HardWhale: A Hardware-Isolated Network Security Enforcement System for Cloud Environments

  • Myoungsung You
  • , Jaehyun Nam
  • , Hyunmin Seo
  • , Minjae Seo
  • , Jaehan Kim
  • , Dongmin Choi
  • , Seungwon Shin

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

With the increasing popularity of containers for deploying microservices, ensuring the security of container networks has become a vital concern. However, current security solutions rely on a host's operating system (OS) to enforce network policies for container traffic. This design incurs severe overhead and cannot guarantee container network security when attackers gain access to the host's OS. Therefore, we propose HardWhale, a hardware-isolated network security enforcement system for containers that delivers high-performance and robust network security without depending on the host's OS. HardWhale leverages a smartNIC, physically isolating the entire container traffic inspection stack from the host and accelerating inspection tasks. Inspection policies securely reside within the smartNIC and are updated in runtime without involving the host, due to our isolated policy management mechanism. This design ensures robust network security for containers, even if the host is exposed to attackers. Evaluations show that HardWhale protects containers against various network attacks in compromised environments and improves HTTP throughput threefold and HTTP latency 2.3-fold compared to state-of-the-art solutions.

Original languageEnglish
Title of host publicationProceedings - 2024 IEEE 44th International Conference on Distributed Computing Systems, ICDCS 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages496-507
Number of pages12
ISBN (Electronic)9798350386059
DOIs
StatePublished - 2024
Event44th IEEE International Conference on Distributed Computing Systems, ICDCS 2024 - Jersey City, United States
Duration: 23 Jul 202426 Jul 2024

Publication series

NameProceedings - International Conference on Distributed Computing Systems
ISSN (Print)1063-6927
ISSN (Electronic)2575-8411

Conference

Conference44th IEEE International Conference on Distributed Computing Systems, ICDCS 2024
Country/TerritoryUnited States
CityJersey City
Period23/07/2426/07/24

Keywords

  • Cloud computing
  • Container
  • Network security
  • Programmable data plane

Fingerprint

Dive into the research topics of 'HardWhale: A Hardware-Isolated Network Security Enforcement System for Cloud Environments'. Together they form a unique fingerprint.

Cite this