diff --git a/documentation/thesis/02-preliminaries.tex b/documentation/thesis/02-preliminaries.tex index aa36b96..8c543c2 100644 --- a/documentation/thesis/02-preliminaries.tex +++ b/documentation/thesis/02-preliminaries.tex @@ -75,6 +75,147 @@ A transparent inline bridge occupies the forwarding path without acting as an \a Transparency should not be understood as complete undetectability. An inline bridge can affect latency, packet ordering, loss behavior, link-state propagation, and bridge-control behavior. If \ac{STP} is enabled, \acp{BPDU} and forwarding-delay behavior may become externally visible \cite{linuxkernelbridgedocs}. If \ac{TLS} proxying is added on top of forwarding, certificate and handshake artifacts can reveal the interception point \cite{durumeric2017httpsinterception}. The transparency goal in this thesis is therefore narrower and technical: the system should forward traffic as a Layer-2 inline bridge without introducing an additional \ac{IP} hop, without requiring endpoint proxy configuration, and without terminating application-layer sessions unless a later manipulation component explicitly does so. +\section{Linux Packet Filtering with \texttt{nftables}} +\label{sec:nftables} + +% cites noch ergänzen: nftables_manpage und nf queue noch + +\texttt{nftables} is a framework for packet filtering and classification in Linux. +The \texttt{nft} command-line tool is used to set up, maintain, and inspect packet-filtering and classification rules in the Linux kernel. +The corresponding Linux kernel subsystem is called \texttt{nf\_tables} and is part of Netfilter. + +An \texttt{nftables} ruleset is organized using several types of objects. +In particular, \textbf{tables} are containers for chains, sets, and stateful objects, while \textbf{chains} are containers for rules. +Tables are identified by an address family and a name. +The supported table families are \texttt{ip}, \texttt{ip6}, \texttt{inet}, \texttt{arp}, \texttt{bridge}, and \texttt{netdev}. +If no family is specified, the \texttt{ip} family is used by default. + + +\subsection{Address Families and Hooks} +\label{sec:nftables-address-families} + +Address families determine the type of packets that \texttt{nftables} processes. +For each address family, the kernel provides hooks at particular stages of the packet-processing path. +These hooks invoke \texttt{nftables} when rules for the respective hooks exist. +The \texttt{ip} family processes IPv4 packets, \texttt{ip6} processes IPv6 packets, and \texttt{inet} provides a combined IPv4/IPv6 family. +The \texttt{arp} family handles IPv4 ARP packets, the \texttt{bridge} family handles packets traversing a bridge device, and the \texttt{netdev} family handles packets on the ingress and egress paths. +\texttt{nftables} objects exist in address-family-specific namespaces. + +For the IPv4, IPv6, and \texttt{inet} address families, \texttt{nftables} defines hooks at different stages of packet processing. +The \texttt{prerouting} hook processes packets entering the system before the routing process. +Packets delivered to the local system are processed by the \texttt{input} hook, while packets forwarded to another host are processed by the \texttt{forward} hook. +Packets generated by local processes pass through the \texttt{output} hook, and packets leaving the system pass through the \texttt{postrouting} hook. +The \texttt{inet} family additionally supports an \texttt{ingress} hook, which is invoked before the Layer-3 protocol handlers and therefore before \texttt{prerouting}. + +The \texttt{bridge} address family handles Ethernet packets traversing bridge devices. +According to the \texttt{nftables} documentation, its list of supported hooks is identical to that of the IPv4, IPv6, and \texttt{inet} families described above. + + +\subsection{Tables, Chains, and