Client Area
Votion Edge Simulation Node
NetworkInfrastructureCloudPerformance

Scaling 1.2Tbps Volumetric DDoS Scrubbing (9424)

V
VOTION CORE CONTRIBUTOR
SYSTEM WRITER
7 min read

Technical Overview

Engineering breakdown of Scaling 1.2Tbps Volumetric DDoS Scrubbing (9424). Bare-metal hardware performance requires isolated kernel parameters, XDP/eBPF fast-path processing, and deterministic memory allocation to sustain line-rate inspection at 1.2Tbps aggregate throughput across 24x 100GbE interfaces.

Kernel Bypass & Memory Architecture

We deploy a custom votion-scrub kernel module that reserves 256 hugepages (1GB each) per NUMA node via hugetlbfs, eliminating TLB misses during packet processing. The RX path uses AF_XDP zero-copy sockets with XDP_UMEM_REG flags, mapping directly to NIC RX rings via mlx5_core driver's xsk_pool abstraction.

# /etc/sysctl.d/99-votion-scrub.conf
net.core.netdev_max_backlog = 2000000
net.core.rmem_max = 2147483647
net.core.wmem_max = 2147483647
vm.nr_hugepages = 6144
vm.hugetlb_shm_group = 1001
kernel.shmmax = 1099511627776
kernel.shmall = 268435456

Flow Classification Pipeline

Each 100GbE port terminates on a dedicated CPU core (isolated via isolcpus=2-49 + nohz_full=2-49). The eBPF classifier (cls_bpf) executes 3-stage inspection:

  1. L3/L4 Header Validation — checksum offload verification, fragment reassembly state machine
  2. Entropy Scoring — per-flow Shannon entropy on payload bytes (sliding window 64KB)
  3. Reputation Lookup — cuckoo-filter IP reputation (128M entries, 4-bit counters) in shared hugepage region

Packets exceeding entropy threshold (H > 7.2 bits/byte) or matching reputation blocklist divert to scrubbing cluster via XDP_REDIRECT to dedicated scrub VFs.

Scrubbing Cluster Topology

Four DL380 Gen11 nodes (2x Xeon 8480+, 512GB DDR5-4800, 2x ConnectX-7 200GbE) form the scrubbing tier. Each node runs 48 worker threads pinned to physical cores, processing redirected traffic through:

  • Protocol Normalization — TCP reassembly, UDP defragmentation, ICMP rate-limiting
  • Anomaly Detection — spectral analysis on flow inter-arrival times (FFT window 10k packets)
  • Mitigation Actions — SYN cookie generation, challenge-response, blackhole routing via BGP FlowSpec

Telemetry & Observability

Real-time metrics exported via prometheus-node-exporter + custom votion-scrub-exporter scraping eBPF maps every 500ms. Key dashboards track: scrub_throughput_bps, scrub_latency_p99_ns, flow_table_utilization, mitigation_actions_total.

Hardware Performance Benchmark Telemetry
4.9x HIGHER THROUGHPUT
Votion Edge Bare-Metal Cluster420
Standard Virtual Hypervisor (AWS / GCP)85
METRIC: Random Disk IOPS (k)TELEMETRY: REAL-TIME HARDWARE HARDENING AUDIT
CODE_COMPILER // EBPF XDP CLASSIFIER (PRODUCTION)
V8_SANDBOX_LIVE
// Input Javascript:JS (ES6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
Press Ctrl + Enter to run
// EXECUTION_LOGS:
[ Ready for execution context... ]
Cloud Compute Cost Calculator
SAVE UP TO 68% ANNUALLY
vCPU Cores (Dedicated):4 Cores
DDR5 RAM:16 GB
NVMe Gen4 Storage:256 GB
Anycast Egress Bandwidth:5 TB
Votion Cloud Estimate$52/moNo hidden ingress/egress fees
Legacy Cloud Estimate$166/moIncludes compute + egress tax
Net Annual Capital Retained$1,368Re-investable technical capital
CLI_BUILDER // VPS_DEPLOYMENT_COMPILER
READY_TO_DEPLOY
// Select Instance Parameters:
Instance Name:
Anycast Region:
vCPU Allocation:
RAM Memory:
NVMe Storage:
Operating System:
// Command Output Console:
[GENERATED_CMD]
votion deploy core-node-01 --cpu 8 --ram 16 --storage 250 --region fra-1 --os ubuntu-24
// CLI STATE VALIDATION:
Config check OK. Ready to pipe.
Anycast Network Topology Diagram
// NODE_TELEMETRY: LunarShield Scrubbing NodeLATENCY: 0.45ms
STATUS: Filtering 1.2Tbps Spectrum Buffer

eBPF/XDP kernel filter evaluates TCP/UDP frames directly on server NIC.