Skip to main navigation Skip to search Skip to main content

Improving the Security of Service Mesh in Kubernetes

  • Amir Javadpour*
  • , Forough Ja'fari
  • , Tarik Taleb
  • , Chafika Benzaid
  • , Luis Rosa
  • , Luis Cordeiro
  • *Corresponding author for this work
  • ICTFicial OY
  • Sharif University of Technology
  • Ruhr University Bochum
  • University of Oulu
  • Consultoria Informática

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Bringing flexibility and scalability to 5G networks has expanded networking technology to facilitate the split of service into microservices and how they can communicate. The network layer dedicated to this communication is called service mesh, and it has become a new target for cyber adversaries. The existing service mesh infrastructures, such as Istio and NGINX, apply the mutual TLS (mTLS) protocol to the connections in the service mesh layer to protect the confidentiality of the data transferred in this layer. However, the main challenge of implementing mTLS is its resource restriction, which significantly conflicts with the scalability and flexibility goals. Therefore, this paper proposes an Encryption as a Service (EaaS) framework that can be implemented on Kubernetes, mitigating man-in-themiddle, (distributed) denial of service, and eavesdropping attacks against service mesh. The implementation results show that the proposed framework decreases the adversary's success rate by at least 45% compared to the cases of having microservices apply the cryptographic processes by themselves.

Original languageEnglish
Title of host publicationProceedings of 2025 IEEE 31st International Conference on Parallel and Distributed Systems, ICPADS 2025
PublisherIEEE Computer Society
ISBN (Electronic)9798331549015
DOIs
StatePublished - 2025
Externally publishedYes
Event31st IEEE International Conference on Parallel and Distributed Systems, ICPADS 2025 - Hefei, China
Duration: 14 Dec 202517 Dec 2025

Publication series

NameProceedings of the International Conference on Parallel and Distributed Systems - ICPADS
ISSN (Print)1521-9097

Conference

Conference31st IEEE International Conference on Parallel and Distributed Systems, ICPADS 2025
Country/TerritoryChina
CityHefei
Period14/12/2517/12/25

Keywords

  • Encryption as a Service (EaaS)
  • Kubernetes
  • Security
  • Service Mesh

Fingerprint

Dive into the research topics of 'Improving the Security of Service Mesh in Kubernetes'. Together they form a unique fingerprint.

Cite this