{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:31:42Z","timestamp":1783096302299,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3670352","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"1390-1404","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Crossing Shifted Moats: Replacing Old Bridges with New Tunnels to Confidential Containers"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-4674-3384","authenticated-orcid":false,"given":"Enriquillo","family":"Valdez","sequence":"first","affiliation":[{"name":"IBM Research, Yorktown Heights, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0290-5367","authenticated-orcid":false,"given":"Salman","family":"Ahmed","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9624-2669","authenticated-orcid":false,"given":"Zhongshu","family":"Gu","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-0397-6281","authenticated-orcid":false,"given":"Christophe","family":"de Dinechin","sequence":"additional","affiliation":[{"name":"Red Hat, Valbonne, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8234-2260","authenticated-orcid":false,"given":"Pau-Chen","family":"Cheng","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6143-1064","authenticated-orcid":false,"given":"Hani","family":"Jamjoom","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. Confidential Containers Architecture Overview. https:\/\/github.com\/ confidential-containers\/documentation\/blob\/main\/architecture.md."},{"key":"e_1_3_2_1_2_1","unstructured":"2023. Release Notes for v0.8.0. https:\/\/github.com\/confidential-containers\/ confidential-containers\/blob\/main\/releases\/v0.8.0.md."},{"key":"e_1_3_2_1_3_1","unstructured":"2023. Security policy for Confidential Containers on Azure Kubernetes Service. https:\/\/learn.microsoft.com\/en-us\/azure\/confidential-computing\/confidentialcontainers- aks-security-policy."},{"key":"e_1_3_2_1_4_1","volume-title":"AMD SEV-TIO: Trusted I\/O for Secure Encrypted Virtualization. https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-businessdocs\/ white-papers\/sev-tio-whitepaper.pdf. White Paper","author":"AMD.","year":"2023","unstructured":"AMD. 2023. AMD SEV-TIO: Trusted I\/O for Secure Encrypted Virtualization. https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-businessdocs\/ white-papers\/sev-tio-whitepaper.pdf. White Paper (2023)."},{"key":"e_1_3_2_1_5_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16)","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark L. Stillwell, David Goltzsche, Dave Eyers, R\u00fcdiger Kapitza, Peter Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16). 689--703."},{"key":"e_1_3_2_1_6_1","unstructured":"Thanh Bui. 2015. Analysis of Docker Security. arXiv:1501.02967"},{"key":"e_1_3_2_1_7_1","unstructured":"CCv0. 2016. Kata Containers. https:\/\/github.com\/kata-containers\/katacontainers\/ commit\/59d733f."},{"key":"e_1_3_2_1_8_1","unstructured":"Container Runtime Interface (CRI) CLI. 2019. https:\/\/github.com\/kubernetessigs\/ cri-tools\/blob\/master\/docs\/crictl.md."},{"key":"e_1_3_2_1_9_1","unstructured":"Constellation. 2022. https:\/\/www.edgeless.systems\/products\/constellation\/."},{"key":"e_1_3_2_1_10_1","unstructured":"Confidential Containers. 2023. https:\/\/github.com\/confidential-containers."},{"key":"e_1_3_2_1_11_1","unstructured":"Enclave Confidential Containers. 2023. https:\/\/github.com\/confidentialcontainers\/ enclave-cc."},{"key":"e_1_3_2_1_12_1","unstructured":"Kata Containers. 2023. https:\/\/katacontainers.io\/."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626827"},{"key":"e_1_3_2_1_14_1","unstructured":"Christophe de Dinechin David Gilbert and James Bottomley. 2023. Attestation in confidential computing. https:\/\/www.redhat.com\/en\/blog\/attestationconfidential- computing."},{"key":"e_1_3_2_1_15_1","volume-title":"ContainerLeaks: Emerging Security Threats of Information Leakages in Container Clouds. In 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). 