---
format: "aidr-story-markdown/v1"
id: "ea803dfd17bfd0bbce68a7f82df99c2d2255fbdbe8215e0fed94941c7711e2da"
canonical_url: "https://aidr.today/ea803dfd?lang=en"
title: "Dropping eBPF CPU Cost by About 90% with Memoization (Not AI Gen)"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-14T14:29:23.000Z"
category: "Infra"
topics: ["ebpf","memoization","performance","infra","optimization","security"]
source_urls: ["https://nathannaveen.dev/posts/dropping-ebpf-cpu-cost-by-90/","https://news.ycombinator.com/item?id=49697477"]
summary: "My brother and I spent a lot of time designing our eBPF security agent to be really fast from the ground up, but recently we discovered we could make it much faster using memoization! A couple of weeks ago, I profiled the eBPF code and found that the most expensive part of the protection isn’t actually enforcing a policy (allow/deny), but figuring out which policy applies to a given file open."
---

# Dropping eBPF CPU Cost by About 90% with Memoization \(Not AI Gen\)

> [Open the canonical story](<https://aidr.today/ea803dfd?lang=en>)

**Published:** 2026-09-14T14:29:23.000Z
**Category:** Infra
**Topics:** ebpf, memoization, performance, infra, optimization, security

## Summary

My brother and I spent a lot of time designing our eBPF security agent to be really fast from the ground up, but recently we discovered we could make it much faster using memoization\! A couple of weeks ago, I profiled the eBPF code and found that the most expensive part of the protection isn’t actually enforcing a policy \(allow/deny\), but figuring out which policy applies to a given file open\.

## Sources

- [Story source](<https://nathannaveen.dev/posts/dropping-ebpf-cpu-cost-by-90/>)
- [Discussion](<https://news.ycombinator.com/item?id=49697477>)

