{"id":{"repo_id":"carleton","oai_identifier":"oai:carleton.scholaris.ca:20.500.14718/44779"},"canonical_url":"https://search.dev.ndltd.org/etd/carleton/oai:carleton.scholaris.ca:20.500.14718/44779","repository":{"repo_id":"carleton","name":"Carleton University","base_url":"https://carleton.scholaris.ca/server/oai/request"},"display":{"title":"A Security Benchmarking Framework for Empirical Evaluation of Container Confinement","abstract":"This thesis presents Houdini, a modular framework for empirically testing container confinement. Houdini executes scripted tests, called tricks, inside an isolated virtual machine to observe whether features like namespaces, cgroups, seccomp, and AppArmor are enforced at runtime. By simulating container actions, Houdini reveals when isolation mechanisms silently fail. Through a series of case studies, Houdini reveals misconfigurations, enforcement failures, and security inconsistencies in container behavior across different combinations of Docker, runc, and Linux kernel versions. These case studies demonstrate how seemingly secure containers can violate isolation guarantees due to subtle interactions between runtime settings and system versions. By making container confinement observable and testable, Houdini provides a practical, empirical foundation for building and validating more secure container systems.","abstract_html":"This thesis presents Houdini, a modular framework for empirically testing container confinement. Houdini executes scripted tests, called tricks, inside an isolated virtual machine to observe whether features like namespaces, cgroups, seccomp, and AppArmor are enforced at runtime. By simulating container actions, Houdini reveals when isolation mechanisms silently fail. Through a series of case studies, Houdini reveals misconfigurations, enforcement failures, and security inconsistencies in container behavior across different combinations of Docker, runc, and Linux kernel versions. These case studies demonstrate how seemingly secure containers can violate isolation guarantees due to subtle interactions between runtime settings and system versions. By making container confinement observable and testable, Houdini provides a practical, empirical foundation for building and validating more secure container systems.","abstract_has_math":false,"creators":["Patel, Huzaifa Habib"],"institution":"Carleton University","degree_name":"Master of Computer Science (M.C.S.)","degree_level":"Master&apos;s","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-24T01:34:20Z","subjects":[],"languages":["en"],"rights":["Copyright © 2025 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["10.22215/etd/2025-16752"],"render_values":[{"text":"10.22215/etd/2025-16752","href":"https://doi.org/10.22215/etd/2025-16752","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/20.500.14718/44779","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Patel, Huzaifa Habib"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-01-19T15:08:36Z"]},{"key":"dc:date.issued","label":"Date","values":["2025"]},{"key":"dc:publisher","label":"Institution","values":["Carleton University"]},{"key":"dc:type","label":"Dc Type","values":["thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Master&apos;s"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Computer Science (M.C.S.)"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright © 2025 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["10.22215/etd/2025-16752"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/20.500.14718/44779"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["This thesis presents Houdini, a modular framework for empirically testing container confinement. Houdini executes scripted tests, called tricks, inside an isolated virtual machine to observe whether features like namespaces, cgroups, seccomp, and AppArmor are enforced at runtime. By simulating container actions, Houdini reveals when isolation mechanisms silently fail. Through a series of case studies, Houdini reveals misconfigurations, enforcement failures, and security inconsistencies in container behavior across different combinations of Docker, runc, and Linux kernel versions. These case studies demonstrate how seemingly secure containers can violate isolation guarantees due to subtle interactions between runtime settings and system versions. By making container confinement observable and testable, Houdini provides a practical, empirical foundation for building and validating more secure container systems."]},{"key":"dc:title","label":"Title","values":["A Security Benchmarking Framework for Empirical Evaluation of Container Confinement"]}]}],"canonical_facts":{"dc:creator":["Patel, Huzaifa Habib"],"dc:date.accessioned":["2026-01-19T15:08:36Z"],"dc:date.issued":["2025"],"dc:description.abstract":["This thesis presents Houdini, a modular framework for empirically testing container confinement. Houdini executes scripted tests, called tricks, inside an isolated virtual machine to observe whether features like namespaces, cgroups, seccomp, and AppArmor are enforced at runtime. By simulating container actions, Houdini reveals when isolation mechanisms silently fail. Through a series of case studies, Houdini reveals misconfigurations, enforcement failures, and security inconsistencies in container behavior across different combinations of Docker, runc, and Linux kernel versions. These case studies demonstrate how seemingly secure containers can violate isolation guarantees due to subtle interactions between runtime settings and system versions. By making container confinement observable and testable, Houdini provides a practical, empirical foundation for building and validating more secure container systems."],"dc:identifier.doi":["10.22215/etd/2025-16752"],"dc:identifier.uri":["https://hdl.handle.net/20.500.14718/44779"],"dc:language.iso":["en"],"dc:publisher":["Carleton University"],"dc:rights":["Copyright © 2025 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."],"dc:title":["A Security Benchmarking Framework for Empirical Evaluation of Container Confinement"],"dc:type":["thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Master&apos;s"],"thesis:degree_name":["Master of Computer Science (M.C.S.)"]},"updated_at":"2026-07-24T01:34:20Z"}