An Abnormal File Access Detection Model for Containers Based on eBPF Listening
Abstract
1. Introduction
- A lightweight eBPF-based container file access monitoring mechanism is proposed. By attaching to the security_file_open hook and reconstructing full file paths through iterative traversal of the dentry structure, the method achieves fine-grained and low-overhead system call collection under high-load scenarios.
- A multimodal file path semantic representation method is developed, which integrates risk-based hierarchical normalization, a fixed-length six-segment structural encoding scheme with explicit structural markers, and Word2Vec-based semantic vectorization, significantly enhancing the hierarchical expressiveness and semantic consistency of path features.
- An attention-enhanced autoencoder-based anomaly detection model is designed. By incorporating a path-segment attention layer and a weighted reconstruction loss function, the model improves the accuracy of abnormal access detection while substantially reducing false-positive rates under unsupervised settings.
- Comprehensive experimental evaluations are conducted from three perspectives—monitoring framework overhead, model parameters and feature embeddings, and multi-model comparisons—demonstrating the proposed method’s advantages in terms of real-time performance, detection accuracy, and false-positive reduction.
2. Related Work
2.1. eBPF-Based Container Security
2.2. File Path Feature Modeling and Semantic Understanding
2.3. Autoencoder-Based Anomaly Detection Methods
3. System Architecture
3.1. Fine-Grained Container Behavior Capture Based on eBPF
| Algorithm 1 Full File Path Reconstruction |
| Input: Pointer to file path structure struct path *path Output: Full file path as a string 1: if path == NULL then 2: return “Path not available” 3: end if 4: Initialize path_string as empty 5: Set current_dentry ← path->dentry 6: while current_dentry≠NULL do 7: name ← current_dentry->d_name 8: if name is not empty then 9: if path_string is empty then 10: path_string ← name 11: else 12: path_string ← name + “/” + path_string 13: end if 14: end if 15: if current_dentry is root or mount point then 16: break 17: end if 18: current_dentry ← current_dentry->d_parent 19: end while 20: return “/” + path_string |
3.2. Rule-Based Preprocessing of Multimodal System Call Data
3.2.1. Structural Hierarchy Normalization and Six-Segment Encoding
- Fixed-Length Constraint
- -
- If , risk-aware truncation rules determine which segments are retained;
- -
- If , padding markers are appended until the length equals six.
- Structural Marker System
- -
- indicates hierarchy truncation;
- -
- indicates padding for length normalization;
- -
- indicates structural irregularity;
- -
- indicates ambiguous hierarchy.
- Example
3.2.2. Path Semantic Vectorization
3.3. Attention-Enhanced Autoencoder for Anomaly Detection
4. Experimental Design and Analysis
4.1. Dataset
- Software environment: The experimental platform ran Ubuntu 22.04 with Linux Kernel version 6.5.0-45-generic, which provides enhanced support for eBPF functionalities. Docker version 27.3 was used for container management, and cgroups were downgraded to v1 at runtime to reproduce specific vulnerability scenarios.
- Hardware environment: The experimental host was equipped with a 13th Gen Intel(R) Core(TM) i5-13490F processor and an NVIDIA GeForce RTX 3060 Ti GPU, ensuring stable performance under high-concurrency workloads.
- Abuse of the release_agent mechanism in cgroups v1 (CVE-2022-0492 [31]);
- System resource manipulation caused by reference count errors in scheduler debugging paths (CVE-2022-48699 [32]);
- Privilege escalation and control-flow hijacking in Kubernetes environments via sensitive paths such as /proc/self/exe (CVE-2022-0811 [33]).
- Limitations and representativeness: Although the constructed dataset covers three representative container escape attack categories and includes multiple repeated executions, it still has limitations. First, the normal workload mainly reflects typical container management and file-access behaviors on a single host environment; additional workloads (e.g., database-intensive or microservice deployments) may introduce different path distributions. Second, the attack scenarios focus on file-access-related escape chains under a specific kernel and container runtime configuration; evaluating more kernel versions, container runtimes, and attack families is an important direction for future work. Nevertheless, because our method is trained only on normal behavior and relies on semantic-aware path modeling rather than attack signatures, the proposed framework is expected to generalize to unseen attacks that manifest as abnormal file-access patterns.
