Processing network traffic at 100 Gigabits per second (100GbE) presents severe CPU overheads for traditional Linux networking stacks. A standard Linux kernel allocates a complex socket buffer metadata structure (`sk_buff`) for every incoming packet, causing heavy memory allocation and cache line bouncing.

eBPF (Extended Berkeley Packet Filter) combined with XDP (eXpress Data Path) provides a programmable in-kernel hook directly inside the Network Interface Card (NIC) driver layer. By executing bytecode before `sk_buff` memory allocation occurs, XDP enables sub-microsecond packet filtering and DDoS mitigation at line rate.

1. The XDP Packet Processing Pipeline

XDP hooks execute at the lowest possible layer in the Linux network subsystem. The execution path follows:

NIC Direct Memory Access (DMA) -> XDP Driver Hook (eBPF Bytecode) -> Return Action Code

Depending on the evaluation outcome of the eBPF program, one of five action codes is returned:

  • `XDP_DROP` (Line-Rate Drop): Instantly discards the packet at the DMA ring buffer. Ideal for dropping SYN flood attacks (14.8M packets/sec per core).
  • `XDP_TX` (Bouncer / Bounce-back): Re-transmits the packet back out the same network interface it arrived on (useful for L4 load balancers).
  • `XDP_REDIRECT`: Bypasses the host stack entirely, routing the packet to a different NIC or AF_XDP socket.
  • `XDP_PASS`: Hands the packet over to the standard Linux kernel network stack (`sk_buff` allocation).

2. C eBPF Kernel Program for High-Speed DDoS Dropper

#include #include #include #include #include // BPF Map storing malicious IP addresses to block struct { __uint(type, BPF_MAP_TYPE_HASH); __uint(max_entries, 100000); __type(key, __be32); __type(value, __u64); // Drop packet counter } blocked_ip_map SEC(".maps"); SEC("xdp") int xdp_ip_filter(struct xdp_md *ctx) { void *data_end = (void *)(long)ctx->data_end; void *data = (void *)(long)ctx->data; // Parse Ethernet Header struct ethhdr *eth = data; if ((void *)(eth + 1) > data_end) return XDP_PASS; // Check for IP packet if (eth->h_proto != __constant_htons(ETH_P_IP)) return XDP_PASS; // Parse IP Header struct iphdr *iph = (void *)(eth + 1); if ((void *)(iph + 1) > data_end) return XDP_PASS; __be32 src_ip = iph->saddr; // Lookup IP in BPF Hash Map __u64 *value = bpf_map_lookup_elem(&blocked_ip_map, &src_ip); if (value) { __sync_fetch_and_add(value, 1); return XDP_DROP; // DROP instantly without kernel sk_buff overhead! } return XDP_PASS; } char _license[] SEC("license") = "GPL";

3. Python BCC Host Controller Program

from bcc import BPF import time import socket import struct # Load eBPF C program and attach to eth0 b = BPF(src_file="xdp_filter.c") fn = b.load_func("xdp_ip_filter", BPF.XDP) b.attach_xdp("eth0", fn, 0) print("[SUCCESS] eBPF XDP Firewall attached to eth0 interface.") # Add malicious IP (192.168.1.50) to blocked BPF map blocked_map = b.get_table("blocked_ip_map") bad_ip = struct.unpack("I", socket.inet_aton("192.168.1.50"))[0] blocked_map[blocked_map.key_type(bad_ip)] = blocked_map.leaf_type(0) try: while True: time.sleep(2) if bad_ip in blocked_map: print(f"[METRIC] Total Packets Dropped from 192.168.1.50: {blocked_map[bad_ip].value}") except KeyboardInterrupt: b.remove_xdp("eth0", 0) print("[INFO] Detached XDP program.")