Rules} +\label{sec:nftables-tables-chains-rules} + +Chains exist in two forms: base chains and regular chains. +A base chain is an entry point for packets from the networking stack. +A regular chain can be used as a jump target and for organizing rules. +When a chain is created with a hook and priority, it becomes a base chain and is connected to the networking stack. +For base chains, the chain type, hook, and priority parameters are mandatory. + +The \texttt{filter} chain type is supported by all families and hooks. +Other chain types have additional restrictions. +For example, \texttt{nat} chains are supported by the \texttt{ip}, \texttt{ip6}, and \texttt{inet} families, while \texttt{route} chains are restricted to the \texttt{output} hook of those families. + +A base chain has a priority that determines its evaluation order relative to other chains attached to the same hook. +Lower numerical priority values are evaluated before higher values. +The evaluation order of chains with identical priorities is undefined. +\texttt{nftables} provides names for several standard priority values, and the priority values used by the \texttt{bridge} family differ from those used by the other families. + +For the \texttt{bridge} family, the predefined priorities include \texttt{dstnat} with a value of $-300$ for \texttt{prerouting}, \texttt{filter} with a value of $-200$ for all hooks, \texttt{out} with a value of $100$ for \texttt{output}, and \texttt{srcnat} with a value of $300$ for \texttt{postrouting}. + +A base chain can also specify a policy. +The supported policies are \texttt{accept} and \texttt{drop}, with \texttt{accept} being the default. +The policy determines what happens to packets for which the rules in the chain do not explicitly produce an acceptance or refusal. + +Rules are contained within chains. +According to the \texttt{nftables} documentation, rules consist of two types of components: expressions and statements. + + +\subsection{Expressions and Statements} +\label{sec:nftables-expressions-statements} + +Expressions represent values. +These values may be constants, such as network addresses and port numbers, or information obtained from a packet during ruleset evaluation. +Expressions can be combined to construct match expressions and can also be used as arguments for operations such as NAT or packet marking. +Each expression has a data type that determines properties including its size, parsing, representation, and compatibility with other expressions. + +\texttt{nftables} provides, among others, meta expressions and payload expressions. +A meta expression accesses metadata associated with a packet. +Available metadata includes the packet length, protocol family, Layer-4 protocol, packet mark, input and output interfaces, and packet type. + +The input and output interfaces can be accessed using \texttt{iif}, \texttt{oif}, \texttt{iifname}, and \texttt{oifname}. +\texttt{iif} and \texttt{oif} operate on interface indices, whereas \texttt{iifname} and \texttt{oifname} operate on interface names. +\texttt{nftables} also provides \texttt{ibrname} and \texttt{obrname}, representing the input and output bridge interface names, respectively. + +Payload expressions refer to information contained in a packet's payload. +For Ethernet headers, \texttt{nftables} provides expressions for the destination address (\texttt{ether daddr}), source address (\texttt{ether saddr}), and EtherType (\texttt{ether type}). + +Further payload expressions provide access to fields of higher-layer protocols. +For example, IPv4 expressions can access fields including source and destination addresses and the upper-layer protocol, while IPv6 expressions provide access to fields including source and destination addresses and the next-header field. +TCP and UDP expressions provide access to