Results 31 to 40 of about 1,010 (196)
The aim of this study was to investigate the impact of eBPF technology on the performance of network solutions in Kubernetes clusters. Two configurations were compared: a traditional iptables-based setup and eBPF based solution via the Cilium networking
Konrad Miziński, Sławomir Przyłucki
doaj +1 more source
vbpf/ebpf-verifier: PLDI '19 Camera Ready
A new eBPF verifier, using abstract ...
Elazar Gershuni +6 more
core +1 more source
DeSFAM: An Adaptive eBPF and AI-Driven Framework for Securing Cloud Containers in Real Time
Containerized applications offer lightweight and scalable deployment but remain exposed to security risks due to a shared kernel. We present DeSFAM (Dynamic eBPF-driven Syscall Filtering and Anomaly Mitigation), a real-time security framework that ...
Sehar Zehra +3 more
doaj +1 more source
Deep Analysis of Containerized Web Server Performance Using eBPF‐Captured Data
Focusing on containerized environments like Docker, we examine performance degradation in these environments using extended Berkeley Packet Filter (eBPF) technology. We develop a monitoring application with eBPF to analyze the relationship between system resources (CPU, memory, and disk I/O) and system calls. Using random forest regression to analyze a
Tomonori Takagaki, Kimihiro Mizutani
wiley +1 more source
High-Performance Software Load Balancer for Cloud-Native Architecture
Driven by increasing in the demand for cloud computing, cloud providers are constantly seeking configuration mechanisms designed to simply install a reliable and easy-to-manage cloud architecture—similar to installing an operating system on a ...
Jung-Bok Lee +5 more
doaj +1 more source
Autonomous Attack Mitigation Through Firewall Reconfiguration
This graphical abstract shows the workflow of the proposed approach for autonomous attack mitigation through firewall reconfiguration. ABSTRACT Packet filtering firewalls represent a main defense line against cyber attacks that target computer networks daily. However, the traditional manual approaches for their configuration are no longer applicable to
Daniele Bringhenti +3 more
wiley +1 more source
Zero-day intrusions on IoT endpoints demand defenses that curtail attacker impact and persistence after breach. This article presents Fine-Grained Runtime Containment Agent (FG-RCA), a lightweight post-exploitation containment system that learns least ...
Fouad Ailabouni +2 more
doaj +1 more source
REMEDIATE: Improving Network and Middlebox Resilience With Virtualisation
ABSTRACT The increasing demand for low‐latency, high‐bandwidth connectivity has introduced novel challenges to delivering strong resilience guarantees in production network environments. Closed hardware platforms, known as middleboxes, that lack visibility and support for state retention remain a key challenge for continuous service delivery during ...
Lyn Hill +3 more
wiley +1 more source
The eBPF Runtime in the Linux Kernel
22 pages, 6 ...
Gbadamosi, Bolaji +6 more
openaire +4 more sources
Dynamic Load Balancing for Direct Server Return Networks Using eBPF for In-Band Metric Feedback
Direct Server Return (DSR) enables backend servers to send responses directly to clients, bypassing the load balancer on the return path. Removing that extra hop trims end-to-end latency and prevents the balancer from becoming a bottleneck at high ...
Sahakyan Hovhannes, Astsatryan Hrachya
doaj +1 more source

