We're eBPF'd: Exploring Adversarial Manipulation of ELF Files in eBPF-Based Programmable Network Stacks

Joe Rose, Marco M. Cook, Filip Holík, Dimitrios P. Pezaros · 2025

Programmable Data Planes (PDP) have enabled customised per-packet forwarding behaviour deployed directly on programmable silicon. While the widely studied P4 data planes have proven highly-effective for data centre environments, they lack flexible and stateful functionality, particularly needed in edge device and host networking environments. eBPF is currently getting significant traction as a network programmability alternative for such environments through the deployment of Executable and Linkable Format (ELF) files to define the data plane behaviour. However, security concerns arise from the combination of high programmability enabled through eBPF, the lack of integrity checking within ELF files, and the exposure of southbound interfaces (node-local or network-wide) to control the PDP. In this paper, we investigate ELF file manipulation and the derived novel attack vectors within the context of eBPF software PDP implementations to disrupt network operations. We demonstrate the efficacy of four proposed attack types that target binary manipulation and runtime injection of ELF files in eBPF programs for PDP packet management. We evaluate the adversarial effects through an emulated testbed environment, and discuss practical countermeasures. Our primary results indicate the effectiveness of these attacks in creating a denial-of-service through a 100% increase in network packets across all nodes.

Read the paper · More papers on PaperTik