source and destination ports as well as additional protocol-specific header fields. + +Statements represent actions that are performed during rule evaluation. +They may alter the control flow by accepting or dropping a packet or by transferring evaluation to another chain. +Statements may also perform other actions, including logging and rejecting packets. +nftables distinguishes between terminal and non-terminal statements. +Terminal statements unconditionally terminate evaluation of the current rule, whereas non-terminal statements either conditionally terminate evaluation or allow it to continue. + + +\subsection{Ruleset Evaluation and Verdicts} +\label{sec:nftables-ruleset-evaluation} + +Packets traverse the networking stack and are evaluated by base chains attached to the hooks they encounter. +If multiple base chains are attached to the same hook, the chains are evaluated according to their priorities, with lower priority values evaluated first. +Base chains may call regular chains using \texttt{jump} and \texttt{goto}, and regular chains may in turn call other regular chains. +Chains in different tables cannot call each other. + +nftables provides the verdict statements \texttt{accept}, \texttt{drop}, \texttt{continue}, \texttt{return}, \texttt{jump}, and \texttt{goto}. +The \texttt{accept} and \texttt{drop} verdicts terminate chain evaluation, but their effects on subsequent processing differ. + +An \texttt{accept} verdict terminates evaluation of the current base chain. +Processing can subsequently continue in another base chain attached to the same hook or in a base chain attached to a later hook. +Consequently, a packet that receives an \texttt{accept} verdict may still subsequently receive a \texttt{drop} verdict from another base chain. + +A \texttt{drop} verdict immediately drops the packet and terminates evaluation of the ruleset. +No further chains are evaluated, and the verdict cannot be overridden by a later \texttt{accept} verdict. + +The \texttt{jump} statement stores the current evaluation position and continues evaluation at the beginning of another regular chain. +When that chain ends, evaluation can return to the stored position. +\texttt{goto} similarly transfers evaluation to another chain but does not store the current position. +\texttt{return} terminates evaluation of the current chain and, where a stored position exists, continues evaluation from that position. + + +\subsection{Queueing Packets to Userspace} +\label{sec:nftables-queue} + +In addition to issuing verdicts directly in the ruleset, nftables provides a \texttt{queue} statement. +The \texttt{queue} statement passes a packet to userspace using the \texttt{nfnetlink\_queue} handler. +The packet is placed into a queue identified by a 16-bit queue number. +The default queue number is 0. + +A userspace application receiving a queued packet can inspect it and may optionally modify it. +The userspace application must subsequently provide either an \texttt{accept} or a \texttt{drop} verdict. +If the packet is accepted, nftables processing resumes with the next base-chain hook rather than with the rule following the \texttt{queue} statement. +The nftables documentation refers to the \texttt{libnetfilter\_queue} documentation for further details concerning userspace queue processing. + +The \texttt{queue} statement can specify a single queue number, a range of queue numbers, or an expression that determines the queue number. +Queue numbers may be computed at runtime using \texttt{numgen}, \texttt{hash}, or \texttt{symhash} expressions, and a map statement can be used to select fixed queue numbers based on inputs such as source IP addresses or interface names. + +Two flags are defined for the \texttt{queue} statement: \texttt{bypass} and \texttt{fanout}. +The \texttt{fanout} flag distributes