XDP filter optimization and traffic-leak reduction
Moving filters to native driver mode, removing expensive loops and adding payload inspection for more reliable attack filtering.
Read in fullParis, France
My work sits between Linux systems, networks and security: Proxmox platforms, routing, BPF/XDP packet filtering, DDoS mitigation, automation and backend tools for operating them.
$ whoami
Curean Niculai
Systems administrator, network engineer and programmer
$ focus --current
$ status
Available for relevant technical conversations
Selected work
Moving filters to native driver mode, removing expensive loops and adding payload inspection for more reliable attack filtering.
Read in fullAn authenticated internal API for querying state stored across several BPF maps.
Read in fullBehavioral and request-level controls for automated browsers that imitate normal visitors and evade basic bot signatures.
Read in fullA multi-stage packet-filtering approach designed to reject malicious traffic before it consumes the normal Linux networking path.
Read in fullWhat I work on
I am most useful where infrastructure, networking and application behavior meet. That includes virtualization hosts, packet paths, routing between networks, abuse controls, backup systems and the small internal services that make operations easier to verify.
I prefer measurable changes, explicit rollback paths and documentation that says what was actually built. The case studies here include the constraints, implementation and limits of the work rather than turning each project into a slogan.
Technology watch
How false route announcements can redirect Internet traffic, and how IRR data and RPKI help network operators reduce the risk.
Read the articleFrom the archive
A new update for the website, notes on the ILShield filtering appliance and early thoughts about opening a datacenter in Romania.
Read the post