YoVDO

Kernel Tracing With EBPF

Offered By: media.ccc.de via YouTube

Tags

Conference Talks Courses System Analysis Courses System Security Courses eBPF Courses

Course Description

Overview

Explore the powerful capabilities of eBPF (extended Berkeley Packet Filter) for kernel tracing in Linux systems through this comprehensive 54-minute conference talk. Dive into the world of dynamic kernel instrumentation and learn how to gain deep insights into both kernel and userspace code across a running system. Discover practical applications of eBPF beyond code profiling, including defensive and offensive security techniques. Understand the internals of eBPF implementation in the Linux kernel, its features, and integration with various components. Learn about pragmatic approaches to using eBPF, non-idiomatic coding styles required for its sandbox, and potential vulnerabilities. Explore how eBPF can be used to trace kernel functions, inspect code and data flow, and even perform privilege escalation in certain container configurations. Gain valuable knowledge on using eBPF to monitor system actions performantly and uncover process secrets, ultimately unlocking a new level of system insight and control.

Syllabus

Introduction
What is eBPF
Why eBPF
Tracing
eBPF Code
STrace Output
UPF Validator
Kernel Mod
Security Monitoring
Limitations
eBPF


Taught by

media.ccc.de

Related Courses

Building Geospatial Apps on Postgres, PostGIS, & Citus at Large Scale
Microsoft via YouTube
Unlocking the Power of ML for Your JavaScript Applications with TensorFlow.js
TensorFlow via YouTube
Managing the Reactive World with RxJava - Jake Wharton
ChariotSolutions via YouTube
What's New in Grails 2.0
ChariotSolutions via YouTube
Performance Analysis of Apache Spark and Presto in Cloud Environments
Databricks via YouTube