Skip to content

Archive

UDP

5 articles
Cybersecurity 24 Sep 2026 5 min read

DNS Cookies Bind UDP Requests to Return-Path Reachability

UDP lets a sender place a source address in a datagram without a transport handshake that proves the sender can receive traffic at that address. DNS inherits that property when it runs over UDP. An off-path attacker can therefore send a query with a forged source address and try to make a DNS server direct its response toward another host. DNS Cookies add a lightweight challenge-and-return mechanism inside EDNS. RFC 7873 defines the COOKIE option, while RFC 9018 tightens Server Cookie construction for interoperable deployments. The mechanism does not turn UDP into an authenticated transport. It gives DNS clients and servers additional evidence about whether a peer has participated in an earlier exchange at the relevant network address.

Cybersecurity 24 Sep 2026 5 min read

DNS Cookies Bind UDP Replies to Recent Client State

UDP gives DNS low-overhead transport, but its source address can be forged and its replies can be imitated by an off-path sender. DNS Cookies add a small piece of client-generated state and, after contact with a supporting server, server-generated state. The mechanism raises the cost of off-path forgery without requiring a server to keep a session table for every client. The mechanism is deliberately limited. RFC 7873 describes DNS Cookies as lightweight transaction security against off-path denial-of-service, amplification, forgery, and cache-poisoning attacks. It does not protect against an adversary that can observe the DNS exchange. RFC 9018 later tightened cookie construction so independently implemented anycast servers can interoperate.

Software Engineering 17 Sep 2026 4 min read

SO_REUSEPORT Forms Kernel-Selected Socket Groups

Multiple Linux sockets can bind the same local address when every participating socket enables SO_REUSEPORT before bind(). Incoming traffic is then assigned to a member of the resulting reuseport group rather than delivered to every socket. The shared address is therefore a kernel selection boundary, not a broadcast endpoint. This behavior supports independent receive or accept loops without forcing all work through one listening descriptor. It also creates a distinct operational property: group membership and the selection policy determine which socket receives a packet or connection.

Linux 17 Sep 2026 6 min read

SO_REUSEPORT Distributes Traffic Across Socket Groups

SO_REUSEPORT changes a local endpoint from a single-socket binding into a socket group. On Linux, multiple TCP or UDP sockets can bind the same local address when every participating socket enables the option before bind() and the bind credentials satisfy the kernel’s reuse rules. That behavior is distinct from merely relaxing address-conflict checks. Incoming traffic must also be assigned to one member of the group. The resulting selection boundary affects listener architecture, queue isolation, process restarts, UDP flow placement, and any design that assumes a port maps to exactly one socket.

Tech 15 Sep 2026 7 min read

QUIC Connection IDs Keep Sessions Across Address Changes

A network connection is often associated with addresses and ports. That works well while both endpoints keep the same network attachment, but mobile devices regularly move between Wi-Fi and cellular service, and NAT devices can replace an external UDP port while an application is still active. QUIC provides another identifier for the transport connection: the connection ID. A non-zero-length connection ID lets an endpoint associate incoming QUIC packets with existing connection state even when the packet arrives from a different IP address or UDP port.