Artículos relacionados a eBPF LINUX SECURITY: A Practical Guide to eBPF, Linux...

eBPF LINUX SECURITY: A Practical Guide to eBPF, Linux Security, Observability, Networking, Tracing, Threat Detection, and Runtime Protection - Tapa blanda

Aurev, Zyren

 
9798174542945: eBPF LINUX SECURITY: A Practical Guide to eBPF, Linux Security, Observability, Networking, Tracing, Threat Detection, and Runtime Protection

Sinopsis

eBPF LINUX SECURITY

A Practical Guide to eBPF, Linux Security, Observability, Networking, Tracing, Threat Detection, and Runtime Protection

Linux environments are becoming more dynamic, distributed, and difficult to monitor. Containers, Kubernetes workloads, cloud infrastructure, microservices, and constantly changing applications require security visibility that can operate close to the Linux kernel.

eBPF Linux Security provides a practical and structured guide to using eBPF for modern Linux observability, threat detection, network security, and runtime protection.

Starting with the fundamentals, this book explains how eBPF programs, maps, hooks, bytecode, helpers, and the verifier work together. It then progresses into practical security monitoring, network protection, container security, Kubernetes environments, advanced eBPF engineering, and production operations.

Inside the Book, You’ll Learn How To:

  • Understand eBPF architecture and its role in modern Linux security
  • Work with eBPF programs, maps, hooks, helpers, and kernel interfaces
  • Use BCC, bpftrace, bpftool, and libbpf for security and observability
  • Monitor system calls, processes, files, users, and kernel activity
  • Build real-time Linux security telemetry with eBPF
  • Understand XDP and high-performance packet processing
  • Apply eBPF and TC to network filtering and security enforcement
  • Detect suspicious processes, commands, system calls, and network behavior
  • Identify indicators of privilege escalation, credential abuse, and persistence
  • Explore malware and rootkit detection using runtime behavioral evidence
  • Apply eBPF security techniques to containers, namespaces, and cgroups
  • Understand Kubernetes network security with eBPF and Cilium
  • Use BTF, CO-RE, and libbpf to develop more portable eBPF security programs
  • Explore BPF LSM and eBPF-based security enforcement
  • Design scalable detection and response architectures
  • Integrate eBPF telemetry with SIEM, SOC, and security platforms
  • Build production-grade Linux runtime security strategies
  • Troubleshoot verifier errors, compatibility issues, telemetry loss, and deployment problems
  • Optimize performance, control resources, and harden eBPF security infrastructure

Rather than presenting eBPF as a magic solution, this book explains where it is effective, where it has limitations, and how it should complement existing Linux security controls.

You’ll learn to distinguish observation from detection, detection from enforcement, and security telemetry from actionable intelligence, an essential foundation for building reliable runtime security systems.

Whether you are a Linux administrator, cybersecurity professional, SOC analyst, DevOps engineer, cloud engineer, Kubernetes practitioner, security researcher, or developer, this book provides a practical foundation for understanding and applying eBPF to real-world Linux security challenges.

If you want to move beyond traditional logs and gain deeper visibility into Linux runtime activity, network behavior, workloads, containers, and kernel-level events, this book gives you the concepts, tools, techniques, and production considerations to build that capability.

"Sinopsis" puede pertenecer a otra edición de este libro.