Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (1): 2-.

    Next Articles

Review of Secure Containers Based on System Call Isolation#br#
#br#

Zhang Tian1, Zhang Jie2, Liu Weijie3, and Liu Ximeng1   

  1. 1(College of Computer and Data Science, Fuzhou University, Fuzhou 350108)
    2(College of Mathematics and Computer Science, Shanxi Normal University, Taiyuan 030031)
    3(College of Cryptology and Cyber Science, Nankai University, Tianjin 300350)
  • Online:2026-01-10 Published:2026-01-10

基于系统调用隔离的安全容器研究综述

章恬1张杰2刘维杰3刘西蒙1   

  1. 1(福州大学计算机与大数据学院福州350108)
    2(山西师范大学数学与计算机科学学院太原030031)
    3(南开大学密码与网络空间安全学院天津300350)
  • 通讯作者: 刘维杰 博士,副教授.主要研究方向为系统安全、虚拟化与容器. weijieliu@nankai.edu.cn
  • 作者简介:章恬 硕士研究生.主要研究方向为系统安全、容器安全. 1669349605@qq.com 张杰 硕士研究生.主要研究方向为系统安全、容器安全. zhangyijie0805@163.com 刘维杰 博士,副教授.主要研究方向为系统安全、虚拟化与容器. weijieliu@nankai.edu.cn 刘西蒙 博士,研究员.主要研究方向为密码学、人工智能安全. snbnix@gmail.com

Abstract: This article elucidates the research progress in enhancing container security through the isolation of system calls. The article firstly outlines the development background of containerization technology and its major security challenges. Subsequently, an indepth analysis is conducted on the role of system call isolation in enhancing the security of containers, including the techniques of limiting the system calls of containerized applications to reduce the attack surface, and leveraging operating system middleware and hardware protection mechanisms to accomplish the isolation and protection of containers. By comparing the implementation principles, performance, and their effects on isolation, reduction of attack surfaces, and data protection, the article reveals the advantages and limitations of system call isolation technologies in enhancing container security.

Key words: secure container, system call, isolation, Seccomp BPF, operating system middleware, hardware protection mechanism

摘要: 阐述了基于系统调用隔离增强容器安全性的研究进展.首先概述了容器技术的发展背景及其面临的主要安全挑战,随后深入分析了系统调用隔离在提升容器安全性中的作用,包括限制容器应用程序的系统调用以减少攻击面、使用操作系统中间件和硬件保护机制等技术实现对容器的隔离和保护.通过比较这些技术的实现原理、性能以及它们在隔离性、减少攻击面和数据保护方面的效果,揭示了系统调用隔离技术在提升容器安全性方面的优势和局限.

关键词: 安全容器, 系统调用, 隔离, Seccomp BPF, 操作系统中间件, 硬件保护机制

CLC Number: