{"id":"https://openalex.org/W4223981499","doi":"https://doi.org/10.1145/3508398.3511515","title":"ProSPEC: Proactive Security Policy Enforcement for Containers","display_name":"ProSPEC: Proactive Security Policy Enforcement for Containers","publication_year":2022,"publication_date":"2022-04-14","ids":{"openalex":"https://openalex.org/W4223981499","doi":"https://doi.org/10.1145/3508398.3511515"},"language":"en","primary_location":{"id":"doi:10.1145/3508398.3511515","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3508398.3511515","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5088387117","display_name":"Hugo Kermabon-Bobinnec","orcid":"https://orcid.org/0000-0003-0044-2178"},"institutions":[{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Hugo Kermabon-Bobinnec","raw_affiliation_strings":["Concordia University, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Concordia University, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I60158472"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091367363","display_name":"Mahmood GholipourChoubeh","orcid":"https://orcid.org/0009-0007-6488-7025"},"institutions":[{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Mahmood Gholipourchoubeh","raw_affiliation_strings":["Concordia University, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Concordia University, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I60158472"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109345392","display_name":"Sima Bagheri","orcid":"https://orcid.org/0000-0002-9798-4418"},"institutions":[{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Sima Bagheri","raw_affiliation_strings":["Concordia University, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Concordia University, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I60158472"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013360015","display_name":"Suryadipta Majumdar","orcid":"https://orcid.org/0000-0002-6501-4214"},"institutions":[{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Suryadipta Majumdar","raw_affiliation_strings":["Concordia University, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Concordia University, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I60158472"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020688490","display_name":"Yosr Jarraya","orcid":"https://orcid.org/0009-0000-6194-5321"},"institutions":[{"id":"https://openalex.org/I4210094041","display_name":"Ericsson (Canada)","ror":"https://ror.org/00nas2c56","country_code":"CA","type":"company","lineage":["https://openalex.org/I1306339040","https://openalex.org/I4210094041"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Yosr Jarraya","raw_affiliation_strings":["Ericsson Security Research, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Ericsson Security Research, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I4210094041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077892893","display_name":"Makan Pourzandi","orcid":"https://orcid.org/0000-0001-9775-6231"},"institutions":[{"id":"https://openalex.org/I4210094041","display_name":"Ericsson (Canada)","ror":"https://ror.org/00nas2c56","country_code":"CA","type":"company","lineage":["https://openalex.org/I1306339040","https://openalex.org/I4210094041"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Makan Pourzandi","raw_affiliation_strings":["Ericsson Security Research, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Ericsson Security Research, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I4210094041"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100730397","display_name":"Lingyu Wang","orcid":"https://orcid.org/0000-0002-7441-7541"},"institutions":[{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Lingyu Wang","raw_affiliation_strings":["Concordia University, Montreal, PQ, Canada"],"affiliations":[{"raw_affiliation_string":"Concordia University, Montreal, PQ, Canada","institution_ids":["https://openalex.org/I60158472"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5088387117"],"corresponding_institution_ids":["https://openalex.org/I60158472"],"apc_list":null,"apc_paid":null,"fwci":2.0843,"has_fulltext":false,"cited_by_count":17,"citation_normalized_percentile":{"value":0.8862694,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"155","last_page":"166"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.992900013923645,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/container","display_name":"Container (type theory)","score":0.8967311382293701},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8295284509658813},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.7891662120819092},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7051219940185547},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.6813639402389526},{"id":"https://openalex.org/keywords/enforcement","display_name":"Enforcement","score":0.5870178937911987},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5395449995994568},{"id":"https://openalex.org/keywords/security-policy","display_name":"Security policy","score":0.5180587768554688},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.25300681591033936},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.07986846566200256}],"concepts":[{"id":"https://openalex.org/C2781018962","wikidata":"https://www.wikidata.org/wiki/Q5164884","display_name":"Container (type theory)","level":2,"score":0.8967311382293701},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8295284509658813},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.7891662120819092},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7051219940185547},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.6813639402389526},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.5870178937911987},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5395449995994568},{"id":"https://openalex.org/C154908896","wikidata":"https://www.wikidata.org/wiki/Q2167404","display_name":"Security policy","level":2,"score":0.5180587768554688},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.25300681591033936},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.07986846566200256},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3508398.3511515","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3508398.3511515","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.49000000953674316,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":10,"referenced_works":["https://openalex.org/W1985994373","https://openalex.org/W2275580678","https://openalex.org/W2293837963","https://openalex.org/W2520233939","https://openalex.org/W2744492707","https://openalex.org/W2917742639","https://openalex.org/W2972955891","https://openalex.org/W2996042910","https://openalex.org/W3019365222","https://openalex.org/W3186243894"],"related_works":["https://openalex.org/W2624990117","https://openalex.org/W2369674902","https://openalex.org/W2186020809","https://openalex.org/W2026856333","https://openalex.org/W2304523314","https://openalex.org/W2005029151","https://openalex.org/W4298412018","https://openalex.org/W2950799274","https://openalex.org/W2950847833","https://openalex.org/W4224884383"],"abstract_inverted_index":{"By":[0],"providing":[1],"lightweight":[2],"and":[3,28],"portable":[4],"support":[5],"for":[6,161],"cloud":[7],"native":[8],"applications,":[9],"container":[10,18,44,78,102,163],"environments":[11,79,103,164],"have":[12],"gained":[13],"significant":[14],"momentum":[15],"lately.":[16],"A":[17],"orchestrator":[19,45],"such":[20,66],"as":[21,73],"Kubernetes":[22],"can":[23,137],"enable":[24],"the":[25,74,84,117,128,156],"automatic":[26],"deployment":[27],"maintenance":[29],"of":[30,34,51,77,155],"a":[31,43,48,88,105,139],"large":[32,75,162],"number":[33],"containerized":[35],"applications.":[36],"However,":[37],"due":[38],"to":[39,101,115,150,166],"its":[40],"critical":[41],"role,":[42],"also":[46],"attracts":[47],"wide":[49],"range":[50],"security":[52,61,67,99,122],"threats":[53,68],"exploiting":[54],"misconfigurations":[55],"or":[56],"implementation":[57],"flaws.":[58],"Moreover,":[59],"enforcing":[60],"policies":[62],"at":[63],"runtime":[64,129],"against":[65],"becomes":[69],"far":[70],"more":[71],"challenging,":[72],"scale":[76],"implies":[80],"high":[81,85],"complexity,":[82],"while":[83,126],"dynamicity":[86],"demands":[87],"short":[89],"response":[90,141],"time.":[91],"In":[92],"this":[93,97],"paper,":[94],"we":[95],"tackle":[96],"key":[98],"challenge":[100],"through":[104],"proactive":[106],"approach,":[107],"namely,":[108],"ProSPEC.":[109],"Our":[110],"approach":[111],"leverages":[112],"learning-based":[113],"prediction":[114],"conduct":[116],"computationally":[118],"intensive":[119],"steps":[120,130],"(e.g.,":[121,131,143],"verification)":[123],"in":[124,148],"advance,":[125],"keeping":[127],"policy":[132],"enforcement)":[133],"lightweight.":[134],"Consequently,":[135],"ProSPEC":[136],"ensure":[138],"practical":[140],"time":[142],"less":[144],"than":[145],"10":[146],"ms":[147,152],"contrast":[149],"600":[151],"with":[153],"one":[154],"most":[157],"popular":[158],"existing":[159],"approaches)":[160],"(up":[165],"800":[167],"Pods).":[168]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":5}],"updated_date":"2026-04-01T17:29:45.350535","created_date":"2025-10-10T00:00:00"}
