OAK

An eBPF-based DevSecOps Approach for Enhancing Security of an Edge Cloud Cluster

Metadata Downloads
Abstract
The information communication technology infrastructure have been undergoing rapid changes due to the emergence of cloud, cloud-native, and edge computing paradigms. The widespread adoption of edge computing has revolutionized the processing and analysis of large volumes of data, enhancing the performance and reliability of cloud-based services. By enabling data processing and storage in proximity to the data source, edge clouds eliminate the need for data to traverse long distances to centralized data centers, resulting in lower latency and faster response times. To further optimize resource utilization and flexibility, edge clouds have largely embraced cloud-native computing, leveraging technologies like containers and orchestrators such as Kubernetes (K8S). While cloud-native computing offers benefits such as agility, scalability, and resiliency throughout the application lifecycle, it also introduces security concerns due to expanded attack surfaces. This thesis suggests an eBPF-based DevSecOps approach which entails several key components for enhancing security of an edge cloud cluster. By using eBPF, this work presents solutions for monitoring network traffic and rate-limiting data bursts in a K8S cluster. Also, an eBPF-based solution for malicious traffic detection is suggested. By integrating these solutions into the DevSecOps workflow, security measures can be incorporated throughout the development, deployment and operations processes. This work uses an enhanced GIST site of the OF@TEIN Playground, which is an edge cloud cluster to verify the suggested solutions.
Author(s)
Ulugbek Khamdamov
Issued Date
2023
Type
Thesis
URI
https://scholar.gist.ac.kr/handle/local/18872
Department
대학원 AI대학원
Advisor
Kim, Jong Won
Degree
Master
Appears in Collections:
Department of AI Convergence > 3. Theses(Master)
공개 및 라이선스
  • 공개 구분공개
파일 목록
  • 관련 파일이 존재하지 않습니다.

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.