Ae

AegisBPF – Deterministic Runtime Enforcement via eBPF LSM

Hacker News

AegisBPF – Deterministic Runtime Enforcement via eBPF LSM

I built AegisBPF to explore deterministic runtime enforcement using BPF-LSM instead of the traditional detect-and-alert model common in eBPF security tooling. Most eBPF-based runtime security systems observe events (tracepoints/kprobes) and alert asynchronously. Aegis attaches to Linux Security Module (LSM) hooks such as: file_open inode_permission bprm_check_security socket_connect / socket_bind This allows operations to be denied synchronously before the syscall completes. Core ideas: Inode-first file enforcement (stable across renames) Dual-stack IPv4/IPv6 network deny rules enforced in-kernel Explicit enforce vs audit posture contract Capability-aware fail-closed mode Structured state transitions (ENFORCE / AUDIT_FALLBACK / DEGRADED) Performance (example baseline, 200k ops): ~2–3% p95 overhead on open ~0.5–1% overhead on connect O(1) map lookups regardless of rule count The project includes: Signed policy bundles (Ed25519) Capability/posture reporting Kernel compatibility matrix CI Documented threat model and TOCTOU analysis I wrote two technical deep dives explaining the design rationale: Part 1 – Synchronous Kernel-Level Denial via eBPF-LSM https://medium.com/@erenari27/part-1-synchronous-kernel-leve... Part 2 – Deterministic Enforcement Contracts & Posture Semantics https://medium.com/@erenari27/part-2-deterministic-enforceme... Happy to discuss hook selection tradeoffs, verifier constraints, seccomp vs LSM, Landlock comparisons, or enforcement failure modes.

Share card

Actual performance

2points
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Indie HackersFits the IH revenue-focused audience · Missing: supports, reddit linkedin, podcasting
60%60% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Product HuntUnlikely to reach the leaderboard · Strong signals: model, using, open · Missing: mac, agents, macos
44%44% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Missing: mobile apps, ios, personal
37%37% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: ide, io · Missing: https docs, excited, just released
35%35% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
AppSumoMay struggle as an AppSumo deal · Missing: plus, platform, intuitive
34%34% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
12%12% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
5%5% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

A
A container runtime implemented in x86_64 assembly55%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

A container runtime implemented in x86_64 assembly

Hacker News3
Su
Subverting Go's Runtime System47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Subverting Go's Runtime System

Hacker News2
To
Toggle Methods and Endpoints at Runtime48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Toggle Methods and Endpoints at Runtime

Hacker News2
Mi
Mixing C++ with Angelscript for runtime introspection and debugging59%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Mixing C++ with Angelscript for runtime introspection and debugging

Hacker News1
Re
Restate, a Distributed Async Runtime55%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Restate, a Distributed Async Runtime

Hacker News2
Ke
Kern – container and resource runtime in a 1.5 MB binary, no daemon43%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Kern – container and resource runtime in a 1.5 MB binary, no daemon

Hacker News70
Ca
Cadenya – An Agent Runtime34%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Cadenya – An Agent Runtime

Hacker News1
Ti
TinyGo interoperability with Arduino-based WebAssembly runtime58%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

TinyGo interoperability with Arduino-based WebAssembly runtime

Hacker News3
Je
Jetpack, a FreeBSD Jail/ZFS-based container runtime45%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Jetpack, a FreeBSD Jail/ZFS-based container runtime

Hacker News96
Ob
Objection – runtime mobile exploration52%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Objection – runtime mobile exploration

Hacker News2