XDP in practice: integrating XDP into our DDoS mitigation pipeline

XDP in practice: integrating XDP into our DDoS mitigation pipeline
复制标题

XDP 实践:将 XDP 集成到我们的 DDoS 缓解管道中

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
W. Johnson
W. Johnson
中科院分区:
--
文献类型:
--
作者:
C. Gallagher;R. Lall;W. Johnson

文献摘要

被引文献

相似文献

为了吸收大型DDoS(分布式拒绝服务)攻击,Cloudflare DDoS缓解团队开发了一种基于内核旁路和经典BPF的解决方案。这允许我们在用户空间中过滤网络数据包,跳过Netfilter和Linux网络堆栈通常进行的数据包处理。这种方法解决了仅使用普通Linux内核特性处理大型数据包泛洪时遇到的性能问题。在本文中,我们将首先介绍我们目前的架构,然后讨论一个建议的解决方案的基础上XDP和eBPF。我们将解释如何在我们的基础设施中使用XDP,以及我们的系统的哪些部分需要重写和调整以使用它。然后,我们将总结到目前为止使用XDP时遇到的问题。
To absorb large DDoS (distributed denial of service) attacks, the Cloudflare DDoS mitigation team has developed a solution based on kernel bypass and classic BPF. This allows us to filter network packets in userspace, skipping the usual packet processing done by Netfilter and the Linux network stack. This approach has solved performance issues that were experienced whilst handling large packet floods using solely the vanilla Linux kernel features. In this paper we will first introduce our current architecture and then discuss a proposed solution based on XDP and eBPF. We will explain how XDP can be used in our infrastructure and which parts of our system need to be rewritten and adapted to make use of it. We will then conclude with the issues we have experienced so far with XDP.