XDP (eXpress Data Path)
Drops volumetric DDoS attacks directly at the NIC network driver layer. No sk_buff allocation, zero kernel memory waste.
ZeroKernel enforces dynamic micro-segmentation directly inside the Linux kernel socket buffer. Intercept and drop hostile network packets at wire-speed before they touch the TCP/IP stack.
Packets Inspected / Sec
Kernel Hook Latency
Context Switch Drop
Observe packets passing directly through the XDP network card driver layer versus traditional user-space iptables handling.
Toggle XDP mitigation to drop hostile payloads before kernel memory allocations occur.
Bypassing the entire userspace network daemon overhead by attaching safe, JIT-compiled bytecode directly into the Linux socket layer.
Drops volumetric DDoS attacks directly at the NIC network driver layer. No sk_buff allocation, zero kernel memory waste.
Pins identity-aware access rules to socket creation. Blocks malicious outbound C2 callbacks right in `connect()` syscalls.
Streams packet metadata to user-space in sub-microsecond batches without lock contention using BPF ring buffers.
Simulate real-time packet inspection, XDP drop rules, and ring-buffer telemetry emission directly from browser runtime.
Real-time packet verification through kernel security maps.
Direct NIC Driver (XDP) vs Traditional iptables/netfilter latency.
Verified patterns for high-performance eBPF probes in C, Rust (Aya), and Go (Cilium/ebpf).
// Clang / C: Wire-speed XDP filter with IP header parsing
#include <linux/bpf.h>
#include <bpf/bpf_helpers.h>
SEC("xdp")
int xdp_firewall(struct xdp_md *ctx) {
void *data = (void *)(long)ctx->data;
void *data_end = (void *)(long)ctx->data_end;
// Bounds check to satisfy the in-kernel eBPF verifier
if (data + sizeof(struct ethhdr) > data_end)
return XDP_PASS;
return XDP_DROP;
}
Official core tooling, kernel interfaces, and production frameworks.
eBPF-based networking, observability, and security for Kubernetes and cloud workloads.
Standard C library for loading eBPF programs and managing BPF objects in Linux kernels.
Toolkit for creating efficient kernel tracing and manipulation programs with Python bindings.
The standard architectural hub for eBPF kernel innovations and specifications.
XDP programs execute before the Linux kernel allocates an `sk_buff` packet descriptor. This achieves raw packet throughput exceeding 24 million packets per second per CPU core.
Supported actions: XDP_DROP, XDP_TX, XDP_REDIRECT, XDP_PASS.
By attaching to `sock_ops` and `cgroup/connect4`, ZeroKernel queries Kubernetes Pod metadata and process namespaces before granting socket descriptors.
Introduced in Linux 5.8, `BPF_MAP_TYPE_RINGBUF` replaces per-CPU perf buffers, eliminating memory reservation overhead and out-of-order event delivery.