Confine: Automated System Call Policy Generation for Container Attack Surface Reduction

Seyedhamed Ghavamnia, Tapti Palit, Azzedine Benameur, Michalis Polychronakis. Confine: Automated System Call Policy Generation for Container Attack Surface Reduction. In Manuel Egele, Leyla Bilge, editors, 23rd International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2020, San Sebastian, Spain, October 14-15, 2020. pages 443-458, USENIX Association, 2020. [doi]

Abstract

Abstract is missing.