The Experts below are selected from a list of 231 Experts worldwide ranked by ideXlab platform
Quan Zhou - One of the best experts on this subject based on the ideXlab platform.
-
a measurement study on linux container security Attacks and countermeasures
Annual Computer Security Applications Conference, 2018Co-Authors: Yuewu Wang, Jiwu Jing, Quan ZhouAbstract:Linux container mechanism has attracted a lot of attention and is increasingly utilized to deploy industry applications. Though it is a consensus that the container mechanism is not secure due to the kernel-sharing property, it lacks a concrete and systematical evaluation on its security using real world exploits. In this paper, we collect an Attack dataset including 223 exploits that are effective on the container platform, and classify them into different categories using a two-dimensional Attack Taxonomy. Then we evaluate the security of existing Linux container mechanism using 88 typical exploits filtered out from the dataset. We find 50 (56.82%) exploits can successfully launch Attacks from inside the container with the default configuration. Since the privilege escalation exploits can completely disable the container protection mechanism, we conduct an in-depth analysis on these exploits. We find the kernel security mechanisms such as Capability, Seccomp, and MAC play a more important role in preventing privilege escalation than the container isolation mechanisms (i.e., Namespace and Cgroup). However, the interdependence and mutual-influence relationship among these kernel security mechanisms may make them fall into the "short board effect" and impair their protection capability. By studying the 11 exploits that still can successfully break the isolation provided by container and achieve privilege escalation, we identify a common 4-step Attack model followed by all 11 exploits. Finally, we propose a defense mechanism to effectively defeat those identified privilege escalation Attacks.
-
ACSAC - A Measurement Study on Linux Container Security: Attacks and Countermeasures
Proceedings of the 34th Annual Computer Security Applications Conference, 2018Co-Authors: Yuewu Wang, Jiwu Jing, Quan ZhouAbstract:Linux container mechanism has attracted a lot of attention and is increasingly utilized to deploy industry applications. Though it is a consensus that the container mechanism is not secure due to the kernel-sharing property, it lacks a concrete and systematical evaluation on its security using real world exploits. In this paper, we collect an Attack dataset including 223 exploits that are effective on the container platform, and classify them into different categories using a two-dimensional Attack Taxonomy. Then we evaluate the security of existing Linux container mechanism using 88 typical exploits filtered out from the dataset. We find 50 (56.82%) exploits can successfully launch Attacks from inside the container with the default configuration. Since the privilege escalation exploits can completely disable the container protection mechanism, we conduct an in-depth analysis on these exploits. We find the kernel security mechanisms such as Capability, Seccomp, and MAC play a more important role in preventing privilege escalation than the container isolation mechanisms (i.e., Namespace and Cgroup). However, the interdependence and mutual-influence relationship among these kernel security mechanisms may make them fall into the "short board effect" and impair their protection capability. By studying the 11 exploits that still can successfully break the isolation provided by container and achieve privilege escalation, we identify a common 4-step Attack model followed by all 11 exploits. Finally, we propose a defense mechanism to effectively defeat those identified privilege escalation Attacks.
Arash Shaghaghi - One of the best experts on this subject based on the ideXlab platform.
-
software defined network sdn data plane security issues solutions and future directions
Handbook of computer networks and cyber security : principles and paradigms, 2020Co-Authors: Arash Shaghaghi, Mohamed Ali Kaafar, Rajkumar Buyya, Sanjay JhaAbstract:Software-defined network (SDN) radically changes the network architecture by decoupling the network logic from the underlying forwarding devices. This architectural change rejuvenates the network-layer granting centralized management and reprogrammability of the networks. From a security perspective, SDN separates security concerns into control and data plane, and this architectural recomposition brings up exciting opportunities and challenges. The overall perception is that SDN capabilities will ultimately result in improved security. However, in its raw form, SDN could potentially make networks more vulnerable to Attacks and harder to protect. In this paper, we provide a comprehensive review of SDN security domain while focusing on its data plane, which is one of the least explored but most critical aspects in securing this technology. We review the most recent enhancements in SDNs, identify the main vulnerabilities of SDNs, and provide a novel Attack Taxonomy for SDNs. Thereafter, we provide a comprehensive analysis of challenges involved in protecting SDN data plane and control plane and provide an in-depth look into available solutions with respect to the identified threats and identify their limitations. To highlight the importance of securing the SDN platform, we also review the numerous security services built on top of this technology. We conclude the paper by offering future research directions.
