frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Shibuya – A High-Performance WAF in Rust with eBPF and ML Engine

https://ghostklan.com/shibuya.html
16•germainluperto•1h ago
Hi HN,

I’ve been working on Shibuya, a next-generation Web Application Firewall (WAF) built from the ground up in Rust.

I wanted to build a WAF that didn't just rely on legacy regex signatures but could understand intent and perform at line-rate using modern kernel features.

What makes Shibuya different:

Multi-Layer Pipeline: It integrates a high-performance proxy (built on Pingora) with rate limiting, bot detection, and threat intelligence.

eBPF Kernel Filtering: For volumetric attacks, Shibuya can drop malicious packets at the kernel level using XDP before they consume userspace resources.

Dual ML Engine: It uses an ONNX-based engine for anomaly detection and a Random Forest classifier to identify specific attack classes like SQLi, XSS, and RCE.

API & GraphQL Protection: Includes deep inspection for GraphQL (depth and complexity analysis) and OpenAPI schema validation.

WASM Extensibility: You can write and hot-load custom security logic using WebAssembly plugins.

Ashigaru Lab: The project includes a deliberately vulnerable lab environment with 6 different services and a "Red Team Bot" to test the WAF against 100+ simulated payloads.

The Dashboard: The dashboard is built with SvelteKit and offers real-time monitoring (ECharts), a "Panic Mode" for instant hardening, and a visual editor for the YAML configuration.

I'm looking for feedback on the architecture and the performance of the Rust-eBPF integration.

Comments

nullcathedral•35m ago
Feel free to correct me, but the ML classifier appears to be rather bare. Less than 20 hardcoded payloads with randomized URL encoding as the only augmentation. How does this generalize to novel evasion techniques? Genuinely curious what your eval numbers look like against real traffic.

https://github.com/theghostshinobi/Shibuya-waf-light-version...

koakuma-chan•10m ago
"The most advanced open-source WAF ever built."

Somehow, the moment I read this, I knew it was AI slop.

nullcathedral•7m ago
The website gave it away for me, felt very AI generated
reconnecting•16m ago
## Shibuya WORLD DOMINATION PLAN (1)

*Month 3*: Top 10 security OSS project su GitHub

*Month 6*: 10k+ stars, 1000+ prod deployments

*Month 9*: Conference talks (OWASP, DevSecOps Days, Black Hat Arsenal)

*Month 12*: Industry standard, "the modern WAF", competitors che copiano te

## MONETIZATION ROADMAP

*Week 12-16*: Free tier (self-hosted, community support)

- Goal: 1000 GitHub stars

- Goal: 100 production deployments

- Goal: Dev che parlano di te su Twitter

*Week 16-20*: Pro tier launch ($49-99/mo) - Managed rules auto-update

- ML models ottimizzati

- Priority support

- Advanced dashboard

- Goal: primi 50 paying customers ($5k MRR)

*Week 20-24*: Enterprise tier (custom pricing) - Multi-tenant

- SSO/SAML

- Compliance reports (PCI-DSS, SOC2)

- SLA + dedicated support

- Custom integrations

- Goal: primi 5 enterprise deals ($50k+ ARR)

*Month 6+*: Exit strategy - Seed funding ($1-2M) o bootstrap to profitability

- Series A ($10M+) se traction è pazzesca

- Acquisition offer da competitor? (Cloudflare che compra per killare? NO GRAZIE, fuck them )

1. The most interesting part here is a deleted commit: https://github.com/theghostshinobi/Shibuya-waf-light-version...

swah•10m ago
Speaking to LLMs looks fresh!
abusaidm•9m ago
They have a roadmap of where they want to be, I think that’s normal. As long as they don’t pull a fast one on the oss community then I think if this catch on and it’s worth it then even if they sell the community can fork if the new owners are not so welcoming.
reconnecting•6m ago
Looks like the Gemini as a full roadmap

## IL PIANO D'ATTACCO

*Episodi 1-3* (core tech): TU + GEMINI

*Episodi 4-9* (features sexy): TU + GEMINI + primi contributor OSS

*Episodi 10-12* (advanced): TU + small team (2-3 dev pagati)

*Episodi 13-18* (domination): Team + community

abusaidm•11m ago
This looks really interesting especially in the age of agents running wild, having code execution be tracked using this as the ingress/egress you can allow and block things based on context and needs, you can setup policies and have them loaded on demand for a specific execution
koakuma-chan•10m ago
What the fuck is this slop?

https://github.com/theghostshinobi/Shibuya-waf-light-version...

Klonoar•2m ago
This is the most generic and uninspired name you could have possibly chosen.

