Enforcing SBOMs through the Linux kernel with eBPF and IMA

Alex Crawford, Eugene Yakubovich, Rob Szumski · 2023

At build-time, we generate SBOMs and sign containers. But at run-time, tools like Open Policy Agent and Kyverno only check the signatures or Kubernetes Pod attributes, not the full contents. Let's go beyond only checking container signatures and explore the possibility of checking an entire container against its software bill of materials (SBOM) in real time. This paper will discuss how features in the Linux kernel - Integrity Measurement Architecture (IMA) and eBPF - could eventually be used on a cluster's nodes to secure running containers and potentially other software. We are aiming to provide this protection without requiring a reboot or installing non-standard kernel modules. This would allow end users to protect machines via a Kubernetes DaemonSet or systemd unit without a need to tweak an operating system image or use a custom kernel.

Read the paper · More papers on PaperTik