An eBPF-Based Programmable Network Architecture for OT Digital Resilience Use-Cases
Filip Holík, Simon Jouët, Dimitrios P. Pezaros · 2025
BPF has enabled, among other use-cases, highly scalable network softwarization via a fully programmable data plane architecture. Previous approaches such as software-defined networking (SDN) and P4 offered some degree of programmability, but required specialized target devices tailored mostly for high-performance data center environments. With eBPF, more complex network functions can be supported even on smaller form factor and lower capacity devices, making it a suitable network softwarization framework for Operation Technology (OT) networks. In our previous work, we introduced BPFabric a platform, protocol and language-independent SDN architecture leveraging a single eBPF program for the data plane implementation. In this work, we modify the original BPFabric architecture by adding an eBPF execution engine pipeline which supports network function chaining and allows sequencing of eBPF programs to achieve complex network functionality. Additionally, we add the application layer which hosts high-level services and provides network visualization and control via a northbound interface. We demonstrate the new architecture on a use-case of an OT network topology composed of programmable devices with various resilience eBPF functions managed by a single controller. The results show architecture flexibility in dynamic function orchestration while being fully transparent from OT devices and causing minimum performance overhead.