237--248","author":"Gao Xing","year":"2017","unstructured":"Xing Gao, Zhongshu Gu, Mehmet Kayaalp, Dimitrios Pendarakis, and Haining Wang. 2017. ContainerLeaks: Emerging Security Threats of Information Leakages in Container Clouds. In 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). 237--248."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354227"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2879605"},{"key":"e_1_3_2_1_18_1","volume-title":"Network and Distributed System Security (NDSS) Symposium","volume":"3","author":"Garfinkel Tal","year":"2003","unstructured":"Tal Garfinkel and Mendel Rosenblum. 2003. A Virtual Machine Introspection Based Architecture for Intrusion Detection. In Network and Distributed System Security (NDSS) Symposium, Vol. 3. San Diega, CA, 191--206."},{"key":"e_1_3_2_1_19_1","unstructured":"Aaron Grattafiori. 2016. NCC Group Whitepaper: Understanding and Hardening Linux Containers."},{"key":"e_1_3_2_1_20_1","volume-title":"Process Implanting: A New Active Introspection Framework for Virtualization. In 2011 IEEE 30th International Symposium on Reliable Distributed Systems. 147--156","author":"Gu Zhongshu","year":"2011","unstructured":"Zhongshu Gu, Zhui Deng, Dongyan Xu, and Xuxian Jiang. 2011. Process Implanting: A New Active Introspection Framework for Virtualization. In 2011 IEEE 30th International Symposium on Reliable Distributed Systems. 147--156."},{"key":"e_1_3_2_1_21_1","unstructured":"Udit Gupta. 2015. Comparison between security majors in virtual machine and linux containers. arXiv:1507.07816"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456243"},{"key":"e_1_3_2_1_23_1","unstructured":"IBM. 2022. Introducing IBM Secure Execution for Linux 1.3.0. https:\/\/ www.ibm.com\/docs\/en\/linuxonibm\/pdf\/l130se03.pdf. (2022)."},{"key":"e_1_3_2_1_24_1","unstructured":"Intel. 2023. Intel TDX Module 1.0 Specification. https:\/\/cdrdv2.intel.com\/v1\/dl\/ getContent\/733568. (2023)."},{"key":"e_1_3_2_1_25_1","unstructured":"Intel. 2023. Intel\u00ae TDX Connect Architecture Specification. https:\/\/ cdrdv2.intel.com\/v1\/dl\/getContent\/773614. (2023)."},{"key":"e_1_3_2_1_26_1","unstructured":"Intel. 2023. Intel\u00ae Trust Domain Extensions. https:\/\/cdrdv2.intel.com\/v1\/dl\/ getContent\/690419. (2023)."},{"key":"e_1_3_2_1_27_1","volume-title":"Protecting VM Register State with Sev-es. White paper","author":"Kaplan David","year":"2017","unstructured":"David Kaplan. 2017. Protecting VM Register State with Sev-es. White paper (2017)."},{"key":"e_1_3_2_1_28_1","volume-title":"AMD Memory Encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD Memory Encryption. White paper (2016)."},{"key":"e_1_3_2_1_29_1","unstructured":"Extend kubectl with plugins. 2021. https:\/\/kubernetes.io\/docs\/tasks\/extendkubectl\/ kubectl-plugins\/."},{"key":"e_1_3_2_1_30_1","unstructured":"Kubernetes kubelet documentation. 2023. https:\/\/kubernetes.io\/docs\/reference\/ command-line-tools-reference\/kubelet\/."},{"key":"e_1_3_2_1_31_1","volume-title":"Speaker: Split-Phase Execution of Application Containers","author":"Lei Lingguang","year":"2017","unstructured":"Lingguang Lei, Jianhua Sun, Kun Sun, Chris Shenefiel, Rui Ma, Yuewu Wang, and Qi Li. 2017. Speaker: Split-Phase Execution of Application Containers. In Springer DIMVA."},{"key":"e_1_3_2_1_32_1","volume-title":"Design and Verification of the Arm Confidential Compute Architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22)","author":"Li Xupeng","year":"2022","unstructured":"Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. 2022. Design and Verification of the Arm Confidential Compute Architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22). 465--484."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274720"},{"key":"e_1_3_2_1_34_1","unstructured":"Command line tool (kubectl). 2023. https:\/\/kubernetes.io\/docs\/reference\/ kubectl\/."