Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to implement comprehensive file tracking systems using eBPF technology in this 23-minute conference talk from the Linux Plumbers Conference. Discover how to develop real-time detection mechanisms for sensitive file creation and establish complete lifecycle monitoring including renames, moves, deletions, compression, decompression, and uploads. Explore the technical challenges of designing reliable file tagging methods that maintain persistent identifiers across file transformations and system operations. Understand the complexities of developing heuristics to detect upload and download activities through various system calls and network behaviors. Examine strategies for extending file tracking capabilities to monitor transfers between multiple systems, enabling detection of potential data exfiltration and unauthorized access attempts at scale. Gain insights into leveraging eBPF for building robust security mechanisms that protect against user data theft and AI model theft while maintaining detailed file lineage records.
Syllabus
Tracking Files across the operating system using eBPF - Carl El Khoury
Taught by
Linux Plumbers Conference