NET-110 · Kernel Networking · Advanced

Socket Layer & Protocol Handling — full syllabus

TCP and UDP implementation details that explain the behaviour you see on the wire.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Engineers who own TCP/UDP services in production and need kernel-level explanations for retransmits, buffer stalls and latency that application metrics cannot provide.

Prerequisites

Course outline

Day 1 — the socket layer and its memory

  • Socket lifecycle: socket(), bind, connect/accept, close and the states in between
  • Send and receive queues: where skbs wait and why
  • Socket memory accounting: net.core and net.ipv4.*_mem knobs
  • Buffer autotuning and when it stops helping
  • Backpressure: what the kernel does when the application is slow

Day 2 — TCP under the hood

  • The state machine as it appears on the wire
  • Timers: retransmission, delayed ACK, keepalive, TIME_WAIT
  • Loss recovery: fast retransmit, SACK and RTO computation
  • Congestion control: CUBIC, BBR and the pluggable CC interface
  • Loading and inspecting a congestion-control module

Day 3 — zero-copy paths and TCP observability

  • sendfile and splice: what they save and what they cost
  • MSG_ZEROCOPY semantics and its error queue
  • io_uring for network I/O
  • ss, tcp_diag and the TCP tracepoints
  • Building a retransmit and latency view you can keep in production

Hands-on labs

  1. Lab: drive a connection into socket memory limits and watch ss -m, /proc and drop counters respond
  2. Lab: reproduce a loss event under tc netem and correlate tcpdump with TCP retransmit tracepoints
  3. Lab: benchmark CUBIC against BBR on an emulated WAN and explain the difference
  4. Lab: measure the CPU cost of copy vs sendfile vs MSG_ZEROCOPY on the same payload
  5. Lab: write a bpftrace tool charting per-connection retransmit and RTT distributions

Capstone project

Take a misbehaving TCP service from symptom to mechanism: using captures and a live system, you identify whether the cause is buffering, timers, congestion control or loss recovery, apply the fix, and deliver before/after evidence — captures, tracepoint data and the configuration or code change — that would survive an incident review.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 24 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 9 of 14 SAR 8,100until 23 OctSAR 9,000
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 4 of 14 KWD 670until 23 OctKWD 740
29 Nov – 1 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 9 of 14 OMR 830until 30 OctOMR 920
6 Dec – 13 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 3 of 20 US$1,580until 6 NovUS$1,750
7 Dec – 9 Dec 20263 full days OttawaIn person · Kanata North Tech Park 4 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 9 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 14 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 8 of 20 US$1,580until 7 NovUS$1,750
14 Dec – 16 Dec 20263 full days LondonIn person · Shoreditch Works 4 of 14 GBP 1,680until 14 NovGBP 1,870
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 13 of 20 US$1,580until 14 NovUS$1,750
21 Dec – 23 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 9 of 14 EUR 1,990until 21 NovEUR 2,210

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.