Visible to the public Taking a Peek: An Evaluation of Anomaly Detection Using System calls for Containers

TitleTaking a Peek: An Evaluation of Anomaly Detection Using System calls for Containers
Publication TypeConference Paper
Year of Publication2021
AuthorsCastanhel, Gabriel R., Heinrich, Tiago, Ceschin, Fabrício, Maziero, Carlos
Conference Name2021 IEEE Symposium on Computers and Communications (ISCC)
Keywordscomposability, computer security, Containers, Filtering, Intrusion detection, machine learning, Metrics, pubcrawl, resilience, Resiliency, Robustness, security, Threat Assessment, Windows Operating System Security
AbstractThe growth in the use of virtualization in the last ten years has contributed to the improvement of this technology. The practice of implementing and managing this type of isolated environment raises doubts about the security of such systems. Considering the host's proximity to a container, approaches that use anomaly detection systems attempt to monitor and detect unexpected behavior. Our work aims to use system calls to identify threats within a container environment, using machine learning based strategies to distinguish between expected and unexpected behaviors (possible threats).
DOI10.1109/ISCC53001.2021.9631251
Citation Keycastanhel_taking_2021