Vittorio Tabare'
Tapping encrypted traffic in a Kubernetes cluster using eBPF-based services.
Rel. Fulvio Giovanni Ottavio Risso, Federico Parola. Politecnico di Torino, Master of science program in Computer Engineering, 2024
Abstract
In the context of modern telecommunications, the introduction of 5G has transformed network architecture from traditional network functions, tied to dedicated hardware, to virtualized solutions managed on cloud-native platforms. In this scenario, Kubernetes emerges as an orchestration platform, enabling agile and scalable management of containerized Network Functions (NFs), which are critical to support the evolution of 5G networks. This thesis focuses on how to effectively monitor the control plane between NFs communicating through protocols such as HTTP/2, while ensuring high performance and strict security standards through the use of eBPF (Extended Berkeley Packet Filter), a revolutionary technology that enables secure, high-performance execution of kernel-level programs without requiring direct changes to the kernel code itself.
eBPF programs are developed in Rust, a language known for its security features, in order to explore its potential
Relators
Academic year
Publication type
Number of Pages
Additional Information
Course of studies
Classe di laurea
Aziende collaboratrici
URI
![]() |
Modify record (reserved for operators) |
