Dropping eBPF CPU Cost by About 90% with Memoization (Not AI Gen)
What happened
My brother and I spent a lot of time designing our eBPF security agent to be really fast from the ground up, but recently we discovered we could make it much faster using memoization! A couple of weeks ago, I profiled the eBPF code and found that the most expensive part of the protection isn’t actually enforcing a policy (allow/deny), but figuring out which policy applies to a given file open.
Summary assembled by rule from the sources below
Why it's spreading
Timeline
- First appeared on Hacker NewsHacker News
- Discussion started on LobstersLobsters