libseccomp provides an easy to use, platform independent, interface to the Linux syscall filtering mechanism.
copied from cf-staging / seccompThe libseccomp library provides an easy to use, platform independent, interface to the Linux Kernel's syscall filtering mechanism. The libseccomp API is designed to abstract away the underlying BPF based syscall filter language and present a more conventional function-call based filtering interface that should be familiar to, and easily adopted by, application developers.