Back to articles
Technology Insight

Optimizing nftables and IPSet on VPS: Defending Against Global Botnet Brute-Force Attacks

May 30, 2026

Introduction to the Modern Threat Landscape

In the contemporary cybersecurity ecosystem, Virtual Private Servers (VPS) are under constant siege. Among the most pervasive threats are automated brute-force attacks orchestrated by distributed botnets. Unlike traditional, single-source attacks, modern botnets leverage thousands of compromised IP addresses scattered across international boundaries. This geographical distribution allows them to bypass simple rate-limiting rules and overwhelm standard authentication mechanisms like SSH, FTP, and custom API endpoints.

For system administrators, mitigating these distributed assaults poses a significant technical challenge. Relying on legacy tools like iptables or basic application-layer firewalls can lead to severe performance degradation. Every incoming packet must be evaluated against a linear list of rules; as the list grows to encompass tens of thousands of banned botnet IPs, CPU consumption spikes, latency increases, and legitimate users experience service disruptions. To solve this, a highly optimized infrastructure layer approach is required: the synergy of nftables and IPSet.

The Architecture of High-Performance Filtering: nftables and IPSet

To understand why this combination is incredibly effective, we must look at the underlying architecture of Linux packet filtering. nftables is the modern successor to iptables, providing a much more efficient virtual machine-based execution environment inside the Linux kernel. It reduces duplication and streamlines how rules are evaluated.

However, when dealing with massive lists of international botnet ranges (which can easily exceed 100,000 discrete subnets), even nftables sets can benefit from optimization. This is where IPSet (or the native high-capacity set structures within nftables) becomes indispensable. Instead of checking packets linearly ($O(n)$ time complexity), an IPSet stores IP addresses and networks in highly optimized hashed data structures. This reduces the lookup time to a constant ($O(1)$ time complexity), regardless of whether the framework is matching against 10 IPs or 10,000,000 IPs.

Key Takeaway: By combining nftables with hashed sets, your VPS can process millions of malicious packets at the kernel level before they ever reach the application layer, consuming virtually zero CPU overhead.

Step-by-Step Implementation Guide

Let us walk through a robust, production-grade implementation designed to block known international botnet IP ranges while dynamically catching and banning active brute-force attackers.

Step 1: Installing Dependencies and Enabling nftables

First, ensure your Linux system is updated and that the legacy iptables framework is replaced by nftables. Execute the following commands on your Debian/Ubuntu or RHEL-based system:

# Update package lists and install nftables
sudo apt update && sudo apt install -y nftables curl ipset

# Enable and start the nftables service
sudo systemctl enable nftables
sudo systemctl start nftables

Step 2: Designing the nftables Base Configuration

We need to establish a clean configuration file that defines our input, forward, and output chains. We will utilize native nftables sets, which mimic the functionality of IPSet with deep integration into the nftables syntax. Edit your /etc/nftables.conf file to establish the core framework:

#!/usr/sbin/nft -f

flush ruleset

table inet filter {
    # Define high-capacity sets for automated blocking
    set botnet_blacklist {
        type ipv4_addr
        flags interval
    }

    set dynamic_bans {
        type ipv4_addr
        size 65535
        flags timeout
        timeout 24h
    }

    chain input {
        type filter hook input priority 0; policy drop;

        # Allow established and related traffic
        ct state established,related accept

        # Allow loopback interface
        iifname "lo" accept

        # Drop packets from the hardcoded international botnet blacklist
        ip saddr @botnet_blacklist drop

        # Drop packets from dynamically banned brute-force IPs
        ip saddr @dynamic_bans drop

        # Allow essential services (e.g., HTTP, HTTPS)
        tcp dport { 80, 443 } accept

        # Protect SSH with dynamic rate-limiting
        tcp dport 22 meter ssh_meter { ip saddr ct count over 5 } add @dynamic_bans { ip saddr } drop
        tcp dport 22 accept
    }
}

Step 3: Integrating International Botnet Intelligence Feeds

Static rules are insufficient against evolving threats. To stop international botnets proactively, we must inject verified, aggregated lists of known malicious subnets (such as those provided by Spamhaus, FireHOL, or local cyber command feeds) directly into our nftables set. Below is an automated bash script to fetch, parse, and load these blocks efficiently:

#!/bin/bash
# /usr/local/bin/update-botnet-list.sh

FEED_URL="[https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset](https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset)"
TMP_FILE="/tmp/botnet.txt"

# Fetch the latest intelligence feed
curl -s "$FEED_URL" | grep -E '^([0-9]{1,3}\.){3}[0-9]{1,3}' > "$TMP_FILE"

# Flush the existing static blacklist set safely
nft flush set inet filter botnet_blacklist

# Populate the set efficiently using atomic batching
( 
  echo "add element inet filter botnet_blacklist {"
  awk '{print $1 ","}' "$TMP_FILE" | sed '$ s/,$//'
  echo "}"
) | nft -f -

rm -f "/tmp/botnet.txt"
echo "Botnet blacklist successfully updated!"

Make this script executable and configure a cron job to run it daily, ensuring your defense architecture remains aligned with emerging international threats:

sudo chmod +x /usr/local/bin/update-botnet-list.sh
(crontab -l 2>/dev/null; echo "0 2 * * * /usr/local/bin/update-botnet-list.sh") | crontab -

Performance Comparison: Legacy vs. Optimized Filtering

To justify the migration to this architecture, consider the empirical performance differences encountered under heavy distributed denial-of-service (DDoS) or brute-force conditions:

  • Traditional iptables (Linear Lookup): As rules increase to 50,000 entries, the kernel spends substantial CPU cycles traversing every row per packet. CPU utilization can easily hit 100%, cascading into packet loss for legitimate traffic.
  • Optimized nftables + Hashed Sets ($O(1)$ Lookup): Regardless of whether the set contains 50,000 or 500,000 entries, the hash function locates the IP instantly. CPU utilization remains flat (typically under 5%), guaranteeing application uptime.

Best Practices for VPS Firewall Management

To maximize the long-term efficacy of your newly optimized firewall configuration, always adhere to the following enterprise-grade operating protocols:

  1. Implement Whitelisting First: Always declare trusted management IPs (such as your corporate VPN or static home IP) in a high-priority whitelist set to mitigate the risk of accidental self-lockouts during automated bans.
  2. Monitor Set Saturation: Keep track of the size of your dynamic bans set using the command nft list set inet filter dynamic_bans to ensure memory limits allocated to the Linux kernel network stack are not breached.
  3. Persist Configuration Across Reboots: Ensure your ruleset changes are written permanently to disk so they survive unexpected service restarts or hardware reboots via nft list ruleset > /etc/nftables.conf.

Conclusion

Mitigating sophisticated, international brute-force botnets does not require expensive, proprietary hardware appliances. By exploiting the architectural advantages of nftables combined with high-capacity hashed data sets, you can convert any standard Linux VPS into an unyielding fortress. This proactive layer of kernel security ensures malicious traffic is dropped seamlessly, preserving critical compute resources for your core applications and legitimate global users.

Optimizing nftables and IPSet on VPS: Defending Against Global Botnet Brute-Force Attacks | DPTCloud