eMicro:基于eBPF的微服务实时多跳访问控制
eMicro: Real-Time Multi-Hop Access Control for Microservices with eBPF
AI总结:
eMicro是基于eBPF的微服务路径感知防御系统,通过三项关键技术防范多跳攻击,经大规模云轨迹验证,具备高效可扩展特性,可部署于大型微服务环境。
AI中文摘要:
现代云应用通常包含数千个微服务,其交互形成复杂的请求路径。传统的服务间访问控制仅限制单个服务到服务的请求,却无法阻止多跳攻击——每一跳请求看似合法,但整体路径违反安全意图。这一漏洞使系统面临未授权访问和数据外泄的风险。本文提出eMicro,一种面向微服务的路径感知防御系统,可在保持高效性和可部署性的同时防范此类攻击。eMicro通过三项关键技术实现实时多跳访问控制:(1)扩展基于历史的访问控制,以捕获服务调用序列;(2)将安全策略编码为高效的确定有限自动机(DFA),支持常数时间查找和紧凑标签传播;(3)基于eBPF的内核内请求追踪,无需代码更改即可实现透明、低开销的执行。对DeathStarBench以及来自Uber、阿里巴巴和字节跳动的生产云轨迹的评估,涵盖1200万个请求工作流和数千个服务,证明了eMicro的可扩展性。eMicro执行策略检查耗时1微秒,存储5000万个策略仅需100MB,且将传播开销降低90%,同时运行时影响可忽略不计。这些结果表明,eMicro提供了可扩展且高效的多跳攻击防护,使其适用于大规模微服务环境的部署。
英文摘要:
Modern cloud applications often comprise thousands of microservices whose interactions form complex request paths. Traditional inter-service access control restricts individual service-to-service requests, but fails to prevent multi-hop attacks, where each hop appears legitimate yet the overall path violates security intent. This gap leaves systems exposed to unauthorized access and data exfiltration. In this paper, we present eMicro, a path-aware defense system for microservices that prevents such attacks while remaining efficient and deployable. eMicro enforces real-time multi-hop access control through three key techniques: (1) history-based access control extended to capture service invocation sequences; (2) security policies encoded as efficient deterministic finite automaton (DFA), supporting constant-time lookups and compact label propagation; (3) eBPF-based in-kernel request tracing for transparent, low-overhead enforcement without code changes. Evaluations on DeathStarBench and production cloud traces from Uber, Alibaba, and ByteDance, covering 12 million request workflows and thousands of services, demonstrate the scalability of eMicro. eMicro performs policy checks in 1 microsecond, stores 50 million policies in only 100 MB, and reduces propagation overhead by 90% with negligible runtime impact. These results show that eMicro delivers scalable and efficient protection against multi-hop attacks, making it practical for deployment in large-scale microservice environments.