platform

Carrier-grade performance, from the NIC driver to the dashboard

A Rust engine with no garbage collector, eBPF/XDP filters running in the NIC driver and a columnar database built for billions of flows. It all runs on your own server, with no third-party cloud involved in detection or mitigation.

Engineering by the numberscore + UI
automated tests in the core
1,198
attack vectors decoded
50
analytical tables in ClickHouse
125
materialized views
20
reflectors blocked in XDP
13
REST API v1 endpoints
46
data flow

How the data flows

Telemetry comes in on the left, the engine decides every 10 s, and the response goes back to the edge over BGP or through the scrubber. Everything is stored in ClickHouse: flows, attacks, decisions and the audit trail.

EdgeWarden architecture Edge routers export flows to the collector, which enriches the data and hands it to the analysis engine. On every 10-second cycle, the engine passes anomalies to the decision stage, which writes the action to the ClickHouse queue, announces FlowSpec, RTBH or a diversion to the routers through GoBGP or ExaBGP, or sends the prefix to the external scrubbing provider. The XDP scrubber reads the queue, receives the diverted traffic and returns clean traffic to the edge, while the analyzer checks its health every 10 seconds. The dashboard, API and alerts receive events from the engine. reads the queue watches /health · 10 s BGP announcements: FlowSpec · RTBH · /32 diversion with NO_EXPORT divert or hand off Edge Juniper MX Huawei NE MikroTik · Cisco and any flow exporter Collector UDP 2055 · 6343 BMP · SNMP · pcap Enrichment ASN · GeoIP · rDNS passive DNS · TLS probe 10 s Analysis engine 50 vectors baseline · burst Dashboard, alerts Web UI :3099 REST API v1 Email · Telegram Webhook · Slack Syslog · SNMP Trap ClickHouse flows · attacks · decisions · queue · audit Decision deterministic cascade CGNAT lock · 80% cap XDP scrubber NIC driver · nft GoBGP · ExaBGP FlowSpec · RTBH · divert External scrubbing mitigation provider

Swipe sideways to see the whole diagram.

Telemetry Writes and queue in ClickHouse BGP announcements Diverted traffic Clean traffic Health watchdog Alerts
  1. Edge routersJuniper, Huawei, MikroTik, Cisco and any device that exports flow data.
  2. CollectorNetFlow, IPFIX and sFlow on UDP 2055/6343, BMP on TCP 11019, SNMP and packet capture.
  3. EnrichmentASN, GeoIP, rDNS, TLS probe, passive DNS, tunnel decoder and port → provider map.
  4. Analysis engine10 s cycle, configurable down to 1 s: decoders, thresholds, baseline, burst, carpet bombing, spoofing, RPKI/IRR and threat intel.
  5. DecisionDeterministic cascade with a CGNAT lock and a ceiling of 80% of the scrubber's measured capacity.
  6. ActionGoBGP or ExaBGP announce to the routers; the XDP/nftables scrubber cleans; the mitigation provider takes whatever doesn't fit.
  7. Dashboard and integrationsWeb UI, REST API v1, email, Telegram, webhook, Syslog and SNMP Trap.
stack

Chosen so it doesn't choke in the middle of an attack

Each piece does one job, in the place where it pays off most. None of them needs an external service to work.

Rust + TokioThe engine

Collection, analysis, decision and mitigation in a single async binary, with no garbage collector and no pauses mid-attack. The release build uses LTO and jemalloc and is hardened against reverse engineering.

tokiojemalloclto

eBPF/XDP with ayaThe data plane

Filter and scrubber run in the NIC driver, before the Linux network stack. A destination that isn't under mitigation passes with a single hash lookup.

ayaXDP_DROPXDP_PASS

ClickHouseFlows and history

Columnar database for billions of flows, with millisecond queries and roughly 10:1 compression. It also holds the mitigation queue, the decisions and the audit trail.

125 tables20 MVsLZ4

MariaDB / MySQLUsers and configuration

Users and roles, dashboards, Managed Objects, API keys and scheduled reports.

