USENIX ATC2020顶会
BASTION: A Security Enforcement Network Stack for Container Networks
Jaehyun Nam, Seungsoo Lee, Hyunmin Seo, Phil Porras, Vinod Yegneswaran, Seungwon Shin
摘要
In this work, we conduct a security analysis of container networks, identifying a number of concerns that arise from the exposure of unnecessary network operations by containerized applications and discuss their implications. We then present a new high-performance security enforcement network stack, called BASTION, which extends the container hosting platform with an intelligent container-aware communication sandbox.
BASTION introduces (i) a network visibility service that provides fine-grained control over the visible network topology per container application, and (ii) a traffic visibility service, which securely isolates and forwards inter-container traffic in a point-to-point manner, preventing the exposure of this traffic to other peer containers. Our evaluation demonstrates how BASTION can effectively mitigate several adversarial attacks in container networks while improving the overall performance up to 25.4% within single-host containers, and 17.7% for cross-host container communications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- KIT: Testing OS-Level Virtualization for Functional Interference BugsCongyu Liu, Sishuai Gong, Pedro FonsecaASPLOS 2023 · 被引用 16 次
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu 等CCS 2023 · 被引用 15 次
- Zeta: A Scalable and Robust East-West Communication Framework in Large-Scale CloudsQianyu Zhang, Gongming Zhao, Hongli Xu, Zhuolong Yu 等NSDI 2022 · 被引用 10 次
- eMicro: Real-Time Multi-Hop Access Control for Microservices with eBPFRizky Ramadhana Putra, Osama Bajaber, Saimon Amanuel Tsegai, Teryl Taylor 等CCS 2026
- RDNet: An RDMA-aware Container Network Interface for Cloud EnvironmentsMyoungsung You, Minjae Seo, Seungwon Shin, Jaehyun NamINFOCOM 2026
它引用的顶会 Paper1
相关 Paper
- Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation ForwardingJietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li 等USENIX Security 2023
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie 等EuroSys 2026 · 被引用 1 次
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani 等USENIX Security 2021 · 被引用 38 次
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che 等USENIX Security 2023
- Parallelizing packet processing in container overlay networksJiaxin Lei, Manish Munikar, Kun Suo, Hui Lu 等EuroSys 2021 · 被引用 22 次
