Skip to content
Back to skills

Systems Networking

ASecurity

Systems-level networking architecture: kernel-bypass (DPDK, io_uring, eBPF/XDP), zero-copy, the network stack data path, NIC offloads, congestion control, and high-connection-count (C10M) server design. Architect-level, not app HTTP. USE WHEN: designing high-throughput/low-latency networking, packet processing, "kernel bypass", "DPDK", "io_uring", "eBPF", "XDP", "zero-copy", "C10M", "line rate", NIC offload, congestion control, software data plane. DO NOT USE FOR: REST/GraphQL API design (u...

  • 31 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 8, 2026
ai-agentsgoapi

Works with

  • api

Security analysis

A100/100

Scanned September 8, 2026

npx -y skills add claude-dev-suite/claude-dev-suite --skill systems-networking --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Systems Networking?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Systems Networking
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/claude-dev-suite-systems-networking/badge)](https://www.skillsdirectory.com/skills/claude-dev-suite-systems-networking)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: systems-networking
description: |
  Systems-level networking architecture: kernel-bypass (DPDK, io_uring, eBPF/XDP),
  zero-copy, the network stack data path, NIC offloads, congestion control, and
  high-connection-count (C10M) server design. Architect-level, not app HTTP.

  USE WHEN: designing high-throughput/low-latency networking, packet processing,
  "kernel bypass", "DPDK", "io_uring", "eBPF", "XDP", "zero-copy", "C10M",
  "line rate", NIC offload, congestion control, software data plane.

  DO NOT USE FOR: REST/GraphQL API design (use api-design skills); app websockets
  (use real-time skills); cloud LB config (use infrastructure skills).
allowed-tools: Read, Grep, Glob
---
# Systems Networking Architecture

## The latency/throughput ladder (pick the lowest tier that meets needs)

| Tier | Mechanism | Throughput/latency | Cost/complexity |
|---|---|---|---|
| Sockets + epoll | Classic kernel stack | Good; syscalls + copies dominate | Lowest |
| **io_uring** | Async, batched, shared rings | Fewer syscalls/copies | Moderate; Linux ≥5.x |
| **eBPF/XDP** | Run code at the driver hook | Drop/redirect at line rate before stack | Verifier limits; per-packet logic |
| **Kernel bypass (DPDK)** | Poll-mode driver in userspace | 10–100M pps, µs latency | High; burns cores, no kernel stack |

Decision drivers: required **pps/latency**, CPU budget (DPDK busy-polls cores),
need for the kernel stack (TLS, routing), and operational complexity.

## Architectural levers

- **Zero-copy**: avoid user/kernel copies (sendfile, splice, io_uring fixed
  buffers, DPDK mbufs). Copies are often the real bottleneck.
- **Per-core / shared-nothing**: thread-per-core with RSS/affinity (Seastar
  model) to kill cross-core contention and cache bouncing.
- **NIC offloads**: checksum, TSO/LRO, RSS, and increasingly full TCP/crypto
  offload; SmartNIC/DPU pushes the data plane off the host CPU.
- **Congestion control**: choose per goal — CUBIC (throughput), BBR
  (latency/bufferbloat), DCTCP (datacenter). Matters for tail latency.
- **C10M**: the bottleneck is per-connection kernel cost and copies → bypass +
  zero-copy + per-core state.

## When to recommend what
- API server, normal scale → sockets/epoll or io_uring; don't over-engineer.
- Software router/firewall/LB at line rate → XDP/eBPF or DPDK.
- µs-tail trading/telco data plane → DPDK + per-core + kernel-bypass, SmartNIC.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…