Speaker
Gürkan Gür
(Zurich University of Applied Sciences ZHAW)
Description
Although eBPF is widely used to extend the Linux kernel, running programs in kernel space introduces critical security risks. Existing technical work often overlooks eBPF's entire security lifecycle. This talk aims to address this gap by systematically analyzing eBPF vulnerabilities, mitigations, and architectural limits. By reviewing research papers and CVEs, we will map real-world exploits to specific components, revealing that current defenses target isolated attacks rather than systemic architectural risks. Finally, we will present key takeaways, outline open directions toward lifecycle-aware, composition-safe security models, and highlight understudied non-verifier components.
Authors
Mr
Gokcan Cantali
(Zurich University of Applied Sciences ZHAW)
Gürkan Gür
(Zurich University of Applied Sciences ZHAW)
Louie Wolf
(Zurich University of Applied Sciences ZHAW)
Mr
Tobias Leu
(Zurich University of Applied Sciences ZHAW)