{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:38:33Z","timestamp":1782833913665,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":75,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,30]],"date-time":"2023-10-30T00:00:00Z","timestamp":1698624000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ICT Challenge and Advanced Network of HRD support program, Ministry of Science and ICT, Korea","award":["IITP-2023-RS-2023-00259867"],"award-info":[{"award-number":["IITP-2023-RS-2023-00259867"]}]},{"name":"Information Technology Research Center support program, Ministry of Science and ICT, Korea","award":["IITP-2023-RS-2023-00258649"],"award-info":[{"award-number":["IITP-2023-RS-2023-00258649"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,30]]},"DOI":"10.1145\/3620678.3624786","type":"proceedings-article","created":{"date-parts":[[2023,10,31]],"date-time":"2023-10-31T13:58:07Z","timestamp":1698760687000},"page":"486-501","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["HELIOS"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5822-5243","authenticated-orcid":false,"given":"Myoungsung","family":"You","sequence":"first","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8907-5495","authenticated-orcid":false,"given":"Jaehyun","family":"Nam","sequence":"additional","affiliation":[{"name":"Dankook University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9240-5213","authenticated-orcid":false,"given":"Minjae","family":"Seo","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1077-5606","authenticated-orcid":false,"given":"Seungwon","family":"Shin","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,10,31]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2008. PCI-SIG Single Root I\/O Virtualization (SR-IOV) Support in Intel\u00ae Virtualization Technology for Connectivity. https:\/\/www.intel.com\/content\/www\/us\/en\/pci-express\/pci-sig-single-root-io-virtualization-support-in-virtualization-technology-for-connectivity-paper.html."},{"key":"e_1_3_2_1_2_1","unstructured":"2013. Namespaces in Operation Part 1: Namespaces Overview. https:\/\/lwn.net\/Articles\/531114\/."},{"key":"e_1_3_2_1_3_1","unstructured":"2014. wrk -- a HTTP Benchmarking Tool. https:\/\/github.com\/wg\/wrk."},{"key":"e_1_3_2_1_4_1","unstructured":"2015. Kubernetes Performance Measurements and Roadmap. https:\/\/kubernetes.io\/blog\/2015\/09\/kubernetes-performance-measurements-and\/."},{"key":"e_1_3_2_1_5_1","unstructured":"2018. Flask Docker Container Image. https:\/\/hub.docker.com\/r\/jcdemo\/flaskapp."},{"key":"e_1_3_2_1_6_1","unstructured":"2019. CVE-2019-8341. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-8341\/."},{"key":"e_1_3_2_1_7_1","unstructured":"2020. CVE-2020-11100. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-11100\/."},{"key":"e_1_3_2_1_8_1","unstructured":"2021. State of Kubernetes Security Report. https:\/\/thechief.io\/c\/editorial\/state-of-kubernetes-security-report."},{"key":"e_1_3_2_1_9_1","unstructured":"2022. 7 Most Infamous Cloud Security Breaches. https:\/\/blog.storagecraft.com\/7-infamous-cloud-security-breaches\/."},{"key":"e_1_3_2_1_10_1","unstructured":"2022. Amazon Web Services. https:\/\/aws.amazon.com\/."},{"key":"e_1_3_2_1_11_1","unstructured":"2023. AppArmor Linux Kernel Security Module. https:\/\/apparmor.net\/."},{"key":"e_1_3_2_1_12_1","unstructured":"2023. bridge(8) --- Linux manual page. https:\/\/man7.org\/linux\/manpages\/man8\/bridge.8.html."},{"key":"e_1_3_2_1_13_1","unstructured":"2023. Calio-felix. https:\/\/docs.projectcalico.org\/reference\/felix\/."},{"key":"e_1_3_2_1_14_1","unstructured":"2023. Cilim Envoy Extension. https:\/\/docs.cilium.io\/en\/v1.13\/security\/network\/proxy\/envoy\/."},{"key":"e_1_3_2_1_15_1","unstructured":"2023. Cilium. https:\/\/www.cilium.io\/."},{"key":"e_1_3_2_1_16_1","unstructured":"2023. Cilium-agent. https:\/\/docs.cilium.io\/en\/stable\/cmdref\/cilium-agent\/."},{"key":"e_1_3_2_1_17_1","unstructured":"2023. CNI: The container network interface. https:\/\/www.cni.dev\/."},{"key":"e_1_3_2_1_18_1","unstructured":"2023. Docker. https:\/\/www.docker.com."},{"key":"e_1_3_2_1_19_1","unstructured":"2023. Docker host networking. https:\/\/docs.docker.com\/network\/host\/."},{"key":"e_1_3_2_1_20_1","unstructured":"2023. DockerHub: envoyproxy\/envoy. https:\/\/hub.docker.com\/r\/envoyproxy\/envoy."},{"key":"e_1_3_2_1_21_1","unstructured":"2023. DockerHub: hashicorp\/boundary. https:\/\/hub.docker.com\/r\/hashicorp\/boundary."},{"key":"e_1_3_2_1_22_1","unstructured":"2023. DockerHub: sysdig. https:\/\/hub.docker.com\/r\/sysdig\/sysdig."},{"key":"e_1_3_2_1_23_1","unstructured":"2023. eBPF Introduction Tutorials. https:\/\/docs.cilium.io\/en\/stable\/bpf\/."