Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Shibuya

A High-Performance WAF in Rust with eBPF and ML Engine

Details

External ID
47126656
Source
HN
Company
—
Product
Shibuya
Website domain
ghostklan.com
Launched
Feb. 23, 2026
Cohort
—
Upvotes
22
Upvotes percentile
0.704177897574124
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN,I’ve been working on Shibuya, a next-generation Web Application Firewall (WAF) built from the ground up in Rust.I wanted to build a WAF that didn't just rely on legacy regex signatures but could understand intent and perform at line-rate using modern kernel features.What makes Shibuya different:Multi-Layer Pipeline: It integrates a high-performance proxy (built on Pingora) with rate limiting, bot detection, and threat intelligence.eBPF Kernel Filtering: For volumetric attacks, Shibuya can drop malicious packets at the kernel level using XDP before they consume userspace resources.Dual ML Engine: It uses an ONNX-based engine for anomaly detection and a Random Forest classifier to identify specific attack classes like SQLi, XSS, and RCE.API & GraphQL Protection: Includes deep inspection for GraphQL (depth and complexity analysis) and OpenAPI schema validation.WASM Extensibility: You can write and hot-load custom security logic using WebAssembly plugins.Ashigaru Lab: The project includes a deliberately vulnerable lab environment with 6 different services and a "Red Team Bot" to test the WAF against 100+ simulated payloads.The Dashboard: The dashboard is built with SvelteKit and offers real-time monitoring (ECharts), a "Panic Mode" for instant hardening, and a visual editor for the YAML configuration.I'm looking for feedback on the architecture and the performance of the Rust-eBPF integration.

Enrichment

Theme
lightweight and on-device AI runtimes
Vertical
Security
Function
Dev tools
Audience
B2B
AI stance
AI feature
Project type
Commercial product
Normalized one-liner
web application firewall in rust with ml
Manually corrected
False

Could you build this?

No Writing a line-rate Web Application Firewall leveraging eBPF in the Linux kernel alongside custom machine learning inference engines requires deep systems, networking, and low-level kernel expertise.

What it would actually take: A production implementation demands writing low-level XDP/eBPF programs in C/Rust attached to kernel network hooks, user-space ring buffers, OWASP Core Rule Set parsing, and ultra-low-latency ML inference (e.g., ONNX runtime or custom C/Rust tensor engines) operating in sub-millisecond budgets. It requires seasoned systems programmers with deep expertise in Linux kernel internals, network packet processing, and memory safety.

Discussion

18 comments analyzed.

Competitors mentioned: Cloudflare (free plan and enterprise), Other open-source WAF projects

Concerns raised: ML classifier too basic with only ~20 hardcoded payloads, unclear generalization to novel evasion, Lacks evaluation numbers against real traffic, Overly ambitious monetization roadmap seems unrealistic, AI-generated marketing copy and website, Unclear differentiation from existing solutions

Feature requests: Code execution tracking with context-aware allow/block policies, On-demand policy loading for specific execution contexts

Competitors

Other products that read as similar to this one — 90 launches clear the similarity bar, closest 8 shown.

Attention rank: #31 of 91 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 104 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.