{"id":"https://openalex.org/W4400977243","doi":"https://doi.org/10.1145/3664476.3670884","title":"No Country for Leaking Containers: Detecting Exfiltration of Secrets Through AI and Syscalls","display_name":"No Country for Leaking Containers: Detecting Exfiltration of Secrets Through AI and Syscalls","publication_year":2024,"publication_date":"2024-07-25","ids":{"openalex":"https://openalex.org/W4400977243","doi":"https://doi.org/10.1145/3664476.3670884"},"language":"en","primary_location":{"id":"doi:10.1145/3664476.3670884","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3670884","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3664476.3670884","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5036413712","display_name":"Marco Zuppelli","orcid":"https://orcid.org/0000-0001-6932-3199"},"institutions":[{"id":"https://openalex.org/I4210101866","display_name":"Informa (Italy)","ror":"https://ror.org/017c2y429","country_code":"IT","type":"company","lineage":["https://openalex.org/I4210101866","https://openalex.org/I4210154378"]},{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Marco Zuppelli","raw_affiliation_strings":["National Research Council of Italy - Institute for Applied Mathematics and Information Technologies, Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council of Italy - Institute for Applied Mathematics and Information Technologies, Italy","institution_ids":["https://openalex.org/I4210155236","https://openalex.org/I4210101866"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025844977","display_name":"Massimo Guarascio","orcid":"https://orcid.org/0000-0001-7711-9833"},"institutions":[{"id":"https://openalex.org/I3005160176","display_name":"Institute for High Performance Computing and Networking","ror":"https://ror.org/04r5fge26","country_code":"IT","type":"facility","lineage":["https://openalex.org/I3005160176","https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Massimo Guarascio","raw_affiliation_strings":["National Research Council of Italy - Institute for High Performance Computing and Networking, Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council of Italy - Institute for High Performance Computing and Networking, Italy","institution_ids":["https://openalex.org/I3005160176","https://openalex.org/I4210155236"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082854095","display_name":"Luca Caviglione","orcid":"https://orcid.org/0000-0001-6466-3354"},"institutions":[{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I4210101866","display_name":"Informa (Italy)","ror":"https://ror.org/017c2y429","country_code":"IT","type":"company","lineage":["https://openalex.org/I4210101866","https://openalex.org/I4210154378"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Luca Caviglione","raw_affiliation_strings":["National Research Council of Italy - Institute for Applied Mathematics and Information Technologies, Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council of Italy - Institute for Applied Mathematics and Information Technologies, Italy","institution_ids":["https://openalex.org/I4210155236","https://openalex.org/I4210101866"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5013104931","display_name":"Angelica Liguori","orcid":"https://orcid.org/0000-0001-9402-7375"},"institutions":[{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I3005160176","display_name":"Institute for High Performance Computing and Networking","ror":"https://ror.org/04r5fge26","country_code":"IT","type":"facility","lineage":["https://openalex.org/I3005160176","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Angelica Liguori","raw_affiliation_strings":["Department of Computer Engineering, Modeling, Electronics, and Systems, National Research Council of Italy - Institute for High Performance Computing and Networking, Italy"],"affiliations":[{"raw_affiliation_string":"Department of Computer Engineering, Modeling, Electronics, and Systems, National Research Council of Italy - Institute for High Performance Computing and Networking, Italy","institution_ids":["https://openalex.org/I3005160176","https://openalex.org/I4210155236"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5036413712"],"corresponding_institution_ids":["https://openalex.org/I4210101866","https://openalex.org/I4210155236"],"apc_list":null,"apc_paid":null,"fwci":1.1251,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.76876539,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5052970051765442},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.4627537727355957}],"concepts":[{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5052970051765442},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4627537727355957}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3664476.3670884","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3670884","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3664476.3670884","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3670884","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W1981844530","https://openalex.org/W1992291252","https://openalex.org/W2249727747","https://openalex.org/W2553461292","https://openalex.org/W2556088991","https://openalex.org/W2899822557","https://openalex.org/W2907416151","https://openalex.org/W2936268283","https://openalex.org/W3017460886","https://openalex.org/W3095995204","https://openalex.org/W4200607257","https://openalex.org/W4226054955","https://openalex.org/W4293195496","https://openalex.org/W4296916870","https://openalex.org/W4386249565"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W2382290278","https://openalex.org/W4395014643"],"abstract_inverted_index":{"Containers":[0],"offer":[1],"lightweight":[2],"execution":[3],"environments":[4],"for":[5,66,106],"implementing":[6],"microservices":[7],"or":[8,54],"cloud-native":[9],"applications.":[10],"Owing":[11],"to":[12,74,88,141],"their":[13],"ubiquitous":[14],"diffusion":[15],"jointly":[16],"with":[17,115],"the":[18,68,109,119,130,143],"complex":[19],"interplay":[20],"of":[21,38,70,118,132,145],"hardware,":[22],"computing,":[23],"and":[24,49],"network":[25],"resources,":[26],"effectively":[27],"enforcing":[28],"container":[29,44],"security":[30],"is":[31,113],"a":[32,63,84,90],"difficult":[33],"task.":[34],"Specifically,":[35],"runtime":[36],"detection":[37],"threats":[39],"poses":[40],"many":[41,50],"challenges":[42],"since":[43],"images":[45],"are":[46,104,122,139],"often":[47],"immutable,":[48],"malware":[51],"deploys":[52],"obfuscation":[53],"elusive":[55],"mechanisms.":[56],"Therefore,":[57],"in":[58],"this":[59],"work,":[60],"we":[61,82],"propose":[62],"deep-learning-based":[64],"approach":[65],"identifying":[67],"presence":[69],"two":[71],"containers":[72,103],"colluding":[73,105],"covertly":[75],"leak":[76],"secret":[77],"information.":[78],"In":[79],"more":[80],"detail,":[81],"consider":[83],"threat":[85],"actor":[86],"trying":[87],"exfiltrate":[89],"4,096-bit":[91],"private":[92],"TLS":[93],"key":[94],"via":[95],"five":[96],"different":[97],"covert":[98],"channels.":[99],"To":[100],"decide":[101],"whether":[102],"leaking":[107],"data,":[108],"deep":[110],"learning":[111],"model":[112],"fed":[114],"statistical":[116],"indicators":[117],"syscalls,":[120],"which":[121],"built":[123],"starting":[124],"from":[125],"simple":[126],"counters.":[127],"Results":[128],"indicate":[129],"effectiveness":[131],"our":[133],"approach,":[134],"even":[135],"if":[136],"some":[137],"adjustments":[138],"needed":[140],"reduce":[142],"number":[144],"false":[146],"positives.":[147]},"counts_by_year":[{"year":2025,"cited_by_count":3}],"updated_date":"2025-12-26T23:08:49.675405","created_date":"2025-10-10T00:00:00"}
