Results 81 to 90 of about 1,010 (196)

XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance

open access: yesIEEE Access
Network Function Virtualization (NFV) offers flexibility but poses a critical challenge in multi-tenant environments: ensuring fairness (resource usage limits) and system security (memory/packet isolation) for each tenant.
Soki Koizumi   +3 more
doaj   +1 more source

BPFflow - Preventing information leaks from eBPF [PDF]

open access: yes
eBPF has seen major industry adoption by enterprises to enhance observability, tracing, and monitoring by hooking at different points in the kernel. However, since the kernel is a critical resource, eBPF can also pose as a threat if misused, potentially ...
Williams, Dan   +3 more
core   +1 more source

From Container to Cluster: Chained Escape Attacks in Kubernetes and Orchestration Platforms

open access: yesIEEE Access
Container virtualization offers a lightweight and agile alternative to traditional virtual machines, yet its reliance on a shared host kernel creates a fundamentally weaker isolation boundary. This architectural choice exposes systems to container escape
Jia-Ning Luo   +2 more
doaj   +1 more source

Risk assessment of food contact materials. [PDF]

open access: yesEFSA J, 2023
Ramírez V, Merkel S, Tietz T, Rivas A.
europepmc   +1 more source

Honey for the Ice Bear - Dynamic eBPF in P4

open access: yesProceedings of the SIGCOMM Workshop on eBPF and Kernel Extensions
Software updates typically require system reboots, leading to service downtimes. We aim to solve this problem for network components allowing updates while avoiding service degradation. In this paper, we explore the integration of eBPF into the P4 pipeline for efficient packet processing. This way, we combine the flexibility and dynamic adaptability of
Simon, Manuel   +3 more
openaire   +2 more sources

Trade-Offs in Kubernetes Security and Energy Consumption

open access: yesUrban Science
As the threat landscape advances and pressure to reduce the energy footprint grows, it is crucial to understand how security mechanisms affect the power consumption of cloud-native platforms.
Ioannis Dermentzis   +2 more
doaj   +1 more source

hyDNS: Acceleration of DNS Through Kernel Space Resolution

open access: yes
The Domain Name System (DNS) is a core component of Internet infrastructure, mapping domain names to IP addresses. The recursive resolver plays a critical role in this process, requiring high performance due to multiple request-response exchanges ...
Parilla, Aidan   +7 more
core   +1 more source

SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions [PDF]

open access: yes
The eBPF framework enables execution of user-provided code in the Linux kernel. In the last few years, a large ecosystem of cloud services has leveraged eBPF to enhance container security, system observability, and network management.
Han, Xueyuan   +3 more
core   +1 more source

SAC-BBR: A Semantic-Aware and Cross-Layer Collaborative Congestion Control Mechanism for Heterogeneous Campus Networks

open access: yesApplied Sciences
With the widespread adoption of Wi-Fi 7 in campus networks, high-density access and large-scale research data transmission challenge traditional congestion control algorithms. TCP-bottleneck bandwidth and round-trip propagation time (BBR) lacks deep link
Zhaolu Li, Ning Xu, Xiaoli Zhang
doaj   +1 more source

eBPF‑Secure: A Lightweight eBPF‑Based Confinement and Observability Framework for Container Security

open access: yesInternational Journal of Intelligent Systems and Data Science
As container adoption accelerates, the need for runtime security and transparent observability has never been greater. Traditional Linux confinement primitives, namespaces, cgroups, seccomp, and LSMs are powerful but often complex to combine and difficult to extend.
openaire   +1 more source

Home - About - Disclaimer - Privacy