},{"key":"e_1_3_2_1_24_1","unstructured":"2023. Flannel-d. https:\/\/github.com\/flannel-io\/flannel."},{"key":"e_1_3_2_1_25_1","unstructured":"2023. Google Cloud Platform (GCP). https:\/\/cloud.google.com\/."},{"key":"e_1_3_2_1_26_1","unstructured":"2023. HAProxy ingress controler. https:\/\/haproxy-ingress.github.io\/."},{"key":"e_1_3_2_1_27_1","unstructured":"2023. Hewlett Packard Enterprise. Netperf. https:\/\/hewlettpackard.github.io\/netperf\/."},{"key":"e_1_3_2_1_28_1","unstructured":"2023. Host network driver. https:\/\/docs.docker.com\/network\/drivers\/host\/."},{"key":"e_1_3_2_1_29_1","unstructured":"2023. iPerf. Network Bandwidth Measurement Tool. https:\/\/iperf.fr\/iperf-download.php."},{"key":"e_1_3_2_1_30_1","unstructured":"2023. Kubernetes. https:\/\/kubernetes.io."},{"key":"e_1_3_2_1_31_1","unstructured":"2023. Kubernetes API Watcher Design. https:\/\/docs.openstack.org\/kuryr\/0.2.0\/devref\/k8s_api_watcher_design.html."},{"key":"e_1_3_2_1_32_1","unstructured":"2023. Kubernetes: Considerations for large clusters. https:\/\/kubernetes.io\/docs\/setup\/best-practices\/cluster-large\/."},{"key":"e_1_3_2_1_33_1","unstructured":"2023. Kubernetes Privilege Escalation. https:\/\/i.blackhat.com\/USA-22\/Thursday\/US-22-Avrahami-Kubernetes-Privilege-Escalation-Container-Escape-Cluster-Admin.pdf."},{"key":"e_1_3_2_1_34_1","unstructured":"2023. Linux SYSSTAT. http:\/\/sebastien.godard.pagesperso-orange.fr\/."},{"key":"e_1_3_2_1_35_1","unstructured":"2023. Microsoft Azure. https:\/\/azure.microsoft.com\/."},{"key":"e_1_3_2_1_36_1","unstructured":"2023. Netronome Agilo CX smartNIC 2x40GbE. https:\/\/www.netronome.com\/media\/documents\/PB_NFP-4000-7-20.pdf."},{"key":"e_1_3_2_1_37_1","unstructured":"2023. Nginx Docker Container. https:\/\/hub.docker.com\/_\/nginx."},{"key":"e_1_3_2_1_38_1","unstructured":"2023. OpenVPN Access Server. https:\/\/hub.docker.com\/r\/mace\/openvpn-as."},{"key":"e_1_3_2_1_39_1","unstructured":"2023. Project Calico. https:\/\/www.projectcalico.org\/."},{"key":"e_1_3_2_1_40_1","unstructured":"2023. Redis Docker Container. https:\/\/hub.docker.com\/_\/redis."},{"key":"e_1_3_2_1_41_1","unstructured":"2023. Service | Kubernetes. https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/service\/."},{"key":"e_1_3_2_1_42_1","unstructured":"2023. TCPdump manpage. https:\/\/www.tcpdump.org\/manpages\/."},{"key":"e_1_3_2_1_43_1","unstructured":"2023. The Istio service mesh. https:\/\/istio.io\/."},{"key":"e_1_3_2_1_44_1","unstructured":"2023. The Linked servie mesh. https:\/\/linkerd.io\/."},{"key":"e_1_3_2_1_45_1","unstructured":"2023. veth -- Virtual Ethernet Device. https:\/\/man7.org\/linux\/manpages\/man4\/veth.4.html\/."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.14722\/madweb.2022.23012"},{"key":"e_1_3_2_1_47_1","volume-title":"Docker Container Security in Cloud Computing. In In Proceedings of Annual Computing and Communication Workshop and Conference. 975--980","author":"Brady Kelly","year":"2020","unstructured":"Kelly Brady, Seung Moon, Tuan Nguyen, and Joel Coffman. 2020. Docker Container Security in Cloud Computing. In In Proceedings of Annual Computing and Communication Workshop and Conference. 975--980."},{"key":"e_1_3_2_1_48_1","volume-title":"Network Policies in Kubernetes: Performance Evaluation and Security Analysis. In In proceedings of Joint European Conference on Networks and Communications & 6G Summit. 407--412","author":"Budigiri Gerald","year":"2021","unstructured":"Gerald Budigiri, Christoph Baumann, Jan Tobias M\u00fchlberg, Eddy Truyen, and Wouter Joosen. 2021. Network Policies in Kubernetes: Performance Evaluation and Security Analysis. In In proceedings of Joint European Conference on Networks and Communications & 6G Summit. 407--412."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380173"},{"key":"e_1_3_2_1_50_1","volume-title":"An Empirical Study of Docker Vulnerabilities and of Static Code Analysis Applicability. In In Proceedings of Latin-American Symposium on Dependable Computing. 27--36","author":"Duarte Ana","year":"2018","unstructured":"Ana Duarte and Nuno Antunes. 2018. An Empirical Study of Docker Vulnerabilities and of Static Code Analysis Applicability. In In Proceedings of Latin-American Symposium on Dependable Computing. 27--36."},{"key":"e_1_3_2_1_51_1","volume-title":"BPFContain: Fixing the Soft Underbelly of Container Security. arXiv preprint arXiv:2102.06972","author":"Findlay William","year":"2021","unstructured":"William Findlay, David Barrera, and Anil Somayaji. 2021. BPFContain: Fixing the Soft Underbelly of Container Security. arXiv preprint arXiv:2102.06972 (2021)."