Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Runtime Security at Scale With EBPF: Hybrid Detection and Root Cause Analysis in CloudNative Systems - Yogeshwara Krishna Kota, Rakuten Mobile & Rutuj Waghare, Rakuten Symphony
Modern Kubernetes workloads make it increasingly difficult to understand what is really happening at runtime. Traditional observability tools often miss critical low-level behaviours, especially across process execution.
In this talk, we present a kernel-level observability approach powered by Sauron eBPF that captures high-fidelity runtime signals directly from the Linux kernel. By tracking process lifecycle events, the system builds a unified, real-time view of workload behaviour.
On top of this telemetry, we introduce a Graph-AI analytics layer: data feed an AI engine that learns semantically meaningful node embeddings and models the process tree as a temporal graph. This allows the system to capture both node-level behaviour and inter-node temporal relationships, enabling the detection of anomalies that traditional approaches typically miss.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Runtime Security at Scale With EBPF: Hybrid Detection and Root Cause Analysis in CloudNative Systems - Yogeshwara Krishna Kota, Rakuten Mobile & Rutuj Waghare, Rakuten Symphony
Modern Kubernetes workloads make it increasingly difficult to understand what is really happening at runtime. Traditional observability tools often miss critical low-level behaviours, especially across process execution.
In this talk, we present a kernel-level observability approach powered by Sauron eBPF that captures high-fidelity runtime signals directly from the Linux kernel. By tracking process lifecycle events, the system builds a unified, real-time view of workload behaviour.
On top of this telemetry, we introduce a Graph-AI analytics layer: data feed an AI engine that learns semantically meaningful node embeddings and models the process tree as a temporal graph. This allows the system to capture both node-level behaviour and inter-node temporal relationships, enabling the detection of anomalies that traditional approaches typically miss.






