HELIOS: Hardware-assisted High-performance Security Extension for Cloud Networking

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Scopus citations

Abstract

With the increasing adoption of containerization in cloud services, container networking has become a critical concern, as it enables the agile deployment of microservices but also introduces new vulnerabilities susceptible to network attacks, posing a threat to container environments. While several security solutions have been introduced to address this concern, they unfortunately exhibit significant shortcomings, including security vulnerabilities and limited performance. We thus propose Helios, a novel hardware-based network security extension that addresses the security and performance limitations in existing solutions. Leveraging a smartNIC, Helios enhances both the security and performance facets of container networking through two key mechanisms: (i) the establishment of physically isolated container communication channels and (ii) the network security engines fully offloaded to the smartNIC. Our evaluation shows that Helios mitigates various network threats initiated from both container- and host-side while performing up to 3x faster than the existing solutions in container communication.

Original languageEnglish
Title of host publicationSoCC 2023 - Proceedings of the 2023 ACM Symposium on Cloud Computing
PublisherAssociation for Computing Machinery, Inc
Pages486-501
Number of pages16
ISBN (Electronic)9798400703874
DOIs
StatePublished - 30 Oct 2023
Event14th ACM Symposium on Cloud Computing, SoCC 2023 - Santa Cruz, United States
Duration: 30 Oct 20231 Nov 2023

Publication series

NameSoCC 2023 - Proceedings of the 2023 ACM Symposium on Cloud Computing

Conference

Conference14th ACM Symposium on Cloud Computing, SoCC 2023
Country/TerritoryUnited States
CitySanta Cruz
Period30/10/231/11/23

Keywords

  • Container Network
  • Security Policy Enforcement
  • SmartNIC

Fingerprint

Dive into the research topics of 'HELIOS: Hardware-assisted High-performance Security Extension for Cloud Networking'. Together they form a unique fingerprint.

Cite this