Benjamin Steenkamer

dblp:283/3072 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2021
0000-0001-5209-2929ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 50% Privacy and data protection · 50%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › virtualization security
container security
0.512021
A Study on the Security Implications of Information Leakages in Container Clouds · IEEE Trans. Dependable Secur. Comput. 2021
Privacy and data protection
information leakage
0.512021
A Study on the Security Implications of Information Leakages in Container Clouds · IEEE Trans. Dependable Secur. Comput. 2021
Cloud and datacenter computing › cloud platform
container cloud
0.512021
A Study on the Security Implications of Information Leakages in Container Clouds · IEEE Trans. Dependable Secur. Comput. 2021

Methods — techniques the papers use, named apart from their topics

covert channel · 1.0co-residence detection · 1.0
YearPublicationVenuePosition
2021 A Study on the Security Implications of Information Leakages in Container Clouds
abstract
Container technology provides a lightweight operating system level virtual hosting environment. Its emergence profoundly changes the development and deployment paradigms of multi-tier distributed applications. However, due to the incomplete implementation of system resource isolation mechanisms in the Linux kernel, some security concerns still exist for multiple containers sharing an operating system kernel on a multi-tenancy container-based cloud service. In this paper, we first present the information leakage channels we discovered that are accessible within containers. Such channels expose a spectrum of system-wide host information to containers without proper resource partitioning. By exploiting such leaked host information, it becomes much easier for malicious adversaries (acting as tenants in a container cloud) to launch attacks that might impact the reliability of cloud services. We demonstrate that the information leakage channels could be exploited to infer private data, detect and verify co-residence, build covert channels, and launch more advanced cloud-based attacks. We discuss the root causes of the containers' information leakage and propose a two-stage defense approach. As demonstrated in the evaluation, our defense is effective and incurs trivial performance overhead.
Xing Gao 0001, Benjamin Steenkamer, Zhongshu Gu, Mehmet Kayaalp 0001, Dimitrios E. Pendarakis, Haining Wang 0001
IEEE Trans. Dependable Secur. Comput.2