4.2. System Monitoring Performance Evaluation
4.3. Model Parameters and Feature Embedding Experiments
4.3.1. Path Embedding Model Parameter Optimization
4.3.2. Autoencoder Hyperparameters and Threshold Determination
- Threshold Determination
4.4. Comparative Analysis of Anomaly Detection Performance
Discussion on Additional Deep-Learning Baselines
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Docker. Docker Official Website. 2025. Available online: https://www.docker.com/ (accessed on 27 August 2025).
- Soltesz, S.; Pötzl, H.; Fiuczynski, M.E.; Bavier, A.; Peterson, L. Container-based Operating System Virtualization: A Scalable, High-performance Alternative to Hypervisors. In Proceedings of the EuroSys 2007, Lisbon, Portugal, 21–23 March 2007; pp. 275–287. [Google Scholar] [CrossRef] [Scilit]
- Linux Man-Pages Project. namespaces(7)—Linux Manual Page. 2025. Available online: https://www.man7.org/linux/man-pages/man7/namespaces.7.html (accessed on 27 August 2025).
- Linux Man-Pages Project. cgroups(7)—Linux Control Groups. 2025. Available online: https://www.man7.org/linux/man-pages/man7/cgroups.7.html (accessed on 27 August 2025).
- Bhaia, N.; Hung, L.H.; Cordingly, R.; Lloyd, W. Understanding Container Isolation: An Investigation of Performance Implications of Container Runtimes. In Proceedings of the 9th International Workshop on Container Technologies and Container Clouds, Bologna, Italy, 11–15 December 2024; pp. 7–12. [Google Scholar] [CrossRef] [Scilit]
- Sun, Y.; Safford, D.; Zohar, M.; Pendarakis, D.; Gu, Z.; Jaeger, T. Security Namespace: Making Linux Security Frameworks Available to Containers. In Proceedings of the 27th USENIX Security Symposium (USENIX Security 18), Baltimore, MD, USA, 15–17 August 2018; pp. 1423–1439. [Google Scholar]
- Koschel, J.; Borrello, P.; Cono D’Elia, D.; Bos, H.; Giuffrida, C. Uncontained: Uncovering Container Confusion in the Linux Kernel. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 5055–5072. [Google Scholar]
- Xiao, J.; Yang, N.; Shen, W.; Li, J.; Guo, X.; Dong, Z.; Xie, F.; Ma, J. Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation Forwarding. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 7517–7534. [Google Scholar]
- Tencent Cloud. White Paper on Container Security; Technical Report; Tencent Cloud: Shenzhen, China, 2021. [Google Scholar]
- Kubernetes. Kubernetes Official Website. 2025. Available online: https://kubernetes.io/ (accessed on 27 August 2025).
- Red Hat. The State of Kubernetes Security Report: 2024 Edition; Technical Report; Red Hat: Raleigh, NC, USA, 2024; Available online: https://www.redhat.com/en/engage/state-kubernetes-security-report-2024 (accessed on 27 August 2025).
- Linux Kernel Documentation. BPF Instruction Set Architecture (ISA). 2025. Available online: https://docs.kernel.org/bpf/standardization/instruction-set.html (accessed on 27 August 2025).
- Falco Project. Falco: Cloud Native Runtime Security. 2025. Available online: https://falco.org/ (accessed on 27 August 2025).
- Aqua Security. Tracee: Linux Runtime Security and Forensics Using eBPF. 2020. Available online: https://github.com/aquasecurity/tracee (accessed on 27 August 2025).
- Cilium Project. Tetragon: eBPF-Based Security Observability and Runtime Enforcement. 2021. Available online: https://tetragon.io/ (accessed on 27 August 2025).
