Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
krizhanovsky
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
krizhanovsky
2mo ago
Hi HN, DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them. Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon
2.
▲
Open-source XDP/TC DDoS filtering for 100G+ Linux networks
(github.com)
3 points
by
krizhanovsky
2mo ago
|
1 comments
3.
▲
by
krizhanovsky
2mo ago
Hi, thank you! Yes, xFW can be coupled with Tempesta FW ( https://github.com/tempesta-tech/tempesta ) and WebShield ( https://github.com/tempesta-tech/webshield ) to provide full L3-L7 DDoS protection
4.
▲
by
krizhanovsky
2mo ago
Hi HN, DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them. Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon
5.
▲
Show HN: Open-Source eBPF Volumetric DDoS Protection
(github.com)
3 points
by
krizhanovsky
2mo ago
|
3 comments
6.
▲
by
krizhanovsky
10mo ago
Most open-source L7 DDoS mitigation and bot-protection approaches rely on challenges (e.g., CAPTCHA or JavaScript proof-of-work) or static rules based on the User-Agent, Referer, or client geolocation. These techniques are increasingly inef
7.
▲
Using ClickHouse for L7 DDoS and Bot Traffic Analytics with Tempesta FW
(tempesta-tech.com)
1 points
by
krizhanovsky
10mo ago
|
1 comments
8.
▲
Performance optimizations for storing web server access logs in ClickHouse
(clickhouse.com)
2 points
by
krizhanovsky
1y ago
|
1 comments
9.
▲
by
krizhanovsky
1y ago
It's useful to store a web server access logs in an analytics database, e.g. to fight against bot attacks. We store structured access logs in Clickhouse, which is already good, but compression and data ordering from the post may improv
10.
▲
Stealth BGP Hijacks with URPF Filtering [pdf]
(usenix.org)
4 points
by
krizhanovsky
1y ago
|
1 comments
11.
▲
by
krizhanovsky
1y ago
uRPF prevents IP spoofing used in volumetric DDoS attacks. However, it seems uRPF is vulnerable to route hijacking on its own
12.
▲
by
krizhanovsky
1y ago
This is quite insightful, thank you. This particular project, WebShield, is simple and it didn't take too long to develop. Basically, with this project we're trying to figure out what can be built having fingerprints and traffic c
13.
▲
by
krizhanovsky
1y ago
That's a good advice, thank you. In our approach we do our best to not to affect user experience. E.g. consider an example of a company website with a blog. The company does it's best to engage more audience to their blog, product
14.
▲
by
krizhanovsky
1y ago
Hi, thank you for the reply! You can read about JA5 at https://tempesta-tech.com/knowledge-base/Traffic-Filtering-b... . But the thing is that the hashes were just inspired by the work of John Althouse and there is no
15.
▲
Show HN: An open source access logs analytics script to block bot attacks
(github.com)
37 points
by
krizhanovsky
1y ago
|
7 comments
16.
▲
The new HTTP/2 vulnerability: 'Made You Reset' CVE-2025-8671
(tempesta-tech.com)
2 points
by
krizhanovsky
1y ago
|
0 comments
17.
▲
Understanding and Improving Web Security Performance
(forbes.com)
1 points
by
krizhanovsky
1y ago
|
0 comments
18.
▲
Building your own WordPress staging with Tempesta FW
(tempesta-tech.com)
2 points
by
krizhanovsky
2y ago
|
0 comments
19.
▲
Full browser stack L7 DDoS against Russian resources
4 points
by
krizhanovsky
5y ago
|
0 comments
20.
▲
by
krizhanovsky
6y ago
The benchmarks https://github.com/ncm/computed-goto/blob/master/benchmarks/... benchmark is not applicable to this discussion because it compares _too_ small state machines. I reference my talk and
21.
▲
by
krizhanovsky
6y ago
> I'm unable to find measurements. I mean, the amount of code duplication is not an optimization parameter, the amount of Mb/s of HTTP parsed is. The measurements are covered in slides 23-24 in http://www.tempesta-te
22.
▲
by
krizhanovsky
6y ago
Thank you, I'm glad that you enjoyed the article! Regarding computed and simple goto I'd like to reference our early article discussing the parser in standard goto https://natsys-lab.blogspot.com/2014/11/
23.
▲
by
krizhanovsky
6y ago
While I addressed safety in a separate section in the article, I wouldn't argue about that: it seems Rust designers made the perfect work in safety. However, C++ is moving in this directly, bu there is the "gap" as it was des
24.
▲
by
krizhanovsky
6y ago
I still don't see any misconceptions. The reason why the kernel uses SIMD with FPU save/restore is to optimize context switches. We addressed the topic in https://netdevconf.info/0x12/session.html?kernel-tls-h
25.
▲
by
krizhanovsky
6y ago
Please read the discussion in https://www.reddit.com/r/Cplusplus/comments/jjtn5v/fast_prog... . In short, everything is doable, but before starting your project, which you're paid for, you have to g
26.
▲
by
krizhanovsky
6y ago
There were quite a long work, for couple of years, on the parser. The first article about the parser is https://natsys-lab.blogspot.com/2014/11/the-fast-finite-stat... and next I updated it significantly in my tal
27.
▲
by
krizhanovsky
6y ago
I didn't mean anything condescending here actually. The point is that when people starting programming, it's good to put them into a restricted environment, so that they get used to use the right tools and in the right way. For ex
28.
▲
by
krizhanovsky
6y ago
But did you? My FreeBSD knowledge is quite outdated, I believe the last version I worked with is 7, but I believe at some point, it was possible to compile C++ kernel modules for FreeBSD. This time I can not find the proof, but plus to that
29.
▲
by
krizhanovsky
6y ago
Also if you don't like my example with quick fix of some dirty project, then consider InnoDB storage engine which was developed in pure C for 2 decades, but now it's C++.
30.
▲
by
krizhanovsky
6y ago
Well, we didn't mention this in the article, but this is very practical actually. About 10 years ago we had a request significant reworking an open source DNS server and the main problem with the project was that almost whole logic was
More ›