Chaos Communication Congress

Chaos Communication Congress

Kernel Tracing With eBPF (35x159)


Data di messa in onda: Dic 30, 2018

Have you ever wanted to trace all syscalls or dump all IPC traffic across a Linux system? Until recently, doing so may have required some significant setup involving a half-baked tracing kernel module, a custom kernel module, or even using a kernel debugger. This talk will introduce the eBPF functionality of the Linux kernel and cover practical uses of the technology beyond mere code profiling. We will show how eBPF can be used both defensively and offensively to protect, or compromise, a system.

  • Posizione #
  • Iniziato: Dic 2011
  • Episodi: 1118
  • Followers: 0
  • Terminata
  • Sconosciuto
  • Sconosciuto