22 tables

RedisHot state

Statistical baselines and real-time alerts. After a restart, the engine restores baselines from Redis instead of relearning the network from scratch.

baselinesalerts

GoBGP v3 / ExaBGPBGP sessions

GoBGP over native gRPC, or ExaBGP. The configuration generated by the UI shows a diff before it is applied and can be rolled back.

gRPC :50051FlowSpecBMP

Next.js 16 + React 19User interface

More than 60 screens in Brazilian Portuguese, light and dark themes, an in-browser SSH terminal, drag-and-drop dashboards and built-in Swagger UI.

:3099xterm.jsOpenAPI
node roles

Keep the decision-maker away from the box that takes the hit

The same installation package runs in three roles, selected by one line in config.toml. Nodes talk to each other through the mitigation queue in ClickHouse, with no proprietary protocol.

What each node role does
Function All-in-onethe default Analyzerout of the traffic path Scrubberin the path of diverted traffic
Receives flows and detectsYesYesNo, the collector binds to loopback only
Decides and announces over BGPYesYesNo
Filters with XDP and nftablesYesNever touches the local filterYes, reading the mitigation queue
Web UI and APIYesYesNo, it runs lean
When to use itSingle network, one server for everythingSeparate the intelligence from the box that receives the attackDedicated scrubbing appliance, with a node quota in the license

Health watchdog: a diversion never turns into a black hole

The analyzer polls the scrubber's /health every 10 s. After 3 consecutive failures, active diversions are withdrawn and no new ones are announced. On the first good response, everything comes back. The scrubber returns 503 if the filter failed to load or if the node is outside the license quota.

  1. responds
  2. responds
  3. 1st failure
  4. 2nd failure
  5. 3rd failure
  6. diversions withdrawn
  7. diverting again
data plane

Filtering in the NIC driver

The EdgeWarden XDP program runs before the Linux network stack. With an empty map, the machine behaves as if the filter weren't there, so it is safe to install. Any failure lets the packet through; it never causes a drop. Included in the Enterprise plan.

L3/L4 sanity

Drops martian addresses, fragments and impossible flag combinations.

Amplification

Blocks 13 well-known reflectors by source port and minimum packet size.

13 reflectors

Per-source rate limit

Token bucket per source address, for botnets and reflectors using real IPs.

up to 65,536 sources

SYN protection New

Drops the first SYN and lets through clients that retransmit, without turning the scrubber into a reflector the way SYN cookies would.

Per-destination limit

Traffic ceiling per victim, adjustable per customer in the Managed Object.

up to 16,384 victims

Content signatures New

4- or 8-byte UDP signatures plus port, defined by the operator, with a counter per signature.

up to 1,024 signatures

The 13 reflectors blocked in the driver

UDP source port. QUIC on UDP/443 is left out on purpose: it is handled by the QUIC detector and by FlowSpec.

  • QOTD17
  • chargen19
  • DNS53
  • portmap111
  • NTP123
  • NetBIOS137
  • SNMP161
  • CLDAP389
  • RIPv1520
  • SSDP1900
  • WS-Discovery3702
  • mDNS5353
  • memcached11211

Observe mode. With a heuristic switched off, the filter counts what it would drop without dropping anything, and the Data plane (Plano de dados) panel shows hits per heuristic every minute. Carpet bombing over IPv4 and IPv6 is handled per prefix, with the victim looked up in an LPM trie.

appliance

100G reference scrubbing center

The reference deployment uses a Dell PowerEdge R760 with two NVIDIA/Mellanox ConnectX-6 Dx cards (4 × 100G ports), Debian 13 and kernel 6.12 LTS. Each router gets one 100G port, or 200G over LACP using one port from each card, which keeps the service up even if an entire card fails.

