Pith. sign in

REVIEW 1 cited by

BPFContain: Fixing the Soft Underbelly of Container Security

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2102.06972 v1 pith:Z5SXAE2V submitted 2021-02-13 cs.CR cs.OS

classification cs.CRcs.OS
keywords bpfcontaincontainerconfinementcontainerscurrentensureimplementationlanguage
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Linux containers currently provide limited isolation guarantees. While containers separate namespaces and partition resources, the patchwork of mechanisms used to ensure separation cannot guarantee consistent security semantics. Even worse, attempts to ensure complete coverage results in a mishmash of policies that are difficult to understand or audit. Here we present BPFContain, a new container confinement mechanism designed to integrate with existing container management systems. BPFContain combines a simple yet flexible policy language with an eBPF-based implementation that allows for deployment on virtually any Linux system running a recent kernel. In this paper, we present BPFContain's policy language, describe its current implementation as integrated into docker, and present benchmarks comparing it with current container confinement technologies.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Docker under Siege: Securing Containers in the Modern Era

    cs.CR 2025-05 reject

    A narrative review of Docker security best practices that adds no original data, experiments, or new techniques.

Pith tools