Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop 2020
DOI: 10.1145/3411495.3421358
|View full text |Cite
|
Sign up to set email alerts
|

bpfbox

Abstract: Process confinement is a key requirement for workloads in the cloud and in other contexts. Existing process confinement mechanisms on Linux, however, are complex and inflexible because they are implemented using a combination of primitive abstractions (e.g., namespaces, cgroups) and complex security mechanisms (e.g., SELinux, AppArmor) that were designed for purposes beyond basic process confinement. We argue that simple, efficient, and flexible confinement can be better implemented today using eBPF, an emergi… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 11 publications
(1 citation statement)
references
References 6 publications
(7 reference statements)
0
1
0
Order By: Relevance
“…Researcher and developers have proposed and produced a wide range of innovative solutions based on eBPF. Examples include a sandboxing facility for containers [26],…”
Section: Ebpfmentioning
confidence: 99%
“…Researcher and developers have proposed and produced a wide range of innovative solutions based on eBPF. Examples include a sandboxing facility for containers [26],…”
Section: Ebpfmentioning
confidence: 99%