Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

BpfJailer - eBPF Based Mandatory Access Control

Linux Plumbers Conference via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore Meta's innovative approach to mandatory access control through this 32-minute conference talk from the Linux Plumbers Conference. Learn how BpfJailer leverages eBPF technology to address critical security challenges in AI workloads and user data protection at Meta scale. Discover the implementation of eBPF-based LSM (Linux Security Module) for jailing untrusted code execution in AI training and prompt processing environments, where microVMs operate within Meta's flat network architecture alongside sensitive workloads. Examine the sophisticated security mechanisms used to protect user data in Meta Private Processing through Confidential Virtual Machines (CVMs), including enforcement of signed binaries, command line argument validation, and prevention of tampering by root users through blocking debuggers and /proc access. Delve into the technical challenges of implementing jailing techniques with bpf LSM, protecting bpf LSM programs and agents from tampering, implementing binary and integrity checks, managing bpf LSM agents at scale, and integrating bpf-based enforcement into containerized workloads. Gain insights into both solved implementations and ongoing challenges in the eBPF security space from Meta's real-world deployment experience.

Syllabus

BpfJailer: eBPF based Mandatory Access Control - Liam Wisehart (Meta)

Taught by

Linux Plumbers Conference

Reviews

Start your review of BpfJailer - eBPF Based Mandatory Access Control

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.