Articles

COMPARATIVE ANALYSIS OF REAL-TIME SECURITY MONITORING TOOLS BASED ON KERNEL AUDIT SUBSYSTEM AND eBPF TECHNOLOGIES IN ALT LINUX

Download PDF Article on eLIBRARY.RU

Abstract

This paper presents the results of a comparative experimental study of real-time security monitoring tools in the Alt Linux operating system environment. Two fundamentally different approaches to threat detection are examined: the classical kernel audit subsystem (auditd) and a modern eBPF-based tool (Tracee). The study identifies practical compatibility limitations of popular eBPF solutions with virtualized environments and provides a quantitative assessment of the performance overhead and anomaly detection capabilities of the tested tools. The experimental environment is deployed on Alt Linux Workstation 11.1 using the VirtualBox hypervisor. The findings contribute to the informed selection of security monitoring tools for domestic Linux distributions.

Online viewer

References

  1. Шаньгин В. Ф. Информационная безопасность компьютерных систем и сетей: учебное пособие. М.: ИД «ФОРУМ»: ИНФРА-М, 2019. 416 с.
  2. Таненбаум А. С., Бос Х. Современные операционные системы. 4-е изд. СПб.: Питер, 2019. 1120 с.
  3. What is eBPF? // eBPF.io. URL: https://ebpf.io/what-is-ebpf/ (дата обращения: 11.05.2025).
  4. Linux Audit Documentation // The Linux Kernel Archives. URL: https://docs.kernel.org/audit/ (дата обращения: 11.05.2025).
  5. Райс Л. Изучаем eBPF: программирование ядра Linux для наблюдаемости и безопасности. М.: ДМК Пресс, 2023. 350 с.
  6. What is Falco? Open source runtime threat detection // Sysdig. URL: https://www.sysdig.com/learn-cloud-native/what-is-falco (дата обращения: 11.05.2025).
  7. The Story of Tracee: The Path to Runtime Security Tool // Aqua Security. URL: https://www.aquasec.com/blog/open-source-container-runtime-security/ (дата обращения: 11.05.2025).
  8. [Modern eBPF] libpman: tracing program type is not supported // GitHub – falcosecurity/falco, issue #2792. URL: https://github.com/falcosecurity/falco/issues/2792 (дата обращения: 11.05.2025).
  9. MITRE ATT&CK Framework // MITRE Corporation. URL: https://attack.mitre.org/ (дата обращения: 11.05.2025).
  10. Уймин А. Г. Сетевое и системное администрирование. Демонстрационный экзамен КОД 1.1: учебно-методическое пособие. СПб.: Лань, 2020. 480 с.

License

Copyright (c) 2025 D. D. Novikova, S. S. Chursina (Authors)

Keywords