Abstract
This letter presents a technique that observes system call mapping behavior of the proxy kernel layer of secure container runtimes. We applied it to file system operations of a secure container runtime, gVisor. We found that gVisor's operations can become more expensive than the native by 48× more syscalls for open, and 6× for read and write.
| Original language | English |
|---|---|
| Pages (from-to) | 229-233 |
| Number of pages | 5 |
| Journal | IEICE Transactions on Information and Systems |
| Volume | E107D |
| Issue number | 2 |
| DOIs | |
| State | Published - Feb 2024 |
Keywords
- Secure container runtime
- System call
- gvisor
Fingerprint
Dive into the research topics of 'Understanding file system operations of a secure container runtime using system call tracing technique'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver