Loading…
June 26 - 27 | Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Linux Security Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (MDT | UTC-6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."
Thursday June 26, 2025 11:05am - 11:50am MDT
In recent years, security researchers and companies have looked to eBPF to build innovative security mechanisms with kernel independent bytecode and a soft guarantee of runtime safety. eBPF and the eBPF LSM in particular are especially useful in environments with bespoke security requirements where other LSMs cannot be or are not used, or kernel rebooting/recompilation is undesirable.
However, eBPF programs, but their nature, present a unique security challenge: any privileged process can fully manipulate the inner workings of all eBPF objects. While SELinux provides a level of coarse-grained access control over eBPF, it is difficult for eBPF developers to tailor SELinux policy to protect their individual tools.
This talk attempts to fill the gap by presenting an eBPF-based mandatory access control framework for protecting eBPF-based tools. The framework uses a configurable policy and no code change required for other tools to opt-in. We will present the design, implementation, and a policy example. We will also highlight areas for future work in the eBPF and LSM subsystems to provide more granular access controls.
Speakers
avatar for Alan Wandke

Alan Wandke

Computer Systems Researcher, National Security Agency
Alan Wandke is a computer systems researcher within the Laboratory for Advanced Cybersecurity Research at the National Security Agency. His technical expertise includes computer science and cybersecurity with a focus on operating systems and cloud security. Recently his research focus... Read More →
avatar for Jacob Satterfield

Jacob Satterfield

Computer Systems Researcher, National Security Agency
Jacob Satterfield is a senior computer systems researcher within the Laboratory for Advanced Cybersecurity Research (LACR) organization of the National Security Agency, where he performs R&D on novel Linux security mechanisms and trusted computing technologies. His technical experience... Read More →
Thursday June 26, 2025 11:05am - 11:50am MDT
Room BBB 3G+3H

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link