Publications

7 Results
Skip to search filters

Towards Improving Container Security by Preventing Runtime Escapes

Proceedings - 2021 IEEE Secure Development Conference, SecDev 2021

Reeves, Michael J.; Tian, Dave J.; Bianchi, Antonio; Celik, Z.B.

Container escapes enable the adversary to execute code on the host from inside an isolated container. These high severity escape vulnerabilities originate from three sources: (1) container profile misconfigurations, (2) Linux kernel bugs, and (3) container runtime vulnerabilities. While the first two cases have been studied in the literature, no works have investigated the impact of container runtime vulnerabilities. In this paper, to fill this gap, we study 59 CVEs for 11 different container runtimes. As a result of our study, we found that five of the 11 runtimes had nine publicly available PoC container escape exploits covering 13 CVEs. Our further analysis revealed all nine exploits are the result of a host component leaked into the container. We apply a user namespace container defense to prevent the adversary from leveraging leaked host components and demonstrate that the defense stops seven of the nine container escape exploits.

More Details

Posters for AA/CE Reception

Kuether, Robert J.; Allensworth, Brooke M.; Backer, Adam B.; Chen, Elton Y.; Dingreville, Remi P.; Forrest, Eric C.; Knepper, Robert; Tappan, Alexander S.; Marquez, Michael P.; Vasiliauskas, Jonathan G.; Rupper, Stephen G.; Grant, Michael J.; Atencio, Lauren C.; Hipple, Tyler J.; Maes, Danae M.; Timlin, Jerilyn A.; Ma, Tian J.; Garcia, Rudy J.; Danford, Forest L.; Patrizi, Laura P.; Galasso, Jennifer G.; Draelos, Timothy J.; Gunda, Thushara G.; Venezuela, Otoniel V.; Brooks, Wesley A.; Anthony, Stephen M.; Carson, Bryan C.; Reeves, Michael J.; Roach, Matthew R.; Maines, Erin M.; Lavin, Judith M.; Whetten, Shaun R.; Swiler, Laura P.

Abstract not provided.

7 Results
7 Results