Container Attestation with Linux IMA namespaces
Lorenzo Ferro
Container Attestation with Linux IMA namespaces.
Rel. Antonio Lioy, Silvia Sisinni, Enrico Bravi. Politecnico di Torino, Master of science program in Computer Engineering, 2023
|
Preview |
PDF (Tesi_di_laurea)
- Thesis
Licence: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) | Preview |
Abstract
In contemporary times, containers play a crucial role in various fields, including cloud computing and microservices, among others. Their popularity continues to grow due to their flexibility, simplified deployment, compatibility with multiple operating systems, rapid availability, and precise allocation of computational resources in microservices. Ensuring the integrity and proper configuration of software on containers is vital for early detection of tampering and breaches, allowing for prompt response to attacks. Remote Attestation is a process through which an external entity evaluates the trustworthiness of a computational node. While effective for physical nodes, it's not yet well-established for virtual nodes, such as containers.
Some proposals have been made to address this issue, but they face challenges, such as inability to verify closed containers, scalability and performance concerns
Publication type
URI
![]() |
Modify record (reserved for operators) |
