Dec. 15, 2023, 10:41 p.m. | SANS Offensive Operations

SANS Offensive Operations www.youtube.com

eBPF-based security solutions are taking the cloud by storm. Many vendors shifted from traditional kernel-module based agents to eBPF agents to provide runtime security for Linux workloads in the cloud. This talk begins with a basic introduction to eBPF and runtime cloud security. It then discusses inherent weaknesses in eBPF-based security solutions and presents several techniques such as resource consumption attacks, memory map attacks, eBPF verifier vulnerabilities, time of check time of use exploits, and agent tampering that all may …

basic cloud cloud security ebpf exploits introduction kernel linux runtime runtime security security security solutions solutions storm vendors weaknesses workloads

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC