arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

eBPF 安全实态:结构集中性、失效机制与发现缺口

eBPF Security in the Wild: Structural Concentration, Failure Mechanisms, and Discovery Gaps

Baihong Chen, Hua Ming, Weifeng Pan, Tian Xie, Xiaojun Qi, Wen Li

arXiv 2609.26254首次发表:更新:

发表机构

Utah State University; University of Michigan; Zhejiang Gongshang University(犹他州立大学; 密歇根大学; 浙江工商大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究实证分析eBPF漏洞,发现其结构集中而非分散,运行时为主要暴露面,原始覆盖率不足以衡量发现有效性。

AI 中文摘要

扩展伯克利包过滤器(eBPF)是一个安全关键的内核内执行框架,然而其漏洞景观在组件、语义鸿沟和测试技术之间仍然支离破碎。我们针对已观测到的 eBPF 漏洞开展了一项实证研究。我们从 Linux 内核修复提交、syzbot 报告和公开的 CVE/NVD 记录中构建了一个多源数据集,并通过一个统一框架对其进行分析,该框架涵盖了结构集中性、机制级失效模式、架构分布以及代表性技术中的发现缺口。我们的结果表明,已观测到的 eBPF 漏洞景观在结构上是集中的,而非广泛分散于许多不相关的弱点类型中。主导部分与一组有限的反复出现的系统级失效相关,尤其是在运行时执行、并发、对象生命周期管理以及跨可信阶段的语义不一致方面。这些失效在 eBPF 流水线中分布不均:运行时是主要的暴露面,而验证器(Verifier)和即时编译器(JIT)则是低频但结构上独特的安全边界。一项基于规则的代表性技术比较以及针对 Linux v5.10 的版本对齐 Syzkaller 案例研究表明,尽管运行时、验证器和 JIT 的原始覆盖率明显,但有效探索在语义上是狭窄的,且观测到的发现集中在运行时失效的一个小子集中。总体而言,仅凭原始覆盖率无法完整反映发现有效性。

英文摘要

Extended Berkeley Packet Filter (eBPF) is a security-critical in-kernel execution framework, yet its vulnerability landscape remains fragmented across components, semantic gaps, and testing techniques. We present an empirical study of observed eBPF vulnerabilities. We construct a multi-source dataset from Linux kernel fixing commits, syzbot reports, and public CVE/NVD records, and analyze it through a unified framework covering structural concentration, mechanism-level failure modes, architectural distribution, and discovery gaps in representative techniques. Our results show that the observed eBPF vulnerability landscape is structurally concentrated rather than broadly dispersed across many unrelated weakness types. The dominant portion is associated with a limited set of recurring system-level failures, especially in runtime execution, concurrency, object lifecycle management, and semantic inconsistencies across trusted stages. These failures are unevenly distributed across the eBPF pipeline: Runtime is the dominant exposure surface, whereas the Verifier and JIT are lowerfrequency but structurally distinct security boundaries. A rubric-based comparison of representative techniques and a version-aligned Syzkaller case study on Linux v5.10 show that, despite visible raw coverage of Runtime, Verifier, and JIT, effective exploration is semantically narrow, and observed discoveries concentrate in a small subset of Runtime failures. Overall, raw coverage alone provides an incomplete view of discovery effectiveness.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