A Fresh Look at the Architecture and Performance of Contemporary Isolation Platforms

10/21/2021
by   Vincent van Rijn, et al.
0

With the ever-increasing pervasiveness of the cloud computing paradigm, strong isolation guarantees and low performance overhead from isolation platforms are paramount. An ideal isolation platform offers both: an impermeable isolation boundary while imposing a negligible performance overhead. In this paper, we examine various isolation platforms (containers, secure containers, hypervisors, unikernels), and conduct a wide array of experiments to measure the performance overhead and degree of isolation offered by the platforms. We find that container platforms have the best, near-native, performance while the newly emerging secure containers suffer from various overheads. The highest degree of isolation is achieved by unikernels, closely followed by traditional containers.

READ FULL TEXT

page 5

page 7

page 9

research
09/03/2020

Enclave-Aware Compartmentalization and Secure Sharing with Sirius

Hardware-assisted trusted execution environments (TEEs) are critical bui...
research
05/07/2021

SERVAS! Secure Enclaves via RISC-V Authenticryption Shield

Isolation is a long-standing challenge of software security. Traditional...
research
05/06/2020

Secure System Virtualization: End-to-End Verification of Memory Isolation

Over the last years, security kernels have played a promising role in re...
research
04/18/2023

Multitenant Containers as a Service (CaaS) for Clouds and Edge Clouds

Cloud computing, offering on-demand access to computing resources throug...
research
07/05/2022

Effect of boundary conditions on a high-performance isolation hexapod platform

Isolation of spacecraft microvibrations is essential for the successful ...
research
10/10/2021

Dynamic Process Isolation

In the quest for efficiency and performance, edge-computing providers el...
research
09/13/2019

Enumerating Isolated Cliques in Temporal Networks

Isolation has been shown to be a valuable concept in the world of clique...

Please sign up or login with your details

Forgot password? Click here to reset