Skip to content

Performance Benchmarks

Real-world flood protection analysis for LiteShield XDP. Tested on kernel 7.0, x86_64, generic XDP mode, veth pair at 10Gbps.


Test Environment

ComponentSpecification
Kernel7.0.0-28-generic
CPUx86_64 (multi-core)
XDP ModeGeneric (SKB)
Test Interfaceveth pair (10Gbps)
Traffic Generatorhping3 --flood mode
Test Duration10 seconds per flood type

Note on XDP Mode

Generic (SKB) mode is used for maximum compatibility. Native (driver) mode is typically 2-3× faster on supported NICs.


Benchmark Results

SYN Flood

Attack: TCP SYN packets to port 80 at maximum rate.

MetricValue
Packets Received2,075,377
Packets Passed18,523
Packets Dropped2,056,854
Drop Rate99.11%
SYN Rule Drops5
Ban Drops2,056,849
Effective PPS~207,000

Analysis: The source IP exceeded the SYN threshold within the first second and was auto-banned. All subsequent packets were dropped at the ban check. The 5 SYN drops represent the initial packets that triggered the threshold before the ban took effect.


UDP Flood

Attack: UDP packets to port 53 at maximum rate.

MetricValue
Packets Received4,058,755
Packets Passed38,911
Packets Dropped4,019,844
Drop Rate99.04%
UDP Rule Drops5
Ban Drops4,019,834
Effective PPS~405,000

Analysis: Same pattern as SYN flood — threshold hit immediately, IP banned, remaining packets dropped. UDP floods are handled at slightly higher rates due to smaller packet size (28 bytes vs 40 bytes for TCP).


ICMP Flood

Attack: ICMP echo requests at maximum rate.

MetricValue
Packets Received5,995,515
Packets Passed42,919
Packets Dropped5,952,596
Drop Rate99.28%
ICMP Rule Drops8
Ban Drops5,952,578
Effective PPS~599,000

Analysis: ICMP floods achieve the highest packet rates due to minimal packet size and no connection state. The firewall maintained full drop rate without any performance degradation.


Mixed Flood (SYN + UDP + ICMP)

Attack: Simultaneous SYN, UDP, and ICMP floods from the same source.

MetricValue
Packets Received11,768,696
Packets Passed61,335
Packets Dropped11,707,361
Drop Rate99.48%
SYN Drops10
UDP Drops7
ICMP Drops12
Ban Drops11,707,332
Effective PPS~1,176,000

Analysis: The firewall handled over 1.1 million packets per second from a single source with 99.48% drop rate. All three protocols were tracked independently — the source was banned after exceeding multiple thresholds simultaneously.


Multi-Source Flood (Random IPs)

Attack: hping3 --rand-source generating packets from random IPs.

MetricValue
Packets Received1,009,835
Packets Passed241
Packets Dropped1,009,594
Drop Rate99.98%
New-Source Drops1,009,594
Ban Drops0
Effective PPS~201,000

Analysis: The global new-source limiter (10 new IPs/sec) was the primary defense. Random IPs couldn't establish per-IP state fast enough to trigger individual bans, so the global limiter caught them. Only 241 packets from the first few IPs passed before the limiter engaged.


CPU Usage

ScenarioCPU %Memory
Idle0.0%0.3%
SYN Flood0.0%0.3%
UDP Flood0.0%0.3%
ICMP Flood0.0%0.3%
Mixed Flood0.0%0.3%

Why is CPU usage zero?

XDP programs run in kernel space, not in the loader process. The loader (liteshield) only attaches the program and exits. All packet processing happens in the kernel's XDP hook, which is why userspace CPU usage is negligible even under million-PPS floods.


Performance Analysis

Throughput Summary

Flood TypePPS HandledDrop RatePrimary Defense
SYN Flood~207,00099.11%Auto-ban
UDP Flood~405,00099.04%Auto-ban
ICMP Flood~599,00099.28%Auto-ban
Mixed Flood~1,176,00099.48%Auto-ban
Random IP Flood~201,00099.98%New-source limiter

Defense Mechanism Breakdown

MechanismWhen It TriggersEffectiveness
Per-IP Rate LimitsSingle IP exceeds PPS/SYN/UDP/ICMP thresholdImmediate (1s window)
Auto-BanAfter rate limit violationBlocks all subsequent packets from that IP
New-Source LimiterGlobal new IPs/sec exceededBlocks packets from IPs not seen before
Flow Rate LimitsPer-flow (src+dst+proto+ports) PPS/BPS exceededBlocks specific high-rate flows
BlacklistManual ban addedImmediate permanent/timed block
WhitelistIP in whitelistBypasses all checks
BlackholeActivated manuallyBlocks all new IPs, preserves existing

Scaling Characteristics

Single IP flood:     PPS limited by per-IP threshold → auto-ban
Multi-IP flood:      PPS limited by new-source limiter → global block
Legitimate traffic:  No impact (below thresholds)

Comparison with Other XDP Firewalls

FeatureLiteShield XDPgamemann/XDP-FirewallOpenShield-XDP
Max PPS (generic)~1.1M~500K~10M+
Max PPS (native)~3M (est)~1.5M~30M+
Drop rate under flood99.5%95%99.9%
CPU overhead~0%~0%~0%
Memory footprint8MB5MB50MB
Attack vectors7542

OpenShield-XDP Comparison

OpenShield-XDP is the commercial big brother with 42 detection vectors, baseline learning, and forensics. LiteShield is the free minimal alternative — 80% of the protection at 10% of the complexity.


Tuning for Your Environment

High-Traffic Server (10+ Gbps)

yaml
thresholds:
  pps: 1000000
  syn: 50000
  udp: 200000
  icmp: 10000
  new_src: 5000
  flow_pps: 100000
  flow_bps: 100000000

VPS / Shared Hosting (1 Gbps)

yaml
thresholds:
  pps: 200000
  syn: 10000
  udp: 50000
  icmp: 5000
  new_src: 1000
  flow_pps: 50000
  flow_bps: 50000000

Home Server / Low Traffic

yaml
thresholds:
  pps: 50000
  syn: 2000
  udp: 10000
  icmp: 1000
  new_src: 100
  flow_pps: 10000
  flow_bps: 10000000

Known Limitations

Per-CPU Maps

ip_stats_map, flow_stats_map, and new_src_map are per-CPU LRU hashes. Rate limits are approximate — a flood spread across many CPUs may appear under the per-CPU threshold while exceeding the global rate. This is a documented trade-off for lock-free performance.

Fragmented Packets

IP fragments pass without L4 rate accounting. The first fragment is rate-limited, but subsequent fragments of the same packet are not. This prevents fragment-based evasion but may allow small fragment floods.

Blackhole Mode

Blackhole mode blocks ALL new IPs. If activated without seeded admin IPs, you will be locked out. Always whitelist your SSH IP before activating.


Conclusion

LiteShield XDP handles over 1 million packets per second with 99.5% drop rate and zero userspace CPU overhead. It's suitable for:

  • VPS and shared hosting under DDoS
  • Game servers facing UDP floods
  • Web servers facing SYN floods
  • Any Linux server needing basic XDP protection

For advanced features (baseline learning, attack forensics, 42 detection vectors), upgrade to OpenShield-XDP.