Sysxchg: Refining privilege with adaptive system call filters
We present the design, implementation, and evaluation of SysXCHG: a system call (syscall)
filtering enforcement mechanism that enables programs to run in accordance with the …
filtering enforcement mechanism that enables programs to run in accordance with the …
Securing the Shared Kernel: Exploring Kernel Isolation and Emerging Challenges in Modern Cloud Computing
Containerization is a rapidly advancing technology in cloud computing, facilitating the
seamless development, deployment, and management of applications across diverse …
seamless development, deployment, and management of applications across diverse …
Optimus: association-based dynamic system call filtering for container attack surface reduction
While container adoption has witnessed significant growth in facilitating the operation of
large-scale applications, this increased attention has also attracted adversaries who exploit …
large-scale applications, this increased attention has also attracted adversaries who exploit …