},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of International Symposium on Research in Attacks, Intrusions and Defenses. 443--458","author":"Ghavamnia Seyedhamed","year":"2020","unstructured":"Seyedhamed Ghavamnia, Tapti Palit, Azzedine Benameur, and Michalis Polychronakis. 2020. Confine: Automated System Call Policy Generation for Container Attack Surface Reduction. In Proceedings of International Symposium on Research in Attacks, Intrusions and Defenses. 443--458."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3386367.3431290"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3314148.3314356"},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of netdev 1","author":"Kicinski Jakub","year":"2016","unstructured":"Jakub Kicinski and Nicolaas Viljoen. 2016. eBPF Hardware Offload to SmartNICs: cls bpf and XDP. Proceedings of netdev 1 (2016)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSCI51800.2020.00110"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_11"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SOSE.2019.00026"},{"key":"e_1_3_2_1_59_1","volume-title":"Securing Serverless Computing: Challenges, Solutions, and Opportunities. arXiv preprint arXiv:2105.12581","author":"Li Xing","year":"2021","unstructured":"Xing Li, Xue Leng, and Yan Chen. 2021. Securing Serverless Computing: Challenges, Solutions, and Opportunities. arXiv preprint arXiv:2105.12581 (2021)."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274720"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNP.2019.8888116"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737507"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2018.03.011"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2022.3206781"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of USENIX Annual Technical Conference. 81--95","author":"Nam Jaehyun","year":"2020","unstructured":"Jaehyun Nam, Seungsoo Lee, Hyunmin Seo, Phil Porras, Vinod Yegneswaran, and Seungwon Shin. 2020. BASTION: A Security Enforcement Network Stack for Container Networks. In Proceedings of USENIX Annual Technical Conference. 81--95."},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the 16th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2019. USENIX ASSOC, 531--547","author":"Pontarelli Salvatore","year":"2019","unstructured":"Salvatore Pontarelli, Roberto Bifulco, Marco Bonola, Carmelo Cascone, Marco Spaziani, Valerio Bruschi, Davide Sanvito, Giuseppe Siracusano, Antonio Capone, Michio Honda, et al. 2019. Flowblaze: Stateful packet processing in hardware. In Proceedings of the 16th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2019. USENIX ASSOC, 531--547."},{"key":"e_1_3_2_1_67_1","volume-title":"Proceedings of Netdev 0.1","author":"Salim Jamal Hadi","year":"2015","unstructured":"Jamal Hadi Salim. 2015. Linux traffic control classifier-action subsystem architecture. Proceedings of Netdev 0.1 (2015)."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3050608"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2911732"},{"key":"e_1_3_2_1_70_1","volume-title":"Proceedings of USENIX Security Symposium. 1423--1439","author":"Sun Yuqiong","year":"2018","unstructured":"Yuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis, Zhongshu Gu, and Trent Jaeger. 2018. Security Namespace: Making Linux Security Frameworks Available to Containers. In Proceedings of USENIX Security Symposium. 1423--1439."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2018.8485865"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS54207.2022.9789778"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2017.8004872"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321408.3323087"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3314148.3314349"}],"event":{"name":"SoCC '23: ACM Symposium on Cloud Computing","location":"Santa Cruz CA USA","acronym":"SoCC '23","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 2023 ACM Symposium on Cloud Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3620678.3624786","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3620678.3624786","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T15:55:04Z","timestamp":1755878104000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3620678.3624786"}},"subtitle":["Hardware-assisted High-performance Security Extension for Cloud Networking"],"short-title":[],"issued":{"date-parts":[[2023,10,30]]},"references-count":75,"alternative-id":["10.1145\/3620678.3624786","10.1145\/3620678"],"URL":"https:\/\/doi.org\/10.1145\/3620678.3624786","relation":{},"subject":[],"published":{"date-parts":[[2023,10,30]]},"assertion":[{"value":"2023-10-31","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}