Netinfo Security ›› 2025, Vol. 25 ›› Issue (8): 1196-1207.doi: 10.3969/j.issn.1671-1122.2025.08.002

Previous Articles     Next Articles

Research on Container Security Framework Based on Namespace and Filesystem Proxy

LU Xinxi1, GUO Jianwei2, YUAN Lijuan3, LIU Yan4, XU Binbin4, LIU Yang5()   

  1. 1. School of Software, Beihang University, Beijing 100191, China
    2. Beijing Academy of Science and Technology, Beijing 100089, China
    3. Baoding University, Baoding 071000, China
    4. Pipechina Digital Co., Ltd., Beijing 102200, China
    5. School of Automation Science and Electrical Engineering, Beihang University, Beijing 100191, China
  • Received:2025-06-03 Online:2025-08-10 Published:2025-09-09

Abstract:

To address the security deficiencies in user identity isolation and filesystem permission control on current container platforms, this paper proposed SecPod, a container security hardening framework based on user namespaces and user-space filesystem proxy mechanisms. Targeting the container runtime layer, SecPod dynamically assigned per-container UID/GID mappings to enforce inter-container identity isolation. Meanwhile, it introduced a container filesystem proxy module that virtualized the container's filesystem view and provided fine-grained access control for file operations. Experimental results show that SecPod effectively blocks various typical container escape and privilege escalation attacks while maintaining compatibility with standard container applications, significantly improving the isolation strength.

Key words: container security, user namespace, privilege isolation

CLC Number: