eBPF-Based Approach to Tracing System Calls and Predicting Privilege Escalation Attacks
Fábio Junior Bertinatto, Daniel Arioza Almeida, Jéferson Campos Nobre, Lisandro Zambenedetti Granville · 2024
The extensive adoption of containerized applications significantly raises the criticality of managing potential vulnerabilities, including privilege escalation within these environments. While the Bag of System Calls (BoSC) is a common technique to detect such attacks, tracing system calls in containerized applications is often inefficient for real-world scenarios. This paper proposes an eBPF-based solution to trace system calls in containerized applications and apply the BoSC technique to identify privilege escalation attempts within containers. We analyzed the cost of different system call hooking methods and found that raw tracepoint programs have the least overhead. Furthermore, we observed a slight increase in overhead when tracing all executed operations within a containerized application. Finally, we confirmed that our solution successfully identifies user efforts to escape containers, concluding that eBPF can be a powerful tool for containerized system security.