Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Container Instrumentation and Enforcement System for Runtime Security of Kubernetes Platform with eBPF

Full metadata record
DC Field Value Language
dc.contributor.authorGwak, Songi-
dc.contributor.authorDoan, Thien-Phuc-
dc.contributor.authorJung, Souhwan-
dc.date.accessioned2023-09-04T05:40:06Z-
dc.date.available2023-09-04T05:40:06Z-
dc.date.issued2023-06-
dc.identifier.issn1079-8587-
dc.identifier.issn2326-005X-
dc.identifier.urihttps://scholarworks.bwise.kr/ssu/handle/2018.sw.ssu/44221-
dc.description.abstractContainerization is a fundamental component of modern cloudnative infrastructure, and Kubernetes is a prominent platform of container orchestration systems. However, containerization raises significant security concerns due to the nature of sharing a kernel among multiple containers, which can lead to container breakout or privilege escalation. Kubernetes cannot avoid it as well. While various tools, such as container image scanning and configuration checking, can mitigate container workload vulnerabilities, these are not foolproof and cannot guarantee perfect isolation or prevent every active threat in runtime. As such, a policy enforcement solution is required to tackle the problem, and existing solutions based on LSM (Linux Security Module) frameworks may not be adequate for some situations. To address this, we propose an enforcement system based on BPF-LSM, which leverages eBPF (extended Berkeley Packet Filter) technology to provide fine-grained control and dynamic adoption of security policies. In this paper, we compare different LSM implementations to highlight the challenges of current enforcement solutions before detailing the design of our eBPF-based Kubernetes Runtime Instrumentation and Enforcement System (KRSIE). Finally, we evaluate the effectiveness of our system using a real-world scenario, as measuring the performance of a policy enforcement system is a complex task. Our results show that KRSIE can successfully control containers' behaviors using LSM hooks at container runtime, offering improved container security for cloudnative infrastructure.-
dc.format.extent14-
dc.language영어-
dc.language.isoENG-
dc.publisherTECH SCIENCE PRESS-
dc.titleContainer Instrumentation and Enforcement System for Runtime Security of Kubernetes Platform with eBPF-
dc.typeArticle-
dc.identifier.doi10.32604/iasc.2023.039565-
dc.identifier.bibliographicCitationINTELLIGENT AUTOMATION AND SOFT COMPUTING, v.37, no.2, pp 1773 - 1786-
dc.identifier.wosid001032466700031-
dc.identifier.scopusid2-s2.0-85178966273-
dc.citation.endPage1786-
dc.citation.number2-
dc.citation.startPage1773-
dc.citation.titleINTELLIGENT AUTOMATION AND SOFT COMPUTING-
dc.citation.volume37-
dc.identifier.urlhttps://www.techscience.com/iasc/v37n2/53245-
dc.publisher.location미국-
dc.type.docTypeArticle-
dc.description.isOpenAccessY-
dc.subject.keywordAuthorContainer-
dc.subject.keywordAuthorkubernetes-
dc.subject.keywordAuthorruntime security-
dc.subject.keywordAuthoreBPF-
dc.subject.keywordAuthorenforcement-
dc.relation.journalResearchAreaAutomation & Control Systems-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalWebOfScienceCategoryAutomation & Control Systems-
dc.relation.journalWebOfScienceCategoryComputer Science, Artificial Intelligence-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
Files in This Item
Go to Link
Appears in
Collections
ETC > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Jung, Sou hwan photo

Jung, Sou hwan
College of Information Technology (Major in IT Convergence)
Read more

Altmetrics

Total Views & Downloads

BROWSE