polito.it
Politecnico di Torino (logo)

An abstract model of cloud-native networks for security enforcement and remediation

Giuseppe Lisena

An abstract model of cloud-native networks for security enforcement and remediation.

Rel. Cataldo Basile, Francesco Settanni. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025

[img]
Preview
PDF (Tesi_di_laurea) - Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (1MB) | Preview
Abstract:

In recent years, Kubernetes has established itself as a dominant platform for container orchestration, becoming an integral component of numerous cloud infrastructures. A significant portion of Kubernetes’ popularity stems from its ecosystem of external components, including operators, network plugins, and various other tools. The proliferation of these components, each tailored to specific use cases, has resulted in a diverse and often overlapping landscape of solutions. This thesis undertakes a comprehensive analysis of several prominent Kubernetesnetwork plugins, operators, and tools, encompassing popular solutions such as Flannel, Calico, Cilium, Network Service Mesh, and Kube-router. The analysis delves into their respective features, performance characteristics, and security implications, enabling a comparative evaluation. Furthermore, this thesis introduces an abstract model that encapsulates the diverse resource types within Kubernetes. Designed to encompass a broad spectrum of Kubernetes resources, the model has been validated against real-world deployments, including GoogleBoutique, IBM Java microservices, and practical applications powered by Kubernetes, Cilium, and KubeArmor. This structured representation offers a foundation for automated processing by software tools.

Relatori: Cataldo Basile, Francesco Settanni
Anno accademico: 2024/25
Tipo di pubblicazione: Elettronica
Numero di pagine: 86
Soggetti:
Corso di laurea: Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering)
Classe di laurea: Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA
Aziende collaboratrici: NON SPECIFICATO
URI: http://webthesis.biblio.polito.it/id/eprint/35458
Modifica (riservato agli operatori) Modifica (riservato agli operatori)