CuraSec

Learn active

Systematic Review: eBPF Security Mechanisms Across 54 Studies (2018-2026)

2026-08-31 19:07 UTC · arXiv cs.CR · read the source ↗ #ebpf#kernel-security#cloud-native
  • Engineer — Learn: A thorough taxonomy of eBPF security applications across DDoS, container, and microservice domains with benchmarked overhead (median 2.4% CPU); useful for evaluating eBPF-based tooling or informing system design, but the notable finding that 96.2% of surveyed research ignores eBPF’s own attack surface is worth factoring into adoption decisions.
  • SOC/IR — Learn: Provides a structured overview of eBPF’s role in intrusion detection and real-time packet inspection with high reported accuracy (94-99%), which is useful background when evaluating eBPF-backed EDR or detection tools, though there are no actionable IOCs or detection content here.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.