Kernel observability with eBPF
Tracing methods that preserve insight while minimizing overhead on untraced or lightly traced processes.
Research
Research at the intersection of Linux observability, system performance, and platform security, with methods designed for real-world workloads.
Tracing methods that preserve insight while minimizing overhead on untraced or lightly traced processes.
Evidence-driven analysis of bottlenecks, runtime behavior, and instrumentation tradeoffs.
Security techniques for Android, Bluetooth, networking, and IoT, with visibility and protection under resource constraints.
Implementations, tools, and workflows that accompany published research.
Kernel observability work on reducing tracing overhead and improving measurement quality under real workloads.
Published and ongoingApplication-layer firewall and protobuf parsing work in the Linux kernel using custom kfunc support and TC-based enforcement.
Prototype