Defending Containerized Applications against 0day Vulnerabilities

Network operators and telecom vendors intend to ensure the security of mobile networks. However, the time between discovering a new security vulnerability in the network and developing and deploying its effective fixes can be delayed weeks and more often in months. Thus, it leaves a window to the attacker to cause more damage. Most of the time, deploying patches is coupled with software updates and when performed in production environment can present new risks resulting in costly downtime, thus generally delayed for business reasons. The main objective of this project is to develop a scalable and efficient solution that provides a mechanism to temporarily patch for a set of containerized applications against newly discovered vulnerabilities for which no security patches exist yet. This temporary patching approach can prevent the recurrence of exploit and allows time for official patches to be released and tested before final deployment.

Faculty Supervisor:

Suryadipta Majumdar;Lingyu Wang

Student:

Partner:

Ericsson Canada Inc (Montreal, QC)

Discipline:

Engineering

Sector:

Information and cultural industries; Professional, scientific and technical services

University:

Concordia University

Program:

Accelerate

Current openings

Find the perfect opportunity to put your academic skills and knowledge into practice!

Find Projects