Limits to the Forensic Analysis of Container Applications in Cloud Environments


연구 분야: Safety



학회: Digital Threats: Research and Practice


초록

User-space virtualization in form of containers is an increasingly popular deployment method for software applications. When containers are used in the cloud, an orchestration layer such as Kubernetes is utilized for automated and efficient management. All large cloud service providers offer container solutions in different cloud models. They differ in the level of administrative responsibility that remains with the user. Since containerized applications are affected by these design choices, incident responders face the challenge of quickly accessing relevant artifacts in case a security incident occurs. We investigate, for three different practical cloud deployment models from AWS (EKS, EKS Fargate, and ECS) and two increasingly severe attack scenarios, how much relevant information is accessible in each situation. We show that critically relevant forensic evidence is not available, especially at lower access levels. Our results reveal the limits to the forensic analysis of container applications in the cloud and call for cloud service providers to provide additional information in more lightweight deployment models for incident response.


Author Profile
Felix C Freiling

Friedrich-Alexander-Universität Erlangen-Nürnberg (FAU) Germany

Germany
Author Profile
Kerstin Schmid

Friedrich-Alexander-Universität Erlangen-Nürnberg (FAU) Germany

Germany
Author Profile
Konstantin Bayreuther

DHBW Mannheim Germany

Germany

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (423건)