logo

Aqua 3.2: Preventing Container Breakouts with Dynamic System Call Profiling

ID: 755f26ae-257e-502a-ba31-c0cac21e5296

STIX ID: report--755f26ae-257e-502a-ba31-c0cac21e5296

Feed Name: Aqua Security Blog

Date Published: 2018-08-02

Date Updated: 2026-04-26

...
...

Aqua's article explains Linux syscalls and the seccomp whitelist model, then presents Aqua 3.2's automated dynamic syscall-profiling feature that creates custom seccomp profiles for containers. The vendor claims the profiler typically reduces usable syscalls to roughly 40–70 (from ~313), cutting the attack surface by an estimated 80–90% and helping prevent kernel-exploit-based container breakouts (e.g., DirtyC0W).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.