BEGIN:VCALENDAR
PRODID:-//Google Inc//Google Calendar 70.9054//EN
VERSION:2.0
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:44CON 2026
X-WR-TIMEZONE:Europe/London
BEGIN:VEVENT
DTSTART:20260918T134000Z
DTEND:20260918T143000Z
DTSTAMP:20260902T152715Z
UID:2b2voje4hlspj1om7qf3l002dn@google.com
CREATED:20260624T145452Z
DESCRIPTION:BPF programs don’t nest\; i.e. they don’t get suspended so t
 hat another program can run at a higher priority. That’s what the documenta
 tion said\, and it’s true for a lot of cases. But if you are using BPF CGro
 upSKB programs to access/inspect/analyse packets\, then this doesn’t apply.
  I will explain why nesting is preferred in these cases\, will describe the
  assumptions that fail\, and the mess that can result for a BPF-based EDR. 
 Packet storms are back\, but for more interesting reasons.\r\rFor backgr
 ound\, packets/datagrams can be hooked with XDP\, TC/TCX\, and CGroupSKB BP
 F programs – I will explain in the talk why we wouldn’t use or recommend ot
 her hooks or types of programs for this. Of these\, only CGroupSKB hooks\, 
 however\, are high enough up the stack to allow datagrams to be easily link
 ed to processes\, making them the obvious choice for BPF-based EDRs.\r\r
 Come with me on a journey through kernel sources to see what dragons need t
 o be slayed. I’ll conclude with tips for analysis and methods to avoid the 
 race conditions.\r\rIt’s a talk for the blue team\, that the red team mi
 ght want to know about.
LAST-MODIFIED:20260902T152627Z
LOCATION:Track 2
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:BPF\, Nesting\, And You – Concurrency Issues Your EDR Might Not Kno
 w It Has – Kev Sheldrake
TRANSP:OPAQUE
END:VEVENT
END:VCALENDAR