Skip to main navigation Skip to search Skip to main content

Reviving eBPF-Based Storage Isolation in FaaS via Model-Rule Decoupling

  • Darong Yang
  • , Hechen Sun
  • , Qicong Lin
  • , Shiyi Li*
  • *Corresponding author for this work
  • Harbin Institute of Technology Shenzhen
  • Alibaba Group Holding Ltd.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The rapid development of Function as a Service (FaaS) has introduced emerging security demands for untrusted functions. Specifically, they necessitate large-scale, fine-grained, high-performance isolation. eBPF offers a promising mechanism for fine-grained isolation in process granularity. However, it suffers from inherent programming constraints (e.g., limitations on instruction count, stack size, and loop). Thus, existing eBPFbased storage isolation (sandbox) requires manual and restricted development of per-function eBPF programs, which hinders practical deployment in FaaS at scale. To address this, we present an eBPF-based file access control (eFAC) architecture atop storage isolation for the first time, with the key idea to decouple the sandbox into a file ACL model and rules. We redesign the eBPF software stack and extract a minimal, uniformly optimized, and transparent file ACL model in an eBPF program to handle the core logic of file access control. We revive eBPF-based storage isolation in FaaS by integrating eFAC into an open-source FaaS platform. Extensive evaluation shows that eFAC enables fast function deployment at scale via simple ACL rules, achieves near-native performance under I/O-intensive workloads, and reduces resource overhead and latency compared to container-based FaaS with lightweight storage isolation.

Original languageEnglish
Title of host publicationProceedings of 2025 IEEE 31st International Conference on Parallel and Distributed Systems, ICPADS 2025
PublisherIEEE Computer Society
ISBN (Electronic)9798331549015
DOIs
StatePublished - 2025
Externally publishedYes
Event31st IEEE International Conference on Parallel and Distributed Systems, ICPADS 2025 - Hefei, China
Duration: 14 Dec 202517 Dec 2025

Publication series

NameProceedings of the International Conference on Parallel and Distributed Systems - ICPADS
ISSN (Print)1521-9097

Conference

Conference31st IEEE International Conference on Parallel and Distributed Systems, ICPADS 2025
Country/TerritoryChina
CityHefei
Period14/12/2517/12/25

Keywords

  • ACL
  • eBPF
  • file system
  • sandbox
  • serverless computing

Fingerprint

Dive into the research topics of 'Reviving eBPF-Based Storage Isolation in FaaS via Model-Rule Decoupling'. Together they form a unique fingerprint.

Cite this