packets between several queues. +The \texttt{bypass} flag allows packets to proceed when the userspace application cannot process them; the documentation recommends consulting the \texttt{libnetfilter\_queue} documentation for performance-tuning recommendations before using this flag. +``` +consulting the \texttt{libnetfilter\_queue} documentation for performance-tuning recommendations before using this flag. + + \section{Linux Packet Processing Path} \label{sec:linux-packet-processing-path} diff --git a/documentation/thesis/ba.bib b/documentation/thesis/ba.bib index 48ef4fc..95c2890 100644 --- a/documentation/thesis/ba.bib +++ b/documentation/thesis/ba.bib @@ -1,316 +1,326 @@ @article{cerf1974protocol, - author = {Cerf, Vinton G. and Kahn, Robert E.}, - title = {A Protocol for Packet Network Intercommunication}, + author = {Cerf, Vinton G. and Kahn, Robert E.}, + title = {A Protocol for Packet Network Intercommunication}, journaltitle = {IEEE Transactions on Communications}, - volume = {22}, - number = {5}, - pages = {637--648}, - date = {1974-05}, - doi = {10.1109/TCOM.1974.1092259} + volume = {22}, + number = {5}, + pages = {637--648}, + date = {1974-05}, + doi = {10.1109/TCOM.1974.1092259} } @techreport{rfc791, - author = {Postel, Jon}, - title = {Internet Protocol}, - type = {RFC}, - number = {791}, + author = {Postel, Jon}, + title = {Internet Protocol}, + type = {RFC}, + number = {791}, institution = {RFC Editor}, - date = {1981-09}, - doi = {10.17487/RFC0791} + date = {1981-09}, + doi = {10.17487/RFC0791} } @techreport{rfc793, - author = {Postel, Jon}, - title = {Transmission Control Protocol}, - type = {RFC}, - number = {793}, + author = {Postel, Jon}, + title = {Transmission Control Protocol}, + type = {RFC}, + number = {793}, institution = {RFC Editor}, - date = {1981-09}, - doi = {10.17487/RFC0793} + date = {1981-09}, + doi = {10.17487/RFC0793} } @techreport{rfc1122, - author = {Braden, Robert}, - title = {Requirements for Internet Hosts -- Communication Layers}, - type = {RFC}, - number = {1122}, + author = {Braden, Robert}, + title = {Requirements for Internet Hosts -- Communication Layers}, + type = {RFC}, + number = {1122}, institution = {RFC Editor}, - date = {1989-10}, - doi = {10.17487/RFC1122} + date = {1989-10}, + doi = {10.17487/RFC1122} } @techreport{rfc1812, - author = {Baker, Fred}, - title = {Requirements for {IP} Version 4 Routers}, - type = {RFC}, - number = {1812}, + author = {Baker, Fred}, + title = {Requirements for {IP} Version 4 Routers}, + type = {RFC}, + number = {1812}, institution = {RFC Editor}, - date = {1995-06}, - doi = {10.17487/RFC1812} + date = {1995-06}, + doi = {10.17487/RFC1812} } @techreport{rfc3022, - author = {Srisuresh, Pyda and Egevang, Kjeld}, - title = {Traditional {IP} Network Address Translator ({Traditional NAT})}, - type = {RFC}, - number = {3022}, + author = {Srisuresh, Pyda and Egevang, Kjeld}, + title = {Traditional {IP} Network Address Translator ({Traditional NAT})}, + type = {RFC}, + number = {3022}, institution = {RFC Editor}, - date = {2001-01}, - doi = {10.17487/RFC3022} + date = {2001-01}, + doi = {10.17487/RFC3022} } @inproceedings{stephan2024packetpath, - author = {Stephan, Alexander and W{\"u}strich, Lars}, - title = {The Path of a Packet Through the Linux Kernel}, + author = {Stephan, Alexander and W{\"u}strich, Lars}, + title = {The Path of a Packet Through the Linux Kernel}, booktitle = {Seminar IITM WS 23}, - date = {2024}, - doi = {10.2313/NET-2024-04-1\_16}, - url = {https://www.net.in.tum.de/fileadmin/TUM/NET/NET-2024-04-1/NET-2024-04-1_16.pdf} + date = {2024}, + doi = {10.2313/NET-2024-04-1\_16}, + url = {https://www.net.in.tum.de/fileadmin/TUM/NET/NET-2024-04-1/NET-2024-04-1_16.pdf} } @inproceedings{hoilandjorgensen2018xdp, - author = {H{\o}iland-J{\o}rgensen, Toke and Brouer, Jesper Dangaard