A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2021; you can also visit the original URL.
The file type is
BPFContain combines a simple yet flexible policy language with an eBPF-based implementation that allows for deployment on virtually any Linux system running a recent kernel. ... Here we present BPFContain, a new container confinement mechanism designed to integrate with existing container management systems. ...  introduced bpfbox as the first full process confinement mechanism using these eBPF LSM hooks. ...arXiv:2102.06972v1 fatcat:qyphvepuczfndixpqqywcpuhcu