NET-201 · Kernel Networking · Advanced

XDP & eBPF Networking — full syllabus

Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.

Duration4 full days in person · 8 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 12,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Engineers who need packet filtering, load balancing or DDoS mitigation at line rate and want to do it inside the kernel rather than beside it.

Prerequisites

Course outline

Day 1 — the XDP hook

  • The eBPF execution model and the verifier, briefly and precisely
  • Where XDP runs: before the skb is allocated
  • Actions: PASS, DROP, TX, REDIRECT, ABORTED
  • Driver support levels: native, generic, offload
  • Loading programs with libbpf and ip link

Day 2 — state, statistics and control

  • Map types and when each is correct
  • Per-CPU maps for statistics that scale
  • Map pinning and sharing between programs and userspace
  • Tail calls and structuring larger programs
  • Control-plane interaction: reading counters, updating policy

Day 3 — building real XDP programs

  • Packet parsing: the bounds checks the verifier demands
  • A rate limiter with token-bucket state in a map
  • An L4 load balancer with XDP_TX and XDP_REDIRECT
  • DDoS mitigation patterns and their limits
  • Verifier errors: reading them and fixing what they mean

Day 4 — AF_XDP and tc-bpf

  • AF_XDP sockets: UMEM, fill/completion rings, rx/tx rings
  • Zero-copy delivery to userspace and its requirements
  • tc-bpf hooks on ingress and egress
  • Traffic classification with tc-bpf
  • Choosing between XDP, AF_XDP, tc-bpf and plain sockets

Hands-on labs

  1. Lab: write, load and iterate an XDP drop program with libbpf and measure the drop rate at line rate
  2. Lab: add per-CPU map statistics and export them to a userspace control program
  3. Lab: build a rate limiter that survives the verifier, then tune it under an iperf3 flood
  4. Lab: steer packets to userspace with AF_XDP and benchmark against the socket path
  5. Lab: classify egress traffic with a tc-bpf program and verify placement with tc -s counters

Capstone project

Build a working line-rate service: an XDP program (filter or L4 load balancer) with map-backed policy, per-CPU statistics and a control-plane loader — then benchmark it against the nftables equivalent and deliver the evidence: throughput, CPU cost, drop counts and a short write-up of where each approach wins.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
8 Nov – 11 Nov 20264 full days RiyadhIn person · KAFD Conference Centre 10 of 14 SAR 10,800until 9 OctSAR 12,000
15 Nov – 18 Nov 20264 full days Kuwait CityIn person · Al Hamra Tower 5 of 14 KWD 890until 16 OctKWD 990
22 Nov – 25 Nov 20264 full days MuscatIn person · Knowledge Oasis Muscat 10 of 14 OMR 1,110until 23 OctOMR 1,230
22 Nov – 1 Dec 20268 half-days Gulf bandLive online · 09:00–13:00 GMT+3 6 of 20 US$2,070until 23 OctUS$2,300
23 Nov – 26 Nov 20264 full days OttawaIn person · Kanata North Tech Park 5 of 14 CAD 3,920until 24 OctCAD 4,350
30 Nov – 3 Dec 20264 full days TorontoIn person · MaRS Discovery District 10 of 14 CAD 3,920until 31 OctCAD 4,350
30 Nov – 9 Dec 20268 half-days Europe bandLive online · 09:00–13:00 CET 11 of 20 US$2,070until 31 OctUS$2,300
7 Dec – 10 Dec 20264 full days LondonIn person · Shoreditch Works 5 of 14 GBP 2,250until 7 NovGBP 2,500
7 Dec – 16 Dec 20268 half-days Americas bandLive online · 13:00–17:00 ET 16 of 20 US$2,070until 7 NovUS$2,300
14 Dec – 17 Dec 20264 full days BerlinIn person · Factory Görlitzer Park 10 of 14 EUR 2,650until 14 NovEUR 2,940

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.