and Borkmann, Daniel and Fastabend, John and Herbert, Tom and Ahern, David and Miller, David}, - title = {The {eXpress} Data Path: Fast Programmable Packet Processing in the Operating System Kernel}, + author = {H{\o}iland-J{\o}rgensen, Toke and Brouer, Jesper Dangaard and Borkmann, Daniel and Fastabend, John and Herbert, Tom and Ahern, David and Miller, David}, + title = {The {eXpress} Data Path: Fast Programmable Packet Processing in the Operating System Kernel}, booktitle = {Proceedings of the 14th International Conference on Emerging Networking Experiments and Technologies}, - series = {CoNEXT '18}, - pages = {54--66}, + series = {CoNEXT '18}, + pages = {54--66}, publisher = {Association for Computing Machinery}, - location = {Heraklion, Greece}, - date = {2018}, - doi = {10.1145/3281411.3281443}, - url = {https://doi.org/10.1145/3281411.3281443} + location = {Heraklion, Greece}, + date = {2018}, + doi = {10.1145/3281411.3281443}, + url = {https://doi.org/10.1145/3281411.3281443} } @inproceedings{scholz2018ebpfpacketfiltering, - author = {Scholz, Dominik and Raumer, Daniel and Emmerich, Paul and Kurtz, Alexander and Lesiak, Krzysztof and Carle, Georg}, - title = {Performance Implications of Packet Filtering with {Linux eBPF}}, + author = {Scholz, Dominik and Raumer, Daniel and Emmerich, Paul and Kurtz, Alexander and Lesiak, Krzysztof and Carle, Georg}, + title = {Performance Implications of Packet Filtering with {Linux eBPF}}, booktitle = {2018 30th International Teletraffic Congress}, - series = {ITC 30}, - pages = {209--217}, + series = {ITC 30}, + pages = {209--217}, publisher = {IEEE}, - location = {Vienna, Austria}, - date = {2018}, - doi = {10.1109/ITC30.2018.00039}, - url = {https://www.net.in.tum.de/fileadmin/bibtex/publications/papers/ITC30-Packet-Filtering-eBPF-XDP.pdf} + location = {Vienna, Austria}, + date = {2018}, + doi = {10.1109/ITC30.2018.00039}, + url = {https://www.net.in.tum.de/fileadmin/bibtex/publications/papers/ITC30-Packet-Filtering-eBPF-XDP.pdf} } @online{gbadamosi2024ebpfruntime, - author = {Gbadamosi, Bolaji and Leonardi, Luigi and Pulls, Tobias and H{\o}iland-J{\o}rgensen, Toke and Ferlin-Reiter, Simone and Sorce, Simo and Brunstr{\"o}m, Anna}, - title = {The {eBPF} Runtime in the {Linux} Kernel}, - date = {2024-10-03}, - eprint = {2410.00026}, + author = {Gbadamosi, Bolaji and Leonardi, Luigi and Pulls, Tobias and H{\o}iland-J{\o}rgensen, Toke and Ferlin-Reiter, Simone and Sorce, Simo and Brunstr{\"o}m, Anna}, + title = {The {eBPF} Runtime in the {Linux} Kernel}, + date = {2024-10-03}, + eprint = {2410.00026}, eprinttype = {arXiv}, - doi = {10.48550/arXiv.2410.00026}, - url = {https://arxiv.org/abs/2410.00026}, - urldate = {2026-05-15} + doi = {10.48550/arXiv.2410.00026}, + url = {https://arxiv.org/abs/2410.00026}, + urldate = {2026-05-15} } @inproceedings{westphal2016bridgefiltering, - author = {Westphal, Florian}, - title = {Bridge Filtering with {nftables}}, + author = {Westphal, Florian}, + title = {Bridge Filtering with {nftables}}, booktitle = {Proceedings of Netdev 1.1}, - location = {Seville, Spain}, - date = {2016}, - url = {https://netdevconf.org/1.1/proceedings/papers/Bridge-filter-with-nftables.pdf}, - urldate = {2026-05-15} + location = {Seville, Spain}, + date = {2016}, + url = {https://netdevconf.org/1.1/proceedings/papers/Bridge-filter-with-nftables.pdf}, + urldate = {2026-05-15} } @article{conti2016mitmsurvey, - author = {Conti, Mauro and Dragoni, Nicola and Lesyk, Viktor}, - title = {A Survey of {Man In The Middle} Attacks}, + author = {Conti, Mauro and Dragoni, Nicola and Lesyk, Viktor}, + title = {A Survey of {Man In The Middle} Attacks}, journaltitle = {IEEE Communications Surveys \& Tutorials}, - volume = {18}, - number = {3}, - pages = {2027--2051}, - date = {2016}, - doi = {10.1109/COMST.2016.2548426}, - url = {https://doi.org/10.1109/COMST.2016.2548426} + volume = {18}, + number = {3}, + pages = {2027--2051}, + date = {2016}, + doi = {10.1109/COMST.2016.2548426}, + url = {https://doi.org/10.1109/COMST.2016.2548426} } @article{nam2012arpmitm, - author = {Nam, Seung Yeob and Jurayev, Sirojiddin and Kim, Seung-Sik and Choi, Kwonhue and Choi, Gyu Sang}, - title = {Mitigating {ARP} Poisoning-Based {Man-in-the-Middle} Attacks in Wired or Wireless {LAN}}, + author = {Nam, Seung Yeob and Jurayev, Sirojiddin and Kim, Seung-Sik and Choi, Kwonhue and Choi, Gyu Sang}, + title = {Mitigating {ARP} Poisoning-Based {Man-in-the-Middle} Attacks in Wired or Wireless {LAN}}, journaltitle = {EURASIP Journal on Wireless Communications and Networking}, - volume = {2012}, - number = {1}, - eid = {89}, - date = {2012}, - doi = {10.1186/1687-1499-2012-89}, - url = {https://doi.org/10.1186/1687-1499-2012-89} + volume = {2012}, + number = {1}, + eid = {89}, + date = {2012}, + doi = {10.1186/1687-1499-2012-89}, + url = {https://doi.org/10.1186/1687-1499-2012-89} } @inproceedings{zhang2007portmirroring, - author = {Zhang, Jian and Moore, Andrew W.}, - title = {Traffic Trace Artifacts due to Monitoring Via Port Mirroring}, + author = {Zhang, Jian and Moore, Andrew W.}, + title = {Traffic Trace Artifacts due to Monitoring Via Port Mirroring}, booktitle = {2007 Workshop on End-to-End Monitoring Techniques and Services}, - series = {E2EMON '07}, - pages = {1--8}, + series = {E2EMON '07}, + pages = {1--8}, publisher = {IEEE}, - date = {2007}, - doi = {10.1109/E2EMON.2007.375317}, - url = {https://www.cl.cam.ac.uk/research/srg/netos/papers/2007-zhang2007traffic.pdf}, - urldate = {2026-05-16} + date = {2007}, + doi = {10.1109/E2EMON.2007.375317}, + url = {https://www.cl.cam.ac.uk/research/srg/netos/papers/2007-zhang2007traffic.pdf}, + urldate = {2026-05-16} } @inproceedings{durumeric2017httpsinterception, - author = {Durumeric, Zakir and Ma, Zane and Springall, Drew and Barnes, Richard and Sullivan, Nick and Bursztein, Elie and Bailey, Michael and Halderman, J. Alex and Paxson, Vern}, - title = {The Security Impact of {HTTPS} Interception}, + author = {Durumeric, Zakir and Ma, Zane and Springall, Drew and Barnes, Richard and Sullivan, Nick and Bursztein, Elie and Bailey, Michael and Halderman, J. Alex and Paxson, Vern}, + title = {The Security Impact of {HTTPS} Interception}, booktitle = {Proceedings of the Network and Distributed System Security Symposium}, - series = {NDSS '17}, - date = {2017}, - doi = {10.14722/ndss.2017.23456}, - url = {https://doi.org/10.14722/ndss.2017.23456} + series = {NDSS '17}, + date = {2017}, + doi = {10.14722/ndss.2017.23456}, + url = {https://doi.org/10.14722/ndss.2017.23456} } @inproceedings{waked2018tlsinterception, - author = {Waked, Louis and Mannan, Mohammad and Youssef, Amr}, - title = {To Intercept or Not to Intercept: Analyzing {TLS} Interception in Network Appliances}, + author = {Waked, Louis and Mannan, Mohammad and Youssef, Amr}, + title = {To Intercept or Not to Intercept: Analyzing {TLS} Interception in Network Appliances}, booktitle = {Proceedings of the 2018 {ACM Asia} Conference on Computer and Communications Security}, - series = {ASIACCS '18}, - pages = {399--412}, + series = {ASIACCS '18}, + pages = {399--412}, publisher = {Association for Computing Machinery}, - location = {Incheon, Republic of Korea}, - date = {2018}, - doi = {10.1145/3196494.3196528}, - url = {https://doi.org/10.1145/3196494.3196528} + location = {Incheon, Republic of Korea}, + date = {2018}, + doi = {10.1145/3196494.3196528}, + url = {https://doi.org/10.1145/3196494.3196528} } @article{decarnedecarnavalet2023tlsinterception, - author = {de Carn{\'e} de Carnavalet, Xavier and van Oorschot, Paul C.}, - title = {A Survey and Analysis of {TLS} Interception Mechanisms and Motivations}, + author = {de Carn{\'e} de Carnavalet, Xavier and van Oorschot, Paul C.