Virtualizing eBPF with Late-Binding
Jing Zhang, Xiaguannan Song, Dong Du, Yubin Xia, Binyu Zang, Haibo Chen
摘要
While eBPF has become the de facto standard for kernel customization in cloud-native systems, its design implicitly assumes a single trust domain. Allowing multiple tenants to deploy their own eBPF programs breaks this assumption, making the system both insecure and inefficient. We identify the root cause as eBPF's static-binding model, which rigidly couples logical eBPF programs to physical kernel hooks, forcing tenants to contend for shared execution contexts.
We propose vBPF, a virtualization layer that shifts to a late-binding model. By repurposing physical hooks as generic interposition points and deferring the binding until the event is attributed at runtime, vBPF decouples tenant context from the underlying kernel. vBPF achieves this via three key mechanisms: (1) a Sniffer that accurately attributes interruptdriven events to tenants, (2) a Dispatcher that replaces linear traversal with scalable 𝑂 (1) program lookup, and (3) a compiler-assisted framework for state isolation. Implemented on Linux 6.12, vBPF enables the secure coexistence of multi-tenant workloads. Our evaluation shows that vBPF reduces latency by up to 3.9× (lmbench) and improves throughput by 29% (PostgreSQL) compared to native contention.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper28
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 被引用 156 次
- XRP: In-Kernel Storage Functions with eBPFYuhong Zhong, Haoyu Li, Yu Jian Wu, Ioannis Zarkadas 等OSDI 2022 · 被引用 100 次
- BMC: Accelerating Memcached using Safe In-kernel Caching and Pre-stack ProcessingYoann Ghigoff, Julien Sopena, Kahina Lazri, Antoine Blin 等NSDI 2021 · 被引用 79 次
- Electrode: Accelerating Distributed Protocols with eBPFYang Zhou, Zezhou Wang, Sowmya Dharanipragada, Minlan YuNSDI 2023 · 被引用 78 次
- Specification and verification in the field: Applying formal methods to BPF just-in-time compilers in the Linux kernelLuke Nelson, Jacob Van Geffen, Emina Torlak, Xi WangOSDI 2020 · 被引用 72 次
相关 Paper
- KRAKENGUARD: Towards Fine-Grained eBPF IsolationJainil Patel, Lucas Graeff Buhl-Nielsen, Adrien Ghosn, Marios KogiasNSDI 2026
- PeeR: First-Class Scheduling for Latency-Critical eBPF ApplicationsJeremy Carin, Ben Holmes, Weiyang Wang, Ankit Bhardwaj 等OSDI 2026
- Accelerating Nested Virtualization with HyperTurtleOri Ben Zur, Jakob Krebs, Shai Aviram Bergman, Mark SilbersteinUSENIX ATC 2025 · 被引用 2 次
- Enforcement of In-Kernel Stateful Security Policies via eBPFLetterio GallettaCCS 2026
- Validating the eBPF Verifier via State EmbeddingHao Sun, Zhendong SuOSDI 2024 · 被引用 18 次
