Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

SeaBee - Defense for the Defense - eBPF-Based Mandatory Access Control Framework

Linux Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore an innovative eBPF-based mandatory access control framework designed to protect eBPF security tools in this 33-minute conference talk from the Linux Foundation. Learn how security researchers have leveraged eBPF to build cutting-edge security mechanisms with kernel-independent bytecode and runtime safety guarantees, particularly valuable in environments with specialized security requirements where traditional LSMs are unsuitable or kernel modifications are impractical. Discover the unique security challenges posed by eBPF programs, where privileged processes can manipulate all eBPF objects, and understand the limitations of SELinux's coarse-grained access control in protecting individual eBPF tools. Examine a comprehensive solution that addresses these gaps through a configurable policy framework requiring no code changes for tool adoption, including detailed coverage of the design, implementation, and practical policy examples. Gain insights into future development opportunities within eBPF and LSM subsystems for implementing more granular access controls, presented by cybersecurity experts from the National Security Agency who demonstrate how to defend the defenders in the evolving landscape of eBPF security.

Syllabus

SeaBee: Defense for the Defense - Alan Wandke & Jacob Satterfield, National Security Agency

Taught by

Linux Foundation

Reviews

Start your review of SeaBee - Defense for the Defense - eBPF-Based Mandatory Access Control Framework

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.