Skip to main navigation Skip to search Skip to main content

TLA2eBPF: Real-Time Protection for Kernel Memory Out-of-Bounds Security

  • Zi Wang
  • , Yuqing Lan*
  • *Corresponding author for this work
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Memory out-of-bounds (OOB) vulnerabilities in the Linux kernel threaten system integrity by enabling privilege escalation, information leakage, and arbitrary code execution. Formal verification techniques such as TLA+ can mathematically guarantee memory-safety invariants but cannot enforce runtime monitoring, whereas eBPF provides real-time kernel instrumentation but relies on manually crafted heuristic rules. This work presents TLA2eBPF, the first semantics-preserving framework that automatically converts TLA+ security specifications into executable eBPF monitoring code. We design (1) bidirectional semantic-mapping rules between TLA+ state machines and eBPF runtime states; (2) a TLAPS-based bisimulation proof system ensuring behavioral equivalence; and (3) an optimized eBPF runtime including cache acceleration, batched event delivery, and probabilistic sampling. Experiments on real CVEs and Syzkaller cases demonstrate 100% detection coverage, 0% false positives, and <3.5% runtime overhead, achieving both formal completeness and practical real-time protection.

Original languageEnglish
Title of host publicationProceedings of 2025 5th International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology, CEI 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages726-729
Number of pages4
ISBN (Electronic)9798350357431
DOIs
StatePublished - 2025
Event2025 5th International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology, CEI 2025 - Nanning, China
Duration: 21 Nov 202523 Nov 2025

Publication series

NameProceedings of 2025 5th International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology, CEI 2025

Conference

Conference2025 5th International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology, CEI 2025
Country/TerritoryChina
CityNanning
Period21/11/2523/11/25

Keywords

  • Bisimulation Proof
  • eBPF
  • Formal Verification
  • Kernel Memory Security
  • Semantic Mapping
  • TLA+

Fingerprint

Dive into the research topics of 'TLA2eBPF: Real-Time Protection for Kernel Memory Out-of-Bounds Security'. Together they form a unique fingerprint.

Cite this