Loading…
May 21 - 22 | Minneapolis, Minnesota
View More Details & Registration
Note: The schedule is subject to change.

The Sched app lets you build your schedule, but it is not a substitute for event registration. You must be registered for Linux Security Summit North America 2026 to participate in the sessions. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.


Friday May 22, 2026 3:20pm - 3:50pm CDT
eBPF has become one of the most powerful security building blocks in Linux, yet that same power makes it a high-value target. This session is a technical deep dive into emerging eBPF threat patterns we’re seeing across modern fleets: privilege escalation paths that hinge on BPF/JIT behavior, abuse of tracing hooks for stealthy data access, and ways attackers hide activity by tampering with observability pipelines. Then we flip to defense: concrete kernel and distro hardening moves that actually change the risk profile (unprivileged BPF controls, JIT hardening settings, capability boundaries, LSM integration, and runtime guardrails). I’ll include short, readable kernel-level snippets and user-space examples using standard BPF tooling so you can reproduce the behaviors in a lab and validate mitigations. The goal is practical: leave with a checklist you can apply to production Linux systems and a mental model for what "safe eBPF" looks like going forward.
Speakers
avatar for Advait Patel

Advait Patel

Senior Site Reliability Engineer, Broadcom
Advait Patel is a Senior Site Reliability Engineer at Broadcom and the creator of DockSec, an open-source, AI-powered Docker security analyzer. With over 8+ years of experience in cloud-native security, DevSecOps, and secure software supply chains, he is passionate about building... Read More →
Friday May 22, 2026 3:20pm - 3:50pm CDT
101A+B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link