A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Tan, Kai, Zhan, Dongyang, Ye, Lin, Zhang, Hongli, Fang, Binxing, Tian, Zhihong
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912594828197888
author Tan, Kai
Zhan, Dongyang
Ye, Lin
Zhang, Hongli
Fang, Binxing
Tian, Zhihong
author_facet Tan, Kai
Zhan, Dongyang
Ye, Lin
Zhang, Hongli
Fang, Binxing
Tian, Zhihong
contents As cloud computing continues to advance and become an integral part of modern IT infrastructure, container security has emerged as a critical factor in ensuring the smooth operation of cloud-native applications. An attacker can attack the service in the container or even perform the container escape attack by tampering with the files. Monitoring container files is important for APT detection and cyberspace security. Existing file monitoring methods are usually based on host operating system or virtual machine introspection to protect file security in real time. The methods based on the host operating system usually monitor file operations in the host operating system. However, when the container escapes to the host, the host operating system will no longer be secure, so these methods face the problem of weak security. Aiming at the problems of low security and high overload introduced in existing container file monitoring, a high-performance container file monitoring method based on virtual machine introspection is proposed. The experimental results show that the proposed approach can effectively monitor the container files and introduce an acceptable monitoring overload.
format Preprint
id arxiv_https___arxiv_org_abs_2509_16030
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection
Tan, Kai
Zhan, Dongyang
Ye, Lin
Zhang, Hongli
Fang, Binxing
Tian, Zhihong
Cryptography and Security
Computers and Society
As cloud computing continues to advance and become an integral part of modern IT infrastructure, container security has emerged as a critical factor in ensuring the smooth operation of cloud-native applications. An attacker can attack the service in the container or even perform the container escape attack by tampering with the files. Monitoring container files is important for APT detection and cyberspace security. Existing file monitoring methods are usually based on host operating system or virtual machine introspection to protect file security in real time. The methods based on the host operating system usually monitor file operations in the host operating system. However, when the container escapes to the host, the host operating system will no longer be secure, so these methods face the problem of weak security. Aiming at the problems of low security and high overload introduced in existing container file monitoring, a high-performance container file monitoring method based on virtual machine introspection is proposed. The experimental results show that the proposed approach can effectively monitor the container files and introduce an acceptable monitoring overload.
title A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2509.16030