Container runtime security detection and prevention techniques
Fuente:
Zenodo
Salvato in:
| Autore principale: | |
|---|---|
| Natura: | Recurso digital |
| Lingua: | inglese |
| Pubblicazione: |
Zenodo
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866901923022503936 |
|---|---|
| author | Ramasankar Molleti |
| author_facet | Ramasankar Molleti |
| contents | <p>Application control is a particular layer of cloud-native security that is aimed at protection during the application’s work in the container. This article provides a comprehension of container runtime security measures, including detection and prevention measures. It goes deeper into the importance of protecting container environments, mainly pointing out the outlook for dangers and risks that may occur at runtime. It also provides an overview of commodity detection techniques, such as container image analysis, runtime behavioral analysis, traffic analysis, Host and file integrity. Further, it dwells on the prevention measures involving image hardening, runtime security policies, the principle of least privilege, secure configurations and updates, patching, workload isolation and segmentation, secrets management, and using the immutable infrastructure. Also, this paper briefly discusses recent solutions such as kernel-level security features, runtime application self-protection (RASP), Sandboxing and unikernel solutions. It also goes further in explaining how automated security tools and platforms, especially open source and commercial tool platforms, can be used to improve the security of containers during runtime. In concluding the study, incident response and forensics need to be implemented across container objects, as it stipulates the need to take preventative measures for security threat detection and response.</p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_15236086 |
| institution | Zenodo |
| language | eng |
| publishDate | 2024 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Container runtime security detection and prevention techniques Ramasankar Molleti Container Runtime Security Behavioral Analysis Multi-layered Defense DevSecOps Orchestration Platforms Kubernetes <p>Application control is a particular layer of cloud-native security that is aimed at protection during the application’s work in the container. This article provides a comprehension of container runtime security measures, including detection and prevention measures. It goes deeper into the importance of protecting container environments, mainly pointing out the outlook for dangers and risks that may occur at runtime. It also provides an overview of commodity detection techniques, such as container image analysis, runtime behavioral analysis, traffic analysis, Host and file integrity. Further, it dwells on the prevention measures involving image hardening, runtime security policies, the principle of least privilege, secure configurations and updates, patching, workload isolation and segmentation, secrets management, and using the immutable infrastructure. Also, this paper briefly discusses recent solutions such as kernel-level security features, runtime application self-protection (RASP), Sandboxing and unikernel solutions. It also goes further in explaining how automated security tools and platforms, especially open source and commercial tool platforms, can be used to improve the security of containers during runtime. In concluding the study, incident response and forensics need to be implemented across container objects, as it stipulates the need to take preventative measures for security threat detection and response.</p> |
| title | Container runtime security detection and prevention techniques |
| topic | Container Runtime Security Behavioral Analysis Multi-layered Defense DevSecOps Orchestration Platforms Kubernetes |
| url | https://doi.org/10.5281/zenodo.15236086 |