Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security engineer is implementing a strategy to prevent malicious processes from making unexpected system calls within a container. They want to define a whitelist of allowed system calls for specific applications, blocking any calls outside this predefined set. Which Linux security mechanism is specifically designed for this purpose?
- AAppArmor
- BSeccomp (Secure Computing mode)
- CLinux Namespaces
- Dcgroups
Show answer & explanationAnswer & explanation
Correct answer: B. Seccomp (Secure Computing mode)
Seccomp (Secure Computing mode) allows administrators to define a filter for system calls that a process can make. This enables whitelisting or blacklisting specific syscalls, effectively reducing the attack surface by preventing unauthorized kernel interactions.
Why the other options are wrong
- A. AppArmor is a Mandatory Access Control system that can enforce policies on file access, network, and capabilities, but Seccomp is more granular for syscall filtering.
- C. Namespaces isolate resources but don't control which system calls can be made.
- D. cgroups control resource limits but not system call access.
Seccomp (Secure Computing mode)
A Linux kernel feature that allows a process to restrict the system calls it can make, enabling the creation of whitelists or blacklists of allowed syscalls to reduce the attack surface.
- Filters system calls at the kernel level.
- Can be used to whitelist or blacklist syscalls.
- Reduces the attack surface of containers.
- Implemented via `seccomp` profiles in Kubernetes Pod Security Context.
Memory trick: Seccomp filters syscalls securely.