eBPF-sec: A Defensive Framework Against eBPF Attacks on Containers

Kejin Xu, Xi Wang, Lun Li, Jin Gao · 2024

The eBPF technology allows users to efficiently extend kernel functionalities and is widely used in cloud-native environments for security control, network monitoring, and system debugging, among other purposes. However, the advent of eBPF introduces new attack surfaces for containers. Attackers can exploit eBPF features to breach container isolation mechanisms and attack the host. Existing container protection mechanisms fail to ensure resistance against potential eBPF attacks while allowing normal use of eBPF functions within containers. In response to this situation, we propose the first defense framework for eBPF attacks in containers that can automatically generate defense strategies. This framework has the following characteristics: 1) Automatic generation of defense strategies: It can generate defense strategies based on the data produced during the normal operation of containers. 2) Nonintrusive: It does not require any modifications to the kernel or container runtime. 3) Low overhead: The application of numerous defense rules only introduces negligible overhead to the container. 4) Dynamic integration: The framework can be dynamically integrated into running containers without the need for stopping or restarting them. Finally, our experiments show that our method can effectively defend against potential eBPF attacks in containers while meeting users’ requirements for eBPF functionalities, with only negligible performance loss.

Read the paper · More papers on PaperTik