eIDPS: A real-time eBPF-based and Machine Learning-powered Network Intrusion Detection and Prevention Solution
Stamatios Kostopoulos, Dimitra Papatsaroucha, Ioannis Kefaloukos, Evangelos Markakis · 2025
As technology evolves rapidly, more and more critical infrastructures are going online. Malicious individuals more often than not try to exploit such infrastructures; thus, cyber-attacks have become a major issue for users and businesses. Current software applications struggle to confront the more sophisticated cyber-attacks that cyber-criminals use. Additionally, network security software applications, which utilize network packets for detecting cyber-attacks, consume a great amount of system resources, such as Central Processing Unit (CPU). This paper proposes a cyber-security software application, named eIDPs, which utilizes minimum system resources and employs novel technologies, such as the Extended Berkeley Packet Filter (eBPF), which can run virtualized functions directly in the kernel, as well as Machine Learning (ML) for analyzing packets, detecting and preventing various network attacks. To the best of our knowledge, this is the first time that such an implementation has been proposed on a packet-level regarding network intrusion detection and/or prevention. The proposed proof-of-concept method was compared to existing techniques for detecting and/or preventing cyber-attacks and the experiment results demonstrated its validity in terms of speed, efficiency, system resource consumption, attack detection, as well as faster cyber-attack prevention. Furthermore, the findings of this paper underline the necessity to shift focus to more advanced technologies that can not only identify but also prevent cyber-attacks in a shorter period of time and highlight the benefits offered by combining eBPF with ML when designing intrusion detection and prevention solutions.