hBPF
secimport
hBPF | secimport | |
---|---|---|
3 | 14 | |
386 | 157 | |
- | - | |
0.0 | 6.5 | |
over 1 year ago | about 2 months ago | |
Python | Python | |
BSD 3-clause "New" or "Revised" License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
hBPF
- HBPF – eBPF in Hardware
-
Hacker News top posts: Apr 1, 2022
HBPF – eBPF in Hardware\ (2 comments)
secimport
-
Securing PyTorch Models with eBPF
In this blog, I will present secimport — a toolkit for creating and running sandboxed applications in Python that utilizes eBPF (bpftrace) to secure Python runtimes.
- I created a python seccomp sandbox, but per-module in your code.
- GitHub - avilum/secimport: Python sandbox toolkit, powered by eBPF and Dtrace
- GitHub - avilum/secimport: Python sandbox toolkit, powered by eBPF / Dtrace
- GitHub - avilum/secimport: seccomp Python sandbox, powered by eBPF and Dtrace
-
Dozens of malicious PyPI packages discovered targeting developers
There is also this, although I haven't tested it yet. The approach is interesting though. https://github.com/avilum/secimport
- GitHub - avilum/secimport: Secure imports for python modules using dtrace
-
Tracing/Sandboxing python modules upon import (like SECCOMP for the interpreter)
Code: https://github.com/avilum/secimport Article (No login required): https://infosecwriteups.com/sandboxing-python-modules-in-your-code-1e590d71fc26?source=friends_link&sk=5e9a2fa4d4921af0ec94f175f7ee49f9
- seccomp for Python import statements: sandbox python modules using dtrace (cross platform)
What are some alternatives?
gilstats.py - A utility for dumping per-thread statistics for CPython GIL using eBPF
birdcage - Cross-platform embeddable sandboxing
postlite - Postgres wire compatible SQLite proxy.
cargo-vet - supply-chain security for Rust
glasgow - Scots Army Knife for electronics
cli - Command line interface for the Phylum API
FPGA_HW_SIM_FWK_2 - FPGA Hardware Simulation Framework
autobox - A set of tools and libraries for automatically generating and initiating sandboxes for Rust programs
dechainy - An open source framework to easily build and deploy eBPF/XDP network monitoring probes and clusters in order to perform Service Programs Chain efficiently.
Contents - Community documentation, code, links to third-party resources, ... See the issues and pull requests for pending content. Contributions are welcome !
crev - Socially scalable Code REView and recommendation system that we desperately need. See http://github.com/crev-dev/cargo-crev for real implemenation.
security-wg - Node.js Ecosystem Security Working Group