Please use this identifier to cite or link to this item: http://repository.iiitd.edu.in/xmlui/handle/123456789/1411
Full metadata record
DC FieldValueLanguage
dc.contributor.authorArora, Mehul-
dc.contributor.authorChakravarty, Sambuddho (Advisor)-
dc.date.accessioned2024-05-08T13:14:55Z-
dc.date.available2024-05-08T13:14:55Z-
dc.date.issued2023-11-29-
dc.identifier.urihttp://repository.iiitd.edu.in/xmlui/handle/123456789/1411-
dc.description.abstractContainers have gained popularity for their efficiency, allowing developers to package and deploy applications seamlessly, thus replacing VMs in the modern-day deployment scenario and becoming a strong base for cloud computation. However, this surge has attracted malicious actors, exemplified by frequent cases of misconfigurations and vulnerabilities. This problem has grown with modern adversaries targeting Container Infrastructure by exploiting escapevulnerabilities, that allow them to gain access to the host system. This paper provides an indepth analysis of container security, and looks at the approach of using containerised honeypots to detect and study such attacks as a potential solution. IN my initial study, I have explored the use of tools like Wireshark and Procmon in obtaining in-depth information about container events from the host system, and did a preliminary study of existing Container Security tools such as Trivy. Initial results reveal that while data can be extensively studied from the host for containers, with instances where running simple malware can also lead to ProcMon registering 180k events in a five minute timespan, challenges in correlating data from monitoring tools with malware runtime exist profoundly. Thus, we aim to further look at methods for dynamic data analysis, study artefacts for building honeypots, and look at automation for scalable deployment of such honeypots in the future.en_US
dc.language.isoen_USen_US
dc.publisherIIIT-Delhien_US
dc.subjectcontainersen_US
dc.subjecthoneypotsen_US
dc.subjectLinux containersen_US
dc.subjectDockeren_US
dc.subjectdetection artifactsen_US
dc.subjectmalware detectionen_US
dc.subjectobfuscation techniquesen_US
dc.titleHoneypots in containerised environmentsen_US
dc.typeOtheren_US
Appears in Collections:Year-2023

Files in This Item:
File Description SizeFormat 
BTP Report - Mehul Arora.pdf
  Restricted Access
522.77 kBAdobe PDFView/Open Request a copy


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.