-
Handbook of Computer Networks and Cyber Security - Software-Defined Network (SDN) Data Plane Security: Issues, Solutions, and Future Directions
Handbook of Computer Networks and Cyber Security, 2020Co-Authors: Arash Shaghaghi, Mohamed Ali Kaafar, Rajkumar Buyya, Sanjay JhaAbstract:Software-defined network (SDN) radically changes the network architecture by decoupling the network logic from the underlying forwarding devices. This architectural change rejuvenates the network-layer granting centralized management and reprogrammability of the networks. From a security perspective, SDN separates security concerns into control and data plane, and this architectural recomposition brings up exciting opportunities and challenges. The overall perception is that SDN capabilities will ultimately result in improved security. However, in its raw form, SDN could potentially make networks more vulnerable to Attacks and harder to protect. In this paper, we provide a comprehensive review of SDN security domain while focusing on its data plane, which is one of the least explored but most critical aspects in securing this technology. We review the most recent enhancements in SDNs, identify the main vulnerabilities of SDNs, and provide a novel Attack Taxonomy for SDNs. Thereafter, we provide a comprehensive analysis of challenges involved in protecting SDN data plane and control plane and provide an in-depth look into available solutions with respect to the identified threats and identify their limitations. To highlight the importance of securing the SDN platform, we also review the numerous security services built on top of this technology. We conclude the paper by offering future research directions.
Sanjay Jha - One of the best experts on this subject based on the ideXlab platform.
-
software defined network sdn data plane security issues solutions and future directions
Handbook of computer networks and cyber security : principles and paradigms, 2020Co-Authors: Arash Shaghaghi, Mohamed Ali Kaafar, Rajkumar Buyya, Sanjay JhaAbstract:Software-defined network (SDN) radically changes the network architecture by decoupling the network logic from the underlying forwarding devices. This architectural change rejuvenates the network-layer granting centralized management and reprogrammability of the networks. From a security perspective, SDN separates security concerns into control and data plane, and this architectural recomposition brings up exciting opportunities and challenges. The overall perception is that SDN capabilities will ultimately result in improved security. However, in its raw form, SDN could potentially make networks more vulnerable to Attacks and harder to protect. In this paper, we provide a comprehensive review of SDN security domain while focusing on its data plane, which is one of the least explored but most critical aspects in securing this technology. We review the most recent enhancements in SDNs, identify the main vulnerabilities of SDNs, and provide a novel Attack Taxonomy for SDNs. Thereafter, we provide a comprehensive analysis of challenges involved in protecting SDN data plane and control plane and provide an in-depth look into available solutions with respect to the identified threats and identify their limitations. To highlight the importance of securing the SDN platform, we also review the numerous security services built on top of this technology. We conclude the paper by offering future research directions.
-
Handbook of Computer Networks and Cyber Security - Software-Defined Network (SDN) Data Plane Security: Issues, Solutions, and Future Directions
Handbook of Computer Networks and Cyber Security, 2020Co-Authors: Arash Shaghaghi, Mohamed Ali Kaafar, Rajkumar Buyya, Sanjay JhaAbstract:Software-defined network (SDN) radically changes the network architecture by decoupling the network logic from the underlying forwarding devices. This architectural change rejuvenates the network-layer granting centralized management and reprogrammability of the networks. From a security perspective, SDN separates security concerns into control and data plane, and this architectural recomposition brings up exciting opportunities and challenges. The overall perception is that SDN capabilities will ultimately result in improved security. However, in its raw form, SDN could potentially make networks more vulnerable to Attacks and harder to protect. In this paper, we provide a comprehensive review of SDN security domain while focusing on its data plane, which is one of the least explored but most critical aspects in securing this technology. We review the most recent enhancements in SDNs, identify the main vulnerabilities of SDNs, and provide a novel Attack Taxonomy for SDNs. Thereafter, we provide a comprehensive analysis of challenges involved in protecting SDN data plane and control plane and provide an in-depth look into available solutions with respect to the identified threats and identify their limitations. To highlight the importance of securing the SDN platform, we also review the numerous security services built on top of this technology. We conclude the paper by offering future research directions.