- Liu, F.T.; Ting, K.M.; Zhou, Z.H. Isolation Forest. In Proceedings of the 8th IEEE International Conference on Data Mining (ICDM 2008), Pisa, Italy, 15–19 December 2008; pp. 413–422. [Google Scholar] [CrossRef] [Scilit]
- Schölkopf, B.; Platt, J.C.; Shawe-Taylor, J.; Smola, A.J.; Williamson, R.C. Estimating the Support of a High-Dimensional Distribution. Neural Comput. 2001, 13, 1443–1471. [Google Scholar] [CrossRef] [Scilit]
- Breunig, M.M.; Kriegel, H.P.; Ng, R.T.; Sander, J. LOF: Identifying Density-Based Local Outliers. In Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, Dallas, TX, USA, 15–18 May 2000; pp. 93–104. [Google Scholar] [CrossRef] [Scilit]
- Cong, X.; Yu, Z.; Fanti, M.P.; Mangini, A.M.; Li, Z. Predictability Verification of Fault Patterns in Labeled Petri Nets. IEEE Trans. Autom. Control 2025, 70, 1973–1980. [Google Scholar] [CrossRef] [Scilit]
- He, Y.; Guo, R.; Xing, Y.; Che, X.; Sun, K.; Liu, Z.; Xu, K.; Li, Q. Cross Container Attacks: The Bewildered eBPF on Clouds. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 5971–5988. [Google Scholar]
- Zehra, S.; Syed, H.J.; Samad, F.; Faseeha, U. DeSFAM: An Adaptive eBPF and AI-Driven Framework for Securing Cloud Containers in Real Time. IEEE Access 2025, 13, 139203–139224. [Google Scholar] [CrossRef] [Scilit]
- Yu, Y.C.; Hung, C.Y.; Chou, L.D. Kernel-level Hidden Rootkit Detection Based on eBPF. Comput. Secur. 2025, 157, 104582. [Google Scholar] [CrossRef] [Scilit]
- Wang, P.; Zhang, A.; Lang, H.; Xun, X.; Zhang, S.; Diao, L. fProcessor: NonIntrusive and On-the-Fly File Data Preprocessing Using eBPF. IEEE Access 2025, 13, 73173–73182. [Google Scholar] [CrossRef] [Scilit]
- Remya, S.; Pillai, M.J.; Niranjan, B.; Ajith Kumar, P.M.; Merin Shaju, K.; Dinoy Raj, K.; Ramasubbareddy, S.; Cho, Y. eBPF-Based Runtime Detection of Semantic DDoS Attacks in Linux Containers. IEEE Access 2025, 13, 169178–169219. [Google Scholar] [CrossRef] [Scilit]
- Kyadige, A.; Rudd, E.M.; Berlin, K. Learning from Context: Exploiting and Interpreting File Path Information for Better Malware Detection. arXiv 2019, arXiv:1905.06987. [Google Scholar] [CrossRef] [Scilit]
- Lee, R.K.; Song, H.M.; Youn, T.Y. Effective Context-Aware File Path Embeddings for Anomaly Detection. Systems 2025, 13, 403. [Google Scholar] [CrossRef] [Scilit]
- Wang, Y.; Chen, X.; Wang, Q.; Yang, R.; Xin, B. Unsupervised Anomaly Detection for Container Cloud Via BiLSTM-Based Variational Auto-Encoder. In Proceedings of the ICASSP 2022–2022 IEEE International Conference on Acoustics, Speech and Signal Processing, Singapore, 23–27 May 2022; pp. 3024–3028. [Google Scholar] [CrossRef] [Scilit]
- Fan, M.; Zuo, J.; Zhu, J.; Lu, Y. Explainable Anomaly-Based Intrusion Detection for Specialized IoT Environments Enabled by Rule Extraction From Autoencoder. IEEE Internet Things J. 2025, 12, 19504–19521. [Google Scholar] [CrossRef] [Scilit]
- Rao, A.R.; Wang, H.; Gupta, C. Functional approach for Two Way Dimension Reduction in Time Series. In Proceedings of the IEEE International Conference on Big Data (Big Data 2022), Osaka, Japan, 17–20 December 2022; pp. 1099–1106. [Google Scholar] [CrossRef] [Scilit]
- Guo, S.; Sivanthi, T.; Sommer, P.; Kabir-Querrec, M.; Coppik, N.; Mudgal, E.; Rossotti, A. A zero-day container attack detection based on ensemble machine learning. In Proceedings of the 2023 IEEE 28th International Conference on Emerging Technologies and Factory Automation (ETFA), Sinaia, Romania, 12–15 September 2023; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
- MITRE. CVE-2022-0492: cgroups v1 release_agent Privilege Escalation Vulnerability. 2022. Available online: https://nvd.nist.gov/vuln/detail/CVE-2022-0492 (accessed on 30 January 2026).
- MITRE. CVE-2022-48699: Linux Kernel Scheduler Debugging Reference Count Vulnerability. 2022. Available online: https://nvd.nist.gov/vuln/detail/CVE-2022-48699 (accessed on 30 January 2026).
- MITRE. CVE-2022-0811: Kubernetes Container Escape via /proc/self/exe. 2022. Available online: https://nvd.nist.gov/vuln/detail/CVE-2022-0811 (accessed on 30 January 2026).