Show HN: PgDog – Scale Postgres without changing the app

https://github.com/pgdogdev/pgdog
109•levkk•4h ago•27 comments

Show HN: Sowbot – open-hardware agricultural robot (ROS2, RTK GPS)

https://sowbot.co.uk/
66•Sabrees•4h ago•24 comments

Show HN: Shibuya – A High-Performance WAF in Rust with eBPF and ML Engine

https://ghostklan.com/shibuya.html
16•germainluperto•1h ago•10 comments

Show HN: AI Timeline – 171 LLMs from Transformer (2017) to GPT-5.3 (2026)

https://llm-timeline.com/
93•ai_bot•11h ago•44 comments

Show HN: CIA World Factbook Archive (1990–2025), searchable and exportable

https://cia-factbook-archive.fly.dev/
449•MilkMp•23h ago•94 comments

Show HN: BVisor – An Embedded Bash Sandbox, 2ms Boot, Written in Zig

https://github.com/butter-dot-dev/bVisor
10•edunteman•2h ago•2 comments

Show HN: AgentDbg - local-first debugger for AI agents (timeline, loops, etc.)

https://github.com/AgentDbg/AgentDbg
3•z-a-f•2h ago•2 comments

Show HN: Unlock the best engineering knowledge in papers for your coding agent

https://code.paperlantern.ai
5•kalpitdixit•2h ago•19 comments

Show HN: What I've learned from shipping 25 mobile apps

https://newsletter.masilotti.com/p/what-ive-learned-from-shipping-25
3•joemasilotti•3h ago•0 comments

Show HN: Free ecommerce platform for link-in-bio people

https://stoar.page/
2•arajnoha•3h ago•2 comments

Show HN: A geometric analysis of Chopin's Prelude No. 4 using 3D topology

https://github.com/jimishol/cholidean-harmony-structure/blob/main/docs/03-case-study-chopin-prelu...
47•jimishol•3d ago•11 comments

Show HN: Mato – a Multi-Agent Terminal Office workspace (tmux-like)

https://github.com/mr-kelly/mato
3•chepy•4h ago•0 comments

Show HN: 3D Mahjong, Built in CSS

https://voxjong.com
120•rofko•1d ago•57 comments

Show HN: Agent Multiplexer – manage Claude Code via tmux

https://github.com/mixpeek/amux
2•Beefin•4h ago•0 comments

Show HN: TTSLab – A voice AI agent and TTS lab running in the browser via WebGPU

https://ttslab.dev
4•MbBrainz•4h ago•1 comments

Show HN: EloPhanto – A self-evolving AI agent that builds its own tools

https://github.com/elophanto/EloPhanto
2•elophanto_agent•5h ago•0 comments

Show HN: Self-hosted lightweight file sharing app. (folderhost)

https://github.com/MertJSX/folderhost
8•mertjsx•5h ago•0 comments

Show HN: I built an iOS app to WebRTC into my Mac terminal from the toilet

https://macky.dev
2•Sayuj01•5h ago•2 comments

Show HN: Local-First Linux MicroVMs for macOS

https://shuru.run
206•harshdoesdev•1d ago•61 comments

Show HN: Slipshow, a multi-paradigm presentation tool

https://slipshow.org
2•panglesd•6h ago•0 comments

Show HN: SkillScan – Free API to detect malicious AI agent skill files

https://skillscan.chitacloud.dev
3•AutoPilotAI•7h ago•0 comments

Show HN: Keep your eyes healthy with 20 20 20 rule reminder using bash

https://gist.github.com/kwkr/b6376b4ade4d14467334bc0dbb845a16
3•zukerpie•7h ago•0 comments

Show HN: Implementing ping from the Ethernet layer (ARP,IPv4,ICMP in user space)

https://github.com/v420v/ping
4•ibuki256•10h ago•1 comments

Show HN: Rendering 18,000 videos in real-time with Python

https://madebymohammed.com/pysaic
36•mbmproductions•1d ago•5 comments

Show HN: Agentic programming needs new processes

https://github.com/agereaude/cx/blob/main/CX.md
3•agereaude•7h ago•1 comments

Show HN: Llama 3.1 70B on a single RTX 3090 via NVMe-to-GPU bypassing the CPU

https://github.com/xaskasdf/ntransformer
384•xaskasdf•1d ago•100 comments

Show HN: Visual Tailwind CSS Style Guide – Single HTML file, no build step

https://winkelstraatnl.github.io/tailwind-style-guide/
3•tomdeleria•8h ago•0 comments

Show HN: TLA+ Workbench skill for coding agents (compat. with Vercel skills CLI)

https://github.com/younes-io/agent-skills/tree/main/skills/tlaplus-workbench
41•youio•1d ago•4 comments

Show HN: Monolith e-commerce platform for serverless

https://www.hoikka.dev/
2•zernobilly•8h ago•0 comments

Show HN: Iron-Wolf – Wolfenstein 3D source port in Rust

https://github.com/Ragnaroek/iron-wolf
86•ragnaroekX•2d ago•28 comments