Перейти к содержимому

eBPF for Security Engineers

Cisco DevNet

0:00 / 0:00

eBPF for Security Engineers

344 просмотра · 1 месяц назад
Cisco DevNet
39,9 тыс. подписчиков
344 просмотра · 1 месяц назад
Can the Linux kernel stop malicious code before it ever runs? Kyle Winders, Senior Technical Advocate at Cisco, breaks down eBPF for security engineers: what it is, why it matters, and how it works, with live demos covering packet filtering, remote code execution detection, and runtime enforcement. This session was originally presented at the Cisco DevNet Zone at Cisco Live Las Vegas 2026. The Beyond the DevNet Zone series brings those conversations to YouTube. 🔗 Resources • Free hands on labs → https://isovalent.com/labs/ • eBPF landing page → https://ebpf.io/ • Isovalent products → https://isovalent.com/product/ • Cisco U → https://u.cisco.com/ • Kyle's Cisco U courses → https://u.cisco.com/search/tutorial?t... • Cisco U YouTube channel →    / @ciscoutube   ⏱ Chapters 00:23 - Guest Intro 01:00 - What eBPF is? 05:36 - eBFP Use Cases 08:10 - eBFP Hello World 09:47 - What is a System Call? 10:15 - Hello World Example 11:48 - Packet Filtering 15:58 - Packet Filtering Example 20:12 - Remote Code Execution 21:40 - Remote Execution Example 24:46 - Network Enforcement 29:11 - Network Enforcement Example 32:35 - Runtime Enforcement 37:33 - Conclusion #CiscoDevNet #BeyondTheDevNetZone #eBPF #Linux