loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Mubin Haque 1 ; 2 and Muhammad Ali Babar 3 ; 1 ; 2

Affiliations: 1 School of Computer Science, University of Adelaide, Australia ; 2 Cyber Security Cooperative Research Centre, Australia ; 3 Centre for Research on Engineering Software Technologies (CREST), University of Adelaide, Australia

Keyword(s): Container images, Configuration, Security, Non-Intrusive Assessment, Machine Learning.

Abstract: The ubiquitous adoption of container images to virtualize the software contents bring significant attention in its security configuration due to intricate and evolving security issues. Early security assessment of container images can prevent and mitigate security attacks on containers, and enabling practitioners to realize the secured configuration. Using security tools, which operate in intrusive manner in the early assessment, raise critical concern in its applicability where the container image contents are considered as highly sensitive. Moreover, the sequential steps and manual intervention required for using the security tools negatively impact the development and deployment of container images. In this regard, we aim to empirically investigate the effectiveness of Open Container Initiative (OCI) properties with the Machine Learning (ML) models to assess the security without peeking inside the container images. We extracted OCI properties from 1,137 real-world container images and investigated six traditional ML models with different OCI properties to identify the optimal ML model and its generalizability. Our empirical results show that the ensemble ML models provide the optimal performance to assess the container image security when the model is built with all the OCI properties. Our empirical evidence will guide practitioners in the early security assessment of container images in non-intrusive way as well as reducing the manual intervention required for using security tools to assess the security of container images. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.218.93.77

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Haque, M. and Ali Babar, M. (2023). A Study on Early & Non-Intrusive Security Assessment for Container Images. In Proceedings of the 18th International Conference on Evaluation of Novel Approaches to Software Engineering - ENASE; ISBN 978-989-758-647-7; ISSN 2184-4895, SciTePress, pages 640-647. DOI: 10.5220/0011987900003464

@conference{enase23,
author={Mubin Haque. and Muhammad {Ali Babar}.},
title={A Study on Early & Non-Intrusive Security Assessment for Container Images},
booktitle={Proceedings of the 18th International Conference on Evaluation of Novel Approaches to Software Engineering - ENASE},
year={2023},
pages={640-647},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011987900003464},
isbn={978-989-758-647-7},
issn={2184-4895},
}

TY - CONF

JO - Proceedings of the 18th International Conference on Evaluation of Novel Approaches to Software Engineering - ENASE
TI - A Study on Early & Non-Intrusive Security Assessment for Container Images
SN - 978-989-758-647-7
IS - 2184-4895
AU - Haque, M.
AU - Ali Babar, M.
PY - 2023
SP - 640
EP - 647
DO - 10.5220/0011987900003464
PB - SciTePress