This event has ended. View the official site or create your own event → Check it out
This event has ended. Create your own
August 22nd - 24th in Toronto, Canada
Register Now for LinuxCon+ContainerCon North America 2016!
View analytic
Monday, August 22 • 11:45am - 12:35pm
A New Way to Combine Containers and Hypervisors with Xen - Dimitri Stiliadis, Aporeto

Sign up or log in to save this to your schedule and see who's attending!

Linux Containers’ isolation capabilities are under scrutiny because of growing runtime usage. Best practices recommend avoiding multitenant deployments as POSIX has a large attack surface. Although the proper usage of MAC, seccomp and CAP reduces the attack surface, there are limited production deployments of these technologies given their management complexity.

Clear Containers and similar approaches propose to solve this problem by running Containers as KVM VMs. While more secure, these approaches require HW abstraction to enable multitenancy.

We propose a new method based on Xen paravirtualization that combines strengths of namespaces and hypervisor isolation. This approach enhances security by virtualizing POSIX and allowing a minimalistic subset of syscalls to be handled by a hypervisor-type entity. Most syscalls execute within a confined kernel to harden the system.


Dimitri Stiliadis

Founder and CEO, Aporeto
Dimitri Stiliadis is the Founder and CEO of Aporeto and was the Founder and CTO of Nuage Networks (Nokia). He has a multi-disciplinary background in distributed systems, security, and networking. He has held several leading roles in Bell Labs Research and received a PhD in computer engineering from the University of California, Santa Cruz. He is the author for more than 50 peer-reviewed papers and holds more than 20 patents.

Monday August 22, 2016 11:45am - 12:35pm
Harbour A

Attendees (28)