Description
Thesis topic in co-operation with the Fraunhofer Institute for Applied and Integrated Security AISEC, Garching
Behavioral Analysis of Container Images
Motivation The use of third-party containers requires the user to trust that the container does not act maliciously. This is often verified by comparing the container’s hash value against a whitelist of known good values. However, this approach does not allow the user to draw any conclusions about the container’s actual behavior. In this thesis, we want to investigate approaches that allow us to describe the expected behavior of containers without requiring the user to perform a manual analysis. This will include identification of files and binaries relevant to the container’s behavior and the analysis of their communication with each other and the outside world.
Task description You will get in touch with the following topics: • Container applications and solutions such as Docker • Operating System Basics • Linux
Existing in-depth knowledge in any of the areas is not required. Generation of own ideas is desired and creative work is encouraged.
Contact Fraunhofer Institute for Applied and Integrated Security (AISEC) Dr. Mathias Morbitzer Email: mathias.morbitzer@aisec.fraunhofer.de Phone: +49 89 322-9986-164
|