A Security Perspective on Unikernels

Talbot, Joshua; Pikula, Przemek; Sweetmore, Craig; Rowe, Samuel; Hanan Hindy; Tachtatzis, Christos; Atkinson, Robert; Bellekens, Xavier;

Abstract


Cloud-based infrastructures have grown in popularity over the last decade leveraging virtualisation, server, storage, compute power and network components to develop flexible applications. The requirements for instantaneous deployment and reduced costs have led the shift from virtual machine deployment to containerisation, increasing the overall flexibility of applications and increasing performances. However, containers require a fully fleshed operating system to execute, increasing the attack surface of an application. Unikernels, on the other hand, provide a lightweight memory footprint, ease of application packaging and reduced start-up times. Moreover, Unikernels reduce the attack surface due to the self-contained environment only enabling low-level features. In this work, we provide an exhaustive description of the unikernel ecosystem; we demonstrate unikernel vulnerabilities and further discuss the security implications of Unikernel-enabled environments through different use-cases.


Other data

Title A Security Perspective on Unikernels
Authors Talbot, Joshua; Pikula, Przemek; Sweetmore, Craig; Rowe, Samuel; Hanan Hindy ; Tachtatzis, Christos; Atkinson, Robert; Bellekens, Xavier
Keywords Container;Docker;Security;Unikernel
Issue Date 1-Jun-2020
Conference International Conference on Cyber Security and Protection of Digital Services Cyber Security 2020
ISBN [9781728164281]
DOI 10.1109/CyberSecurity49315.2020.9138883
Scopus ID 2-s2.0-85091985846

Recommend this item

Similar Items from Core Recommender Database

Google ScholarTM

Check



Items in Ain Shams Scholar are protected by copyright, with all rights reserved, unless otherwise indicated.