An In-Depth Analysis of eBPF-Based System Security Tools in Cloud-Native Environments
Jin Her, Jongseop Kim, Jinwoo Kim, Seungsoo Lee · IEEE Access · 2025
Kubernetes-based microservice architectures are central to modern cloud-native environments, offering flexibility, scalability, and diverse use cases. Given their large-scale and complex deployments, auditing is crucial for detecting potential threats. To address this need, various eBPF (extended Berkeley Packet Filter)-based security tools (ESSTs) have been developed, leveraging eBPF to monitor process and network activities in Kubernetes environments, log suspicious events, and enforce security policies. However, administrators often face challenges in selecting the most suitable ESST due to a lack of comprehensive comparative analyses. In this paper, we conduct an in-depth evaluation of four widely used ESSTs—KubeArmor, Falco, Tetragon, and Tracee—focusing on their internal architectures, auditing capabilities, overall performance, and real-world case studies in practice. Based on our findings, we provide key insights to guide administrators in selecting the appropriate ESST for their specific needs. We believe our research enhances the understanding of ESSTs, contributing to the development of more secure and high-performance cloud-native environments.