DaLaw2 c6a77c9611 feat: v0.9 closeout — eBPF-optional, Suricata bridge, WORM audit, migration cleanup
- eBPF-optional startup: null-object services, preflight classifier,
  EbpfHealth (Healthy / Unavailable{stage, category, reason}) surfaced
  via GET /health/ebpf and WebSocket metrics; the rest of the system
  (HTTP, SOAR, ML) comes up even when XDP/AF_XDP is unavailable.
- Suricata bridge (M1–M4): subprocess supervisor with auto-restart
  backoff, eve.json tail → alert translation → DetectionEvent,
  GET /health/suricata; AF_PACKET capture mode (does not conflict with
  our AF_XDP). M5 smoke test deferred until deployment hardware.
- WORM audit log: hash-chained audit_log with prev_hash/row_hash,
  BEFORE UPDATE/DELETE triggers, verify_audit_log_chain(),
  `--verify-audit-log` CLI.
- Migration code removed (system not yet released): plaintext→encrypted
  DB auto-migration, plaintext secrets migration, ALTER TABLE retrofit
  blocks, and related log variants. Init paths for default user_groups
  kept; decrypt_to_file / encrypt_to_file ops utilities kept.
- Licensing removed: deleted license-generator/ (Ed25519 + MAC binding);
  not going commercial.
- README: kernel × NIC driver compatibility matrix (no single "minimum
  kernel version" — depends on driver).
- unwrap/expect audit (164 sites): 0 production-unsafe unwraps; all 9
  production sites are infallible literals with SAFETY comments; 155
  sites are in test modules.
- Cargo: tokio features gained process, io-util, fs, signal (for
  Suricata subprocess lifecycle).
- Frontend submodule: advanced to dbe5342 (inactivity auto-logout);
  v11 allowlist UI work held back.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-15 23:45:38 +08:00

NetGuardia

Project Overview

NetGuardia is a high-performance network security solution that combines eBPF XDP technology with deep learning models to provide advanced network protection. The system operates as a standalone network appliance that can run on any Ubuntu-based system with compatible network hardware.

Core Technologies

  • eBPF XDP Technology - Provides high-performance packet processing directly at the data link layer
  • Deep Learning Models - Identifies and predicts potential network attacks with intelligent threat detection
  • Hardware Integration - Designed to work with Intel i350 T2 and similar enterprise-grade network interface cards

Functional Modules

Resource Overview

Home

  • Real-time control system occupancy rate

Dashboard Overview

Dashboard

  • Real-time network traffic monitoring and visualization
  • Recent traffic statistics and trend analysis

Detailed Traffic Statistics

Statistics

  • Detailed traffic usage information per IP address

Network Access Control

accessControl

  • IPv4/IPv6 whitelist and blacklist management
  • Precise port-level access control

System Features

  • High Performance - Low-latency packet processing with minimal network performance impact
  • User-Friendly - Cross-platform web management interface with intuitive operation
  • Reliability - Hardware-accelerated processing ensures stable operation
  • Scalability - Modular design supports functional expansion

System Requirements

NetGuardia requires the combination of a kernel with eBPF support and a NIC driver that implements AF_XDP on that kernel. There is no single "minimum kernel version" — it depends on which NIC driver you use.

  • Linux with eBPF + AF_XDP support for your NIC driver. Any modern distribution (Ubuntu 22.04+, Debian 12+, RHEL 9+, Fedora recent) is fine as long as the driver matrix below lines up.
  • Dual-port NIC with an AF_XDP-capable driver (see matrix).
  • Root / sudo access for eBPF program loading.

NIC driver / kernel matrix (AF_XDP)

Driver NIC family (examples) Min kernel for AF_XDP
mlx5 Mellanox ConnectX-4/5/6/7 5.x (early)
ixgbe Intel 82599, X520, X540, X550 5.x
i40e Intel X710, XL710, XXV710 5.x
ice Intel E810 5.5+
igb Intel i350 T2 (reference hardware) 6.17
igc Intel I225/I226 6.x
virtio_net QEMU/KVM virtual NICs varies; AF_XDP is limited

If you are using the reference Intel i350 T2, you need Linux 6.17 or newer because igb AF_XDP support landed in that release. On a kernel older than 6.17 the system will still build, but ingress/egress setup will fail at runtime when AF_XDP binding is attempted — check driver support with ethtool -i <iface> and confirm against the matrix above before deploying.

Hardware Compatibility

  • Network Interface: dual-port NIC with an AF_XDP-capable driver on your kernel (see matrix above). Intel i350 T2 is the reference hardware.
  • CPU: multi-core recommended; XDP scales with RX queue count.
  • Memory: 8 GB minimum, 16 GB+ for high-traffic environments.

NetGuardia is not limited to embedded platforms — it runs on standard server hardware, virtual machines, or dedicated appliances as long as the driver/kernel requirement above is met.

Description
NetGuardia is a network defense system that integrates eBPF XDP and deep learning models
Readme 121 MiB
Languages
Rust 96.7%
Shell 2.9%
HCL 0.4%