5 ms·
i've been looking at this recently and this isn't just for bots. ebpf fingerprinting is how cloudflare quickly detects ddos attacks. https://blog.cloudflare.co
by spense 1y ago
i've been looking at this recently and this isn't just for bots. ebpf fingerprinting is how cloudflare quickly detects ddos attacks.
https://blog.cloudflare.com/defending-the-internet-how-cloudflare-blocked-a-monumental-7-3-tbps-ddos/#real-time-fingerprinting https://blog.cloudflare.com/defending-the-internet-how-cloud...
- v5v3 1y agoWhat's the simplest way to implement eBPF filtering? As in a NFTables/Fail2Ban level usability.
- vetrom 1y agosomething like https://github.com/renanqts/xdpdropper https://github.com/renanqts/xdpdropper or cilium's host firewall or https://github.com/boylegu/TyrShield https://github.com/boylegu/TyrShield exist or https://github.com/ebpf-security/xdp-firewall https://github.com/ebpf-security/xdp-firewall today and implement ebpf filter based firewalling. Of these there is a sample integration for XDPDropper to fail2ban that never got merged https://github.com/fail2ban/fail2ban/pull/3555/files https://github.com/fail2ban/fail2ban/pull/3555/files -- I don't think anyone else has really worked on that junction of functionality yet. There's also wazuh which seems to package ebpf tooling up with a ton of detection and management components, but its not a simple to deploy as fail2ban.
- v5v3 1y agoThank you
- mhio 1y agohttps://bpfilter.io/ https://bpfilter.io/ https://github.com/facebook/bpfilter https://github.com/facebook/bpfilter https://lwn.net/Articles/1017705/ https://lwn.net/Articles/1017705/
- v5v3 1y agoThank you!