77
Views
0
CrossRef citations to date
0
Altmetric
Research Article

Optimization of docker container security and its performance evaluation

, &
 

Abstract

Containers have replaced virtual machines because of their superior performance and lower resource use. The largest problems they face arise when security issues, such as establishing an appropriate level of isolation, are neglected. Namespaces and groups are tools offered by the Linux kernel, present limitations in its implementation. The solution to mitigate them, on the other hand, involves the use of a heterogeneous and complex set of additional measures: control MAC access, privilege segregation using capabilities and call filtering to the core with scomp. These mechanisms, however, are complex and require detailed knowledge of the technology on which it is based. The suppliers of platform as a service (PaaS) have the advantage the economy of scale to meet these challenges. In this work we deal with security in different contexts, and try to determine if running containers in operation in an infrastructure of reduced size can maintain an acceptable level of security. We’ve done this by looking at container technology and excellent security procedures from a guidebook.

Subject Classification:

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.