eBPF-Based Cybersecurity Mechanisms: A Systematic Literature Review

📅 2026-08-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该研究通过PRISMA方法系统地回顾了基于eBPF的网络安全机制,分析其在不同领域的应用及挑战,旨在解决碎片化知识整合问题。
📝 Abstract
Extended Berkeley Packet Filter (eBPF) has emerged as a kernel-level framework enabling dynamic security enforcement in modern operating systems. While eBPF's cybersecurity potential has attracted significant attention, existing work remains fragmented across domains, evaluation methodologies, and deployment contexts. This systematic literature review applies PRISMA methodology to identify, categorize, and synthesize peer-reviewed research on eBPF-based cybersecurity mechanisms. Following a structured screening of 3,735 records from six databases, 54 primary studies (2018-2026) were analyzed and organized into a seven-domain taxonomy: DDoS mitigation, intrusion detection, IoT security, container security, microservice protection, networking, and security tools. Analysis reveals eBPF enables low-overhead security enforcement (median 2.4% CPU overhead [1.1-8.6%], ranging from nanosecond-scale costs for infrequent hooks to 10-20% for kernel hot paths) with high detection accuracy (94-99%). It particularly excels in kernel-level monitoring, real-time packet processing, and cloud-native workload protection. However, significant challenges persist: verifier-imposed constraints limit algorithm complexity, 85.1% (46/54) of studies require low-level programming expertise, kernel version fragmentation hinders portability, and 96.2% (52/54) of research fails to address eBPF's own vulnerabilities. This review identifies critical research gaps in multi-tenant isolation, adversarial machine learning (ML) robustness, production validation, and standardized evaluation frameworks. By consolidating fragmented knowledge and highlighting architectural trade-offs between safety and expressiveness, this work provides a foundation for next-generation eBPF security systems and actionable directions for kernel programmability research.
Problem

Research questions and friction points this paper is trying to address.

eBPF
Cybersecurity
Kernel-level Framework
Evaluation Methodologies
Deployment Contexts
Innovation

Methods, ideas, or system contributions that make the work stand out.

eBPF
Cybersecurity
Low-overhead Security Enforcement
Real-time Packet Processing
Cloud-native Workload Protection
🔎 Similar Papers
No similar papers found.
S
Stamatios Kostopoulos
Department of Electrical & Computer Engineering, Hellenic Mediterranean University, Heraklion, Greece
P
Panagiotis Tsakonas
Department of Electrical & Computer Engineering, Hellenic Mediterranean University, Heraklion, Greece
Evangelos K. Markakis
Evangelos K. Markakis
Electrical & Computer Engineering, Hellenic Mediterranean University
Edge NetworkingBroadband NetworksCyber SecurityEmergency CommunicationsPublic Safety