- Liao, Y.C.; Langweg, H. Cost-benefit analysis of kernel tracing systems for forensic readiness. In Proceedings of the 2nd International Workshop on Security and Forensics in Communication Systems (SFCS), Kyoto, Japan, 3 June 2014; pp. 25–36. [Google Scholar] [CrossRef] [Scilit]
- Linux Kernel Documentation. ftrace—Function Tracer. 2025. Available online: https://www.kernel.org/doc/html/latest/trace/ftrace.html (accessed on 27 August 2025).
- Linux Kernel Community. perf(1)—Linux Performance Analysis Tools. 2025. Available online: https://www.man7.org/linux/man-pages/man1/perf.1.html (accessed on 27 August 2025).
- SystemTap Project. SystemTap Beginner’s Guide. 2024. Available online: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/systemtap_beginners_guide/index (accessed on 27 August 2025).
- Wehbe, N.; Alameddine, H.A.; Pourzandi, M.; Assi, C. Empowering 5G SBA security: Time series transformer for HTTP/2 anomaly detection. Comput. Secur. 2025, 148, 104114. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Li, Q.; Zhang, C.; Wang, L.; Wang, C.; Bai, Z.; Luo, H.; Gao, T.; Ma, K.; Pan, L. DistriAD: Distributed anomaly detection for large-scale microservice systems. In Proceedings of the 2025 IEEE International Conference on Web Services (ICWS), Helsinki, Finland, 7–12 July 2025; pp. 825–834. [Google Scholar] [CrossRef] [Scilit]






| Host PID | Host PPID | Container ID | Device ID | Inode | Flags | Path |
|---|---|---|---|---|---|---|
| 2851 | 2795 | 4b0e5a55… 9438788f | 7146988523 013275691 | 4103 | 33345 | /tmp/cgrp/x/notify_on_release |
| Risk Level | Determination Criteria | Truncation Strategy | Retention Mode |
|---|---|---|---|
| High Risk | Involving kernel interfaces or privileged operations | Tail-priority truncation | + last 5 segments |
| Medium Risk | System configuration or service component paths | “” structural truncation | First 3 segments + last 2 segments + |
| Low Risk | User-space or temporary file paths | “” dynamic focusing | First 2 segments + last 3 segments + |
| Parameter Combination | Average Cosine Similarity |
|---|---|
| vs:100, ws:3, mc:1 | 0.4460 |
| vs:100, ws:5, mc:1 | 0.4385 |
| vs:50, ws:3, mc:1 | 0.4313 |
| vs:100, ws:3, mc:3 | 0.4247 |
| vs:50, ws:5, mc:1 | 0.4180 |
| vs:10, ws:3, mc:1 | 0.4095 |
| vs:50, ws:3, mc:3 | 0.4012 |
| vs:10, ws:5, mc:1 | 0.3940 |
| vs:50, ws:7, mc:1 | 0.3888 |
| vs:10, ws:3, mc:3 | 0.3816 |
| Method | Paradigm | Recall | FPR | MCC |
|---|---|---|---|---|
| Proposed AEA | Reconstruction-based | 0.820 | 0.0079 | 0.852 |
| Isolation Forest | Partition-based | 0.780 | 0.0099 | 0.820 |
| One-Class SVM | Boundary-based | 0.780 | 0.0171 | 0.808 |
| LOF | Density-based | 0.790 | 0.0085 | 0.835 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Zhou, N.; Chen, H.; Chen, Z.; Li, C.; Li, F. An Abnormal File Access Detection Model for Containers Based on eBPF Listening. Mathematics 2026, 14, 991. https://doi.org/10.3390/math14060991
Zhou N, Chen H, Chen Z, Li C, Li F. An Abnormal File Access Detection Model for Containers Based on eBPF Listening. Mathematics. 2026; 14(6):991. https://doi.org/10.3390/math14060991
Chicago/Turabian StyleZhou, Naqin, Hao Chen, Zeyu Chen, Chao Li, and Fan Li. 2026. "An Abnormal File Access Detection Model for Containers Based on eBPF Listening" Mathematics 14, no. 6: 991. https://doi.org/10.3390/math14060991
APA StyleZhou, N., Chen, H., Chen, Z., Li, C., & Li, F. (2026). An Abnormal File Access Detection Model for Containers Based on eBPF Listening. Mathematics, 14(6), 991. https://doi.org/10.3390/math14060991