}, + title = {A Survey and Analysis of {TLS} Interception Mechanisms and Motivations}, journaltitle = {ACM Computing Surveys}, - volume = {55}, - number = {13s}, - articleno = {269}, - pages = {1--40}, - date = {2023}, - doi = {10.1145/3580522}, - url = {https://doi.org/10.1145/3580522} + volume = {55}, + number = {13s}, + articleno = {269}, + pages = {1--40}, + date = {2023}, + doi = {10.1145/3580522}, + url = {https://doi.org/10.1145/3580522} } @manual{ieee8021q2022, - author = {{IEEE}}, - title = {{IEEE Standard for Local and Metropolitan Area Networks--Bridges and Bridged Networks}}, + author = {{IEEE}}, + title = {{IEEE Standard for Local and Metropolitan Area Networks--Bridges and Bridged Networks}}, organization = {IEEE}, - type = {IEEE Std 802.1Q-2022}, - date = {2022-12-22}, - url = {https://standards.ieee.org/ieee/802.1Q/10323/}, - urldate = {2026-05-16} + type = {IEEE Std 802.1Q-2022}, + date = {2022-12-22}, + url = {https://standards.ieee.org/ieee/802.1Q/10323/}, + urldate = {2026-05-16} } @inproceedings{perlman1985spanningtree, - author = {Perlman, Radia}, - title = {An Algorithm for Distributed Computation of a Spanningtree in an Extended {LAN}}, + author = {Perlman, Radia}, + title = {An Algorithm for Distributed Computation of a Spanningtree in an Extended {LAN}}, booktitle = {Proceedings of the Ninth Symposium on Data Communications}, - series = {SIGCOMM '85}, - pages = {44--53}, + series = {SIGCOMM '85}, + pages = {44--53}, publisher = {Association for Computing Machinery}, - location = {Whistler Mountain, British Columbia, Canada}, - date = {1985}, - doi = {10.1145/319056.319004}, - url = {https://doi.org/10.1145/319056.319004} + location = {Whistler Mountain, British Columbia, Canada}, + date = {1985}, + doi = {10.1145/319056.319004}, + url = {https://doi.org/10.1145/319056.319004} } @online{linuxkernelnetworkingdocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Networking --- The Linux Kernel documentation}, - year = {2026}, - url = {https://docs.kernel.org/networking/index.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Networking --- The Linux Kernel documentation}, + year = {2026}, + url = {https://docs.kernel.org/networking/index.html}, urldate = {2026-04-18} } @online{linuxkernelskbuffdocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {struct sk\_buff --- The Linux Kernel documentation}, - year = {2026}, - url = {https://docs.kernel.org/networking/skbuff.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {struct sk\_buff --- The Linux Kernel documentation}, + year = {2026}, + url = {https://docs.kernel.org/networking/skbuff.html}, urldate = {2026-04-18} } @online{linuxkernelbridgedocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Ethernet Bridging --- The Linux Kernel documentation}, - year = {2026}, - url = {https://docs.kernel.org/networking/bridge.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Ethernet Bridging --- The Linux Kernel documentation}, + year = {2026}, + url = {https://docs.kernel.org/networking/bridge.html}, urldate = {2026-04-18} } @online{linuxkernelswitchdevdocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Ethernet switch device driver model (switchdev) --- The Linux Kernel documentation}, - year = {2026}, - url = {https://www.kernel.org/doc/html/latest/networking/switchdev.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Ethernet switch device driver model (switchdev) --- The Linux Kernel documentation}, + year = {2026}, + url = {https://www.kernel.org/doc/html/latest/networking/switchdev.html}, urldate = {2026-05-16} } @online{linuxkernelflowtabledocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Netfilter's Flowtable Infrastructure --- The Linux Kernel documentation}, - year = {2026}, - url = {https://docs.kernel.org/networking/nf_flowtable.