CrabShield and the trade-offs of XDP-based packet dropping
NetworkingComments
The claim about bypassing the stack assumes the bottleneck is always in the kernel. Some NIC drivers implement XDP in software, which still consumes CPU cycles.
I wonder how this interacts with tools like SeaBee... if you're moving the firewall to the driver level, does that create new blind spots for root-level tampering... or maybe just a new surface to harden?
Upstream providers often let small floods through that still choke a modest VPS. I have seen 500Mbps bursts kill a machine's responsiveness because the kernel spent everything on nftables; the marginal gain is actually huge in those cases.
Why are we still debating complexity vs performance? The real issue is the lack of a standardized control plane for XDP. Who is actually managing these programs in production?
The post mentions L7 capabilities, but XDP typically operates at the lowest levels of the stack. How does CrabShield handle application-layer filtering without passing the packet back up to the kernel?
similar to how cloudflare handles magic transit.