基于eBPF的网络安全机制:系统文献综述
eBPF-Based Cybersecurity Mechanisms: A Systematic Literature Review
AI总结:
该综述采用PRISMA方法分析54项eBPF安全研究,明确其低开销、高准确率的优势,指出存在的挑战与研究缺口,为下一代eBPF安全系统提供基础。
AI中文摘要:
扩展伯克利数据包过滤器(eBPF)已成为现代操作系统中支持动态安全实施的内核级框架。尽管eBPF的网络安全潜力已受到大量关注,但现有研究在领域、评估方法和部署场景方面仍较为零散。本系统文献综述采用PRISMA方法,识别、分类并综合分析了基于eBPF的网络安全机制的同行评审研究。在对六个数据库的3735条记录进行结构化筛选后,分析了54项2018至2026年的主要研究,并将其整理为七领域分类:DDoS缓解、入侵检测、物联网安全、容器安全、微服务保护、网络和安全工具。分析显示,eBPF可实现低开销的安全实施(CPU开销中位数为2.4%,范围1.1%-8.6%,从低频钩子的纳秒级成本到内核热路径的10%-20%不等),且检测准确率高(94%-99%)。它在内核级监控、实时数据包处理和云原生工作负载保护方面表现尤为突出。然而,仍存在重大挑战:验证器施加的约束限制了算法复杂性,85.1%(46/54)的研究需要低级编程专业知识,内核版本碎片化阻碍了可移植性,且96.2%(52/54)的研究未解决eBPF自身的漏洞。本综述明确了多租户隔离、对抗性机器学习(ML)鲁棒性、生产验证和标准化评估框架方面的关键研究缺口。通过整合零散知识并强调安全性与表达性之间的架构权衡,本研究为下一代eBPF安全系统提供了基础,并为内核可编程性研究提供了可行方向。
英文摘要:
Extended Berkeley Packet Filter (eBPF) has emerged as a kernel-level framework enabling dynamic security enforcement in modern operating systems. While eBPF's cybersecurity potential has attracted significant attention, existing work remains fragmented across domains, evaluation methodologies, and deployment contexts. This systematic literature review applies PRISMA methodology to identify, categorize, and synthesize peer-reviewed research on eBPF-based cybersecurity mechanisms. Following a structured screening of 3,735 records from six databases, 54 primary studies (2018-2026) were analyzed and organized into a seven-domain taxonomy: DDoS mitigation, intrusion detection, IoT security, container security, microservice protection, networking, and security tools. Analysis reveals eBPF enables low-overhead security enforcement (median 2.4% CPU overhead [1.1-8.6%], ranging from nanosecond-scale costs for infrequent hooks to 10-20% for kernel hot paths) with high detection accuracy (94-99%). It particularly excels in kernel-level monitoring, real-time packet processing, and cloud-native workload protection. However, significant challenges persist: verifier-imposed constraints limit algorithm complexity, 85.1% (46/54) of studies require low-level programming expertise, kernel version fragmentation hinders portability, and 96.2% (52/54) of research fails to address eBPF's own vulnerabilities. This review identifies critical research gaps in multi-tenant isolation, adversarial machine learning (ML) robustness, production validation, and standardized evaluation frameworks. By consolidating fragmented knowledge and highlighting architectural trade-offs between safety and expressiveness, this work provides a foundation for next-generation eBPF security systems and actionable directions for kernel programmability research.