Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Real-Time Monitoring of Interactive Processes in Containerized Environments
Karlstad University, Faculty of Health, Science and Technology (starting 2013), Department of Mathematics and Computer Science (from 2013).
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesisAlternative title
Realtidsövervakning av interaktiva processer i containeriserade miljöer (Swedish)
Abstract [en]

As container technology has become a central part of modern IT infrastructure, the need for efficient log management and security monitoring has increased. Containers provide flexibility and performance advantages over traditional virtual machines but introduce new security challenges, particularly regarding visibility and monitoring processes within containerized environments.

This thesis presents a real-time monitoring solution that tracks and logs interactive processes within Docker containers. A monitoring framework was developed to detect and attach to active container processes using strace, a tool for system call tracing. The collected data is filtered to extract relevant command executions and exported to Elasticsearch for indexing and storage. The monitored data is then structured and visualized in Kibana, making it easier to analyze container activity. The system applies process filtering to reduce redundant logging and limit unnecessary data collection to improve efficiency. The implementation includes automated container event detection, multithreading, and selective data capture to maintain performance. Monitoring operates stealthily within the containerized environment, preventing logged containers from detecting its presence. Maintaining this level of stealth is important when monitoring must occur without influencing container behavior. If a container identifies an active tracking system, it may alter execution patterns, suppress specific processes, or attempt to avoid detection altogether. By remaining undetectable, the system records activity in its most natural state, allowing for accurate interaction analysis and identifying anomalies without interference. Resource usage is carefully managed to avoid excessive overhead while allowing detailed tracking of interactive processes.

By tackling key challenges in container observability, this work enhances security monitoring by demonstrating how system call tracing can provide deeper visibility without disrupting normal operations. The proposed approach offers a structured method for monitoring containerized processes while preserving efficiency and stealth.

Place, publisher, year, edition, pages
2025.
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kau:diva-104112OAI: oai:DiVA.org:kau-104112DiVA, id: diva2:1955213
Subject / course
Computer Science
Educational program
Engineering: Computer Engineering (300 ECTS credits)
Presentation
2025-04-14, 15:00 (English)
Supervisors
Examiners
Available from: 2025-04-30 Created: 2025-04-29 Last updated: 2025-04-30Bibliographically approved

Open Access in DiVA

fulltext(2254 kB)13 downloads
File information
File name FULLTEXT01.pdfFile size 2254 kBChecksum SHA-512
8c13bebd670a73306cdfe8e5b1c543934ae20969816523ec95a789e730a4dc4b1c1893a202fa1e65674d343dbf1fcaa4d2aa7d04a09e7357409f2ffd47a7f2cc
Type fulltextMimetype application/pdf

By organisation
Department of Mathematics and Computer Science (from 2013)
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 13 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 18 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf