YoVDO

Falco and eBPF: Optimizing Large-Scale Tracing Tools

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Falco Courses Scalability Courses Cloud Security Courses eBPF Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the challenges and potential of Falco and eBPF in high-throughput scenarios through this conference talk. Delve into the complexities of building large-scale tracing tools, focusing on Falco's use of BPF for tracing system events. Examine the portability issues across various kernel versions and the limitations they impose on leveraging modern BPF concepts. Learn about the current BPF probe architecture, its strengths, and daily criticalities. Discover potential mitigations for existing problems and future plans for improvement, including the exploitation of modern BPF tracing features where possible. Gain insights into instrumentation and consumer issues, current mitigations, and upcoming enhancements in this technical exploration of Falco and eBPF's capabilities and limitations.

Syllabus

Intro
Falco: a peculiar eBPF use case
How instrumentation works?
Consumer issue
Current mitigations
Instrumentation issue
Future enhancements
The portability issue


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Bypassing Falco - Cluster Compromise Without Tripping the SOC
secwestnet via YouTube
Introduction to Falco - Cloud-Native Runtime Security
Rawkode Academy via YouTube
Overcoming CVE Shock - Adding Perspective in Vulnerability Scanning
Devoxx via YouTube
How to Secure a Kubernetes Cluster from Scratch
Devoxx via YouTube
Tools to Help You Secure Your Kubernetes Cluster
Devoxx via YouTube