Securing 3rd Party App Integration in Docker-based Cloud Software Ecosystems
Christian Binkowski, Stefan Appel, Andreas A{\ss}muth

TL;DR
This paper proposes a comprehensive security framework for integrating third-party applications into Docker-based cloud ecosystems, emphasizing sandbox testing and lifecycle security to mitigate vulnerabilities.
Contribution
It introduces a novel security approach that leverages Docker's features for safe third-party app integration in cloud environments, including sandbox testing and lifecycle management.
Findings
Enhanced security through sandbox testing of third-party apps
Lifecycle security measures for Docker-based ecosystems
Improved protection against Docker vulnerabilities
Abstract
Open software ecosystems are beneficial for customers; they benefit from 3rd party services and applications, e.g. analysis of data using apps, developed and deployed by other companies or open-source communities. One significant advantage of this approach is that other customers may benefit from these newly developed applications as well. Especially software ecosystems utilizing container technologies are prone to certain risks. Docker, in particular, is more vulnerable to attacks than hypervisor based virtualisation as it directly operates on the host system. Docker is a popular representative of containerisation technology which offers a lightweight architecture in order to facilitate the set-up and creation of such software ecosystems. Popular Infrastructure as a Service cloud service providers, like Amazon Web Services or Microsoft Azure, jump on the containerisation bandwagon and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Computing and Resource Management · IoT and Edge/Fog Computing · Software System Performance and Reliability
