Research Report: Enhanced eBPF Verification and eBPF-based Runtime Safety Protection

被引:0
|
作者
Jin, Guang [1 ]
Li, Jason [1 ]
Briskin, Greg [1 ]
机构
[1] Trusted Sci & Technol Inc, Rockville, MD 20850 USA
关键词
cybersecurity; formal verification; eBPF; runtime verification;
D O I
10.1109/SPW63631.2024.00026
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The extended Berkeley Packet Filter (eBPF) technology has been extending the capabilities of current Operating Systems (OSs) rapidly in recent years. The eBPF community is wellaware of using formal verification methods to ensure the security of eBPF programs. However, each of the two primary kinds of formal methods, namely abstract interpretation and symbolic execution, comes with their own set of pros and cons. This research report presents our formal eBPF verification approach, which combines the merits of both types of formal methods to ensure soundness, completeness, precision and recall for our solution. This solid security foundation makes eBPF-based applications particularly appealing in the field of cybersecurity. In addition, this research report describes our eBPF-based solution to enhance the runtime security for prebuilt user-space programs. Grounded in a formally provable security foundation, our eBPF-based runtime safety monitoring solution avoids introducing new errors, offers customization to counter various vulnerabilities, and eliminates the need for offline instrumentation.
引用
收藏
页码:224 / 230
页数:7
相关论文
共 50 条
  • [31] Requirement engineering for active safety pedestrian protection systems based on accident research
    Froeming, R.
    Schindler, V.
    Kuehn, M.
    ADVANCED MICROSYSTEMS FOR AUTOMOTIVE APPLICATIONS 2006, 2006, : 79 - 106
  • [32] Research on Modern Tram Auxiliary Safety Protection Technology Based on Obstacles Detection
    Wang, Gang
    Zeng, Xiaoqing
    Bian, Dong
    Wang, Weiyang
    INTERNATIONAL SYMPOSIUM FOR INTELLIGENT TRANSPORTATION AND SMART CITY (ITASC) 2017 PROCEEDINGS, 2017, 62 : 37 - 50
  • [33] Research on safety protection of smart microgrid operation control based on automatic regulation
    Shi G.
    International Journal of Mechatronics and Applied Mechanics, 2021, 1 (09): : 58 - 63
  • [34] Research on the Protection of Cultivated Land Based on Food Safety: A Piece of Literature Review
    Hu, Qin
    Wei, Junying
    He, Puming
    2017 6TH INTERNATIONAL CONFERENCE ON APPLIED SOCIAL SCIENCE (ICASS 2017), PT 1, 2017, 97 : 396 - 400
  • [35] Development and Verification of Microclimate Control System for Enhanced Driver Comfort and Safety Based on Skin Resistance Measurements
    Kollarik, Rastislav
    Vitazek, Ivan
    Janca, Jan
    Jukic, Zeljko
    ACTA TECHNOLOGICA AGRICULTURAE, 2024, 27 (04) : 227 - 233
  • [36] Analysis and countermeasure research on management mechanism of hazardous chemicals based on active safety protection
    Liu Z.
    Chemical Engineering Transactions, 2018, 71 : 649 - 654
  • [37] Research of building safety management system of reply protection in Power Company based on workflow
    Chen, Xing
    ENERGY AND POWER TECHNOLOGY, PTS 1 AND 2, 2013, 805-806 : 1190 - 1193
  • [38] RESEARCH ON SAFETY AND ENVIRONMENTAL PROTECTION CONTROL METHODS BASED ON UNDERGROUND AND FOUNDATION PIT ENGINEERING
    Chen, Weiguo
    FRESENIUS ENVIRONMENTAL BULLETIN, 2020, 29 (12): : 10832 - 10839
  • [39] Research on safety verification methods of static data of train control systems based on deep association rules
    Wang, Tongdian
    Xu, Qingyang
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (09): : 13124 - 13140
  • [40] Research on influencing factors of food safety internet rumor attention based on protection motivation theory
    Hong W.
    Wang C.
    Wu L.
    Pu X.
    Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2022, 42 (11): : 3121 - 3138