eMicro: Real-Time Multi-Hop Access Control for Microservices with eBPF
Rizky Ramadhana Putra, Osama Bajaber, Saimon Amanuel Tsegai, Teryl Taylor, Frederico Araujo, Yuede Ji, Peng Gao
摘要
Modern cloud applications often comprise thousands of microservices whose interactions form complex request paths. Traditional inter-service access control restricts individual service-to-service requests, but fails to prevent multi-hop attacks, where each hop appears legitimate yet the overall path violates security intent. This gap leaves systems exposed to unauthorized access and data exfiltration. In this paper, we present eMicro, a path-aware defense system for microservices that prevents such attacks while remaining efficient and deployable. eMicro enforces real-time multi-hop access control through three key techniques: (1) history-based access control extended to capture service invocation sequences; (2) security policies encoded as efficient deterministic finite automaton (DFA), supporting constant-time lookups and compact label propagation; (3) eBPF-based in-kernel request tracing for transparent, low-overhead enforcement without code changes. Evaluations on DeathStarBench and production cloud traces from Uber, Alibaba, and ByteDance, covering 12 million request workflows and thousands of services, demonstrate the scalability of eMicro. eMicro performs policy checks in 1 microsecond, stores 50 million policies in only 100 MB, and reduces propagation overhead by 90% with negligible runtime impact. These results show that eMicro delivers scalable and efficient protection against multi-hop attacks, making it practical for deployment in large-scale microservice environments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates 等NDSS 2018 · 被引用 157 次
- Lifting the veil on Meta's microservice architecture: Analyses of topology and request workflowsDarby Huye, Yuri Shkuro, Raja R. SambasivanUSENIX ATC 2023 · 被引用 65 次
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang 等USENIX Security 2021 · 被引用 64 次
- BASTION: A Security Enforcement Network Stack for Container NetworksJaehyun Nam, Seungsoo Lee, Hyunmin Seo, Phil Porras 等USENIX ATC 2020 · 被引用 55 次
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani 等USENIX Security 2021 · 被引用 38 次
相关 Paper
- PathFence: Reducing Cross-Path Dependencies in MicroservicesXuhang Gu, Qingyang WangHPDC 2025
- SafeTree: Expressive Tree Policies for MicroservicesKaruna Grewal, Brighten Godfrey, Justin HsuOOPSLA 2025 · 被引用 1 次
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che 等USENIX Security 2023
- P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPFOsama Bajaber, Bo Ji, Peng GaoS&P 2024 · 被引用 11 次
- Fast and Efficient Scaling for Microservices with SurgeGuardAnyesha Ghosh, Neeraja J. Yadwadkar, Mattan ErezSC 2024 · 被引用 3 次
