Results 81 to 90 of about 1,010 (196)
Network Function Virtualization (NFV) offers flexibility but poses a critical challenge in multi-tenant environments: ensuring fairness (resource usage limits) and system security (memory/packet isolation) for each tenant.
Soki Koizumi +3 more
doaj +1 more source
BPFflow - Preventing information leaks from eBPF [PDF]
eBPF has seen major industry adoption by enterprises to enhance observability, tracing, and monitoring by hooking at different points in the kernel. However, since the kernel is a critical resource, eBPF can also pose as a threat if misused, potentially ...
Williams, Dan +3 more
core +1 more source
From Container to Cluster: Chained Escape Attacks in Kubernetes and Orchestration Platforms
Container virtualization offers a lightweight and agile alternative to traditional virtual machines, yet its reliance on a shared host kernel creates a fundamentally weaker isolation boundary. This architectural choice exposes systems to container escape
Jia-Ning Luo +2 more
doaj +1 more source
Risk assessment of food contact materials. [PDF]
Ramírez V, Merkel S, Tietz T, Rivas A.
europepmc +1 more source
Honey for the Ice Bear - Dynamic eBPF in P4
Software updates typically require system reboots, leading to service downtimes. We aim to solve this problem for network components allowing updates while avoiding service degradation. In this paper, we explore the integration of eBPF into the P4 pipeline for efficient packet processing. This way, we combine the flexibility and dynamic adaptability of
Simon, Manuel +3 more
openaire +2 more sources
Trade-Offs in Kubernetes Security and Energy Consumption
As the threat landscape advances and pressure to reduce the energy footprint grows, it is crucial to understand how security mechanisms affect the power consumption of cloud-native platforms.
Ioannis Dermentzis +2 more
doaj +1 more source
hyDNS: Acceleration of DNS Through Kernel Space Resolution
The Domain Name System (DNS) is a core component of Internet infrastructure, mapping domain names to IP addresses. The recursive resolver plays a critical role in this process, requiring high performance due to multiple request-response exchanges ...
Parilla, Aidan +7 more
core +1 more source
SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions [PDF]
The eBPF framework enables execution of user-provided code in the Linux kernel. In the last few years, a large ecosystem of cloud services has leveraged eBPF to enhance container security, system observability, and network management.
Han, Xueyuan +3 more
core +1 more source
With the widespread adoption of Wi-Fi 7 in campus networks, high-density access and large-scale research data transmission challenge traditional congestion control algorithms. TCP-bottleneck bandwidth and round-trip propagation time (BBR) lacks deep link
Zhaolu Li, Ning Xu, Xiaoli Zhang
doaj +1 more source
eBPF‑Secure: A Lightweight eBPF‑Based Confinement and Observability Framework for Container Security
As container adoption accelerates, the need for runtime security and transparent observability has never been greater. Traditional Linux confinement primitives, namespaces, cgroups, seccomp, and LSMs are powerful but often complex to combine and difficult to extend.
openaire +1 more source

