RUS  ENG
Full version
JOURNALS // Proceedings of the Institute for System Programming of the RAS // Archive

Proceedings of ISP RAS, 2020 Volume 32, Issue 3, Pages 71–77 (Mi tisp513)

This article is cited in 1 paper

Tracing network packets in the Linux kernel using eBPF

M. G. Kovalev

St Petersburg State University

Abstract: During the development and maintenance of complex network infrastructure for a big project, developers face a lot of problems. Although there exist plenty of tools and software that helps to troubleshoot such problems, their functionality is limited by the API that Linux kernel provides. Usually, they are narrowly targeted on solving one problem and cannot show a system-wide network stack view, which could be helpful in finding the source of the malfunction. This situation could be changed with the appearance of a new type of tools powered by the Linux kernel's eBPF technology, which provides a flexible and powerful way to run a userspace code inside the kernel. In this paper, an approach to tracing the path of network packets in the Linux kernel using eBPF is described.

Keywords: Linux, kernel, networking, tracing, eBPF.

Language: English

DOI: 10.15514/ISPRAS-2020-32(3)-6



© Steklov Math. Inst. of RAS, 2026