{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T06:19:00Z","timestamp":1783059540726,"version":"3.54.6"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T00:00:00Z","timestamp":1773705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T00:00:00Z","timestamp":1773705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,17]]},"DOI":"10.1109\/saner67736.2026.00076","type":"proceedings-article","created":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T19:41:17Z","timestamp":1783021277000},"page":"1-6","source":"Crossref","is-referenced-by-count":0,"title":["eBPF-VulnBench: A Benchmark of Real-World eBPF Malicious Bytecode"],"prefix":"10.1109","author":[{"given":"Yujin","family":"Kwon","sequence":"first","affiliation":[{"name":"School of Computer Science, Engineering and Converged Technology, Duksung Women&#x0027;s University,Seoul,Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yujeong","family":"Choi","sequence":"additional","affiliation":[{"name":"Duksung Women&#x0027;s University,Department of Cyber Security,Seoul,Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dohwan","family":"Ji","sequence":"additional","affiliation":[{"name":"Hanbat National University,Department of Information and Communication Engineering,Daejeon,Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinyoung","family":"Kim","sequence":"additional","affiliation":[{"name":"Sungkyunkwan University,Department of Software,Suwon,Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3371038"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/HPSR.2018.8850758"},{"key":"ref3","first-page":"375","article-title":"{XRP}:{In-Kernel} storage functions with {eBPF}","volume-title":"16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22)","author":"Zhong","year":"2022"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3672197.3673430"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/AICIT62434.2024.10730620"},{"key":"ref6","first-page":"5971","article-title":"Cross container attacks: The bewildered {eBPF} on clouds","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"He","year":"2023"},{"key":"ref7","volume-title":"Analysis and testing of ebpf attack surfaces","author":"Messina","year":"2024"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3614389"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00134"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3643778"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3609510.3609822"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.5220\/0012470800003648"},{"key":"ref13","article-title":"Detection methods of ebpf-based rootkits in linux","author":"Stry\u030c\u010dek","year":"2024","journal-title":"BOOK OF ABSTRACTS"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3609021.3609305"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3688808"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3748355.3748374"},{"key":"ref17","volume-title":"TripleCross: A linux ebpf rootkit with backdoor, c2, library injection, execution hijacking, persistence and stealth capabilities","author":"Bajo","year":"2022"},{"key":"ref18","volume-title":"eBPF-Attack: Poc for \u201ccross container attacks: The bewildered ebpf on clouds","author":"He","year":"2023"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3689938.3694781"},{"key":"ref20","first-page":"7467","article-title":"Approximation enforced execution of untrusted linux kernel extensions","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Sun","year":"2025"},{"key":"ref21","article-title":"bpftime: userspace ebpf runtime for uprobe, syscall and kernel-user interactions","author":"Zheng","year":"2023","journal-title":"arXiv preprint"},{"key":"ref22","article-title":"Wasm-bpf: Streamlining ebpf deployment in cloud environments with webassembly","author":"Zheng","year":"2024","journal-title":"arXiv preprint"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CNS66487.2025.11194984"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom62794.2024.00035"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC61673.2024.10733575"},{"key":"ref26","article-title":"SANER2026 Artifact Repository","volume-title":"Supplementary materials for ebpfvulnbench","year":"2026"}],"event":{"name":"2026 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)","location":"Limassol, Cyprus","start":{"date-parts":[[2026,3,17]]},"end":{"date-parts":[[2026,3,20]]}},"container-title":["2026 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11576582\/11576527\/11576669.pdf?arnumber=11576669","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T05:38:16Z","timestamp":1783057096000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11576669\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,17]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/saner67736.2026.00076","relation":{},"subject":[],"published":{"date-parts":[[2026,3,17]]}}}