Pith. sign in

REVIEW 1 cited by

Analysis of Docker Security

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1501.02967 v1 pith:HSL6UTUZ submitted 2015-01-13 cs.CR

classification cs.CR
keywords securityvirtualizationdockercontainer-basedanalysisefficientleveltechnologies
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Over the last few years, the use of virtualization technologies has increased dramatically. This makes the demand for efficient and secure virtualization solutions become more obvious. Container-based virtualization and hypervisor-based virtualization are two main types of virtualization technologies that have emerged to the market. Of these two classes, container-based virtualization is able to provide a more lightweight and efficient virtual environment, but not without security concerns. In this paper, we analyze the security level of Docker, a well-known representative of container-based approaches. The analysis considers two areas: (1) the internal security of Docker, and (2) how Docker interacts with the security features of the Linux kernel, such as SELinux and AppArmor, in order to harden the host system. Furthermore, the paper also discusses and identifies what could be done when using Docker to increase its level of security.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. ORCA: Unveiling Obscure Containers In The Wild

    cs.SE 2025-09 conditional novelty 6.0 of 10

    ORCA reconstructs container layer history to detect packages hidden by deleted metadata or source-built software, reporting a median 40% higher file coverage than Docker Scout and Syft.

Pith tools