extended Berkeley Packet Filter

is a powerful technology that allows running sandboxed programs within the Linux kernel without modifying the kernel source code.

a generic in-kernel execution environment

    All notes