logo

Open-source XDP/TC DDoS filtering for 100G+ Linux networks

Posted by krizhanovsky |2 hours ago |1 comments

krizhanovsky 2 hours ago

Hi HN,

DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them.

Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon handles gRPC requests from CLI tool or WebAPI (via C library).

It supports two packet-path architectures:

* host-based protection, such as CDN edge or on-premises application delivery controller (ADC) cases, where the host is a TCP connection endpoint. This is good for protecting a local web or DNS server.

* router-based protection, such as ISP, hosting, or IaaS provider cases, where the host routes IP packets to protected servers or networks.

Router-based deployment can be always-on/pass-through or on-demand/redirection protection. In the later case, a node may not "see" normal clean traffic and may receive only traffic containing a DDoS attack. Also, the node may receive only client-to-server traffic, as in direct server return (DSR) or some traffic scrubbing scenarios. In this mode a DDoS sensor and mitigation controllers are typically needed.

Traffic performance metrics are exported in Prometheus format.

DDoS incidents are aggregated per source IP and logged to ClickHouse for analysis.

A dry-run (evaluation) - mode allows you to observe all reported incidents and metrics without blocking traffic..

Single Xeon Gold 6348 with ConnectX-6 dual 100Gbps reach 196Mpps and 176Gbps of filtering capacity.

* GitHub repository: https://github.com/tempesta-tech/xFW

* documentation: https://tempesta-tech.com/tempesta-escudo/knowledge-base/XFW...

* performance benchmarks: https://tempesta-tech.com/tempesta-escudo/knowledge-base/Per...

* Netdev 0x1a talk: https://netdevconf.info/0x1A/sessions/talk/tempesta-xfw-open...