XDP filter optimization and traffic-leak reduction
Moving filters to native driver mode, removing expensive loops and adding payload inspection for more reliable attack filtering.
Read in fullParis, France
I spend most of my time close to the stack: Linux hosts, Proxmox, routing, packet filtering, DDoS problems and the small tools that make this kind of work less painful to run.
$ whoami
Curean Niculai
Systems administrator, network engineer and programmer
$ focus --current
$ status
Available for relevant technical conversations
Selected work
Moving filters to native driver mode, removing expensive loops and adding payload inspection for more reliable attack filtering.
Read in fullAn authenticated internal API for querying state stored across several BPF maps.
Read in fullBehavioral and request-level controls for automated browsers that imitate normal visitors and evade basic bot signatures.
Read in fullA multi-stage packet-filtering approach designed to reject malicious traffic before it consumes the normal Linux networking path.
Read in fullWhat I work on
Most of the projects here came from practical constraints: a host taking bad traffic, a tunnel behaving strangely because of MTU, a Proxmox workflow that needed to be repeatable, or a panel that had to pull useful state out of an existing game-server database.
I try to write these pages the way I would explain the work to another technical person: what the issue was, what I changed, and where the limits were.
Technology watch
How false route announcements can redirect Internet traffic, and how IRR data and RPKI help network operators reduce the risk.
Read the articleFrom the archive
A quick website update, plus what I am currently doing with ILShield and my longer-term plans in Romania.
Read the post