Mitigating attacks against internet infrastructure through eBPF programs
Universities are increasingly targeted by layer 7 DDoS attacks, specifically those aimed at their DNS authoritative nameservers, which can cripple critical services. Our project focused on developing a robust defense within the SURF network by leveraging Linux eBPF programs for real-time, in-kernel DNS traffic filtering. This approach allows us to inspect and filter packets at incredible speeds, crucial for mitigating the impact of these high-volume attacks directed at these essential servers.
Speaker
01
eBPF
02
DDoS
03
Linux
