Overview
What this challenge is about.
Design a defense-in-depth sandbox with seccomp-bpf and gVisor, test 8 escape techniques, then deliver your report to earn a verifiable certificate.
CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced
The Brief
What you'll do, and what you'll demonstrate.
Replace a Docker-only sandbox with a defense-in-depth layered sandbox that blocks all 8 attempted escape techniques while keeping runtime overhead under 15 percent.
Earning criteria — what you'll demonstrate
- Design defense-in-depth using seccomp, namespaces, and gVisor together
- Write production-grade seccomp-bpf filters with audit + deny semantics
- Run an honest red-team exercise against your own design
- Quantify performance overhead against a real baseline
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Computer Systems Security
Master · Cs Se
Fit score: 1
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
Careers
Roles this prepares you for.
Real titles. Real skill bridges. Pick the one closest to your trajectory.