Systems and Network Security with eBPF

Santiago Horacio Nicolau, Juan Carlos Hernández, Marcelo Arroyo · 2024

eBFP technology allows users to develop special programs that will be executed in the context of an operating system kernel. Initially, the project was aimed at packet filter development but later evolved to enable other operations such as observability, performance and security. This article describes the main concepts of eBPF, development tools and their application in the implementation of system and network security policies in GNU/Linux systems.

Read the paper · More papers on PaperTik