基于eBPF的虛擬化網(wǎng)絡(luò)與云原生網(wǎng)絡(luò)應(yīng)用
網(wǎng)絡(luò)安全與數(shù)據(jù)治理 2期
施蘇峰
(1.東南大學(xué) 網(wǎng)絡(luò)空間安全學(xué)院,江蘇 南京211189;2.網(wǎng)絡(luò)通信與安全紫金山實(shí)驗(yàn)室,江蘇 南京211111)
摘要: 近年來(lái),隨著eBPF的內(nèi)核代碼安全注入機(jī)制的發(fā)展,eBPF已經(jīng)在網(wǎng)絡(luò)優(yōu)化、性能監(jiān)控等方面獲得大量應(yīng)用。介紹了eBPF在網(wǎng)絡(luò)功能虛擬化領(lǐng)域的應(yīng)用概述,以及其基于容器架構(gòu)發(fā)展而來(lái)的云原生網(wǎng)絡(luò)功能領(lǐng)域的應(yīng)用概述,并舉出了eBPF用于上述領(lǐng)域的典型應(yīng)用:網(wǎng)絡(luò)功能虛擬化領(lǐng)域的負(fù)載均衡、快速丟包、限流應(yīng)用,以及云原生網(wǎng)絡(luò)功能領(lǐng)域的Kubernetes容器網(wǎng)絡(luò)加速、服務(wù)網(wǎng)格加速應(yīng)用。
中圖分類號(hào): TP393
文獻(xiàn)標(biāo)識(shí)碼: A
DOI: 10.19358/j.issn.2097-1788.2023.02.002
引用格式: 施蘇峰. 基于eBPF的虛擬化網(wǎng)絡(luò)與云原生網(wǎng)絡(luò)應(yīng)用[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2023,42(2):9-18.
文獻(xiàn)標(biāo)識(shí)碼: A
DOI: 10.19358/j.issn.2097-1788.2023.02.002
引用格式: 施蘇峰. 基于eBPF的虛擬化網(wǎng)絡(luò)與云原生網(wǎng)絡(luò)應(yīng)用[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2023,42(2):9-18.
Virtual network and cloud native network application based on eBPF
Shi Sufeng1,2
(1.School of Cyber Science and Engineering,Southeast University,Nanjing 211189,China; 2.Purple Mountain Laboratories,Nanjing 211111,China)
Abstract: In recent years, with the development of eBPF kernel code security injection mechanism, eBPF has been widely used in network optimization, performance monitoring and other aspects. This paper introduces the application of eBPF in the field of network function virtualization and the application of eBPF in the field of cloud native network function based on container architecture. Typical applications of eBPF used in the above fields are presented, including load balancing, fast packet loss and network traffic rate limiting applications in the field of network virtualization. In addition, the Kubernetes container network acceleration and service grid acceleration applications in the field of cloud native network functions are also mentioned.
Key words : eBPF;network function virtualization;cloud native;load balancing;Kubernetes;service mesh
0 引言
隨著eBPF(extended Berkeley Packet Filter)技術(shù)在網(wǎng)絡(luò)功能虛擬化以及云原生網(wǎng)絡(luò)功能領(lǐng)域的逐漸成熟,其復(fù)用內(nèi)核協(xié)議棧、內(nèi)核安全校驗(yàn)、流量短路等優(yōu)勢(shì)使得傳統(tǒng)的網(wǎng)絡(luò)功能虛擬化以及云原生網(wǎng)絡(luò)功能擁有了創(chuàng)新性的發(fā)展。
本文詳細(xì)內(nèi)容請(qǐng)下載:http://theprogrammingfactory.com/resource/share/2000005207
作者信息:
施蘇峰(1998-),通信作者,男,碩士研究生,主要研究方向:eBPF、云原生、網(wǎng)絡(luò)功能虛擬化。E-mail:1257989860@qq.com。
此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。