead","author":"Sultan Sari","year":"2019","unstructured":"Sari Sultan , Imtiaz Ahmad , and Tassos Dimitriou . 2019. Container security: Issues, challenges, and the road ahead . IEEE access 7 ( 2019 ), 52976--52996. Sari Sultan, Imtiaz Ahmad, and Tassos Dimitriou. 2019. Container security: Issues, challenges, and the road ahead. IEEE access 7 (2019), 52976--52996."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2945930"},{"key":"e_1_3_2_1_28_1","volume-title":"Mart\u00edn Ochoa, and Jianying Zhou.","author":"Wong Ann Yi","year":"2021","unstructured":"Ann Yi Wong , Eyasu Getahun Chekole , Mart\u00edn Ochoa, and Jianying Zhou. 2021 . Threat modeling and security analysis of containers: A survey. arXiv preprint arXiv:2111.11475 (2021). Ann Yi Wong, Eyasu Getahun Chekole, Mart\u00edn Ochoa, and Jianying Zhou. 2021. Threat modeling and security analysis of containers: A survey. arXiv preprint arXiv:2111.11475 (2021)."},{"key":"e_1_3_2_1_29_1","volume-title":"2022 14th International Conference on COMmunication Systems & NETworkS (COMSNETS). IEEE, 129--137","author":"Zhu Hui","year":"2022","unstructured":"Hui Zhu and Christian Gehrmann . 2022 . Kub-Sec, an automatic Kubernetes cluster AppArmor profile generation engine . In 2022 14th International Conference on COMmunication Systems & NETworkS (COMSNETS). IEEE, 129--137 . Hui Zhu and Christian Gehrmann. 2022. Kub-Sec, an automatic Kubernetes cluster AppArmor profile generation engine. In 2022 14th International Conference on COMmunication Systems & NETworkS (COMSNETS). IEEE, 129--137."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3176752"}],"event":{"name":"RACS '23: International Conference on Research in Adaptive and Convergent Systems","location":"Gdansk Poland","acronym":"RACS '23","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"]},"container-title":["Proceedings of the International Conference on Research in Adaptive and Convergent Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3599957.3606222","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3599957.3606222","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:13Z","timestamp":1750178833000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3599957.3606222"}},"subtitle":["Automated Services to Secure Containers in the DevOps Paradigm"],"short-title":[],"issued":{"date-parts":[[2023,8,6]]},"references-count":32,"alternative-id":["10.1145\/3599957.3606222","10.1145\/3599957"],"URL":"https:\/\/doi.org\/10.1145\/3599957.3606222","relation":{},"subject":[],"published":{"date-parts":[[2023,8,6]]},"assertion":[{"value":"2023-08-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}