Enhancing Container Security with Per-Process Per-Container Egress Packet Filtering Using eBPF
Ruturaj Mohite, B. Thangaraju · 2024
With growing use of containers and container or-chestration in production systems, it is more important than ever to secure compromised containers from malicious uses. A compromised container could become a part of a botnet or could talk back to an attacker's server, exposing sensitive information. In this paper, we discuss the implementation of a packet filter which filters packets based on their L3 and L4 headers as well as their process and container of origin. To achieve this, we use extended Berkeley Packet Filter (eBPF) programs to probe into kernel functions and use hook points provided by the kernel to monitor and filter egress packets. Primarily, we use an eBPF program of type 'BPF _PROG_TYPE_CGROUP _SKB’ that not only allows us to filter TCPIUDP packets, but also packets transmitted over raw sockets (e.g, ICMP packets). To attach this program to any new containers, we also explore an in-kernel solution to detect new containers at runtime. We conclude the paper by conducting an experiment to measure the latency overhead added by our proposed solution.