Skip to content
Open access

A Real-Time eBPF-Based Intrusion Detection Framework for Adaptive and Scalable Linux Kernel Security

Sep 2026 · Al-Farooq Journal of Sciences · 0 citations · 11 references

Abstract

The Linux kernel represents a critical attack surface due to its privileged execution level, making it a frequent target for attacks such as privilege escalation and advanced persistent threats (APTs). Traditional intrusion detection systems (IDS)typically operate in user space and rely on static or signature based techniques, limiting visibility into kernel-level activities. This paper presents a real-time intrusion detection framework based on Extended Berkeley Packet Filter (eBPF). The framework utilizes eBPF programs attached to kernel trace points and kprobes to capture runtime events with low overhead, enabling fine-grained system observability without requiring kernel modification or system restart. The proposed approach adopts behavior-based detection using contextual runtime features and a Random Forest classifier for runtime classification. Dynamic policy adaptation is supported through eBPF maps .The framework was evaluated using a controlled dataset containing approximately 38,000 kernel runtime events collected from benign activities and controlled attack scenarios. Experimental results achieved 99.92% accuracy and 0.99 recall while maintaining CPU utilization below 1% during continuous monitoring. Additional evaluation using the public DongTing benchmark dataset achieved 99.60% accuracy, demonstrating strong generalization capability across heterogeneous kernel behavior environments. The results indicate that combining eBPF monitoring with lightweight machine learning provides an effective and scalable approach for kernel-level intrusion detection in Linux systems.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.