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Netfilter's Flowtable Infrastructure --- The Linux Kernel documentation}, + year = {2026}, + url = {https://docs.kernel.org/networking/nf_flowtable.html}, urldate = {2026-05-15} } @online{linuxkernelscalingdocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Scaling in the Linux Networking Stack --- The Linux Kernel documentation}, - year = {2026}, - url = {https://docs.kernel.org/networking/scaling.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Scaling in the Linux Networking Stack --- The Linux Kernel documentation}, + year = {2026}, + url = {https://docs.kernel.org/networking/scaling.html}, urldate = {2026-05-15} } @online{linuxkerneltracepointsdocs, - author = {{The Linux Kernel Documentation Authors}}, - title = {Using the Linux Kernel Tracepoints --- The Linux Kernel documentation}, - year = {2026}, - url = {https://www.kernel.org/doc/html/latest/trace/tracepoints.html}, + author = {{The Linux Kernel Documentation Authors}}, + title = {Using the Linux Kernel Tracepoints --- The Linux Kernel documentation}, + year = {2026}, + url = {https://www.kernel.org/doc/html/latest/trace/tracepoints.html}, urldate = {2026-05-16} } @online{man7packet, - author = {{Linux man-pages project}}, - title = {packet(7) --- Linux manual page}, - date = {2025-09-21}, - url = {https://man7.org/linux/man-pages/man7/packet.7.html}, + author = {{Linux man-pages project}}, + title = {packet(7) --- Linux manual page}, + date = {2025-09-21}, + url = {https://man7.org/linux/man-pages/man7/packet.7.html}, urldate = {2026-05-16} } @online{man7tcbpf, - author = {{Linux man-pages project}}, - title = {tc-bpf(8) --- Linux manual page}, - date = {2025-08-08}, - url = {https://man7.org/linux/man-pages/man8/tc-bpf.8.html}, + author = {{Linux man-pages project}}, + title = {tc-bpf(8) --- Linux manual page}, + date = {2025-08-08}, + url = {https://man7.org/linux/man-pages/man8/tc-bpf.8.html}, urldate = {2026-05-16} } @online{man7bridge, - author = {{Linux man-pages project}}, - title = {bridge(8) --- Linux manual page}, - date = {2012-08-01}, - url = {https://man7.org/linux/man-pages/man8/bridge.8.html}, + author = {{Linux man-pages project}}, + title = {bridge(8) --- Linux manual page}, + date = {2012-08-01}, + url = {https://man7.org/linux/man-pages/man8/bridge.8.html}, urldate = {2026-05-16} } @online{man7iplink, - author = {{Linux man-pages project}}, - title = {ip-link(8) --- Linux manual page}, - date = {2012-12-13}, - url = {https://man7.org/linux/man-pages/man8/ip-link.8.html}, + author = {{Linux man-pages project}}, + title = {ip-link(8) --- Linux manual page}, + date = {2012-12-13}, + url = {https://man7.org/linux/man-pages/man8/ip-link.8.html}, urldate = {2026-05-16} } @online{nftableshooks, - author = {{The nftables Project}}, - title = {Netfilter Hooks}, - year = {2023}, - url = {https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks}, + author = {{The nftables Project}}, + title = {Netfilter Hooks}, + year = {2023}, + url = {https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks}, urldate = {2026-05-15} } @online{nftablesbridgefiltering, - author = {{The nftables Project}}, - title = {Bridge Filtering}, - year = {2021}, - url = {https://wiki.nftables.org/wiki-nftables/index.php/Bridge_filtering}, + author = {{The nftables Project}}, + title = {Bridge Filtering}, + year = {2021}, + url = {https://wiki.nftables.org/wiki-nftables/index.php/Bridge_filtering}, urldate = {2026-05-15} } + +@online{nftables_manpage, + title = {nft(8) -- Administration Tool of the nftables Framework + for Packet Filtering and Classification}, + author = {{The Netfilter Project}}, + organization = {The Netfilter Project}, + year = {2026}, + url = {https://netfilter.org/projects/nftables/manpage.html}, + note = {Accessed: 2026-08-08} +}