frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Shibuya – A High-Performance WAF in Rust with eBPF and ML Engine

https://ghostklan.com/shibuya.html
20•germainluperto•2h ago
Hi HN,

I’ve been working on Shibuya, a next-generation Web Application Firewall (WAF) built from the ground up in Rust.

I wanted to build a WAF that didn't just rely on legacy regex signatures but could understand intent and perform at line-rate using modern kernel features.

What makes Shibuya different:

Multi-Layer Pipeline: It integrates a high-performance proxy (built on Pingora) with rate limiting, bot detection, and threat intelligence.

eBPF Kernel Filtering: For volumetric attacks, Shibuya can drop malicious packets at the kernel level using XDP before they consume userspace resources.

Dual ML Engine: It uses an ONNX-based engine for anomaly detection and a Random Forest classifier to identify specific attack classes like SQLi, XSS, and RCE.

API & GraphQL Protection: Includes deep inspection for GraphQL (depth and complexity analysis) and OpenAPI schema validation.

WASM Extensibility: You can write and hot-load custom security logic using WebAssembly plugins.

Ashigaru Lab: The project includes a deliberately vulnerable lab environment with 6 different services and a "Red Team Bot" to test the WAF against 100+ simulated payloads.

The Dashboard: The dashboard is built with SvelteKit and offers real-time monitoring (ECharts), a "Panic Mode" for instant hardening, and a visual editor for the YAML configuration.

I'm looking for feedback on the architecture and the performance of the Rust-eBPF integration.

Comments

nullcathedral•1h ago
Feel free to correct me, but the ML classifier appears to be rather bare. Less than 20 hardcoded payloads with randomized URL encoding as the only augmentation. How does this generalize to novel evasion techniques? Genuinely curious what your eval numbers look like against real traffic.

https://github.com/theghostshinobi/Shibuya-waf-light-version...

koakuma-chan•52m ago
"The most advanced open-source WAF ever built."

Somehow, the moment I read this, I knew it was AI slop.

nullcathedral•50m ago
The website gave it away for me, felt very AI generated
reconnecting•58m ago
> Shibuya WORLD DOMINATION PLAN (1)

*Month 3*: Top 10 security OSS project su GitHub

*Month 6*: 10k+ stars, 1000+ prod deployments

*Month 9*: Conference talks (OWASP, DevSecOps Days, Black Hat Arsenal)

*Month 12*: Industry standard, "the modern WAF", competitors che copiano te

## MONETIZATION ROADMAP

*Week 12-16*: Free tier (self-hosted, community support)

- Goal: 1000 GitHub stars

- Goal: 100 production deployments

- Goal: Dev che parlano di te su Twitter

*Week 16-20*: Pro tier launch ($49-99/mo) - Managed rules auto-update

- ML models ottimizzati

- Priority support

- Advanced dashboard

- Goal: primi 50 paying customers ($5k MRR)

*Week 20-24*: Enterprise tier (custom pricing) - Multi-tenant

- SSO/SAML

- Compliance reports (PCI-DSS, SOC2)

- SLA + dedicated support

- Custom integrations

- Goal: primi 5 enterprise deals ($50k+ ARR)

*Month 6+*: Exit strategy - Seed funding ($1-2M) o bootstrap to profitability

- Series A ($10M+) se traction è pazzesca

- Acquisition offer da competitor? (Cloudflare che compra per killare? NO GRAZIE, fuck them )

1. Deleted file/commit: https://github.com/theghostshinobi/Shibuya-waf-light-version...

swah•53m ago
Speaking to LLMs looks fresh!
abusaidm•52m ago
They have a roadmap of where they want to be, I think that’s normal. As long as they don’t pull a fast one on the oss community then I think if this catch on and it’s worth it then even if they sell the community can fork if the new owners are not so welcoming.
abusaidm•54m ago
This looks really interesting especially in the age of agents running wild, having code execution be tracked using this as the ingress/egress you can allow and block things based on context and needs, you can setup policies and have them loaded on demand for a specific execution
koakuma-chan•53m ago
What the fuck is this slop?

https://github.com/theghostshinobi/Shibuya-waf-light-version...

Klonoar•45m ago
This is the most generic and uninspired name you could have possibly chosen.
FajitaNachos•26m ago
For the most busiest crossing in the world? I liked it. Have you been there?
Klonoar•11m ago
I lived in Japan for several years, yes.
q3k•38m ago
This makes me want to stop reading 'Show HN' threads.
wasting_time•22m ago
Why?
FajitaNachos•27m ago
I'm just here to say that I like the name.

