SeCoNetBench: A modular framework for secure container networking benchmarks

Research output: Contribution to book/conference proceedings/anthology/reportConference contributionContributed



Container security, especially in the quest for controlled access and secured communication between containers, has spawned a multitude of implementations, based on various concepts and design choices. They are characterized by very different performance properties, which so far have not comprehensively been benchmarked nor compared in a fair manner. The emerging paradigm of moving execution to edge clouds requires both: efficiency in the light of ephemeral containers and mobility, and security in the face of resource sharing between various tenants at hosts of various providers. In this paper we introduce SeCoNetBench, a modular benchmarking platform for container network security, and compare the most prominent frameworks for access control and network isolation in the container ecosystem. The results demonstrate that trade-offs have to be made during infrastructure deployment, and we provide guidelines for designing high-performance secure container networking platforms in adversarial settings.


Original languageEnglish
Title of host publicationProceedings - 4th IEEE European Symposium on Security and Privacy Workshops, EUROS and PW 2019
Number of pages8
ISBN (electronic)9781728130262
Publication statusPublished - 1 Jun 2019

External IDs

Scopus 85071924606