IEICE Transactions on Information and Systems
Online ISSN : 1745-1361
Print ISSN : 0916-8532
Regular Section
Understanding File System Operations of a Secure Container Runtime Using System Call Tracing Technique
Sunwoo JANGYoung-Kyoon SUHByungchul TAK
著者情報
ジャーナル フリー

2024 年 E107.D 巻 2 号 p. 229-233

詳細
抄録

This letter presents a technique that observes system call mapping behavior of the proxy kernel layer of secure container runtimes. We applied it to file system operations of a secure container runtime, gVisor. We found that gVisor's operations can become more expensive than the native by 48× more syscalls for open, and 6× for read and write.

著者関連情報
© 2024 The Institute of Electronics, Information and Communication Engineers
前の記事 次の記事
feedback
Top