UNIX99, a UNIX-like OS for the TI-99/4A

https://forums.atariage.com/topic/380883-unix99-a-unix-like-os-for-the-ti-994a/
68•marcodiego•1h ago•9 comments

The Age Verification Trap: Verifying age undermines everyone's data protection

https://spectrum.ieee.org/age-verification
958•oldnetguy•6h ago•772 comments

Americans are destroying Flock surveillance cameras

https://techcrunch.com/2026/02/23/americans-are-destroying-flock-surveillance-cameras/
232•mikece•2h ago•110 comments

Show HN: PgDog – Scale Postgres without changing the app

https://github.com/pgdogdev/pgdog
124•levkk•5h ago•33 comments

'Viking' was a job description, not a matter of heredity: Ancient DNA study

https://www.science.org/content/article/viking-was-job-description-not-matter-heredity-massive-an...
105•bookofjoe•2d ago•78 comments

SIM (YC X25) Is Hiring the Best Engineers in San Francisco

https://www.ycombinator.com/companies/sim/jobs/Rj8TVRM-software-engineer-platform
1•waleedlatif1•13m ago

Ladybird adopts Rust

https://ladybird.org/posts/adopting-rust/
914•adius•9h ago•499 comments

Elsevier shuts down its finance journal citation cartel

https://www.chrisbrunet.com/p/elsevier-shuts-down-its-finance-journal
467•qsi•12h ago•91 comments

Show HN: Sowbot – open-hardware agricultural robot (ROS2, RTK GPS)

https://sowbot.co.uk/
74•Sabrees•5h ago•30 comments

The Lighthouse: How extreme isolation transforms the body and mind

https://www.newscientist.com/article/2231732-the-lighthouse-how-extreme-isolation-transforms-the-...
42•nixass•3d ago•7 comments

A simple web we own

https://rsdoiel.github.io/blog/2026/02/21/a_simple_web_we_own.html
136•speckx•5h ago•86 comments

Magical Mushroom – Europe's first industrial-scale mycelium packaging producer

https://magicalmushroom.com/index
297•microflash•13h ago•103 comments

Binance fired employees who found $1.7B in crypto was sent to Iran

https://www.nytimes.com/2026/02/23/technology/binance-employees-iran-firings.html
174•boplicity•1h ago•88 comments

Sub-$200 Lidar could reshuffle auto sensor economics

https://spectrum.ieee.org/solid-state-lidar-microvision-adas
351•mhb•4d ago•465 comments

ASML unveils EUV light source advance that could yield 50% more chips by 2030

https://www.reuters.com/world/china/asml-unveils-euv-light-source-advance-that-could-yield-50-mor...
134•pieterr•3h ago•30 comments

0 A.D. Release 28: Boiorix

https://play0ad.com/new-release-0-a-d-release-28-boiorix/
308•jonbaer•4d ago•111 comments

Benchmarks for concurrent hash map implementations in Go

https://github.com/puzpuzpuz/go-concurrent-map-bench
57•platzhirsch•1d ago•2 comments

Generalized Sequential Probability Ratio Test for Families of Hypotheses [pdf]

https://sites.stat.columbia.edu/jcliu/paper/GSPRT_SQA3.pdf
14•luu•3d ago•3 comments

The peculiar case of Japanese web design (2022)

https://sabrinas.space
193•montenegrohugo•6h ago•85 comments

Show HN: Fostrom, an IoT Cloud Platform built for developers

https://fostrom.io/
8•arjunbajaj•3d ago•4 comments

Emulating Goto in Scheme with Continuations

https://terezi.pyrope.net/ccgoto/
34•usually•4d ago•13 comments

femtolisp: A lightweight, robust, scheme-like Lisp implementation

https://github.com/JeffBezanson/femtolisp
94•tosh•8h ago•14 comments

"Car Wash" test with 53 models

https://opper.ai/blog/car-wash-test
60•felix089•57m ago•55 comments

Decided to fly to the US to buy some hard drives

https://old.reddit.com/r/DataHoarder/comments/1rb9ot4/decided_to_fly_to_the_us_to_buy_some_hard_d...
76•HelloUsername•4h ago•36 comments

A lithium-ion breakthrough that could boost range and lower costs

https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/forget-solid-state-batteries-rese...
23•thelastgallon•2h ago•1 comments

Show HN: AI Timeline – 171 LLMs from Transformer (2017) to GPT-5.3 (2026)

https://llm-timeline.com/
102•ai_bot•12h ago•45 comments

SETI@home: Data Acquisition and Front-End Processing (2025)

https://iopscience.iop.org/article/10.3847/1538-3881/ade5a7
77•tosh•11h ago•18 comments

What it means that Ubuntu is using Rust

https://smallcultfollowing.com/babysteps/blog/2026/02/23/ubuntu-rustnation/
80•zdw•3h ago•101 comments

I built Timeframe, our family e-paper dashboard

https://hawksley.org/2026/02/17/timeframe.html
1480•saeedesmaili•1d ago•347 comments

What Is a Centipawn Advantage?

https://win-vector.com/2026/02/19/what-is-a-centipawn-advantage/
48•jmount•4d ago•20 comments