Downloads: 9
Original Research | Computer Science and Engineering | Volume 15 Issue 7, July 2026 | Pages: 40 - 75 | United States
Multi-Signal Trust Scoring for Cloud-Native Microservice Security: An eBPF-Based Framework for Stealth Attack Detection Without Sidecar Proxies
Abstract: Cloud-native microservice environments generate extensive east-west service communication that existing eBPF-based security tools-including Cilium Tetragon and Falco-cannot adequately detect stealth trust-boundary violations due to their reliance on single-signal detection. This work proposes Context-Aware eBPF Trust Boundary Evaluation (CA-eBPF), a sidecar-less detection framework that computes adaptive trust scores by continuously correlating five contextual dimensions-workload identity, behavioral consistency, network telemetry, process integrity, and distributed trace correlation-from kernel-level eBPF telemetry without requiring payload decryption. The framework is evaluated against four single- and dual-signal baselines through a controlled simulation study of 5,000 communication events, complemented by a real-cluster validation on AWS EC2 in which Cilium Tetragon captured 58,186 genuine kernel-level eBPF events confirming framework deployability and telemetry capture. In the simulation study, CA-eBPF achieved an F1-score of 92.42%, accuracy of 96.24%, and AUC-ROC of 0.995, with stealth attack detection of 89.20% compared to 65.20% for the best-performing baseline-a 24 percentage-point improvement attributable to multi-signal contextual scoring. An integrated eBPF-based enforcement design is presented; end-to-end enforcement validation and quantitative performance benchmarking against sidecar-based service meshes are identified as future work.
Keywords: eBPF, trust boundary evaluation, microservice security, sidecar-less architecture, Kubernetes, runtime security, stealth attack detection, contextual telemetry, cloud-native security
How to Cite?: Umashankara Kalaiah, "Multi-Signal Trust Scoring for Cloud-Native Microservice Security: An eBPF-Based Framework for Stealth Attack Detection Without Sidecar Proxies", Volume 15 Issue 7, July 2026, International Journal of Science and Research (IJSR), Pages: 40-75, https://www.ijsr.net/getabstract.php?paperid=SR26629100308, DOI: https://dx.doi.org/10.21275/SR26629100308