/kShield

kShield is a Linux kernel privilege escalation attack defense system based on eBPF.

Clarification

When the paper is accepted, the full source code of the kShield framework will be uploaded in the GitHub repository. Thank you for your attention.

kShield: An eBPF Runtime Defence Framework for Linux Kernel Privilege Escalation Attacks

kShield is a runtime defense framework for the Linux kernel based on eBPF, It consists of a management subsystem and a defense subsystem that effectively protects against five mainstream kernel privilege escalation attacks.