C10M – Defending the Internet At Scale

ShmooCon IX - 2013

Presented by: Rob Graham
Date: Saturday February 16, 2013
Time: 10:00 - 10:50
Location: Regency B/C/D
Track: Belay It!

A decade ago, engineers tackled the “c10k” scalability problems that prevented servers from handling more than 10,000 concurrent connections. This problem was solved by fixing OS kernels and moving from threaded servers like Apache to event-driven servers like Nginx/NodeJS. This talk is about the next level in scalability: systems that handle 10 MILLION concurrent connections. Such systems already exist, though instead of being called “servers” they are called “devices”, like firewalls, IPS, DPI, load balancers, carrier NAT, etc. It’s not hardware that makes these systems scale, but software. Indeed, many of these scalable “devices” are simply x86 servers with a different logo on the front panel. This talk broadly covers the major areas of making a scalable system from a standard x86 desktop, discussing asynchronous event driven design, custom stacks, multi-core programming, low-level optimizations, and security.

Rob Graham

Robert David Graham CEO of Errata Security Created the first IPS (BlackICE Guard), which is now sold as “Proventia”, which scales to 10 million concurrent connections on x86 hardware. http://erratasec.blogspot.com @ErrataRob robert_david_graham@yahoo.com


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats