Milestone M6: Add per-IP and protocol-aware rate limiting to XDP/eBPF.
- Prevent volumetric or burst DoS attacks (TCP/UDP/ICMP).
- Support configurable thresholds (pps/bps) per src IP or subnet.
- Block or shape offending traffic.
- Document as part of MITRE ATT&CK T1498, T1499 coverage.
References:
Milestone M6: Add per-IP and protocol-aware rate limiting to XDP/eBPF.
References: