{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:38:38Z","timestamp":1782833918458,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/"}],"funder":[{"name":"NSERC Discovery Grant","award":["RGPIN-4468-2018"],"award-info":[{"award-number":["RGPIN-4468-2018"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,9]]},"DOI":"10.1145\/3411495.3421358","type":"proceedings-article","created":{"date-parts":[[2020,11,5]],"date-time":"2020-11-05T23:35:56Z","timestamp":1604619356000},"page":"91-103","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["bpfbox"],"prefix":"10.1145","author":[{"given":"William","family":"Findlay","sequence":"first","affiliation":[{"name":"Carleton University, Ottawa, ON, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anil","family":"Somayaji","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, ON, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Barrera","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, ON, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of Summer Usenix. http:\/\/cseweb.ucsd.edu\/classes\/wi11\/cse221\/papers\/accetta86","author":"Accetta Mike","year":"1986","unstructured":"Mike Accetta , Robert Baron , William Bolosky , David Golub , Richard Rashid , Avadis Tevanian , and Michael Young . 1986 . Mach: A new kernel foundation for UNIX development . In Proceedings of Summer Usenix. http:\/\/cseweb.ucsd.edu\/classes\/wi11\/cse221\/papers\/accetta86 .pdf Mike Accetta, Robert Baron, William Bolosky, David Golub, Richard Rashid, Avadis Tevanian, and Michael Young. 1986. Mach: A new kernel foundation for UNIX development. In Proceedings of Summer Usenix. http:\/\/cseweb.ucsd.edu\/classes\/wi11\/cse221\/papers\/accetta86.pdf"},{"key":"e_1_3_2_1_2_1","unstructured":"bcc authors. 2020. iovisor\/bcc. The IOVisor Project. https:\/\/github.com\/iovisor\/bcc  bcc authors. 2020. iovisor\/bcc. The IOVisor Project. https:\/\/github.com\/iovisor\/bcc"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/504390.504408"},{"key":"e_1_3_2_1_4_1","first-page":"131","article-title":"Checking for Race Conditions in File Accesses","volume":"9","author":"Bishop Matt","year":"1996","unstructured":"Matt Bishop and Michael Dilger . 1996 . Checking for Race Conditions in File Accesses . Computing Systems , Vol. 9 , 2 (1996), 131 -- 152 . https:\/\/static.usenix.org\/publications\/compsystems\/1996\/spr_bishop.pdf Matt Bishop and Michael Dilger. 1996. Checking for Race Conditions in File Accesses. Computing Systems, Vol. 9, 2 (1996), 131--152. https:\/\/static.usenix.org\/publications\/compsystems\/1996\/spr_bishop.pdf","journal-title":"Computing Systems"},{"key":"e_1_3_2_1_5_1","unstructured":"Bubblewrap authors. 2020. Bubblewrap. https:\/\/github.com\/containers\/bubblewrap  Bubblewrap authors. 2020. Bubblewrap. https:\/\/github.com\/containers\/bubblewrap"},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the Annual Conference on USENIX Annual Technical Conference","author":"Cantrill Bryan M.","unstructured":"Bryan M. Cantrill , Michael W. Shapiro , and Adam H. Leventhal . 2004. Dynamic Instrumentation of Production Systems . In Proceedings of the Annual Conference on USENIX Annual Technical Conference ( Boston, MA) (ATEC '04 ). USENIX Association, Berkeley, CA, USA, 2--2. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/usenix04\/tech\/general\/full_papers\/cantrill\/cantrill.pdf Bryan M. Cantrill, Michael W. Shapiro, and Adam H. Leventhal. 2004. Dynamic Instrumentation of Production Systems. In Proceedings of the Annual Conference on USENIX Annual Technical Conference (Boston, MA) (ATEC '04 ). USENIX Association, Berkeley, CA, USA, 2--2. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/usenix04\/tech\/general\/full_papers\/cantrill\/cantrill.pdf"},{"key":"e_1_3_2_1_7_1","volume-title":"NOMS 2020 - 2020 IEEE\/IFIP Network Operations and Management Symposium.","author":"Cassagnes C.","unstructured":"C. Cassagnes , L. Trestioreanu , C. Joly , and R. State . 2020. The rise of eBPF for non-intrusive performance monitoring . In NOMS 2020 - 2020 IEEE\/IFIP Network Operations and Management Symposium. C. Cassagnes, L. Trestioreanu, C. Joly, and R. State. 2020. The rise of eBPF for non-intrusive performance monitoring. In NOMS 2020 - 2020 IEEE\/IFIP Network Operations and Management Symposium."},{"key":"e_1_3_2_1_8_1","unstructured":"Kees Cook. 2010. [PATCH] security: Yama LSM. https:\/\/lkml.org\/lkml\/2010\/6\/21\/407  Kees Cook. 2010. [PATCH] security: Yama LSM. https:\/\/lkml.org\/lkml\/2010\/6\/21\/407"},{"key":"e_1_3_2_1_9_1","volume-title":"Notes from a container. LWN.net (October 29","author":"Corbet Jonathan","year":"2007","unstructured":"Jonathan Corbet . 2007. Notes from a container. LWN.net (October 29 2007 ). https:\/\/lwn.net\/Articles\/256389\/ Jonathan Corbet. 2007. Notes from a container. LWN.net (October 29 2007). https:\/\/lwn.net\/Articles\/256389\/"},{"key":"e_1_3_2_1_10_1","unstructured":"Jonathan Corbet. 2019. KRSI ? the other BPF security module. LWN.net (December 27 2019). https:\/\/lwn.net\/Articles\/808048\/  Jonathan Corbet. 2019. KRSI ? the other BPF security module. LWN.net (December 27 2019). https:\/\/lwn.net\/Articles\/808048\/"},{"key":"e_1_3_2_1_11_1","unstructured":"Glauber Costa. 2020. How io_uring and eBPF Will Revolutionize Programming in Linux. https:\/\/thenewstack.io\/how-io_uring-and-ebpf-will-revolutionize-programming-in-linux\/  Glauber Costa. 2020. How io_uring and eBPF Will Revolutionize Programming in Linux. https:\/\/thenewstack.io\/how-io_uring-and-ebpf-will-revolutionize-programming-in-linux\/"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 14st Large Installation Systems Administration Conference (LISA). USENIX Association","author":"Cowan Crispin","year":"2000","unstructured":"Crispin Cowan , Steve Beattie , Greg Kroah-Hartman , Calton Pu , Perry Wagle , and Virgil Gligor . 2000 . SubDomain: Parsimonious Server Security . In Proceedings of the 14st Large Installation Systems Administration Conference (LISA). USENIX Association , New Orleans, LA, United States. https:\/\/www.usenix.org\/legacy\/event\/lisa 2000\/full_papers\/cowan\/cowan.pdf Crispin Cowan, Steve Beattie, Greg Kroah-Hartman, Calton Pu, Perry Wagle, and Virgil Gligor. 2000. SubDomain: Parsimonious Server Security. In Proceedings of the 14st Large Installation Systems Administration Conference (LISA). USENIX Association, New Orleans, LA, United States. https:\/\/www.usenix.org\/legacy\/event\/lisa2000\/full_papers\/cowan\/cowan.pdf"},{"key":"e_1_3_2_1_13_1","unstructured":"Docker. 2020. Docker security. https:\/\/docs.docker.com\/engine\/security\/security\/  Docker. 2020. Docker security. https:\/\/docs.docker.com\/engine\/security\/security\/"},{"key":"e_1_3_2_1_14_1","unstructured":"Will Drewry. 2012. Dynamic seccomp policies (using BPF filters). https:\/\/lwn.net\/Articles\/475019\/  Will Drewry. 2012. Dynamic seccomp policies (using BPF filters). https:\/\/lwn.net\/Articles\/475019\/"},{"key":"e_1_3_2_1_15_1","unstructured":"Firejail authors. 2020. Firejail. https:\/\/firejail.wordpress.com\/  Firejail authors. 2020. Firejail. https:\/\/firejail.wordpress.com\/"},{"key":"e_1_3_2_1_16_1","unstructured":"Flatpak authors. 2020. Flatpak. https:\/\/flatpak.org\/  Flatpak authors. 2020. Flatpak. https:\/\/flatpak.org\/"},{"key":"e_1_3_2_1_17_1","volume-title":"Network and Distributed System Security (NDSS) Symposium. Internet Society","author":"Garfinkel Tal","year":"2004","unstructured":"Tal Garfinkel , Ben Pfaff , and Mendel Rosenblum . 2004 . Ostia: A Delegating Architecture for Secure System Call Interposition .. In Network and Distributed System Security (NDSS) Symposium. Internet Society , San Diego, California. https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/ 2017\/09\/Ostia-A-Delegating-Architecture-for-Secure-System-Call-Interposition-Tal-Garfinke.pdf Tal Garfinkel, Ben Pfaff, and Mendel Rosenblum. 2004. Ostia: A Delegating Architecture for Secure System Call Interposition.. In Network and Distributed System Security (NDSS) Symposium. Internet Society, San Diego, California. https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/2017\/09\/Ostia-A-Delegating-Architecture-for-Secure-System-Call-Interposition-Tal-Garfinke.pdf"},{"key":"e_1_3_2_1_18_1","unstructured":"Ian Goldberg David Wagner Randi Thomas and Eric Brewer. 1996. A Secure Environment for Untrusted Helper Applications (Confining the Wily Hacker). In USENIX Security. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/sec96\/full_papers\/goldberg\/goldberg.pdf  Ian Goldberg David Wagner Randi Thomas and Eric Brewer. 1996. A Secure Environment for Untrusted Helper Applications (Confining the Wily Hacker). In USENIX Security. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/sec96\/full_papers\/goldberg\/goldberg.pdf"},{"key":"e_1_3_2_1_19_1","volume-title":"Mac OS X, and FreeBSD","author":"Gregg Brendan","unstructured":"Brendan Gregg and Jim Mauro . 2011. DTrace: Dynamic Tracing in Oracle Solaris , Mac OS X, and FreeBSD 1 st ed.). Prentice Hall . Brendan Gregg and Jim Mauro. 2011. DTrace: Dynamic Tracing in Oracle Solaris, Mac OS X, and FreeBSD 1st ed.). Prentice Hall.","edition":"1"},{"key":"e_1_3_2_1_20_1","unstructured":"Andreas Gruenbacher and Seth Arnold. 2007. AppArmor Technical Documentation. http:\/\/lkml.iu.edu\/hypermail\/linux\/kernel\/0706.1\/0805\/techdoc.pdf  Andreas Gruenbacher and Seth Arnold. 2007. AppArmor Technical Documentation. http:\/\/lkml.iu.edu\/hypermail\/linux\/kernel\/0706.1\/0805\/techdoc.pdf"},{"key":"e_1_3_2_1_21_1","volume-title":"Linux Conference","volume":"2005","author":"Harada Toshiharu","year":"2005","unstructured":"Toshiharu Harada , Takashi Horie , and Kazuo Tanaka . 2005 . Towards a manageable Linux security . In Linux Conference , Vol. 2005 . https:\/\/osdn.net\/projects\/tomoyo\/docs\/lc2005-en.pdf\/en\/2\/lc2005-en.pdf Toshiharu Harada, Takashi Horie, and Kazuo Tanaka. 2005. Towards a manageable Linux security. In Linux Conference, Vol. 2005. https:\/\/osdn.net\/projects\/tomoyo\/docs\/lc2005-en.pdf\/en\/2\/lc2005-en.pdf"},{"key":"e_1_3_2_1_22_1","unstructured":"Andrew Hurst. 2004. Analysis of Perl's taint mode. http:\/\/hurstdog.org\/papers\/hurst04taint.pdf  Andrew Hurst. 2004. Analysis of Perl's taint mode. http:\/\/hurstdog.org\/papers\/hurst04taint.pdf"},{"key":"e_1_3_2_1_23_1","volume-title":"CapExec: Towards Transparently-Sandboxed Services. In International Conference on Network and Service Management (CNSM). IEEE. https:\/\/doi.org\/10","author":"Jadidi Mahya Soleimani","year":"2019","unstructured":"Mahya Soleimani Jadidi , Mariusz Zaborski , Brian Kidney , and Jonathan Anderson . 2019 . CapExec: Towards Transparently-Sandboxed Services. In International Conference on Network and Service Management (CNSM). IEEE. https:\/\/doi.org\/10 .23919\/CNSM46954.2019.9012736 10.23919\/CNSM46954.2019.9012736 Mahya Soleimani Jadidi, Mariusz Zaborski, Brian Kidney, and Jonathan Anderson. 2019. CapExec: Towards Transparently-Sandboxed Services. In International Conference on Network and Service Management (CNSM). IEEE. https:\/\/doi.org\/10.23919\/CNSM46954.2019.9012736"},{"key":"e_1_3_2_1_24_1","unstructured":"K Jain and R Sekar. 2000. User-Level Infrastructure for System Call Interposition: A Platform for Intrusion Detection and Confinement. In NDSS. https:\/\/www.cs.unc.edu\/ fabian\/course_papers\/jain-userlevel.pdf  K Jain and R Sekar. 2000. User-Level Infrastructure for System Call Interposition: A Platform for Intrusion Detection and Confinement. In NDSS. https:\/\/www.cs.unc.edu\/ fabian\/course_papers\/jain-userlevel.pdf"},{"key":"e_1_3_2_1_25_1","volume-title":"2nd International SANE Conference. http:\/\/ivanlef0u.fr\/repo\/madchat\/sysadm\/bsd\/kamp.pdf","author":"Kamp Poul-Henning","year":"2000","unstructured":"Poul-Henning Kamp and Robert N M Watson . 2000 . Jails: Confining the omnipotent root . In 2nd International SANE Conference. http:\/\/ivanlef0u.fr\/repo\/madchat\/sysadm\/bsd\/kamp.pdf Poul-Henning Kamp and Robert N M Watson. 2000. Jails: Confining the omnipotent root. In 2nd International SANE Conference. http:\/\/ivanlef0u.fr\/repo\/madchat\/sysadm\/bsd\/kamp.pdf"},{"key":"e_1_3_2_1_26_1","volume-title":"Namespaces in operation, part 1: namespaces overview. LWN.net (January 4","author":"Kerrisk Michael","year":"2013","unstructured":"Michael Kerrisk . 2013. Namespaces in operation, part 1: namespaces overview. LWN.net (January 4 2013 ). https:\/\/lwn.net\/Articles\/332974\/ Michael Kerrisk. 2013. Namespaces in operation, part 1: namespaces overview. LWN.net (January 4 2013). https:\/\/lwn.net\/Articles\/332974\/"},{"key":"e_1_3_2_1_27_1","volume-title":"Practical and Effective Sandboxing for Non-root Users. In 2013 USENIX Annual Technical Conference (USENIX ATC 13)","author":"Kim Taesoo","year":"2013","unstructured":"Taesoo Kim and Nickolai Zeldovich . 2013 . Practical and Effective Sandboxing for Non-root Users. In 2013 USENIX Annual Technical Conference (USENIX ATC 13) . USENIX Association, San Jose, CA, 139--144. https:\/\/www.usenix.org\/system\/files\/conference\/atc13\/atc13-kim.pdf Taesoo Kim and Nickolai Zeldovich. 2013. Practical and Effective Sandboxing for Non-root Users. In 2013 USENIX Annual Technical Conference (USENIX ATC 13). USENIX Association, San Jose, CA, 139--144. https:\/\/www.usenix.org\/system\/files\/conference\/atc13\/atc13-kim.pdf"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/362375.362389"},{"key":"e_1_3_2_1_29_1","unstructured":"Michael Larabel and Matthew Tippett. 2011. Phoronix Test Suite. http:\/\/www.phoronix-test-suite.com\/  Michael Larabel and Matthew Tippett. 2011. Phoronix Test Suite. http:\/\/www.phoronix-test-suite.com\/"},{"key":"e_1_3_2_1_30_1","unstructured":"libbpf authors. 2020. libbpf. https:\/\/github.com\/libbpf\/libbpf  libbpf authors. 2020. libbpf. https:\/\/github.com\/libbpf\/libbpf"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224075"},{"key":"e_1_3_2_1_32_1","first-page":"x93","volume-title":"USENIX Winter","volume":"93","author":"McCanne Steven","year":"1992","unstructured":"Steven McCanne and Van Jacobson . 1992 . The BSD Packet Filter: A New Architecture for User-level Packet Capture . USENIX Winter , Vol. 93 (1992). https:\/\/www.tcpdump.org\/papers\/bpf-useni x93 .pdf Steven McCanne and Van Jacobson. 1992. The BSD Packet Filter: A New Architecture for User-level Packet Capture. USENIX Winter, Vol. 93 (1992). https:\/\/www.tcpdump.org\/papers\/bpf-usenix93.pdf"},{"key":"e_1_3_2_1_33_1","volume-title":"USENIX Security Symposium. ACM Berkeley, CA, 17--31","author":"Morris James","year":"2002","unstructured":"James Morris , Stephen Smalley , Greg Kroah-Hartman , Chris Wright , and Crispin Cowan . 2002 . Linux security modules: General security support for the linux kernel . In USENIX Security Symposium. ACM Berkeley, CA, 17--31 . https:\/\/www.usenix.org\/legacy\/event\/sec02\/full_papers\/wright\/wright.pdf James Morris, Stephen Smalley, Greg Kroah-Hartman, Chris Wright, and Crispin Cowan. 2002. Linux security modules: General security support for the linux kernel. In USENIX Security Symposium. ACM Berkeley, CA, 17--31. https:\/\/www.usenix.org\/legacy\/event\/sec02\/full_papers\/wright\/wright.pdf"},{"key":"e_1_3_2_1_34_1","unstructured":"Andrii Nakryiko. 2020 a. BPF Portability and CO-RE. https:\/\/facebookmicrosites.github.io\/bpf\/blog\/2020\/02\/19\/bpf-portability-and-co-re.html  Andrii Nakryiko. 2020 a. BPF Portability and CO-RE. https:\/\/facebookmicrosites.github.io\/bpf\/blog\/2020\/02\/19\/bpf-portability-and-co-re.html"},{"key":"e_1_3_2_1_35_1","unstructured":"Andrii Nakryiko. 2020 b. BPF ring buffer. https:\/\/lwn.net\/Articles\/820559\/  Andrii Nakryiko. 2020 b. BPF ring buffer. https:\/\/lwn.net\/Articles\/820559\/"},{"key":"e_1_3_2_1_36_1","first-page":"5","article-title":"Playing with ptrace","volume":"2002","author":"Padala Pradeep","year":"2002","unstructured":"Pradeep Padala . 2002 . Playing with ptrace , Part I. Linux Journal , Vol. 2002 , 103 (2002), 5 . https:\/\/www.linuxjournal.com\/article\/6100 Pradeep Padala. 2002. Playing with ptrace, Part I. Linux Journal, Vol. 2002, 103 (2002), 5. https:\/\/www.linuxjournal.com\/article\/6100","journal-title":"Part I. Linux Journal"},{"key":"e_1_3_2_1_37_1","unstructured":"David S Peterson Matt Bishop and Raju Pandey. 2002. A Flexible Containment Mechanism for Executing Untrusted Code. In USENIX Security. https:\/\/www.usenix.org\/legacy\/event\/sec02\/full_papers\/peterson\/peterson_html\/  David S Peterson Matt Bishop and Raju Pandey. 2002. A Flexible Containment Mechanism for Executing Untrusted Code. In USENIX Security. https:\/\/www.usenix.org\/legacy\/event\/sec02\/full_papers\/peterson\/peterson_html\/"},{"key":"e_1_3_2_1_38_1","volume-title":"LISA","volume":"4","author":"Price Daniel","year":"2004","unstructured":"Daniel Price and Andrew Tucker . 2004 . Solaris Zones: Operating System Support for Consolidating Commercial Workloads .. In LISA , Vol. 4 . 241--254. Solaris Zones : Operating System Support for Consolidating Commercial Workloads Daniel Price and Andrew Tucker. 2004. Solaris Zones: Operating System Support for Consolidating Commercial Workloads.. In LISA, Vol. 4. 241--254. Solaris Zones: Operating System Support for Consolidating Commercial Workloads"},{"key":"e_1_3_2_1_39_1","unstructured":"Niels Provos. 2003. Improving Host Security with System Call Policies. In USENIX Security. https:\/\/www.usenix.org\/legacy\/events\/sec03\/tech\/full_papers\/provos\/provos_html\/  Niels Provos. 2003. Improving Host Security with System Call Policies. In USENIX Security. https:\/\/www.usenix.org\/legacy\/events\/sec03\/tech\/full_papers\/provos\/provos_html\/"},{"key":"e_1_3_2_1_40_1","unstructured":"Mickael Salaun. 2020. landlock.io. https:\/\/landlock.io\/  Mickael Salaun. 2020. landlock.io. https:\/\/landlock.io\/"},{"key":"e_1_3_2_1_41_1","unstructured":"Seccomp authors. 2020. Seccomp BPF (SECure COMPuting with filters). https:\/\/www.kernel.org\/doc\/html\/latest\/userspace-api\/seccomp_filter.html  Seccomp authors. 2020. Seccomp BPF (SECure COMPuting with filters). https:\/\/www.kernel.org\/doc\/html\/latest\/userspace-api\/seccomp_filter.html"},{"key":"e_1_3_2_1_42_1","unstructured":"SELinux authors. 2020. SELinux Userspace Tools. https:\/\/github.com\/SELinuxProject\/selinux  SELinux authors. 2020. SELinux Userspace Tools. https:\/\/github.com\/SELinuxProject\/selinux"},{"key":"e_1_3_2_1_43_1","first-page":"3","article-title":"A Study of Security Isolation","volume":"49","author":"Shu Rui","year":"2016","unstructured":"Rui Shu , Peipei Wang , Sigmund A Gorski III, Benjamin Andow , Adwait Nadkarni , Luke Deshotels , Jason Gionta , William Enck , and Xiaohui Gu . 2016 . A Study of Security Isolation Techniques. Comput. Surveys , Vol. 49 , 3 (Dec. 2016), 1--37. https:\/\/doi.org\/10.1145\/2988545 10.1145\/2988545 Rui Shu, Peipei Wang, Sigmund A Gorski III, Benjamin Andow, Adwait Nadkarni, Luke Deshotels, Jason Gionta, William Enck, and Xiaohui Gu. 2016. A Study of Security Isolation Techniques. Comput. Surveys, Vol. 49, 3 (Dec. 2016), 1--37. https:\/\/doi.org\/10.1145\/2988545","journal-title":"Techniques. Comput. Surveys"},{"key":"e_1_3_2_1_44_1","unstructured":"KP Singh. 2019. MAC and Audit policy using eBPF (KRSI). https:\/\/lwn.net\/ml\/linux-kernel\/20191220154208.15895-1-kpsingh@chromium.org\/  KP Singh. 