On Security Measures for Containerized Applications Imaged with Docker
Samuel P. Mullinix, Erikton Konomi, Renee Davis Townsend, Reza M., Parizi

TL;DR
This paper surveys the security landscape of Docker containers, analyzing vulnerabilities, existing tools, and methodologies to evaluate and improve container security in modern IT environments.
Contribution
It provides a comprehensive overview of Docker security issues, intrinsic vulnerabilities, and industry tools, offering insights into current best practices and research metrics.
Findings
Docker's security vulnerabilities stem from OS-level and image implementation issues.
Existing tools help identify and mitigate security risks in Docker environments.
Research metrics reveal areas needing improved security measures.
Abstract
Linux containers have risen in popularity in the last few years, making their way to commercial IT service offerings (such as PaaS), application deployments, and Continuous Delivery/Integration pipelines within various development teams. Along with the wide adoption of Docker, security vulnerabilities and concerns have also surfaced. In this survey, we examine the state of security for the most popular container system at the moment: Docker. We will also look into its origins stemming from the Linux technologies built into the OS itself; examine intrinsic vulnerabilities, such as the Docker Image implementation; and provide an analysis of current tools and modern methodologies used in the field to evaluate and enhance its security. For each section, we pinpoint metrics of interest, as they have been revealed by researchers and experts in the domain and summarize their findings to paint…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Software System Performance and Reliability · Security and Verification in Computing
