Compact memory budget for lean VPS and edge hosts.
Stop the flood at the wire.
DDoS Shield is a Rust + Aya eBPF/XDP protection engine that intercepts abusive traffic before it burns CPU on sockets, TLS, reverse proxies, or application workers.
Built around the cheapest possible decision.
The hot path stays tiny, bounded, and kernel-native so the server spends its resources on real users instead of attack traffic.
Minimal packet decision path engineered for XDP execution.
64-byte line-rate reference for a 10GbE interface.
Stateless cookie computation profile using SipHash-2-4.
Small surface. Serious packet control.
DDoS Shield combines deterministic XDP decisions with compact telemetry and an adaptive userspace control plane.
Earliest practical interception
Drop obviously hostile packets in the receive path before they climb through the full Linux networking stack.
Count-Min Sketch telemetry
Depth 4 × width 16,384 gives fixed-memory flow pressure tracking without heavyweight per-source state.
Stateless SYN challenge
SipHash-2-4 SYN cookies and XDP_TX keep connection floods from forcing unnecessary allocation.
Epoch decay
Traffic history ages out predictably so counters stay useful during long-running attacks and changing traffic patterns.
Adaptive anomaly scoring
Isolation Forest scoring lives outside the tightest packet path, keeping expensive reasoning away from every packet.
Tokio control plane
Async orchestration handles configuration, policy updates, telemetry, and lifecycle management without bloating the dataplane.
One packet. One bounded decision path.
The architecture is intentionally split so the XDP program does only the work that must happen at packet speed.
NIC RX
Frame arrives from the network interface.
XDP parse
Bounded header parsing and sanity checks.
Rate signal
Compact counters + Count-Min Sketch update.
Policy
PASS, DROP, or stateless challenge.
XDP_TX
Reply to selected SYN traffic without climbing the stack.
Userspace
Tokio telemetry, decay, anomaly scoring, and control.
Don’t pay L7 prices for L3/L4 garbage.
Every abusive packet rejected before TCP, TLS, Nginx, or the application is work the machine never has to perform.
Start free. Turn on Pro when the infrastructure matters.
No traffic-based billing. No surprise bandwidth charges. One predictable price per protected host.
Serious kernel-first protection for developers, homelabs, test environments, and lean VPS deployments.
Get DDoS ShieldEverything in Standard, plus adaptive detection, deeper visibility, and production-focused controls for internet-facing infrastructure.
Upgrade to Pro ($24/mo) →Standard vs Pro
Choose the control depth your host needs.| Capability | Standard | Pro |
|---|---|---|
| XDP/eBPF packet filtering | ✓ | ✓ |
| Kernel-first mitigation | ✓ | ✓ |
| Count-Min Sketch detection | ✓ | ✓ |
| SYN-cookie protection | ✓ | ✓ |
| Epoch decay | ✓ | ✓ |
| XDP_TX challenge / response | ✓ | ✓ |
| Local CLI + configuration | ✓ | ✓ |
| Basic traffic policies | ✓ | ✓ |
| Adaptive anomaly detection | — | Included |
| Isolation Forest engine | — | Included |
| Advanced policy tuning | — | Included |
| Extended telemetry | — | Included |
| Performance analytics | — | Included |
| Priority updates | Community | Priority |
| Support | Community | Priority |
| Production / commercial use | Evaluation | Included |
Rust-native. Linux-native. No heavyweight appliance.
The project is built as a compact host protection layer: an Aya XDP dataplane plus a Tokio userspace controller, designed to fit naturally into Linux infrastructure.
$ sudo shieldctl status --live interface enp1s0 mode xdp-native dataplane attached policy PASS / DROP / TX_CHALLENGE cms 4 × 16384 ≈128 KiB epoch-decay active syn-cookie SipHash-2-4 anomaly Isolation Forest control-plane Tokio ● protection engine active
Engineered for mission-critical hosts.
Whether you need kernel-level debugging, incident escalation, or enterprise licensing, reach our team directly.
Technical Support
Direct communication with our engineering team for eBPF/XDP driver issues, policy tuning, and kernel telemetry.
[email protected]Sales & Inquiries
Contact our commercial team for multi-host Pro deployments, custom SLA requirements, and enterprise volume discounts.
[email protected]Protection belongs closer to the wire.
A compact XDP defense engine for operators who want less overhead, fewer moving parts, and a much smaller attack cost per packet.