Evaluating Docker Container Security through Penetration Testing: A Smart Computer Security


연구 분야: Strategies



학회: 2023 International Conference on Communication, Security and Artificial Intelligence (ICCSAI)


초록

The widespread adoption of containerization, exemplified by Docker, has transformed software deployment, enabling agile applications. However, its popularity invites malicious exploits, heightening security incidents in containerized environments. This paper details a comprehensive penetration testing approach for Docker container security, spotlighting file system vulnerabilities and artifacts. Using penetration testing methodologies, the study systematically scrutinizes Docker container file systems. Detection of Common Vulnerabilities and Exposures (CVEs) and Common Exploit Weaknesses (CEWs) within the file system identifies potential attacker entry points. The paper also delves into artifact extraction from the file system, encompassing logs, configurations, and command traces. These artifacts unveil the container's activities, shedding light on potential intrusion vectors. Examination of container metadata and configurations uncovers misconfigurations and potential attack surfaces. By Exploration of file system vulnerabilities and artifacts equips security practitioners with crucial insights for bolstering Docker container defense.


Author Profile
Drake Mubanda

School of Cyber Security and Digital Forensics National Forensic Sciences University Gandhinagar India

Andorra
Author Profile
Ngaira Mandela

School of Cyber Security and Digital Forensics National Forensic Sciences University Gandhinagar India

Andorra
Author Profile
Tumaini Mbinda

School of Cyber Security and Digital Forensics National Forensic Sciences University Gandhinagar India

Andorra

📄 논문 정보

발행 연도 2023년
인용수 6
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (40건)