In addition to his blog post, which will probably be great, my reading list would be:
* First, the McCanne BPF+ paper.
* Then, the pcap source code, particularly pcap/optimize.c, perhaps starting with the peephole optimization stuff.
* Finally, one of the BPF JIT projects (there's one on SourceForge). Amusingly: the Linux BPF JIT was at one point used as an aid to memory corruption, by jit-spraying kernel memory. So also consider reading any of the jit-spray papers.