Skip to content

Latest commit

 

History

254 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Beeper: Application-Layer Parsing in eBPF

Crates.io GPL-v3 licensed Build Status DOI

beeper

Beeper (BEEline's ParsER) is an application-layer parser for eBPF. It allows you to process L7 protocols directly in the kernel, which can accelerate user space applications significantly. It achieves this by constructing an Aho-Corasick-like DFA in user space, reducing the parsing complexity to an eBPF-compatible level. With beeper, you can for example monitor application-layer traffic, redirect it based on its payload, or respond to it, directly from the kernel. For more information, please have a look at the full paper.

Protocol Status Minimal Kernel Version
HTTP/1.1 6.8
HTTP/2 6.8
gRPC WIP

Use cases

hyper-fast-path uses beeper to serve static assets from the kernel. This improves the throughput of HTTP servers by up to 2.8x.

Usage

First, in the Rust program, create a new parser instance, add the desired headers that it should parse, and attach it to an existing eBPF program:

use beeper::h2;

let h2 = h2::Parser::new()
    .capture_hdr(&beeper::header::PATH)?
    .capture_hdr(&http::header::CONTENT_LENGTH)?
    .replace_parse_msg("parse_h2")
    .replace_extract("extract_h2_match")
    .attach(prog_fd)?;

Next, in your eBPF program, import the beeper.h header, define the stub functions, and call them with the input buffer:

#include "beeper.h"

// stub funcs
BEEPER_EXTRACT_MATCH(extract_h2_match)
BEEPER_H2_PARSE_MSG(parse_h2)

// the header matches occur in the same order as configured in user space
#define H2_PATH_MID 0
#define H2_CONTENT_LENGTH_MID 1

SEC("sk_msg")
int msg_verdict(struct sk_msg_md *msg) {
    struct parse_res pres = { 0 };
    struct h2_frame frame = { 0 };
    int msg_len = parse_h2(msg, &pres, &frame);
    if (msg_len >= 0) {
        struct hdr_str path = { 0 };
        if (extract_h2_match(msg, &pres, H2_PATH_MID, &path) == 0) {
            // note that path can be Huffman-encoded
        }
    }
}

Finally, to make this all compile, beeper relies on xbpf. Add the following to build.rs:

use beeper::build::clang_args;
use xbpf::build::Builder;

fn main() {
    Builder::new()
        .clang_arg(clang_args().iter())
        .export_headers()
        .build();
}

Please refer to the example for a simple HTTP monitoring tool.

Build

To build and test beeper, you need to install the following packages:

sudo apt install clang-18 llvm-18 libelf-dev zlib1g-dev linux-headers-`uname -r` linux-tools-`uname -r` 

You should now be able to compile and test beeper as follows:

RUST_LOG=trace cargo test

Citation

If you use this library to conduct your own research, please cite the full paper as follows:

@misc{beeline,
      title={Enforcing Application-Layer Policies in eBPF}, 
      author={Laurin Brandner and Ayush Mishra and Sebastiano Miano and Aurojit Panda and Gianni Antichi and Laurent Vanbever},
      year={2026},
      eprint={2605.31084},
      archivePrefix={arXiv},
      primaryClass={cs.NI},
      url={https://arxiv.org/abs/2605.31084}, 
}

About

Application-layer parsing in eBPF

Topics

Resources

Stars

9 stars

Watchers

2 watching

Forks

Releases

Contributors

Languages