networking
24 posts found
Why Transport Layer Fingerprinting Will Replace IP Reputation
Perimeter security models that rely on IP reputation fail against residential proxy pools. Edge defense is shifting to transport-layer fingerprinting, inspectin…
Why Dropping All ICMP Breaks Path MTU Discovery
Blocking all ICMP traffic does not hide your servers from network scanners. Instead, it breaks Path MTU Discovery, causing silent connection freezes during TLS …
How to Tunnel Datagrams with MASQUE CONNECT-UDP Over HTTP/3
Configure RFC 9298 MASQUE CONNECT-UDP over HTTP/3 to tunnel datagrams without head-of-line blocking.
TPROXY vs REDIRECT: Transparent Socket Interception on Linux
Intercepting routed TCP and UDP traffic on a Linux gateway without rewriting packet headers requires Netfilter TPROXY. Here is why REDIRECT breaks UDP and conne…
Eliminating Multi-Core Socket Contention with SO_REUSEPORT and SO_INCOMING_CPU
High-throughput TCP servers on multi-core Linux hit latency walls from accept queue spinlocks. Learn how SO_REUSEPORT and SO_INCOMING_CPU isolate socket queues …
X25519MLKEM768 vs X25519: Evaluating Hybrid Post-Quantum Key Encapsulation
A technical comparison of X25519 and hybrid X25519MLKEM768 in TLS 1.3, evaluating handshake wire overhead, CPU cycles, cryptanalytic resilience, and edge middle…
The Evolution of Web Application Firewalls: From RegEx Rules to AST Tokenizers and Wasm Filters
A technical timeline of how HTTP inspection evolved from brittle regular expressions and ReDoS traps to lexical tokenizers, WebAssembly filters, and streaming p…
Defensive Sysctl Parameters for Production IP Stacks
Default Linux kernel settings leave servers exposed to route hijacking, spoofed packets, and connection floods. Here are ten sysctl directives to secure the net…
You’re Debugging DNS in the Wrong Namespace
Network namespaces isolate DNS resolvers from the host. A practical guide to finding which namespace your process lives in, dropping into it, and tracing the ac…
TCP Keepalive Does Not Keep Your Connection Alive
Linux defaults to a 2-hour keepalive time. Dead connections sit in your process table for hours before the kernel notices. Here is how to fix that and why appli…