Projects

Thesis work, a security tool, and industrial automation.

MSc thesis, 2026

AccNet: kernel-bypass networking for unmodified applications

Kernel-bypass stacks like DPDK are fast, but they normally need the application rewritten against a new API. AccNet removes that requirement. A custom Linux kernel exposes generic entry and exit eBPF hooks on the system-call path; the hooks can rewrite an intercepted call into a different one, or implement and short-circuit it entirely. AccNet uses them to catch the socket calls of an unmodified TCP application and redirect its data through shared-memory ring buffers to Machnet, a DPDK-based transport, so an ordinary binary gets the fast path without knowing it.

Transmit is zero-copy: the ring buffer the eBPF hook writes into is registered with DPDK, so the NIC reads the payload from where the hook left it. Making that work needed two kernel modifications, a writeable ring-buffer mapping and eventfd kfuncs, so the bypass could wake the application the way the kernel would, which also keeps epoll, poll and select working untouched. Built with a co-author of Machnet.

AccNet data path An unmodified application issues socket system calls. An eBPF syscall hook at the kernel boundary redirects them into per-connection ring buffers, which Machnet in user space drains and transmits through DPDK straight to the NIC. The ordinary Linux TCP/IP path is shown dimmed as the slow path. user space kernel kernel boundary Unmodified application in a container Machnet DPDK transport NIC eBPF syscall hook intercepts the syscall Shared-memory ring buffers registered with DPDK Linux TCP/IP stack slow path, unchanged send() / recv() zero-copy
The fast path (amber) leaves the kernel stack untouched; sockets the daemon doesn't claim fall through to ordinary TCP.

Measured against tuned Linux TCP

  • 1.59–2.59× lower median latency on microbenchmarks
  • ~2× throughput for unmodified memcached and lighttpd
  • 2.34× throughput for an unmodified Go server, which libc-level interception can't reach
  • 0.94–1.17 µs added per message compared with native Machnet
  • C
  • C++
  • eBPF
  • DPDK
  • Linux kernel
  • Shared-memory IPC
  • Machnet

A paper based on this work is under submission, so the source stays private for now. Happy to walk through the design and the thesis in conversation.

Security tooling

Spectre-PHT gadget detector

A binary-level Spectre-PHT detector that extends the angr symbolic-execution engine to model speculative execution, without needing relational analysis. 100% precision and recall on the standard litmus gadgets. Open source.

  • Python
  • angr
  • Symbolic execution
github.com/YBushi/angr-speculative-pht

Industrial automation, MicroStep

EtherCAT configuration generator

Parses the electrical schematics of a CNC machine and generates the YAML, EBI and ENI configuration files its EtherCAT devices need, plus the I/O change scripts for updating I/O maps. Replaced a manual process and cut setup time by about 80%.

  • Python
  • EtherCAT
  • Code generation