← Latest papers
💻 computer science

Resource-Aware eBPF/XDP-Assisted DDoS Mitigation for IoT Edge Systems: Design and Management Trade-Offs

This paper presents and evaluates a resource-aware eBPF/XDP architecture for mitigating DDoS attacks on IoT edge systems, demonstrating that while the approach effectively blocks malicious traffic and preserves service continuity, it requires careful platform-specific resource budgeting to manage the associated CPU and latency trade-offs.

Original authors: Abdurrahman Tolay

Published 2026-09-16
📖 5 min read🧠 Deep dive

Original authors: Abdurrahman Tolay

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where the small, unassuming devices that monitor our homes, farms, and factories are not just passive sensors, but active guardians of their own safety. These devices, known as the Internet of Things, often run on modest computers with limited power and memory. When a massive wave of unwanted digital traffic, called a Distributed Denial of Service attack, crashes against them, these small machines can easily be overwhelmed, causing their services to shut down. For years, the solution has been to send this traffic to powerful, distant servers to be filtered out before it ever reaches the device. But what if the network connection is slow, or the traffic has already arrived at the doorstep? The challenge then becomes a delicate balancing act: how can a tiny, resource-hungry device stop a flood of bad data without using up so much of its own energy that it stops working entirely?

This question lies at the heart of a recent study by Abdurrahman Tolay at Istinye University, which explores a new way to protect these vulnerable edge devices. The research focuses on a specific method of defense that lives inside the device's own operating system, using two technologies called eBPF and XDP. Think of eBPF as a safe, verified way to run small programs directly inside the computer's core, and XDP as a checkpoint right at the front door where every piece of data arrives. Instead of letting every packet of data travel deep into the system to be checked, these tools allow the device to inspect and count incoming traffic almost immediately. If a single source starts sending too many packets too quickly, the system can flag it. However, the actual decision to block that source is made by a separate, simpler program running outside the core, which then tells the device's firewall to ignore that sender. This split approach keeps the heavy lifting of decision-making away from the critical, fast-moving path of the data, aiming to keep the device running smoothly even under attack.

To test this idea, the researcher set up two different environments. First, they used a virtual simulation, a digital sandbox where they could control every variable perfectly. In this simulated world, the system proved highly effective, blocking about 99 percent of the malicious traffic while keeping the protected service fully responsive. The cost was low, using only about 30 percent of a single processor core and adding a tiny delay of just one to two milliseconds. This initial success suggested the concept was sound, but a virtual environment cannot fully replicate the physical limits of real hardware. To get the true picture, the researcher moved the experiment to a Raspberry Pi 4, a small, affordable computer often used as a model for the kind of limited hardware found in real-world IoT devices.

On the physical Raspberry Pi, the results were more nuanced, revealing the true trade-offs of running such a defense on constrained hardware. When subjected to a flood of up to 30,000 packets per second, the system successfully blocked about 94 percent of the malicious traffic. Crucially, the device did not crash; it remained responsive and continued to deliver more than 90 percent of the legitimate data it was supposed to handle. Without this protection, the same flood of traffic would have rendered the device completely unresponsive. However, this survival came at a significant price. To maintain this level of defense, the system consumed approximately 85 percent of one of the device's four processor cores. It also added a delay of three to four milliseconds to the data passing through. While the device stayed online, it was working very hard to do so, leaving very little processing power available for any other tasks.

The study concludes that this hybrid approach works, but it is not a magic bullet that solves the problem without cost. The system is "resource-aware," meaning it can preserve the continuity of a service, but only if the administrator carefully budgets the device's resources and sets the right limits. The research explicitly rules out the idea that this method is a low-overhead solution that runs for free; on a physical device, the defense itself becomes a heavy workload. Furthermore, the study clarifies that this system is not a perfect detector of all bad actors. It relies on counting how fast a single source is sending data, which means a legitimate burst of traffic from a normal device could accidentally trigger a block, or a clever attacker could split their traffic among many sources to slip under the radar. The system is designed as a first line of defense to reduce the load on a local device, not as a complete replacement for broader network security.

Ultimately, the work demonstrates that local security is possible on small, limited devices, but it requires a careful management of expectations. The researchers found that by separating the fast, simple act of counting packets from the slower, more complex act of making blocking decisions, they could keep a device alive during an attack. Yet, the physical reality of the Raspberry Pi showed that keeping the lights on during a storm demands a substantial portion of the device's own power. For engineers and managers deploying these systems, the lesson is clear: you can build a shield for your edge devices, but you must ensure the device has enough strength left over to do its actual job while holding that shield up. The path forward involves refining these thresholds and perhaps combining this local defense with larger, upstream protections to share the burden, ensuring that the small guardians of our digital world can stand their ground without collapsing under the weight of their own protection.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →