Linked Presentation: Confine: Automated System Call Policy Generation for Container Attack Surface Reduction