Skip to main navigation Skip to search Skip to main content

Understanding file system operations of a secure container runtime using system call tracing technique

  • Amazon Korea

Research output: Contribution to journalArticlepeer-review

Abstract

This letter presents a technique that observes system call mapping behavior of the proxy kernel layer of secure container runtimes. We applied it to file system operations of a secure container runtime, gVisor. We found that gVisor's operations can become more expensive than the native by 48× more syscalls for open, and 6× for read and write.

Original languageEnglish
Pages (from-to)229-233
Number of pages5
JournalIEICE Transactions on Information and Systems
VolumeE107D
Issue number2
DOIs
StatePublished - Feb 2024

Keywords

  • Secure container runtime
  • System call
  • gvisor

Fingerprint

Dive into the research topics of 'Understanding file system operations of a secure container runtime using system call tracing technique'. Together they form a unique fingerprint.

Cite this