Kernel-native DDoS defense

Stop the flood at the wire.

DDoS Shield is a Rust + Aya eBPF/XDP protection engine that intercepts abusive traffic before it burns CPU on sockets, TLS, reverse proxies, or application workers.

RUST + AYAXDP NATIVE1.3 MB ENGINESTATELESS SYN DEFENSE
LIVE PACKET PATH
Attack packetsDROP
Legitimate trafficPASS
Decision pointXDP
143unit tests
12traffic fixtures
0clippy warnings
Rustmemory-safe control plane
Performance profile

Built around the cheapest possible decision.

The hot path stays tiny, bounded, and kernel-native so the server spends its resources on real users instead of attack traffic.

Engine footprint~1.3 MB

Compact memory budget for lean VPS and edge hosts.

Hot-path budget<40 ns

Minimal packet decision path engineered for XDP execution.

10GbE packet ceiling14.88 Mpps

64-byte line-rate reference for a 10GbE interface.

SYN-cookie compute295.36 Mpps

Stateless cookie computation profile using SipHash-2-4.

Defense engine

Small surface. Serious packet control.

DDoS Shield combines deterministic XDP decisions with compact telemetry and an adaptive userspace control plane.

XDP

Earliest practical interception

Drop obviously hostile packets in the receive path before they climb through the full Linux networking stack.

kernel first
CMS

Count-Min Sketch telemetry

Depth 4 × width 16,384 gives fixed-memory flow pressure tracking without heavyweight per-source state.

128 KiB sketch
SYN

Stateless SYN challenge

SipHash-2-4 SYN cookies and XDP_TX keep connection floods from forcing unnecessary allocation.

no state explosion
DEC

Epoch decay

Traffic history ages out predictably so counters stay useful during long-running attacks and changing traffic patterns.

bounded history
ML

Adaptive anomaly scoring

Isolation Forest scoring lives outside the tightest packet path, keeping expensive reasoning away from every packet.

<50 µs scoring goal
CTL

Tokio control plane

Async orchestration handles configuration, policy updates, telemetry, and lifecycle management without bloating the dataplane.

clean separation
Packet architecture

One packet. One bounded decision path.

The architecture is intentionally split so the XDP program does only the work that must happen at packet speed.

01

NIC RX

Frame arrives from the network interface.

02

XDP parse

Bounded header parsing and sanity checks.

03

Rate signal

Compact counters + Count-Min Sketch update.

04

Policy

PASS, DROP, or stateless challenge.

05

XDP_TX

Reply to selected SYN traffic without climbing the stack.

06

Userspace

Tokio telemetry, decay, anomaly scoring, and control.

Design rule: no unnecessary work in the per-packet path.eBPF dataplane · async control plane
Applicationbusiness logic
Reverse proxy / WAFHTTP / TLS
TCP/IP stackkernel networking
DDoS Shield / XDPDROP HERE
NICwire ingress
Why kernel-first

Don’t pay L7 prices for L3/L4 garbage.

Every abusive packet rejected before TCP, TLS, Nginx, or the application is work the machine never has to perform.

✓Preserve CPU cycles and application workers for legitimate sessions.
✓Reduce state pressure during SYN floods and high-packet-rate attacks.
✓Keep protection practical for low-cost $5–$20 VPS deployments.
Simple pricing

Start free. Turn on Pro when the infrastructure matters.

No traffic-based billing. No surprise bandwidth charges. One predictable price per protected host.

Annual: $216 / protected host / year
Standard
$0/ forever
Free for personal, lab, and evaluation use.

Serious kernel-first protection for developers, homelabs, test environments, and lean VPS deployments.

Get DDoS Shield
✓XDP/eBPF packet filtering
✓Kernel-first mitigation path
✓Count-Min Sketch telemetry
✓Stateless SYN-cookie defense
✓Epoch decay + local policies
✓CLI configuration and local operation
Pro
$24/ host / month
Billed monthly. Cancel anytime.
Most popular

Everything in Standard, plus adaptive detection, deeper visibility, and production-focused controls for internet-facing infrastructure.

Upgrade to Pro ($24/mo) →
✓Everything in Standard
✓Adaptive anomaly detection
✓Isolation Forest scoring
✓Advanced policy tuning
✓Extended telemetry + performance analytics
✓Priority updates and support
Predictable by design. Attack volume does not change the subscription price.

Standard vs Pro

Choose the control depth your host needs.
CapabilityStandardPro
XDP/eBPF packet filtering✓✓
Kernel-first mitigation✓✓
Count-Min Sketch detection✓✓
SYN-cookie protection✓✓
Epoch decay✓✓
XDP_TX challenge / response✓✓
Local CLI + configuration✓✓
Basic traffic policies✓✓
Adaptive anomaly detection—Included
Isolation Forest engine—Included
Advanced policy tuning—Included
Extended telemetry—Included
Performance analytics—Included
Priority updatesCommunityPriority
SupportCommunityPriority
Production / commercial useEvaluationIncluded
Pricing shown for the current launch plan and may change before general availability. Taxes, if applicable, are excluded. Pro is licensed per protected host.
Operator experience

Rust-native. Linux-native. No heavyweight appliance.

The project is built as a compact host protection layer: an Aya XDP dataplane plus a Tokio userspace controller, designed to fit naturally into Linux infrastructure.

AyaTokioSipHash-2-4Count-Min SketchIsolation Forest
shieldctl / live
$ sudo shieldctl status --live

interface       enp1s0
mode            xdp-native
dataplane       attached
policy          PASS / DROP / TX_CHALLENGE
cms             4 × 16384  ≈128 KiB
epoch-decay     active
syn-cookie      SipHash-2-4
anomaly         Isolation Forest
control-plane   Tokio

● protection engine active
Direct communication

Engineered for mission-critical hosts.

Whether you need kernel-level debugging, incident escalation, or enterprise licensing, reach our team directly.

ENG

Technical Support

Direct communication with our engineering team for eBPF/XDP driver issues, policy tuning, and kernel telemetry.

[email protected] Lead Technical Support · 24/7 Priority
BIZ

Sales & Inquiries

Contact our commercial team for multi-host Pro deployments, custom SLA requirements, and enterprise volume discounts.

[email protected] Commercial Team · Rapid Response
DDoS Shield v0.2

Protection belongs closer to the wire.

A compact XDP defense engine for operators who want less overhead, fewer moving parts, and a much smaller attack cost per packet.

Upgrade to Pro ($24/mo) →
Performance methodology. 14.88 Mpps is the 10GbE 64-byte wire-rate reference. The <40 ns hot-path and 295.36 Mpps SYN-cookie values are analytical hot-path / computation figures; end-to-end throughput varies by NIC, CPU, driver, kernel, and traffic mix.