Netinfo Security ›› 2024, Vol. 24 ›› Issue (4): 534-544.doi: 10.3969/j.issn.1671-1122.2024.04.004

Previous Articles     Next Articles

An eBPF-Based Threat Observability System for Cloud-Oriented Environment

LIU Sinuo1,2, RUAN Shuhua1,2(), CHEN Xingshu1,2, ZHENG Tao1,2   

  1. 1. School of Cyber Science and Engineering, Sichuan University, Chengdu 610065, China
    2. Cyber Science Research Institute, Sichuan University, Chengdu 610065, China
  • Received:2024-01-29 Online:2024-04-10 Published:2024-05-16

Abstract:

As the types of threats in the cloud and the diversity of attack vectors increase, single-dimensional threat data struggles to accurately portray complex and ever-changing threat behaviors. This paper proposed ETOS (eBPF-based threat observability system), a multi-level threat observation system tailored for cloud environments. By assessing the risk of each action within threat behaviors, ETOS strategically setd up observation points for hierarchical classification of critical actions, dynamically activates eBPF probes as needed on the target machines, and thus acquiring multi-dimensional structured threat behavior data. This approach effectively represents threat behaviors in cloud environments, significantly reduces the preprocessing cost for data analysis. We also designed a generic eBPF threat probe template to automate the expansion of the probe library. ETOS was examined on a container cloud platform by reproducing 18 container escape CVE and observing their threat behaviors. The experimental results show that ETOS is capable of observing threat behaviors on multiple levels, collecting multi-dimensional structured threat data. The introduced overhead on the system and network remains below 2%, meeting the operational requirements of cloud platforms.

Key words: threat observability, eBPF observability, cloud computing security, data acquisition

CLC Number: