Brendan Gregg 4/27/2023

eBPF Observability Tools Are Not Security Tools

Read Original

This article argues that eBPF observability tools are fundamentally designed for performance analysis with minimal overhead, not for security. Using them for security creates risks, as attackers can overwhelm them to cause event drops (like with tcpdump) or use other evasion techniques, leading to incomplete and unreliable security monitoring.

eBPF Observability Tools Are Not Security Tools

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

2
Designing Design Systems
TkDodo Dominik Dorfmeister 2 votes
4
Introducing RSC Explorer
Dan Abramov 1 votes
6
Fragments Dec 11
Martin Fowler 1 votes
7
Adding Type Hints to my Blog
Daniel Feldroy 1 votes
8
Refactoring English: Month 12
Michael Lynch 1 votes
10