A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866912594828197888 |
|---|---|
| author | Tan, Kai Zhan, Dongyang Ye, Lin Zhang, Hongli Fang, Binxing Tian, Zhihong |
| author_facet | Tan, Kai Zhan, Dongyang Ye, Lin Zhang, Hongli Fang, Binxing Tian, Zhihong |
| contents | As cloud computing continues to advance and become an integral part of modern IT infrastructure, container security has emerged as a critical factor in ensuring the smooth operation of cloud-native applications. An attacker can attack the service in the container or even perform the container escape attack by tampering with the files. Monitoring container files is important for APT detection and cyberspace security. Existing file monitoring methods are usually based on host operating system or virtual machine introspection to protect file security in real time. The methods based on the host operating system usually monitor file operations in the host operating system. However, when the container escapes to the host, the host operating system will no longer be secure, so these methods face the problem of weak security. Aiming at the problems of low security and high overload introduced in existing container file monitoring, a high-performance container file monitoring method based on virtual machine introspection is proposed. The experimental results show that the proposed approach can effectively monitor the container files and introduce an acceptable monitoring overload. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2509_16030 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection Tan, Kai Zhan, Dongyang Ye, Lin Zhang, Hongli Fang, Binxing Tian, Zhihong Cryptography and Security Computers and Society As cloud computing continues to advance and become an integral part of modern IT infrastructure, container security has emerged as a critical factor in ensuring the smooth operation of cloud-native applications. An attacker can attack the service in the container or even perform the container escape attack by tampering with the files. Monitoring container files is important for APT detection and cyberspace security. Existing file monitoring methods are usually based on host operating system or virtual machine introspection to protect file security in real time. The methods based on the host operating system usually monitor file operations in the host operating system. However, when the container escapes to the host, the host operating system will no longer be secure, so these methods face the problem of weak security. Aiming at the problems of low security and high overload introduced in existing container file monitoring, a high-performance container file monitoring method based on virtual machine introspection is proposed. The experimental results show that the proposed approach can effectively monitor the container files and introduce an acceptable monitoring overload. |
| title | A High-performance Real-time Container File Monitoring Approach Based on Virtual Machine Introspection |
| topic | Cryptography and Security Computers and Society |
| url | https://arxiv.org/abs/2509.16030 |