Tag: Linux security

eBPF for DDoS protection
eBPF Use Cases

Protect Linux from DDoS with eBPF

I build small, safe kernel programs that stop high-rate packet floods at the NIC driver level so the system stays responsive under stress. XDP runs before the Linux networking stack, letting an ebpf program parse headers, count packets per source IP, and drop bursts with minimal latency. My approach uses a BPF hash map keyed […]

William 
eBPF IDS Linux
eBPF Use Cases

Create eBPF IDS on Linux

I will walk you through a working eBPF IDS Linux setup that hooks kernel events, streams signals to user space, and keeps performance predictable. I start from how the verifier and JIT work in the linux kernel so you can pick the right attach points. I explain kprobes, tracepoints, uprobes, XDP, and LSM in plain […]

William 
eBPF port scanning detection
Security Tools

Detect Port Scans with eBPF

The eBPF port scanning detection approach shows how kernel-level programs can answer TCP SYNs without leaving the fast path. I guide you through a compact XDP example that reads Ethernet, IPv4, and TCP headers in the kernel. You will see how a simple program spots a SYN and replies with a SYN-ACK to emulate an […]

William 
eBPF shell detection
Security Tools

Detect Shell with eBPF

I use eBPF shell detection to catch stealthy programs that land inside the kernel and then hide from normal tools. You will see why watching load-time events matters more than chasing artifacts later. The kernel grants deep visibility into system activity, but that same access gives attackers a way to hide a reverse shell or […]

William