Container runtime security detection and prevention techniques

Fuente: Zenodo
Salvato in:
Dettagli Bibliografici
Autore principale: Ramasankar Molleti
Natura: Recurso digital
Lingua:inglese
Pubblicazione: Zenodo 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866901923022503936
author Ramasankar Molleti
author_facet Ramasankar Molleti
contents <p>Application control is a particular layer of cloud-native security that is aimed at protection during the application’s work in the container. This article provides a comprehension of container runtime security measures, including detection and prevention measures. It goes deeper into the importance of protecting container environments, mainly pointing out the outlook for dangers and risks that may occur at runtime. It also provides an overview of commodity detection techniques, such as container image analysis, runtime behavioral analysis, traffic analysis, Host and file integrity. Further, it dwells on the prevention measures involving image hardening, runtime security policies, the principle of least privilege, secure configurations and updates, patching, workload isolation and segmentation, secrets management, and using the immutable infrastructure. Also, this paper briefly discusses recent solutions such as kernel-level security features, runtime application self-protection (RASP), Sandboxing and unikernel solutions. It also goes further in explaining how automated security tools and platforms, especially open source and commercial tool platforms, can be used to improve the security of containers during runtime. In concluding the study, incident response and forensics need to be implemented across container objects, as it stipulates the need to take preventative measures for security threat detection and response.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_15236086
institution Zenodo
language eng
publishDate 2024
publisher Zenodo
record_format zenodo
spellingShingle Container runtime security detection and prevention techniques
Ramasankar Molleti
Container Runtime Security
Behavioral Analysis
Multi-layered Defense
DevSecOps
Orchestration Platforms
Kubernetes
<p>Application control is a particular layer of cloud-native security that is aimed at protection during the application’s work in the container. This article provides a comprehension of container runtime security measures, including detection and prevention measures. It goes deeper into the importance of protecting container environments, mainly pointing out the outlook for dangers and risks that may occur at runtime. It also provides an overview of commodity detection techniques, such as container image analysis, runtime behavioral analysis, traffic analysis, Host and file integrity. Further, it dwells on the prevention measures involving image hardening, runtime security policies, the principle of least privilege, secure configurations and updates, patching, workload isolation and segmentation, secrets management, and using the immutable infrastructure. Also, this paper briefly discusses recent solutions such as kernel-level security features, runtime application self-protection (RASP), Sandboxing and unikernel solutions. It also goes further in explaining how automated security tools and platforms, especially open source and commercial tool platforms, can be used to improve the security of containers during runtime. In concluding the study, incident response and forensics need to be implemented across container objects, as it stipulates the need to take preventative measures for security threat detection and response.</p>
title Container runtime security detection and prevention techniques
topic Container Runtime Security
Behavioral Analysis
Multi-layered Defense
DevSecOps
Orchestration Platforms
Kubernetes
url https://doi.org/10.5281/zenodo.15236086