2019. MAC and Audit policy using eBPF (KRSI). https:\/\/lwn.net\/ml\/linux-kernel\/20191220154208.15895-1-kpsingh@chromium.org\/"},{"key":"e_1_3_2_1_45_1","first-page":"43","article-title":"Implementing SELinux as a Linux security module","volume":"1","author":"Smalley Stephen","year":"2001","unstructured":"Stephen Smalley , Chris Vance , and Wayne Salamon . 2001 . Implementing SELinux as a Linux security module . NAI Labs Report , Vol. 1 , 43 , 139. https:\/\/www.cs.unibo.it\/ sacerdot\/doc\/so\/slm\/selinux-module.pdf Stephen Smalley, Chris Vance, and Wayne Salamon. 2001. Implementing SELinux as a Linux security module. NAI Labs Report, Vol. 1, 43, 139. https:\/\/www.cs.unibo.it\/ sacerdot\/doc\/so\/slm\/selinux-module.pdf","journal-title":"NAI Labs Report"},{"key":"e_1_3_2_1_46_1","unstructured":"Snapcraft. 2020. Security policy and sandboxing. https:\/\/snapcraft.io\/docs\/security-sandboxing  Snapcraft. 2020. Security policy and sandboxing. https:\/\/snapcraft.io\/docs\/security-sandboxing"},{"key":"e_1_3_2_1_47_1","unstructured":"Alexei Starovoitov and Daniel Borkmann. 2014. Rework\/optimize internal BPF interpreter's instruction set. Kernel Patch. https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=bd4cf0ed331a275e9bf5a49e 6d0fd55dffc551b8  Alexei Starovoitov and Daniel Borkmann. 2014. Rework\/optimize internal BPF interpreter's instruction set. Kernel Patch. https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=bd4cf0ed331a275e9bf5a49e 6d0fd55dffc551b8"},{"key":"e_1_3_2_1_48_1","volume-title":"USENIX Security Symposium","volume":"46","author":"Watson Robert NM","year":"2010","unstructured":"Robert NM Watson , Jonathan Anderson , Ben Laurie , and Kris Kennaway . 2010 . Capsicum: Practical Capabilities for UNIX .. In USENIX Security Symposium , Vol. 46 . 2. https:\/\/www.usenix.org\/legacy\/event\/sec10\/tech\/full_papers\/Watson.pdf Robert NM Watson, Jonathan Anderson, Ben Laurie, and Kris Kennaway. 2010. Capsicum: Practical Capabilities for UNIX.. In USENIX Security Symposium, Vol. 46. 2. https:\/\/www.usenix.org\/legacy\/event\/sec10\/tech\/full_papers\/Watson.pdf"},{"key":"e_1_3_2_1_49_1","volume-title":"mbox","year":"2020","unstructured":"zoidbergwill mbox . 2020 . Awesome eBPF: A curated list of awesome projects related to eBPF. https:\/\/github.com\/zoidbergwill\/awesome-ebpf zoidbergwill et almbox. 2020. Awesome eBPF: A curated list of awesome projects related to eBPF. https:\/\/github.com\/zoidbergwill\/awesome-ebpf"}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Cloud Computing Security Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411495.3421358","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3411495.3421358","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:31:41Z","timestamp":1750195901000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411495.3421358"}},"subtitle":["Simple Precise Process Confinement with eBPF"],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":49,"alternative-id":["10.1145\/3411495.3421358","10.1145\/3411495"],"URL":"https:\/\/doi.org\/10.1145\/3411495.3421358","relation":{},"subject":[],"published":{"date-parts":[[2020,11,9]]},"assertion":[{"value":"2020-11-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}