  • 100G/200G architecture per router, with capacity validated in each deployment
  • Drops in the tens of Mpps per port with a native-XDP NIC
  • Loop-free path by design: /32 or /128 diversion with a community and NO_EXPORT; clean traffic returns through a table that never contains the diversion
  • Stock kernel mlx5 driver, no vendor package to install
  • Recommended NICs: Mellanox ConnectX-5/6 and Intel E810 at the high end; X710, X520/X540 and ConnectX-4 for best value
Two ConnectX-6 Dx cards with two 100G ports each; each router uses one port from each card in LACP, for 200G in total Dell PowerEdge R760 Debian 13 · kernel 6.12 LTS ConnectX-6 Dx · card 1 CPU 0 NUMA node ConnectX-6 Dx · card 2 CPU 1 NUMA node Router 1 LACP 2 × 100G Router 2 LACP 2 × 100G
One port from each card per router. If an entire card fails, the router keeps 100G. Without LACP, the 4 ports serve up to 4 Juniper routers at 100G each.

Two deployment modes

Scrubbing center deployment modes
ItemMode A: everything on the R760Mode B: separate analyzer
recommended
On the R760Collector, ClickHouse, MariaDB, UI, GoBGP and XDPOnly the core with XDP
BGP with the edgeThe R760 itselfThe analyzer
Health watchdogNot neededRequired

Edge routers with a clean-path template

Juniper MXValidated in production

One port per router, dirty and clean traffic on the same cable; an input filter sends clean traffic to the CLEAN routing-instance. IPv4 and IPv6.

Huawei NE40E / NE8000Validation pending

VRP8 template written from the official documentation, with one dirty port and one clean port. It still needs lab validation.

Measured capacity, not promised capacity. Clean forwarding capacity is measured in each deployment and recorded in the system. EdgeWarden only diverts up to 80% of the measured value; above that, the decision falls through to external scrubbing, then FlowSpec on the vector and, as a last resort, RTBH.

compatibility

Open protocols, real-world vendors

Any router that exports flow data and speaks BGP FlowSpec or RTBH is covered by the standard features. Vendor-specific features are listed below, with no overstatement.

Collection and telemetry

  • NetFlow v5
  • NetFlow v9RFC 3954
  • IPFIXRFC 7011
  • sFlow v5
  • SNMP v1/v2c/v3
  • BMPRFC 7854
  • libpcap · AF_PACKET v3
  • AF_XDP · DPDKcoming soon

Mitigation

  • BGP FlowSpecRFC 5575/8955
  • RTBH
  • GoBGPgRPC
  • ExaBGP
  • eBPF/XDP
  • nftables

Route validation

  • RPKI/RTR
  • IRRRIPE · RADb

Decoded tunnels

  • VxLAN
  • GENEVE
  • GRE
  • L2TP
  • IP-in-IP
  • MPLS-in-UDP
Integration by vendor
VendorStandard flow and BGPVendor-specific features
JuniperJunOS, MXYesFlowSpec and RTBH in production, IPv4/IPv6 scrubbing templates, firewall counters (JUNIPER-FIREWALL-MIB), static filter hardening, PBR via prefix-list, SSH terminal
HuaweiVRP8, NE40E/NE8000YesPBR via ACL and SSH terminal. Scrubbing template written, awaiting lab validation
MikroTikRouterOSYesPBR via address-list and SSH terminal
CiscoIOS, IOS-XRYesIn-browser SSH terminal. No automatic PBR
Nokia, Arista and othersYesNo vendor-specific integration: they work through NetFlow/IPFIX/sFlow and BGP FlowSpec/RTBH
REST API v1

Plug it into your NOC, Zabbix, SIEM or customer portal

REST API v1 documented in OpenAPI/Swagger: 46 endpoints, scoped keys, per-IP and per-customer restrictions, rate limiting and webhooks.

