A Linux eBPF (Extended Berkeley Packet Filter) security agent can achieve a 90% reduction in CPU cost by implementing a memoization-based cache to store the results of path-based policy checks, allowing for faster enforcement of access control rules. The cache uses a key-value pair approach, storing the inode number, mount namespace ID, and mount ID, and utilizing bitmasks to store policies for space efficiency. This approach enables the agent to avoid repetitive path walks and reduces kernel CPU cycles. AI summary
Firehose
Filtered to tagged “eBPF” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives
Browse by tag
artificial intelligence 87continual learning 32AI 24reinforcement learning 14agentic coding 13AI safety 13open-weight models 13AI agents 10existential risk 9AI ethics 8cybersecurity 8ethics 7language models 7machine learning 7natural language processing 6open-source 6Reinforcement learning 6security 6artificial general intelligence 5Diffusion models 5recursive self-improvement 5robotics 5software development 5Agentic AI 4large language models 4mathematics 4multi-agent systems 4Recursive self-improvement 4agentic AI 3agents 3