Benutzer: Gast  Login
Titel:

Network Profiles for Detecting Application-Characteristic Behavior Using Linux eBPF

Dokumenttyp:
Konferenzbeitrag
Autor(en):
Wüstrich, Lars; Schacherbauer, Markus; Budeus, Markus; Freiherr von Künßberg, Dominik; Gallenmüller, Sebastian; Pahl, Marc-Oliver; Carle, Georg
Abstract:
Applications often show unique communication behavior. Knowledge about this behavior is beneficial in various use cases, such as anomaly or dependency detection. In this paper, we present network profiles that characterize typical application behavior. This requires a reliable and accurate association of processes and applications, which is challenging. We, therefore, introduce an eBPF-based matcher for this task that enables the creation of network profiles. In our evaluation we show that eBPF...     »
Stichworte:
application profiling, extended berkeley packet filter (eBPF)
Kongress- / Buchtitel:
Proceedings of the 1st Workshop on eBPF and Kernel Extensions
Verlag / Institution:
Association for Computing Machinery
Verlagsort:
New York, NY, USA
Jahr:
2023
Monat:
September
Seiten:
8–14
Print-ISBN:
9798400702938
Serientitel:
eBPF ’23
Volltext / DOI:
doi:10.1145/3609021.3609294
WWW:
https://doi.org/10.1145/3609021.3609294
 BibTeX