Rahul Bisht - One of the best experts on this subject based on the ideXlab platform.
-
docker security a threat model Attack Taxonomy and real time Attack scenario of dos
International Conference on Cloud Computing, 2020Co-Authors: Aparna Tomar, Diksha Jeena, Preeti Mishra, Rahul BishtAbstract:As the last decade experienced an explosion in the development and use of virtualization technologies, the need for an efficient and secure virtualization solution has also been increased. All the solutions that emerged can be classified into two major classes i.e. hypervisor-based virtualization and container-based virtualization. Container technologies have been around for a very long time but Docker is a relatively new and the most dominant candidate among all the other technologies. Along with so many advantages, it has a few disadvantages as well in which its security is the primary and the most crucial concern. In this paper, we propose a threat model for Docker with all the possible Attack scenarios in Docker-based host systems. Furthermore, the paper also provides a detailed classification of Attacks that can take place on various layers of Docker along with the description of each one of them. Lastly, the paper presents a real-time case study on Denial of Service (DoS) Attack in the Docker environment.
Preeti Mishra - One of the best experts on this subject based on the ideXlab platform.
-
docker security a threat model Attack Taxonomy and real time Attack scenario of dos
International Conference on Cloud Computing, 2020Co-Authors: Aparna Tomar, Diksha Jeena, Preeti Mishra, Rahul BishtAbstract:As the last decade experienced an explosion in the development and use of virtualization technologies, the need for an efficient and secure virtualization solution has also been increased. All the solutions that emerged can be classified into two major classes i.e. hypervisor-based virtualization and container-based virtualization. Container technologies have been around for a very long time but Docker is a relatively new and the most dominant candidate among all the other technologies. Along with so many advantages, it has a few disadvantages as well in which its security is the primary and the most crucial concern. In this paper, we propose a threat model for Docker with all the possible Attack scenarios in Docker-based host systems. Furthermore, the paper also provides a detailed classification of Attacks that can take place on various layers of Docker along with the description of each one of them. Lastly, the paper presents a real-time case study on Denial of Service (DoS) Attack in the Docker environment.
-
Intrusion detection techniques in cloud environment
Journal of Network and Computer Applications, 2017Co-Authors: Preeti Mishra, Emmanuel S. Pilli, Vijay Varadharajan, Udaya TupakulaAbstract:Security is of paramount importance in this new era of on-demand Cloud Computing. Researchers have provided a survey on several intrusion detection techniques for detecting intrusions in the cloud computing environment. Most of them provide a discussion over traditional misuse and anomaly detection techniques. Virtual Machine Introspection (VMI) techniques are very helpful in detecting various stealth Attacks targeting user-level and kernel-level processes running in virtual machines (VMs) by placing the analyzing component outside the VM generally at hypervisor. Hypervisor Introspection (HVI) techniques ensure the hypervisor security and prevent a compromised hypervisor to launch further Attacks on VMs running over it. Introspection techniques introspect the hypervisor by using hardware-assisted virtualization-enabled technologies. The main focus of our paper is to provide an exhaustive literature survey of various Intrusion Detection techniques proposed for cloud environment with an analysis of their Attack detection capability. We propose a threat model and Attack Taxonomy in cloud environment to elucidate the vulnerabilities in cloud. Our Taxonomy of IDS techniques represent the state of the art classification and provides a detailed study of techniques with their distinctive features. We have provided a deep insight into Virtual Machine Introspection (VMI) and Hypervisor Introspection (HVI) based techniques in the survey. Specific research challenges are identified to give future direction to researchers. We hope that our work will enable researchers to launch and dive deep into intrusion detection approaches in a cloud environment.