Skip to content

Author

Stamatios Kostopoulos

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access Aug 2026

eBPF-based cybersecurity mechanisms: a systematic literature review

Extended Berkeley Packet Filter (eBPF) has emerged as a kernel-level programmable framework enabling dynamic security enforcement in modern operating systems. While eBPF’s potential for cybersecurity applications has attracted significant research attention, existing work remains fragmented across disparate domains, evaluation methodologies, and deployment contexts. This systematic literature review applies PRISMA methodology to identify, categorize, and synthesize peer-reviewed research on eBPF-based cybersecurity mechanisms. Following structured screening of 3735 records from six databases, 54 primary studies published between 2018-2026 were analyzed and organized into a seven-domain taxonomy spanning DDoS mitigation, intrusion detection, Internet-of-Things (IoT) security, container security, microservice protection, networking, and security tools and frameworks. Analysis reveals that eBPF enables low-overhead security enforcement (median 2.4% overhead [1.1–8.6%] of the average CPU usage, ranging from negligible nanosecond-scale costs for infrequently used hooks to higher 10–20% CPU percentages for kernel hot paths) with high detection accuracy (94–99%) across domains, particularly excelling in kernel-level monitoring, real-time packet processing, and cloud-native workload protection. However, significant challenges persist: verifier-imposed constraints limit algorithm complexity, 85.1% (46/54) of studies require low-level programming expertise, kernel version fragmentation hinders portability, and 96.2% (52/54) of research fails to address eBPF’s own security vulnerabilities. The review identifies critical research gaps in multi-tenant isolation, adversarial machine learning (ML) robustness, production validation, and standardized evaluation frameworks. By consolidating fragmented knowledge and highlighting architectural trade-offs between safety and expressiveness, this work provides a foundation for next-generation eBPF security systems and outlines actionable directions for kernel programmability research.

Stamatios Kostopoulos, Panagiotis Tsakonas, Evangelos K. Markakis · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.