Tag Archive

linux

44 posts found

TPROXY vs REDIRECT: Transparent Socket Interception on Linux

Intercepting routed TCP and UDP traffic on a Linux gateway without rewriting packet headers requires Netfilter TPROXY. Here is why REDIRECT breaks UDP and conne…

Eliminating Multi-Core Socket Contention with SO_REUSEPORT and SO_INCOMING_CPU

High-throughput TCP servers on multi-core Linux hit latency walls from accept queue spinlocks. Learn how SO_REUSEPORT and SO_INCOMING_CPU isolate socket queues …

Streaming Mixture-of-Experts Weight Tensors Directly from NVMe Storage

Sparse Mixture-of-Experts models waste massive RAM holding idle expert weights. By combining zero-copy kernel memory mapping, io_uring transfers, and predictive…

The Evolution of Web Application Firewalls: From RegEx Rules to AST Tokenizers and Wasm Filters

A technical timeline of how HTTP inspection evolved from brittle regular expressions and ReDoS traps to lexical tokenizers, WebAssembly filters, and streaming p…

Voltage Glitching and Side-Channel Leakage in Embedded Cryptographic Silicon

Hardware security modules and cold storage wallets isolate private keys inside microcontroller flash memory. When attackers obtain physical access, precision vo…

Defensive Sysctl Parameters for Production IP Stacks

Default Linux kernel settings leave servers exposed to route hijacking, spoofed packets, and connection floods. Here are ten sysctl directives to secure the net…

The Evolution of Telemetry: From Syslog Scrapers to eBPF and ClickHouse

A technical timeline tracing how telemetry evolved from isolated Prometheus scrapers in 2018 to OpenTelemetry standards, eBPF in-kernel probing, and ClickHouse …

You’re Debugging DNS in the Wrong Namespace

Network namespaces isolate DNS resolvers from the host. A practical guide to finding which namespace your process lives in, dropping into it, and tracing the ac…

TCP Keepalive Does Not Keep Your Connection Alive

Linux defaults to a 2-hour keepalive time. Dead connections sit in your process table for hours before the kernel notices. Here is how to fix that and why appli…

Linux Systemd Sandboxing: Ten Security Directives for Production Daemons

Harden production Linux services using native systemd security directives including namespaces, seccomp syscall filters, and memory protection.

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید