NET-110 · Kernel Networking
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Who this course is for
Engineers who own TCP/UDP services in production and need kernel-level explanations for retransmits, buffer stalls and latency that application metrics cannot provide.
Prerequisites
Course outline
Day 1 — the socket layer and its memory
- Socket lifecycle: socket(), bind, connect/accept, close and the states in between
- Send and receive queues: where skbs wait and why
- Socket memory accounting: net.core and net.ipv4.*_mem knobs
- Buffer autotuning and when it stops helping
- Backpressure: what the kernel does when the application is slow
Day 2 — TCP under the hood
- The state machine as it appears on the wire
- Timers: retransmission, delayed ACK, keepalive, TIME_WAIT
- Loss recovery: fast retransmit, SACK and RTO computation
- Congestion control: CUBIC, BBR and the pluggable CC interface
- Loading and inspecting a congestion-control module
Day 3 — zero-copy paths and TCP observability
- sendfile and splice: what they save and what they cost
- MSG_ZEROCOPY semantics and its error queue
- io_uring for network I/O
- ss, tcp_diag and the TCP tracepoints
- Building a retransmit and latency view you can keep in production
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: drive a connection into socket memory limits and watch ss -m, /proc and drop counters respond
- Lab: reproduce a loss event under tc netem and correlate tcpdump with TCP retransmit tracepoints
- Lab: benchmark CUBIC against BBR on an emulated WAN and explain the difference
- Lab: measure the CPU cost of copy vs sendfile vs MSG_ZEROCOPY on the same payload
- Lab: write a bpftrace tool charting per-connection retransmit and RTT distributions
Capstone project
Take a misbehaving TCP service from symptom to mechanism: using captures and a live system, you identify whether the cause is buffering, timers, congestion control or loss recovery, apply the fix, and deliver before/after evidence — captures, tracepoint data and the configuration or code change — that would survive an incident review.
What you leave with
- A mechanism-first method for diagnosing TCP behaviour
- Hands-on command of ss, tcp_diag, tracepoints and bpftrace for sockets
- Measured experience with CUBIC vs BBR under loss and delay
- A zero-copy decision framework: when sendfile, MSG_ZEROCOPY or io_uring is worth it
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who own TCP/UDP services in production and need kernel-level explanations for retransmits, buffer stalls and latency that application metrics cannot provide. It sits at advanced level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: NET-101 or equivalent packet-path knowledge; Sockets programming experience in any language; Comfort reading kernel source with guidance. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 22 Nov – 24 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 9 of 14 | SAR 8,100until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 4 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 9 of 14 | OMR 830until 30 Oct | ||
| 6 Dec – 13 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 3 of 20 | US$1,580until 6 Nov | ||
| 7 Dec – 9 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 4 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 9 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 8 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 4 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 13 of 20 | US$1,580until 14 Nov | ||
| 21 Dec – 23 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 9 of 14 | EUR 1,990until 21 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1013 days
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Practitioner-taught
SAR 7,880Next 18 Oct
NET-1203 days
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Practitioner-taught
SAR 7,880Next 1 Nov
NET-2014 days
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Practitioner-taught
SAR 12,000Next 8 Nov
NET-2103 days
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Practitioner-taught
SAR 9,000Next 25 Oct
NET-2203 days
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Practitioner-taught
SAR 9,000Next 11 Oct