Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Build a Kernel-Module Sandbox for an Untrusted Code Service
Code

Build a Kernel-Module Sandbox for an Untrusted Code Service

FreeVerified credential4 weeksExpert

Overview

What this challenge is about.

Design a defense-in-depth sandbox with seccomp-bpf and gVisor, test 8 escape techniques, then deliver your report to earn a verifiable certificate.

The scenario

The startup (used by 4 of the top 10 tech companies' hiring teams, expanding to mainland China) cannot afford a third escape — one more would trigger contract-cancellation clauses.

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Replace a Docker-only sandbox with a defense-in-depth layered sandbox that blocks all 8 attempted escape techniques while keeping runtime overhead under 15 percent.

Earning criteria — what you'll demonstrate

  • Design defense-in-depth using seccomp, namespaces, and gVisor together
  • Write production-grade seccomp-bpf filters with audit + deny semantics
  • Run an honest red-team exercise against your own design
  • Quantify performance overhead against a real baseline

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Computer Systems Security

Master · Security

Strong alignment

This challenge maps to Computer Systems Security at the Master level. It sharpens the same practical skills your coursework expects — but in a real industry context with actual constraints and deliverables.

One more thing

You can put a credential on your CV by Friday.