eBPF maps, hash collisions and a very long night (part 2)
Over the last few months we have spent a lot of time on eBPF maps, hash collisions and a very long night. This is what we learned.The numbersAcross the last quarter, 71%…
Over the last few months we have spent a lot of time on eBPF maps, hash collisions and a very long night. This is what we learned.The numbersAcross the last quarter, 71%…
We get asked about designing a risk score that analysts can explain more than almost anything else, so here is the long answer.What we changedWe moved the decision from a single threshold…
Over the last few months we have spent a lot of time on how we deploy rule changes to every edge in under 30 seconds. This is what we learned.Observability firstEvery mitigation…
how we test WAF rules against seven days of real traffic sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.What…
measuring the real cost of a TLS handshake under attack sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Challenges beat…
Over the last few months we have spent a lot of time on what we learned from load-testing our own edge to failure. This is what we learned.Challenges beat blocksBlocking lists go…
Over the last few months we have spent a lot of time on the hidden cost of retries during a flood. This is what we learned.Measuring successWe track three numbers for every…
We get asked about hTTP/2 rapid reset one year later more than almost anything else, so here is the long answer.Challenges beat blocksBlocking lists go stale within minutes when attackers rotate through…
Over the last few months we have spent a lot of time on measuring the real cost of a TLS handshake under attack. This is what we learned.Observability firstEvery mitigation decision is…
Here is a question we could not answer well a year ago: what really happens with hTTP/2 rapid reset one year later? We can answer it now.Testing in production, safelyEvery rule starts…
building a per-route baseline without storing every request sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Challenges beat blocksBlocking lists…
We get asked about the hidden cost of retries during a flood more than almost anything else, so here is the long answer.Protecting the originNone of this matters if the attacker can…