• [$] Sending packets directly from BPF

    From LWN.net@86:200/23 to All on Wed Jul 15 06:40:08 2026


    Tetragon, the BPF-based security monitoring tool,
    uses BPF to monitor different aspects of a running kernel and
    enforce user-specified policies. It sends its data to a user-space process, which forwards the data to a central monitoring service elsewhere in the network, however. This
    presents a point of vulnerability: if an attacker can kill Tetragon's user-space
    agent, it won't be able to properly report on the situation. Song Liu, Mahé Tardy, and Liam Wiseheart spoke about their work removing the need for the user-space agent at the 2026

    Linux Storage, Filesystem, Memory-Management, and
    BPF Summit.

    https://lwn.net/Articles/1081696/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (86:200/23)