Tcpdump use the BPF syntax to filter packages. In the current
linux kernel,BPF was implemented and extended as a kernel virtual machine,when cooperated with the perf module,they can be used for collect trace info of the system. see https://lwn.net/Articles/599755/