Page 483 - 《软件学报》2026年第3期
P. 483
1446 软件学报 2026 年第 37 卷第 3 期
[34] UTC. Auto-reloading for /etc/nsswitch.conf. 2025. https://sourceware.org/bugzilla/show_bug.cgi?id=12459
[35] CVE. CVE-2022-1227. 2022. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1227
[36] Mouw E. Linux kernel procfs guide. 2001. https://www23.big.or.jp/~sian/linux/DocBook/procfs-guide/index.html
[37] Avrahami Y. Breaking out of Docker via runC—Explaining CVE-2019-5736. 2019. https://unit42.paloaltonetworks.com/breaking-docker-
via-runc-explaining-cve-2019-5736/
[38] CVE. CVE-2024-21626. 2024. https://www.cve.org/CVERecord?id=CVE-2024-21626
[39] podman-top—Display the running processes of a container. 2019. https://docs.podman.io/en/latest/markdown/podman-top.1.html
[40] Linux. cgroup-v1: Require capabilities to set release_agent—kernel/git/torvalds/linux. git—Linux kernel source tree. 2022. https://git.
kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
[41] Huang H, Wang HL, Rao J, Wu S, Fan H, Yu C, Jin H, Suo K, Pan LS. vKernel: Enhancing container isolation via private code and data.
IEEE Trans. on Computers, 2024, 73(7): 1711–1723. [doi: 10.1109/TC.2024.3383988]
[42] SPEC. http://www.spec.org/index.html
[43] Henning JL. SPEC CPU2006 benchmark descriptions. ACM SIGARCH Computer Architecture News, 2006, 34(4): 1–17. [doi: 10.1145/
1186736.1186737]
[44] Sun Microsystems. FileBench. 2004. http://www.nfsv4bat.org/Documents/nasconf/2004/filebench.pdf
[45] Tsai CC, Zhan Y, Reddy J, Jiao YZ, Zhang T, Porter DE. How to get more value from your file system directory cache. In: Proc. of the
25th Symp. on Operating Systems Principles. Monterey: ACM, 2015. 441–456. [doi: 10.1145/2815400.2815405]
[46] Gao X, Gu ZS, Kayaalp M, Pendarakis D, Wang HN. ContainerLeaks: Emerging security threats of information leakages in container
clouds, In: Proc. of the 47th Annual IEEE/IFIP Int’l Conf. on Dependable Systems and Networks. Denver: IEEE, 2017. 237–248. [doi: 10.
1109/DSN.2017.49]
[47] Gao X, Gu ZS, Li ZF, Jamjoom H, Wang C. Houdini’s escape: Breaking the resource rein of Linux control groups. In: Proc. of the 2019
ACM SIGSAC Conf. on Computer and Communications Security. London: ACM, 2019. 1073–1086. [doi: 10.1145/3319535.3354227]
[48] Yang NZ, Shen WB, Li JK, Yang YT, Lu KJ, Xiao JT, Zhou TY, Qin CG, Yu W, Ma JF, Ren K. Demons in the shared kernel: Abstract
resource attacks against OS-level virtualization. In: Proc. of the 2021 ACM SIGSAC Conf. on Computer and Communications Security.
ACM, 2021. 764–778. [doi: 10.1145/3460120.3484744]
[49] Jian ZQ, Chen L. A defense method against docker escape attack. In: Proc. of the 2017 Int’l Conf. on Cryptography, Security and Privacy.
Wuhan: ACM, 2017. 142–146. [doi: 10.1145/3058060.3058085]
[50] Wang K, Wu S, Li SB, Huang Z, Fan H, Yu C, Jin H. Precise control of page cache for containers. Frontiers of Computer Science, 2024,
18(2): 182102. [doi: 10.1007/s11704-022-2455-0]
[51] Abbas M, Khan S, Monum A, Zaffar F, Tahir R, Eyers D, Irshad H, Gehani A, Yegneswaran V, Pasquier T. PACED: Provenance-based
automated container escape detection. In: Proc. of the 2022 IEEE Int’l Conf. on Cloud Engineering. Pacific Grove: IEEE, 2022. 261–272.
[doi: 10.1109/IC2E55432.2022.00035]
[52] GitHub, Inc. Kata containers. 2025. https://github.com/kata-containers
[53] GitHub, Inc. Gvisor. 2025. https://github.com/google/gvisor
[54] CVE. CVE-2022-2023. 2022. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2023
[55] Yang YT, Shen WB, Ruan BN, Liu WM, Ren K. Security challenges in the container cloud. In: Proc. of the 3rd IEEE Int’l Conf. on
Trust, Privacy and Security in Intelligent Systems and Applications. Atlanta: IEEE, 2021. 137–145. [doi: 10.1109/TPSISA52974.2021.
00016]
[56] Sandhu RS, Coyne EJ, Feinstein HL, Youman CE. Role-based access control models. Computer, 1996, 29(2): 38–47. [doi: 10.1109/2.
485845]
附中文参考文献
[13] 钟柏松, 张宇成, 周明建. Linux 虚拟文件系统分析. 计算机与现代化, 2010(9): 76–78. [doi: 10.3969/j.issn.1006-2475.2010.09.021]
作者简介
李志, 博士, 副教授, CCF 专业会员, 主要研究领域为云原生安全, 操作系统与虚拟化安全, 云原生黑产分析, AI Agent 安全.
夏书婷, 硕士生, 主要研究领域为容器安全.
李圣杰, 硕士生, 主要研究领域为云原生安全.
刘维杰, 博士, 副教授, CCF 专业会员, 主要研究领域为系统安全, 虚拟化, 程序分析及其在大模型安全领域的应用.
王振辰, 硕士生, 主要研究领域为系统安全.
金海, 博士, 教授, 博士生导师, CCF 会士, 主要研究领域为计算机系统结构, 虚拟化技术, 集群计算, 网格计算, 并行与分布式计算, 对等计
算, 普适计算, 语义网, 存储与安全.

