Security of virtualization systems has become a central topic in the field of computer security. Although such systems are widely deployed, a uniform approach to the definition and verification of their security is still missing. In this paper we make the first step towards this unification. We consider two models for defining security threats for virtualisation systems, namely one defined by Reshetova et al. and one defined by the Common Criteria Recognition Arrangement. We argue that the two models are equivalent in the sense that they define the same security perimeter. Such equivalence allows the possibility of deriving the security of a system in one model given its security in the other model. As a use case we consider the security of the Docker virtualisation system.

On the Evaluation of Security Properties of Containerized Systems

CATUOGNO, Luigi;
2016-01-01

Abstract

Security of virtualization systems has become a central topic in the field of computer security. Although such systems are widely deployed, a uniform approach to the definition and verification of their security is still missing. In this paper we make the first step towards this unification. We consider two models for defining security threats for virtualisation systems, namely one defined by Reshetova et al. and one defined by the Common Criteria Recognition Arrangement. We argue that the two models are equivalent in the sense that they define the same security perimeter. Such equivalence allows the possibility of deriving the security of a system in one model given its security in the other model. As a use case we consider the security of the Docker virtualisation system.
2016
9781509055661
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11367/120604
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 15
  • ???jsp.display-item.citation.isi??? 10
social impact