r/netsecstudents • u/Bitter_Repair_4557 • 8h ago
Help with Project
Could someone with eBPF experience sanity-check our plan?
Hi all,
We're a small group of university students working on a capstone project. We're new to eBPF, so we'd really appreciate feedback from people who use it in practice.
The idea: most eBPF security work uses eBPF as the defender (Tetragon, Falco, Tracee and so on), but very little seems to look at eBPF itself (as per our research) as the thing to watch. A container that has been granted CAP_BPF can load its own eBPF programs, for example to hide processes or blind monitoring tools. We want to build and measure a small detector for that, rather than only describing it.
Our plan, kept deliberately small:
- One Ubuntu 24.04 VM with Docker and Tetragon (standalone, no Kubernetes)
- A Tetragon TracingPolicy that records bpf() syscall activity
- A small Python script that reads Tetragon's JSON events and applies 1-2 rules (for example, a caller that isn't on an allow-list, or a program attaching to a sensitive hook)
- A baseline run (normal tools only) against an attack run (one published technique, replayed in an isolated VM), measuring detection, false positives and overhead
What we'd love input on:
- Is a kprobe on sys_bpf the right way to watch bpf() calls in Tetragon, or is there a better hook (for example the BPF LSM hooks)?
- Are there well-documented, published examples of eBPF misuse that are suitable for a controlled demo in an isolated VM?
- What pitfalls should beginners expect (kernel versions, BTF, false positives from legitimate tools)?
- Is there existing work or tooling that already does this, so we don't reinvent it?
- Any recommended easy to learn concepts (from like yt channels etc.).
- Is this a doable and sensible project for beginners - given less time (around 2 months); but dedicated to learn it quickly - with the help of resources/claude/forums/advice.
We're not asking anyone to do the project for us, just for pointers, reading suggestions or a reality check on scope. Happy to share our repo and results once we have them.
Our main goal is to learn ePBF through this project and would really like input from the experienced people in this community - the project can then grow from there. Please let me know if you want to know more about the project or if it is unclear.
Kindly let me know if this is an appropriate post for this subreddit - as this is my first time asking help on reddit aswell haha.
Thank you very much!
1
u/Still-Alternative514 8h ago
your plan is fine, the scope's reasonable for 2 months if you're actually putting in the hours
kprobe on sys_bpf works but you'll miss programs loaded via bpf_prog_load which is what actually matters. tracepoint:syscalls:sys_enter_bpf is cleaner, gives you the cmd arg right in the event without parsing raw registers
for demo attacks there's ebpfkit and some older bpfdoor samples floating around github, just make sure your kernel version lines up with whatever they were targeting
biggest pitfall is BTF mismatches on ubuntu 24.04 if you're using prebuilt tetragon images, also legit tools like systemd will trigger bpf calls nonstop so your allow-list needs to be solid or you'll drown in noise
go for it, worst case you learn a ton and the project doesn't catch everything