  • Swagger UI built in at /api-docs, which works even on an appliance with no internet access
  • The key is shown only once; the server stores only its SHA-256 hash
  • Scopes for traffic, flows, attacks, violations, mitigations, Managed Objects, reports and system
  • Apply FlowSpec, RTBH, diversion or external scrubbing with a POST, under the same safeguards as the UI
  • Default limit of 120 requests per minute per key, answered with 429 and Retry-After
  • Zabbix-ready health check at /api/v1/system/health
Active attacks in the last hour
# example key: create yours under Configurações → Chaves de API (Settings → API Keys)
export EW=https://edgewarden.example.net
export FSK=fsk_a1b2c3d4e5f60718_YOUR_SECRET

curl -s -H "Authorization: Bearer $FSK" \
  "$EW/api/v1/attacks?status=active&hours=1"

{
  "data": [{
    "target_ip": "203.0.113.9",
    "attack_type": "udp_flood",
    "severity": "high",
    "status": "active",
    "bytes_per_sec": 3750000000,
    "source_count": 18422,
    "zone_group": "AS65000-CUSTOMERS",
    "zone_cidr": "203.0.113.0/24"
  }],
  "pagination": { "page": 1, "total": 1 }
}

The response above is abbreviated. Mitigations requested through the API are queued as pending, and the core applies them on the next cycle, in about 10 s.

Alerts arrive without anyone having to ask

Each Managed Object can have its own channels. Use the API to enrich the event, not to find out about the attack.

  • Syslog and SIEMEvents in CEF, JSON or RFC 5424, over UDP or TCP.
  • SNMP Trap v2cFor Zabbix, PRTG, LibreNMS and SolarWinds, with encoding that holds up under bursts.
  • TelegramTarget, vector and action taken, straight to the NOC group.
  • EmailThrough your own SMTP server, with scheduled reports and Attack Analyst (Analista de Ataques) bulletins.
  • Webhookattack_detected event in JSON, posted to your system.
  • Slack and TeamsThrough the channel's incoming webhook.
licensing and security

Your network doesn't stop because a license server went down

Licensing

  • License signed with Ed25519 and verified offline
  • Heartbeat every 24 h, plus a 30-day grace period with no contact with the server
  • Hardware fingerprint that survives bonding, LACP and VLANs
  • The binary is the same on every plan; the license unlocks the features and the quota of routers and scrubbing nodes
Last confirmed heartbeatGrace period
day 0day 15day 30

The server itself

  • Services run as www-data, without sudo, with only the capabilities they need: CAP_NET_RAWCAP_NET_BIND_SERVICECAP_BPFCAP_NET_ADMIN
  • Router credentials encrypted with AES-256-GCM; SSH to the edge is implemented in pure Rust
  • A unique session secret generated on each installation
  • Host firewall in nftables, editable from the UI
  • Updates verified with sha256sum, keeping configuration and logs, with rollback
hardware

Recommended sizing

Pick the tier based on your network's flow volume. The installation guide has the commands for every step, from sysctl to HTTPS.

Hardware requirements by tier
Resource SmallRegional ISP Medium recommendedISP / mid-size DC EnterpriseTier-1 / large DC
VolumeUp to 20K flows/s, networks up to ~5 GbpsUp to 50K flows/s, networks up to ~20 Gbps100K+ flows/s, networks of 40 Gbps+
CPU8 cores (Xeon / EPYC)16 cores (Xeon Scalable / EPYC)32+ cores (EPYC / Xeon Platinum)
RAM32 GB DDR464 GB DDR4 ECC128+ GB DDR4/DDR5 ECC
Disk500 GB NVMe SSD2 TB NVMe SSD4+ TB NVMe (RAID 10)
Network1 Gbps10 Gbps25 / 40 / 100 Gbps
OSDebian 13+ (Trixie)Debian 13+ (Trixie)Debian 13+ (Trixie)
  • eBPF/XDP: Debian 13 already ships kernel 6.x; use a NIC with native XDP (Mellanox or Intel recommended).
  • ClickHouse: from the Medium tier up, move it to a dedicated server.
  • Retention: size the disk for the retention period you need (compression is around 10:1).
  • High availability: for Enterprise, a cluster of 2 or more nodes is recommended.

The architecture checks out. Ready to see it on your network?

We'll show you EdgeWarden running on flows from your own routers, and you get a demo license with every Enterprise feature for 7 days. The demo and support are in Portuguese.