Publication | Open Access
Simple and precise static analysis of untrusted Linux kernel extensions
86
Citations
24
References
2019
Year
Unknown Venue
Internet Traffic AnalysisEngineeringInformation SecuritySoftware AnalysisFormal VerificationBerkeley Packet FilterHardware SecurityDenial-of-service AttackSystems EngineeringTrusted Execution EnvironmentTrusted Operating SystemEbpf EcosystemStatic AnalysisOperating System SecurityComputer EngineeringFirewall (Computing)Computer ScienceStatic Program AnalysisData SecurityCryptographySoftware SecurityPrecise Static AnalysisProgram AnalysisNetwork Traffic MeasurementSystem Software
Extended Berkeley Packet Filter (eBPF) is a Linux subsystem that allows safely executing untrusted user-defined extensions inside the kernel. It relies on static analysis to protect the kernel against buggy and malicious extensions. As the eBPF ecosystem evolves to support more complex and diverse extensions, the limitations of its current verifier, including high rate of false positives, poor scalability, and lack of support for loops, have become a major barrier for developers.
| Year | Citations | |
|---|---|---|
Page 1
Page 1