Secure Inter-Container Communications Using XDP/eBPF

被引:7
|
作者
Nam, Jaehyun [1 ]
Lee, Seungsoo [2 ]
Porras, Phillip [3 ]
Yegneswaran, Vinod [3 ]
Shin, Seungwon [4 ]
机构
[1] Dankook Univ, Dept Comp Engn, Yongin 16890, South Korea
[2] Incheon Natl Univ, Dept Comp Sci & Engn, Incheon 22012, South Korea
[3] SRI Int, Menlo Pk, CA 94025 USA
[4] Korea Adv Inst Sci & Technol, Sch Elect Engn, Daejeon 34141, South Korea
基金
新加坡国家研究基金会;
关键词
Container security; network sandboxing; policy enforcement; security function chaining; XDP/eBPF;
D O I
10.1109/TNET.2022.3206781
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
While the use of containerization technologies for virtual application deployment has grown at an astonishing rate, the question of the robustness of container networking has not been well scrutinized from a security perspective, even though inter-container networking is indispensable for microservices. Thus, this paper first analyzes container networks from a security perspective, discussing the implications based on their architectural limitations. Then, it presents Bastion(+), a secure inter-container communication bridge. Bastion(+) introduces (i) a network security enforcement stack that provides fine-grained control per container application and securely isolates intercontainer traffic in a point-to-point manner. Bastion(+) also supports (ii) selective security function chaining, enabling various security functions to be chained between containers for further security inspections (e.g., deep packet inspection) according to the container's network context. Bastion(+) incorporates (iii) a security policy assistant that helps an administrator discover inter-container networking dependencies correctly. Our evaluation demonstrates how Bastion(+) can effectively mitigate several adversarial attacks in container networks while improving the overall performance up to 25.4% within single-host containers and 17.7% for cross-host container communications.
引用
收藏
页码:934 / 947
页数:14
相关论文
共 50 条
  • [1] On the Use of Kernel Bypass Mechanisms for High-Performance Inter-container Communications
    Ara, Gabriele
    Abeni, Luca
    Cucinotta, Tommaso
    Vitucci, Carlo
    HIGH PERFORMANCE COMPUTING: ISC HIGH PERFORMANCE 2019 INTERNATIONAL WORKSHOPS, 2020, 11887 : 1 - 12
  • [2] Comparative Evaluation of Kernel Bypass Mechanisms for High-performance Inter-container Communications
    Ara, Gabriele
    Cucinotta, Tommaso
    Abeni, Luca
    Vitucci, Carlo
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE (CLOSER), 2020, : 44 - 55
  • [3] Inter-container Communication Aware Container Placement in Fog Computing
    Bourhim, El Houssine
    Elbiaze, Halima
    Dieye, Mouhamad
    2019 15TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2019,
  • [4] Shimmy: Accelerating inter-container communication for the IoT Edge
    Khasgiwale, Manan
    Sharma, Vasu
    Mishra, Shivakant
    Thadichi, Biljith
    John, Jaiber
    Khanna, Rahul
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 4461 - 4466
  • [5] Revealing intra- and inter-container fruit quality heterogeneity within overseas refrigerated container shipments using a physics-based digital twin
    Verreydt, Celine
    Berry, Tarl
    Lukasse, Leo
    Turan, Deniz
    Cronje, Paul
    Defraeye, Thijs
    JOURNAL OF AGRICULTURE AND FOOD RESEARCH, 2025, 19
  • [6] Secure broadcast for inter vehicle communications
    Durresi, Arjan
    Durresi, Mimoza
    Bulusu, Vijay
    Barolli, Leonard
    International Journal of High Performance Computing and Networking, 2007, 5 (1-2) : 54 - 61
  • [7] eQUIC Gateway: Maximizing QUIC Throughput using a Gateway Service based on eBPF plus XDP
    Pantuza, Gustavo
    Vieira, Marcos A. M.
    Vieira, Luiz F. M.
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [8] Partition-Aware Packet Steering Using XDP and eBPF for Improving Application-Level Parallelism
    Enberg, Pekka
    Rao, Ashwin
    Tarkoma, Sasu
    PROCEEDINGS OF THE 1ST ACM CONEXT WORKSHOP ON EMERGING IN-NETWORK COMPUTING PARADIGMS (ENCP '19), 2019, : 27 - 33
  • [9] Low-Latency Physical-Layer Function Chaining Using Inter-Container Shared Memory for Fully Virtualized Access Networks
    Suzuki, Takahiro
    Kim, Sang-Yuep
    Kani, Jun-ichi
    Yoshida, Tomoaki
    2024 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION, OFC, 2024,
  • [10] Secure Inter-Frame Space Communications for Wireless LANs
    Lee, Il-Gu
    FUTURE INTERNET, 2018, 10 (06)