},{"key":"e_1_3_2_1_35_1","volume-title":"Whispers between the Containers: High-Capacity Covert Channel Attacks in Docker","author":"Luo Yang","unstructured":"Yang Luo, Wu Luo, Xiaoning Sun, Qingni Shen, Anbang Ruan, and Zhonghai Wu. 2016. Whispers between the Containers: High-Capacity Covert Channel Attacks in Docker. In IEEE Trustcom\/BigDataSE\/ISPA."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663171.2663188"},{"key":"e_1_3_2_1_37_1","volume-title":"Innovative Instructions and Software Model for Isolated Execution. The Second Workshop on Hardware and Architectural Support for Security and Privacy 10","author":"McKeen Frank","year":"2013","unstructured":"Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R Savagaonkar. 2013. Innovative Instructions and Software Model for Isolated Execution. The Second Workshop on Hardware and Architectural Support for Security and Privacy 10, 1 (2013)."},{"key":"e_1_3_2_1_38_1","unstructured":"Pradipta Banerjee. December 2 2021. Restricting Kata Agent API. https:\/\/ medium.com\/kata-containers\/restricting-kata-agent-api-e3dc88bf8270."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813650"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813720"},{"key":"e_1_3_2_1_41_1","volume-title":"23rd USENIX Security Symposium (USENIX Security . 255--269","author":"Saltaformaggio Brendan","year":"2014","unstructured":"Brendan Saltaformaggio, Zhongshu Gu, Xiangyu Zhang, and Dongyan Xu. 2014. DSCRETE: Automatic Rendering of Forensic Information from Memory Images via Application Logic Reuse. In 23rd USENIX Security Symposium (USENIX Security . 255--269."},{"key":"e_1_3_2_1_42_1","volume-title":"Strengthening VM Isolation with Integrity Protection and More. White Paper","author":"AMD SEV-SNP.","year":"2020","unstructured":"AMD SEV-SNP. 2020. Strengthening VM Isolation with Integrity Protection and More. White Paper (2020)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23500"},{"key":"e_1_3_2_1_45_1","volume-title":"27th USENIX Security Symposium (USENIX Security . 1423--1439","author":"Sun Yuqiong","year":"2018","unstructured":"Yuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis, Zhongshu Gu, and Trent Jaeger. 2018. Security Namespace: Making Linux Security Frameworks Available to Containers. In 27th USENIX Security Symposium (USENIX Security . 1423--1439."},{"key":"e_1_3_2_1_46_1","unstructured":"Tonic. 2022. A gRPC over HTTP\/2 implementation focused on high performance interoperability and flexibility. https:\/\/crates.io\/crates\/tonic."},{"key":"e_1_3_2_1_47_1","unstructured":"Agent Control tool. 2022. https:\/\/github.com\/kata-containers\/kata-containers\/ tree\/main\/src\/tools\/agent-ctl."},{"key":"e_1_3_2_1_48_1","unstructured":"Trustee. 2023. Trusted Components for Attestation and Secret Management. https:\/\/github.com\/confidential-containers\/trustee\/tree\/main\/kbs."},{"key":"e_1_3_2_1_49_1","volume-title":"Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17)","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai, Donald E Porter, and Mona Vij. 2017. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17). 645--658."},{"key":"e_1_3_2_1_50_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Xiao Jietao","year":"2023","unstructured":"Jietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li, Xin Guo, Zhiqiang Dong, Fei Xie, and Jianfeng Ma. 2023. Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation Forwarding. In 32nd USENIX Security Symposium (USENIX Security 23). 7517--7534."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3564634"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670352","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3670352","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:52:43Z","timestamp":1755841963000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670352"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":51,"alternative-id":["10.1145\/3658644.3670352","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3670352","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}