Yaksha-Prashna: Understanding eBPF Bytecode Network Function Behavior

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Singh, Animesh, Kumar, K Shiv, VenkataKeerthy, S., Mamidipaka, Pragna, Aaseesh, R V B R N, Sen, Sayandeep, Kodeswaran, Palanivel, Benson, Theophilus A., Upadrasta, Ramakrishna, Tammana, Praveen
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910019770908672
author Singh, Animesh
Kumar, K Shiv
VenkataKeerthy, S.
Mamidipaka, Pragna
Aaseesh, R V B R N
Sen, Sayandeep
Kodeswaran, Palanivel
Benson, Theophilus A.
Upadrasta, Ramakrishna
Tammana, Praveen
author_facet Singh, Animesh
Kumar, K Shiv
VenkataKeerthy, S.
Mamidipaka, Pragna
Aaseesh, R V B R N
Sen, Sayandeep
Kodeswaran, Palanivel
Benson, Theophilus A.
Upadrasta, Ramakrishna
Tammana, Praveen
contents Many cloud infrastructure organizations increasingly rely on third-party eBPF-based network functions for use cases like security, observability, and load balancing, so that not everyone requires a team of highly skilled eBPF experts. However, the network functions from third parties (e.g., F5, Palo Alto) are available in bytecode format to cloud operators, giving little or no understanding of their functional correctness and interaction with other network functions in a chain. Also, eBPF developers want to provide proof of functional correctness for their developed network functions without disclosing the source code to the operators. We design Yaksha-Prashna, a system that allows operators/developers to assert and query bytecode's conformance to its specification and dependencies on other bytecodes. Our work builds domain-specific models that enable us to employ scalable program analysis to extract and model eBPF programs. Using Yaksha-Prashna language, we express 24 properties on standard and non-standard eBPF-based network functions with 200-1000x speedup over the state-of-the-art work.
format Preprint
id arxiv_https___arxiv_org_abs_2602_11232
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Yaksha-Prashna: Understanding eBPF Bytecode Network Function Behavior
Singh, Animesh
Kumar, K Shiv
VenkataKeerthy, S.
Mamidipaka, Pragna
Aaseesh, R V B R N
Sen, Sayandeep
Kodeswaran, Palanivel
Benson, Theophilus A.
Upadrasta, Ramakrishna
Tammana, Praveen
Cryptography and Security
Programming Languages
Software Engineering
Many cloud infrastructure organizations increasingly rely on third-party eBPF-based network functions for use cases like security, observability, and load balancing, so that not everyone requires a team of highly skilled eBPF experts. However, the network functions from third parties (e.g., F5, Palo Alto) are available in bytecode format to cloud operators, giving little or no understanding of their functional correctness and interaction with other network functions in a chain. Also, eBPF developers want to provide proof of functional correctness for their developed network functions without disclosing the source code to the operators. We design Yaksha-Prashna, a system that allows operators/developers to assert and query bytecode's conformance to its specification and dependencies on other bytecodes. Our work builds domain-specific models that enable us to employ scalable program analysis to extract and model eBPF programs. Using Yaksha-Prashna language, we express 24 properties on standard and non-standard eBPF-based network functions with 200-1000x speedup over the state-of-the-art work.
title Yaksha-Prashna: Understanding eBPF Bytecode Network Function Behavior
topic Cryptography and Security
Programming Languages
Software Engineering
url https://arxiv.org/abs/2602.11232