연구 분야: Strategies
학회: 2023 International Conference on Communication, Security and Artificial Intelligence (ICCSAI)
The widespread adoption of containerization, exemplified by Docker, has transformed software deployment, enabling agile applications. However, its popularity invites malicious exploits, heightening security incidents in containerized environments. This paper details a comprehensive penetration testing approach for Docker container security, spotlighting file system vulnerabilities and artifacts. Using penetration testing methodologies, the study systematically scrutinizes Docker container file systems. Detection of Common Vulnerabilities and Exposures (CVEs) and Common Exploit Weaknesses (CEWs) within the file system identifies potential attacker entry points. The paper also delves into artifact extraction from the file system, encompassing logs, configurations, and command traces. These artifacts unveil the container's activities, shedding light on potential intrusion vectors. Examination of container metadata and configurations uncovers misconfigurations and potential attack surfaces. By Exploration of file system vulnerabilities and artifacts equips security practitioners with crucial insights for bolstering Docker container defense.
| 발행 연도 | 2023년 |
|---|---|
| 인용수 | 6 |
| 출판 국가 | Andorra |
| 사이트 | IEEE |
| 좋아요 수 | 0 |