YoVDO

Linux Monitoring at Scale with eBPF

Offered By: Security BSides San Francisco via YouTube

Tags

Security BSides Courses eBPF Courses

Course Description

Overview

Explore advanced Linux monitoring techniques using eBPF in this 29-minute conference talk from BSidesSF 2017. Delve into the implementation of Berkeley Packet Filter (BPF) virtual machine in recent Linux kernels, enabling safe and efficient syscall hooking. Learn about lightweight alerting strategies for large-scale environments, focusing on process execution, network connections, and file integrity monitoring. Discover how to achieve meaningful security monitoring with less than 1% overhead, balancing comprehensive fleet-wide alerting with targeted, in-depth scrutiny of specific subsets. Gain insights from experts Brendan Gregg and Alex Maestretti on leveraging eBPF for efficient, scalable Linux monitoring in security-critical environments.

Syllabus

BSidesSF 2017 - Linux Monitoring at Scale with eBPF (Brendan Gregg & Alex Maestretti)


Taught by

Security BSides San Francisco

Related Courses

Analyzing Postgres Performance Problems Using Perf and eBPF
Microsoft via YouTube
Citus Con - An Event for Postgres - Americas Livestream
Microsoft via YouTube
EBPF - The Next Power Tool of SREs
USENIX via YouTube
Kernel Tracing With EBPF
media.ccc.de via YouTube
Building Observability for 99% Developers
Docker via YouTube