<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>运行时防护 on 黄文卓 | DevOps Engineer</title>
    <link>https://socake.github.io/tags/%E8%BF%90%E8%A1%8C%E6%97%B6%E9%98%B2%E6%8A%A4/</link>
    <description>Recent content in 运行时防护 on 黄文卓 | DevOps Engineer</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh-CN</language>
    <managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor>
    <webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster>
    <copyright>© 2026 Wenzhuo Huang</copyright>
    <lastBuildDate>Thu, 02 Apr 2026 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E8%BF%90%E8%A1%8C%E6%97%B6%E9%98%B2%E6%8A%A4/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Tetragon eBPF 运行时安全实战：进程/网络/文件策略、与 Falco 的对比</title>
      <link>https://socake.github.io/posts/tetragon-runtime-security/</link>
      <pubDate>Thu, 02 Apr 2026 10:00:00 +0800</pubDate>
      <author>17691281867@163.com (Wenzhuo Huang)</author>
      <guid>https://socake.github.io/posts/tetragon-runtime-security/</guid>
      <description>Kubernetes 运行时安全是传统 EDR 难以覆盖的盲区。Tetragon 用 eBPF 在内核态采集进程、网络、文件和系统调用事件，并能在内核就地阻断攻击动作。本文从架构原理出发，讲解 TracingPolicy 语法、典型攻击检测（反弹 shell、提权、敏感文件访问）、阻断机制、性能开销，以及它与 Falco 的差异。</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/tetragon-runtime-security/featured.jpg" />
    </item>
    
  </channel>
</rss>
