Can libp2p punch through NATs?
How efficient is libp2p’s DCUtR protocol in connecting actual peers directly?
We approach security from the point of view of the DHT's Keyspace Density.
The following plots examine the peer distribution within the keyspace, aiding in the identification of potential Sybil and eclipse attacks.
In Kademlia, every object indexed by the DHT requires a binary identifier. In the libp2p DHT implementation, peers are identified by the digest of `sha256(peer_id)` and CIDs are identified by the digest of `sha256(cid)`. This Kademlia identifier determines the location of an object within the Kademlia XOR keyspace.
The plot shows how many peers are included in a particular region of the keyspace. Too many peers within one region indicate a potential issue.
The plot shows the distribution of the PeerIDs across the Poisson curve. Too many PeerIDs outside the curve indicate a potential issue.
Although not directly a security metric, very high node churn can affect the performance of a DHT-based network. For instance, Provider Records might become unavailable faster than republication of those records, if the nodes responsible to hold them go offline. In turn, this will result in some keys not being available in the network.
CDF of Peer Departure Times
Blog posts, papers and talks by the ProbeLab team about IPFS.
How efficient is libp2p’s DCUtR protocol in connecting actual peers directly?
The promise of decentralized peer-to-peer (P2P) systems is fundamentally gated by the challenge of Network Address Translation (NAT) traversal, with existing solutions often reintroducing the …
How a statistical approach cut IPFS content publishing times by over one order of magnitude.
The ProbeLab team has been busy building new IPFS Gateway performance measurements
What we've achieved in 2025 and what we're targeting in 2026
The Internet's transformation from a decentralized network of networks into a landscape dominated by centralized platforms has created systemic risks including infrastructure fragility, censorship vulnerabilities, …