A Real-Time eBPF-Based Intrusion Detection Framework for Adaptive and Scalable Linux Kernel Security
The Linux kernel represents a critical attack surface due to its privileged execution level, making it a frequent target for attacks such as privilege escalation and advanced persistent threats (APTs). Traditional intrusion detection systems (IDS)typically operate in user space and rely on static or signature based te...